Oyoon Altaqnya for Information Technology & Cybersecurity
Cybersecurity self-assessment report
- Prepared for
- Company
- Sector
- Date
- Framework
- NIST Cybersecurity Framework (CSF) 2.0
Overall score
out of 100
Maturity level
Score by function
- Govern / 100
- Identify / 100
- Protect / 100
- Detect / 100
- Respond / 100
- Recover / 100
Key findings
Priority actions
The gaps to close first, starting with the controls that stop the most common attacks. For each one: the risk, what you can do and why we recommend it.
Your answers describe comprehensive, tested controls in every area. Keep validating them independently.
-
GV.RM Govern
Cyber risk strategy
- Your answer
- The risk
- Without a strategy and an agreed risk appetite, security spending follows the latest incident or audit finding rather than the risks that matter most, and management cannot tell whether the organization is protected enough.
- What you can do
-
- Agree with management which services and data matter most and how much cyber risk the organization is willing to accept.
- Write a short cybersecurity strategy with a few clear objectives, owners and a two- to three-year roadmap.
- Record cyber risks in the enterprise risk register and review them alongside other business risks.
- Why we recommend this
- A strategy turns security from a list of purchases into a plan that management can approve, fund and measure. We recommend linking it to enterprise risk management because that is where decisions on budgets and priorities are already made.
- How we can help
-
GV.RR Govern
Roles and accountability
- Your answer
- The risk
- When no one is clearly accountable, decisions on risk are delayed or never taken, security tasks fall between IT and the business, and incidents are handled without the authority to act quickly.
- What you can do
-
- Name one security leader who is accountable for cybersecurity and has direct access to senior management.
- Document security responsibilities across IT, risk, compliance and the business, for example in a RACI matrix.
- Give the security function a budget tied to its strategy, and review it every year.
- Why we recommend this
- Clear accountability is the condition for every other improvement: someone has to own the plan, report on it and escalate risks. Giving the security leader a line to senior management, separate from day-to-day IT operations, also reduces the conflict between keeping systems running and keeping them secure.
- How we can help
-
GV.PO Govern
Security policies
- Your answer
- The risk
- Without approved policies, staff and suppliers have no clear rules to follow, controls are applied inconsistently, and the organization has little basis for holding anyone to account or for satisfying auditors and regulators.
- What you can do
-
- Approve a concise policy set covering acceptable use, access control, data protection, incident management and suppliers.
- Communicate the policies to every employee and contractor, and record their acknowledgment.
- Review the policies at least once a year, and check compliance through spot checks or internal audit.
- Why we recommend this
- Policies put management’s expectations in writing, which is the first thing auditors, regulators and frameworks such as ISO/IEC 27001 look for. We recommend a short policy set that is enforced over a long one that nobody reads.
- How we can help
-
GV.RM Govern
Governance, risk and compliance tooling
- Your answer
- The risk
- When risks, policies and evidence live in scattered files, owners change without handover, reviews are missed and every audit becomes a search for documents. Management gets an out-of-date picture of where the organization stands.
- What you can do
-
- List the registers you maintain today: risks, policies, controls, audits and suppliers.
- Give each item an owner, a review date and a status in one shared place.
- Reuse evidence across frameworks such as ISO/IEC 27001 and NIST CSF 2.0 instead of collecting it again for each audit.
- Evaluate a GRC platform once your processes are stable enough to configure.
- Why we recommend this
- A single system of record keeps accountability visible and turns audits into a routine instead of a project. We recommend defining the processes first and choosing a platform second, because a tool cannot fix a process that nobody owns.
- How we can help
-
GV.OV Govern
Management oversight
- Your answer
- The risk
- If management sees cybersecurity only after an incident, risks are accepted by default rather than by decision, and improvement work loses funding and priority.
- What you can do
-
- Agree a handful of measures that show your security position, such as MFA coverage, critical patch status and open high-risk findings.
- Report them to senior management at least every quarter, together with the top risks and the progress of improvement work.
