Controls library

Every missing control, in one place

Every case on this site ends with the one control that would have stopped it or cut it short. Here they all are, grouped by type. Start with the group that sounds most like your business.

Identity and accessVendors and third partiesPatching and monitoringPayments and fraudInsider riskBackups and recovery
Close the same gap

Check which of these you have

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Identity and access

Logins, two-step verification, and who can reset them. Read the guide: Employee offboarding checklist: how to cut off a former employee's access the same day Read the guide: How to verify callers before password resets, and protect your phone number from SIM swaps Read the guide: Which two-step login actually stops phishing, and how a small office rolls it out

No SMS account recovery
SEC 2024
Multifactor authentication on all remote access
COLONIAL PIPELINE 2021
Strict limits on internal admin tools
TWITTER 2020
Mandatory default password change
MIRAI 2016
Independent custody of signing keys
RONIN 2022
Phishing-resistant MFA, not push approvals
UBER 2022
Verify callers before help desk resets
MGM 2023
Keep critical keys off personal devices
LASTPASS 2022
MFA on every remote portal
CHANGE HEALTHCARE 2024
Mandatory two-step login for all accounts
23ANDME 2023
Enforced MFA and credential rotation
SNOWFLAKE 2024
Block personal browser profiles at work
OKTA 2023
Phishing-resistant MFA like hardware keys
RETOOL 2023
Verify new hires' identity and location
LAPTOP FARM 2023
Revoke cloud access at offboarding
CISCO WEBEX 2018
Phishing-resistant hardware security keys
TWILIO 2022
Two-factor login on remote access
UKRAINE GRID 2015
Access control on sensitive databases
VASTAAMO 2020
Verify identity before issuing MFA tokens
EA 2021
No secret keys in code
UBER 2016
Phishing-resistant multi-factor authentication
ICLOUD PHISHING 2014
Device-bound sessions for vendor staff
DMM BITCOIN 2024
Enforced two-factor for remote access
OPM 2015
Force new unique passwords plus MFA
ASTROS HACK 2013
Rotate and validate login signing keys
STORM-0558 2023
MFA on every account, even test
MICROSOFT 2024
Two-factor login on social accounts
AP TWEET 2013
Verify caller identity before sharing
MOTOROLA 1992
MFA on remote VPN access
MEDIBANK 2022
No plaintext password files on shares
SONY PICTURES 2014
MFA on remote access
ASHLEY MADISON 2015
Verify identity before credential resets
CLOROX 2023
Non-SMS MFA and carrier port locks
SIM SWAP 2018
Consistent identity checks across support
ICLOUD WIPE 2012
Isolate authentication secrets from corporate network
RSA SECURID 2011
Unique credentials for remote access
OLDSMAR 2021
MFA on the cloud admin console
CODE SPACES 2014
Change default passwords before deployment
ZOMBIE ALERT 2013
MFA on all third-party remote access
BRITISH LIBRARY 2023
Separate power to change withdrawal signers
POLY NETWORK 2021
No SMS codes guarding exchange funds
FTX DRAIN 2022
MFA for admins and disciplined patching
NORSK HYDRO 2019

Vendors and third parties

Contractors, IT providers and suppliers with a key to your systems. Read the guide: How to manage vendor, IT provider and contractor access to your systems

Vendor access segmented from payment systems
TARGET 2013
Integrity checks on the build pipeline
SOLARWINDS 2020
Security due diligence before acquisition
MARRIOTT 2018
Independently verify what signers approve
BYBIT 2025
Monitor vendor privileged credential use
C&M SOFTWARE 2025
Help desk identity verification
CAESARS 2023
Vendor controls on prepaid card limits
ATM HEIST 2013
Verify employers and vendors independently
FAKE SECURITY FIRM
Vendor remote access risk assessment
KASEYA 2021
Vet who owns and services ATMs
RIVIERA MAYA 2020
Third-party help desk caller verification
M&S 2025
Written scope approved by all owners
IOWA COURTHOUSE 2019

Patching and monitoring

Known holes left open and alarms nobody answered. Read the guide: How a small business keeps software and devices patched, and why default passwords must go

Timely patching and verified monitoring
EQUIFAX 2017
Continuous review of cloud configurations
CAPITAL ONE 2019
Verified, controlled code deployment
KNIGHT CAPITAL 2012
Patch critical flaws within days
WANNACRY 2017
Encrypt card data in transit internally
HEARTLAND 2008
Act on security alerts promptly
IRISH HSE 2021
Complete inventory of connected devices
NASA JPL 2018
Strong wireless encryption and segmentation
TJX 2007
Lock down forgotten development servers
SANDS CASINO 2014
Escalate and disclose breaches promptly
YAHOO 2014
Purge data from file-transfer servers
MOVEIT 2023
Authenticate commands sent to field devices
DALLAS SIRENS 2017
Isolate infotainment from vehicle controls
JEEP 2015
Remediate prior security audit findings
ATLANTA 2018
Audit and monitor account usage logs
BERKELEY HACK 1986
Segment IoT devices from core network
CASINO FISH TANK
Test upgrade defaults before deployment
NOMAD BRIDGE 2022
Retire deprecated verification code before launch
WORMHOLE 2022
Reconcile wallets against the ledger daily
MT GOX 2014
Patch internet-facing VPNs within days
TRAVELEX 2020

Payments and fraud

Fake invoices, fake bosses and money that moved without a second check. Read the guide: How to stop fake invoices, changed bank details and fake-boss payment requests

Independent verification of outgoing payment orders
BANGLADESH BANK 2016
Verify payment changes with known supplier
FAKE INVOICES 2013
Verify payment requests out of band
ARUP 2024
Callback verification before urgent payments
VOICE DEEPFAKE 2019
Independent second approval on withdrawals
BITFINEX 2016
Call back on a known number
FAKE SUPPORT 2024
Reconcile SWIFT messages with core banking
PNB 2018
Balance checks on every withdrawal
SILK ROAD 2012
Verify payee identity before sending funds
HUSHPUPPI 2020
Out-of-band verification of large transfers
CITIBANK 1994
Dual approval for large wires
FACC 2016
MFA on executive email accounts
UNATRAC 2018
Callback verification for wire requests
UBIQUITI 2015
Verify the asset actually exists
ONECOIN 2017

Insider risk

Trusted people with too much access and nobody watching.

Segregation of duties
LOTTERY 2010
Monitor privileged insider access
UBIQUITI 2020
Least-privilege limits on support data
COINBASE 2025
Separate trading from trade settlement
BARINGS 1995
Role-based access to user data
TWITTER 2015
Insider bribe reporting channel
TESLA 2020
Identity proofing during remote hiring
KNOWBE4 2024
Independent confirmation of every trade
SOCGEN 2008
Disable access at termination time
CREDIT UNION 2021
No single-person admin control
SAN FRANCISCO 2008
Need-to-know access with monitoring
DISCORD LEAKS 2023
Monitor privileged support staff actions
AT&T UNLOCKS 2017
Cut ex-contractor access; authenticate commands
MAROOCHY 2000
Rotate shared credentials at offboarding
FORMER EMPLOYEE 2016
Independent audits of client asset custody
QUADRIGA 2018
Monitor downloads by departing staff
WAYMO SECRETS 2016
Revoke every external account at offboarding
LEDGER 2023

Backups and recovery

What decides whether an attack is a bad week or the end of the business. Read the guide: Backups that survive ransomware: offline copies, tested restores and a one-page plan

Offline backup of login servers
NOTPETYA 2017