I think that the far right side of the OSC&R matrix needs to be beefed up to help the customer connect how all the things to the left in OSC&R were connected which culminated in something bad happening to their company or resources in the Impact column.
Said a different way, if OSC&R is an end-to-end lifecycle of how an attack starts, evolves, and finally delivers value for an attacker we need to expand on what that final "value" is for the criminal.
To this end, I suggest that we create two new items in the last column of OSC&R:
- Proprietary data stolen
- Customers compromised