- Record the decisions taken, and follow them up at the next review.
- Why we recommend this
- Regular oversight turns risk acceptance into a management decision and gives the security team the mandate and budget to act. Frameworks such as NIST CSF 2.0 and ISO/IEC 27001 expect evidence that management directs and reviews cybersecurity.
- How we can help
-
GV.SC Govern
Supplier and third-party risk
- Your answer
- The risk
- Suppliers with remote access or with your data can become the way in. An attacker who compromises a supplier, or a supplier with weak security, can reach your systems through trusted access that is rarely monitored.
- What you can do
-
- List every supplier with access to your systems, networks or data, and rank them by risk.
- Add security requirements, a right to assess and a duty to report incidents to their contracts.
- Reassess critical suppliers regularly, and review and remove their access when it is no longer needed.
- Why we recommend this
- Supplier access is often broad, permanent and unmonitored, so it can undo the controls you apply to your own staff. A risk-based approach focuses your effort on the few suppliers that could cause the most harm.
- How we can help
-
ID.AM Identify Critical control
Asset inventory
- Your answer
- The risk
- Systems you don’t know about are not patched, monitored or backed up. Forgotten servers, unmanaged devices and unknown cloud services are a common way in for attackers.
- What you can do
-
- Combine data from your directory, endpoint management, network scans and cloud accounts into one inventory.
- Record an owner and a criticality rating for every system, application and important data set.
- Automate discovery, including of internet-facing assets, so new or unknown assets are found and reviewed quickly.
- Why we recommend this
- Every other control depends on knowing what you have: you can’t protect, patch or monitor what isn’t on the list. We recommend automated discovery because manual lists quickly go out of date.
-
ID.AM Identify
Laptop, desktop and mobile device management
- Your answer
- The risk
- Unmanaged devices miss updates, hold company data with no protection and cannot be locked or wiped if lost. Attackers look for the weakest device that can still reach email and files.
- What you can do
-
- List every type of device that reaches company data, including personal phones and tablets.
- Enroll them in a management platform that applies security settings, updates and applications automatically.
- Separate work data from personal data on staff-owned devices, and enable remote lock and wipe.
- Why we recommend this
- You cannot enforce a security baseline on devices you do not manage. Unified endpoint management and mobile device management give you one place to apply settings and to act when a device is lost, instead of relying on each user.
- How we can help
-
ID.AM Identify
Security tool coverage
- Your answer
- The risk
- Each security tool sees only part of the estate, and no two asset lists agree. Systems without endpoint protection or logging, or with no owner, stay invisible until an attacker or an auditor finds them.
- What you can do
-
- Choose the controls every asset must have, for example endpoint protection, patching and log collection.
- Combine the asset lists from your directory, endpoint, cloud, vulnerability and network tools into one view.
- Report assets that miss a control or have no owner, and track each gap to closure.
- Why we recommend this
- Owning a tool is not the same as having coverage. Comparing your tools against each other shows where protection is missing without buying anything new, so you can close the gaps in priority order.
-
ID.RA Identify
Internet-facing exposure
- Your answer
- The risk
- Attackers start by listing what you expose. Forgotten test servers, open administration pages and expired certificates are easy to find from outside and are often missed from inside.
- What you can do
-
- Start from your domains and address ranges, and discover what is actually reachable from the internet.
- Compare the result with your asset list, and assign an owner to every unknown or forgotten system.
- Monitor continuously, and review new exposures every month.
- Why we recommend this
- Seeing your organization as an outsider does shows risks that internal tools miss. Continuous discovery catches new exposures as they appear, before an attacker does.
- How we can help
-
ID.RA Identify
Risk assessment
- Your answer
- The risk
- Without a structured risk assessment, security effort is spread evenly or driven by vendors and headlines, while the threats most likely to harm your critical services may go unaddressed.
- What you can do
-
- Assess the risks to your critical services, considering realistic threats, their likelihood and their business impact.
