The company is taking three steps to detect malware and prevent intrusion into the internal system. These steps include keeping the system up-to-date, using right anti-virus software, and running cross-checking of the system periodically. The company also uses Windows operating system on all its computers with automatic updates for security patches. In addition, periodic cross-checks will be done to ensure the entire system is secure. Other risks identified include brute force login, flood at primary facility, disk error, and unreadable display. To mitigate these risks, information security controls from ISO 27002 (2005) will be implemented. These controls include training employees on information security awareness, implementing account lockout policy to prevent brute force login, transferring data centre location to the top floor to prevent flood damage, having instant copies of files at different locations to prevent disk error, and upgrading physical system to reduce human-led mistakes.