Why this matters

How genetic assets can be acquired, exposed, inferred from, altered, disrupted, or lost, and where controls can interrupt those pathways. Evaluate the particular asset, access pathway, affected parties, and evidence before assigning a risk classification. These are analytical controls to consider, not a claim that every organization faces the same exposure.

Acquisition

Collection of discarded material can happen before the person understands that a genetic analysis is possible.

Kinship and inference

A match can produce leads about relatives. Analytical outputs need uncertainty, population context, and confirmation.

Surveillance and breaches

Account security and permissions matter at the network level when one account exposes connected profiles.

Integrity and ransomware

Protect sample identity and workflow outputs as well as confidentiality. Recovery must restore trustworthy data, not merely readable files.

Supply chain

Dependencies, remote access, and reference inputs belong inside the threat model.

Separate a possibility from an observed event

A threat describes something that could go wrong. An incident describes something that happened. Between the two sits evidence: who had access, which assets were reachable, what action occurred, and what consequences can be supported. A plausible attack path is useful for prevention even when no attack has been observed.

Consider a hypothetical laboratory that allows a maintenance account to reach both an instrument and shared storage. That connection raises a question about access boundaries. It does not establish that the account has been stolen or the storage compromised. The next step is to inspect permissions, authentication, and activity records, then decide whether the path can be reduced.

Describe the path in ordinary language

A useful threat description names an actor, an entry point, an asset, and a consequence. For example: someone with an exposed account credential can view connected family profiles, which may reveal relationships beyond the account owner. This is more actionable than saying “DNA is vulnerable.” It points directly to authentication, sharing permissions, and the amount of information returned through an account.

Match the response to the failure

Encryption can help with unauthorized reading, but it does not establish whether the right sample was labeled or whether a secondary use was permitted. Backups can help restore availability, but restoring the wrong version of a reference dataset may preserve an error. Consent controls can govern legitimate use without stopping an intruder.

For that reason, each threat review should end with a specific control and a way to check it. Ask what evidence would show that the control works, who maintains it, and what remains exposed if it fails. A long list of controls without those answers can create confidence without reducing uncertainty.

Core definitions

Reference framework

Cornerstone reading

Evidence and classification methodology

Case families