- Record each risk in a register with an owner, a treatment decision and a target date.
- Repeat the assessment at least yearly and after major changes, such as new systems, services or suppliers.
- Why we recommend this
- A risk assessment tells you where to spend first and gives management a defensible basis for accepting or treating each risk. It is also a core requirement of ISO/IEC 27001.
- How we can help
-
ID.RA Identify
Threat intelligence
- Your answer
- The risk
- Without threat intelligence, you learn about campaigns against your sector, leaked staff credentials or fake websites using your name only after they have been used against you or your customers.
- What you can do
-
- Define what you need to know: the threats, fraud types and assets that matter most to your organization.
- Follow national and sector sources, such as CERT advisories and industry groups, and make someone responsible for reviewing them.
- Monitor for leaked credentials, look-alike domains and fake social media accounts, and act on what you find.
- Why we recommend this
- Intelligence tells you which threats are likely, so you can prioritize defenses and detection rules instead of reacting to everything. Monitoring for leaks and brand abuse also protects your customers from fraud that happens outside your network.
- How we can help
-
ID.RA Identify Critical control
Vulnerability management
- Your answer
- The risk
- Unpatched vulnerabilities, especially on internet-facing systems, are one of the most common ways attackers get in, and known flaws are often exploited soon after they are published.
- What you can do
-
- Scan all systems regularly, starting with internet-facing services, and include cloud assets.
- Set fix deadlines by severity and exposure, with the shortest deadlines for critical flaws on internet-facing systems.
- Track every finding to closure, and report overdue fixes to management.
- Why we recommend this
- Vulnerability management closes known doors before attackers use them, which makes it one of the most cost-effective controls. We recommend prioritizing by real exposure and exploitability, not by severity score alone, so your teams fix what matters first.
-
ID.RA Identify
Cloud infrastructure posture
- Your answer
- The risk
- Cloud resources are created in minutes and are reachable from anywhere. A public storage bucket, an account with too many permissions or a container with a known flaw can expose data before anyone notices.
- What you can do
-
- List every cloud account and subscription, and who is responsible for each.
- Check configuration against a baseline such as the CIS Benchmarks, and fix public exposure and excessive permissions first.
- Scan workloads, containers and infrastructure code, and send findings to the team that owns the resource.
- Why we recommend this
- Cloud risk changes daily, so a one-time review goes out of date quickly. A cloud-native protection platform keeps checking and ranks findings by real exposure, so teams fix what matters first.
-
ID.IM Identify
Independent security testing
- Your answer
- The risk
- Controls that have never been tested may not work as intended. Without independent testing, weaknesses in configurations, applications and processes stay hidden until an attacker finds them.
- What you can do
-
- Commission an independent penetration test of your internet-facing systems and critical applications.
- Repeat it at least yearly and after major changes, and retest every fix.
- Feed the findings into your risk register and security roadmap.
- Why we recommend this
- Independent testing shows how an attacker would actually get in and whether your controls stop them. It also gives management and regulators objective evidence that a self-assessment cannot provide.
- How we can help
-
PR.AA Protect
Identity and access management
- Your answer
- The risk
- Accounts that keep their rights after people change roles or leave are easy targets. When access is granted informally, nobody can show who can reach what, and an attacker who steals one account inherits all of its rights.
- What you can do
-
- Define roles and the access each role needs, and base access requests on them.
- Run joiner, mover and leaver steps so access changes the day a role changes, and disable accounts as soon as people leave.
- Review who has access to critical systems at least twice a year, with the business owner signing off.
- Introduce single sign-on so users and administrators manage fewer separate accounts.
- Why we recommend this
- Controlling the identity lifecycle removes the forgotten access that attackers rely on, and gives auditors a record of who approved what. Single sign-on reduces password reuse and makes access easier to withdraw.
- How we can help
-
PR.AA Protect Critical control
Multi-factor authentication
- Your answer
- The risk
- With passwords alone, one phished, guessed or reused password is enough to access email, remote access or cloud services. Stolen credentials are one of the most common ways attackers get in.
- What you can do
-
- Enforce MFA first on email, remote access, cloud services and every administrator account.
- Extend it to all users, and remove exceptions and legacy sign-in methods that bypass it.
- Move administrators and other high-risk users to phishing-resistant methods, such as FIDO2 security keys or passkeys.
- Why we recommend this
- MFA means a stolen password is no longer enough on its own, which closes one of the most common attack paths for a modest cost. We recommend managing it centrally, with conditional access, so the same rules apply to every application and exceptions are visible.
- How we can help
-
PR.AA Protect Critical control
Privileged access
- Your answer
- The risk
- Administrator accounts give full control of your systems. If one is compromised, an attacker can disable security, steal data or deploy ransomware across the organization, and shared accounts make their actions impossible to trace.
- What you can do
-
- Reduce administrator accounts to the minimum, and separate them from everyday user accounts.
- Keep privileged passwords in a vault, rotate them, and protect privileged access with MFA.
- Grant administrator rights only when needed, record privileged sessions, and review privileged accounts every quarter.
- Why we recommend this
- Ransomware and data theft usually depend on gaining administrator rights, so controlling those rights limits the damage of any intrusion. A privileged access management (PAM) platform enforces this consistently and gives auditors a record of every privileged action.
- How we can help
-
PR.AT Protect
Security awareness
- Your answer
- The risk
- Phishing and social engineering target people rather than systems. Untrained staff are more likely to click a malicious link, give away a password or approve a fraudulent payment, and less likely to report it quickly.
- What you can do
-
- Run short, regular awareness training, tailored to roles such as finance, IT and executives.
- Run phishing simulations, and use the results to target further training rather than to blame individuals.
- Give every user a simple way to report suspicious messages, and acknowledge the reports.
- Why we recommend this
- No technology stops every deceptive message, so staff who recognize and report attacks become an extra layer of detection. Measuring reporting rates over time shows management whether the program is working.
- How we can help
-
PR.PS Protect Critical control
Email security
- Your answer
- The risk
- Email is one of the most common ways attacks begin: phishing steals credentials, attachments deliver malware and ransomware, and fake messages from executives or suppliers lead to fraudulent payments. Without DMARC, criminals can also send email that appears to come from your domain.
- What you can do
-
- Enable advanced filtering that analyzes links and attachments, including after delivery.
- Publish SPF and DKIM for every domain you send from, then move DMARC to enforcement in stages.
- Add a report-phishing button, and a process to remove malicious emails from every mailbox quickly.
- Why we recommend this
- Stopping malicious email before it reaches people removes the starting point of many attacks, and DMARC protects your customers and partners from emails that impersonate you. We recommend combining email protection with awareness training, because neither is enough on its own.
- How we can help
-
PR.DS Protect
Data protection
- Your answer
- The risk
- If you don’t know where sensitive data is or who can access it, it can be copied, leaked or encrypted by ransomware without anyone noticing. Data breaches bring regulatory, legal and reputational consequences that last long after the incident.
- What you can do
-
- Identify and classify sensitive data, such as customer, financial and personal data, and record where it is stored.
- Encrypt sensitive data at rest and in transit, and keep the keys in a managed key store or a hardware security module (HSM).
- Limit access to those who need it, and monitor or block unusual copying and transfers with data loss prevention (DLP).
- Why we recommend this
- Protecting the data itself, not only the systems around it, means that a breach of one system does not automatically expose your most valuable information. Classification comes first because it tells you which data needs the strongest controls, so you don’t pay to protect everything at the same level.
- How we can help
-
PR.DS Protect
Encryption and key management
- Your answer
- The risk
- Unencrypted data is readable by anyone who copies it, and keys left in files or shared between teams make strong encryption weak. If a key is lost without a backup, the data it protects is lost too.
- What you can do
-
- Encrypt sensitive data at rest and in transit, starting with databases, laptops, backups and remote access.
- Move keys into a managed key store or a hardware security module (HSM), and name an owner for each key.
- Rotate keys on a schedule, back them up securely and test recovery.
- Log every use of a key, so that you can answer an auditor.
- Why we recommend this
- Encryption only protects data as well as its keys are protected. Central key management gives clear ownership, rotation and an audit trail, and tested recovery means encryption cannot become the cause of data loss.
- How we can help
-
PR.DS Protect Critical control
Backups
- Your answer
- The risk
- Ransomware deliberately looks for backups to encrypt or delete. If your backups sit on the same network, share the same credentials or have never been restored, you may be unable to recover your systems or data at all.
- What you can do
-
- Keep at least one copy of critical data offline or immutable, so that it cannot be changed or deleted.
- Protect backup systems with separate credentials, MFA and their own network segment.
- Test restores of critical systems on a schedule, and measure them against your recovery targets.
- Why we recommend this
- After a ransomware attack, a clean and tested backup is often the difference between a disruption and a crisis. We recommend immutable copies and regular restore tests, because a backup that has never been restored is only an assumption.
- How we can help
-
PR.PS Protect Critical control
Secure configuration and patching
- Your answer
- The risk
- Default settings, unnecessary services and missing updates give attackers easy footholds. Inconsistent configurations also make it hard to know which systems are exposed when a new vulnerability is announced.
- What you can do
-
- Adopt secure baselines, such as CIS Benchmarks, for servers, endpoints, network devices and directories.
- Apply critical security updates within set deadlines, and record and review every exception.
- Check configurations against the baseline automatically, and correct any drift.
- Why we recommend this
- Hardening removes weaknesses before anyone can exploit them, and a standard baseline makes every system easier to protect, monitor and audit. Automated checks show where configurations have drifted without reviewing every device by hand.
- How we can help
-
PR.PS Protect
Cloud and workplace security
- Your answer
- The risk
- Cloud services can be reached from anywhere, so one weak setting, such as legacy sign-in, open external sharing or excessive administrator rights, can expose email and files to the internet. Default settings often favor convenience over security.
- What you can do
-
- Review your cloud tenant against a security baseline, such as the CIS Microsoft 365 Foundations Benchmark.
- Block legacy authentication, require MFA, and allow access to company data only from managed, compliant devices.
- Control external sharing, label sensitive files, and monitor administrator and configuration changes.
- Why we recommend this
- Under the shared responsibility model, the provider secures its platform, but the settings, identities and data in your tenant are yours to protect. We recommend a governed design and baseline from the start, because correcting settings after users and data have moved is much harder.
-
PR.IR Protect
Network protection
- Your answer
- The risk
- In a flat network, an attacker who compromises one computer can reach every server, including your most critical systems. Internet-facing applications without dedicated protection are also open to direct attack.
- What you can do
-
- Separate critical systems into their own network zones, such as servers, management, backup and operational technology (OT).
- Allow only the traffic each zone needs, deny everything else by default, and review firewall rules regularly.
- Protect internet-facing applications and APIs with a web application firewall (WAF), and give remote users secure, controlled access.
- Why we recommend this
- Segmentation contains an intrusion to one part of the network and limits how far ransomware or an attacker can spread. A web application firewall adds a layer of protection for the applications that must stay open to the internet, while weaknesses in their code are fixed.
-
PR.IR Protect
Control of devices on the network
- Your answer
- The risk
- Anyone who connects to the network starts inside your perimeter. Unknown laptops, forgotten printers and cameras, and visitors’ devices often share a network with servers, and attackers use them as a way in.
- What you can do
-
- Find out what is connected today, including printers, cameras and other devices that cannot run security software.
- Authenticate users and devices with 802.1X, and give guests and contractors separate, limited access.
- Place each type of device in its own network segment, and restrict devices that fail compliance checks.
- Why we recommend this
- Network access control turns an open network into a controlled one and gives you a live list of what is connected. Starting in monitor mode avoids blocking legitimate devices by surprise.
- How we can help
-
PR.IR Protect
Segmentation between applications
- Your answer
- The risk
- Attackers who gain a foothold move from server to server looking for data and administrator rights. Where servers can reach each other freely, one compromise can spread across the whole data center.
- What you can do
-
- Map how your critical applications communicate with each other and with their data.
- Allow only the connections each application needs, starting with the most critical ones, and test the rules in monitor mode first.
- Log and review blocked connections, and update the rules when applications change.
- Why we recommend this
- Limiting movement inside the network keeps one intrusion small. Micro-segmentation applies the rule at workload level, so protection stays in place when servers move or scale.
- How we can help
-
PR.IR Protect
Secure access for remote users and branches
- Your answer
- The risk
- When staff work outside the office, web browsing and cloud applications bypass the controls built around the head office. Broad VPN access also lets one stolen account reach far more than it needs.
- What you can do
-
- Map where users, branches and applications are, and how their traffic reaches the internet and the cloud.
- Apply the same web, cloud and data protection policies to every location.
- Give access to private applications per user, device and application, instead of broad VPN access to the whole network.
- Why we recommend this
- SASE and SSE move security to where users and applications are, so policy follows the user. Per-application access limits what a stolen account can reach.
- How we can help
-
PR.IR Protect
Protection of internet-facing services
- Your answer
- The risk
- Internet-facing applications face constant automated attacks, and a flood of traffic can take a payment or customer service offline within minutes. Even a short outage costs customers, income and trust.
- What you can do
-
- List the websites, portals and APIs that must stay online, and rank them by business importance.
- Protect them with a web application and API firewall tuned to your applications, while weaknesses in the code are fixed.
- Add DDoS protection sized for those services, and rehearse the response with your teams and your internet provider.
- Why we recommend this
- A web application firewall blocks common attacks while code is fixed, and DDoS protection keeps services reachable when attackers try to flood them. Testing the two together shows how the service behaves under realistic conditions.
-
PR.IR Protect
DNS, DHCP and IP address management
- Your answer
- The risk
- Malware and phishing rely on DNS to reach their servers and websites. Without DNS filtering and logging, these connections go unnoticed, and unmanaged IP addressing makes it hard to trace which device was involved in an incident.
- What you can do
-
- Bring DNS, DHCP and IP address management onto a central DDI platform with change control.
- Enable protective DNS to block known malicious and newly registered domains.
- Log DNS queries and send them to your security monitoring, so investigations can see which device contacted what.
- Why we recommend this
- Every device already uses DNS, so filtering it protects users, servers and unmanaged devices without installing anything on them. Central DDI also gives you an accurate, auditable record of which device used which address.
- How we can help
-
PR.IR Protect
Infrastructure resilience
- Your answer
- The risk
- A single hardware failure, a power or cooling problem, or an attack on an exposed management interface can stop critical services for hours or days. Ageing platforms that no longer receive security updates add to the risk.
- What you can do
-
- Identify the services that need high availability and the single points of failure they depend on.
- Design redundancy, capacity and a disaster recovery site to match the availability each service needs.
- Isolate and harden the management interfaces of hypervisors and storage, and replace platforms that no longer receive updates.
- Why we recommend this
- Availability is part of security: customers and regulators judge you on whether services stay up, whatever caused the outage. We recommend designing resilience around business requirements, so that you invest most where downtime costs most.
- How we can help
-
DE.CM Detect Critical control
Log monitoring
- Your answer
- The risk
- Without central logs, attacks can go unnoticed for a long time, and when an incident is discovered there is no record of how the attacker got in, what they accessed, or whether they are still present.
- What you can do
-
- Collect logs from identities, critical servers, firewalls, remote access, email and cloud services in a central platform such as a SIEM.
- Keep logs long enough to investigate incidents, and protect them from being changed or deleted.
- Build detection rules around your main risks, tune them to reduce false positives, and review alerts every day.
- Why we recommend this
- Logs are the evidence trail for detecting and investigating attacks, and many regulations and standards require them. We recommend starting with the sources that matter most for your risks rather than collecting everything, so that detection is useful from the start.
- How we can help
-
DE.CM Detect
Identity threat detection
- Your answer
- The risk
- Attackers increasingly log in instead of breaking in. With one stolen password they can reach the directory, raise their privileges and move through the network while looking like a normal user.
- What you can do
-
- Collect sign-in and directory logs from Active Directory and your cloud identity providers.
- Alert on password spraying, impossible travel, new privileged accounts and unusual access to sensitive systems.
- Agree response actions, such as forcing a sign-out or a password reset, and who may take them.
- Why we recommend this
- Identity is the new perimeter, and endpoint tools see little of what happens inside a directory. Identity threat detection and response adds that visibility and links it to your other alerts.
-
DE.CM Detect
Endpoint detection
- Your answer
- The risk
- Traditional antivirus misses many modern attacks, such as fileless malware, misuse of legitimate administration tools and hands-on intrusions. Without endpoint detection, this activity leaves no alert and little evidence.
- What you can do
-
- Deploy endpoint detection and response (EDR) on every workstation and server, including those in branches and remote sites.
- Monitor it centrally, and agree who investigates alerts and who may isolate a device.
- Consider extended detection and response (XDR) to correlate endpoint, identity, email and cloud alerts in one place.
- Why we recommend this
- Workstations and servers are where attacks run, so visibility there gives the earliest and most detailed evidence of an intrusion. EDR also lets you isolate a compromised device remotely, which can stop an attack from spreading.
- How we can help
-
DE.CM Detect
Network threat detection
- Your answer
- The risk
- Once inside, attackers move between systems and send data out over the network. Without visibility of internal traffic, lateral movement, command-and-control traffic and data theft can continue unnoticed, especially on systems that cannot run security agents, such as OT and legacy devices.
- What you can do
-
- Identify the network segments and choke points that carry traffic to and from your critical systems.
- Deploy network sensors at those points to analyze traffic, including the metadata of encrypted traffic.
- Send network alerts to your SIEM or XDR, and train analysts to investigate them.
- Why we recommend this
- Network traffic is hard for an attacker to hide, so NDR detects intrusions that endpoint tools miss and covers devices where no agent can be installed. It also provides evidence of what was accessed or sent out when you investigate an incident.
- How we can help
-
DE.CM Detect
Ransomware readiness
- Your answer
- The risk
- Ransomware attackers spend days inside a network gaining access and looking for backups before they encrypt anything. If detection, containment and recovery have not been planned and tested, an attack can stop the organization for days.
- What you can do
-
- Review how ransomware would enter, spread and reach your backups in your environment.
- Enable detection of ransomware behavior and the ability to isolate a device quickly.
- Protect backups with immutable copies and separate credentials, and test a full restore.
- Rehearse a ransomware scenario with management and technical teams.
- Why we recommend this
- Ransomware is a chain of steps, and breaking any of them limits the damage. Combining detection, containment and tested recovery means you do not depend on the attacker to get your data back.
- How we can help
-
DE.CM Detect
Service health monitoring
- Your answer
- The risk
- Without end-to-end monitoring, customers notice outages and slowdowns first, root causes take longer to find, and unusual behavior that may signal an attack or a failing control goes unnoticed.
- What you can do
-
- Map each critical business service to the applications and infrastructure it depends on.
- Monitor the availability, performance and user experience of those services, and define what healthy looks like for each.
- Route alerts to the responsible teams based on user impact, and review recurring problems.
- Why we recommend this
- Monitoring at the level of business services lets you fix problems before customers notice and provides evidence for service-level reporting. It also supports security, because unexpected changes in behavior can be an early sign of an attack.
- How we can help
-
DE.AE Detect
Alert analysis
- Your answer
- The risk
- Alerts that no one reviews give no protection. An attack can be detected by your security tools and still succeed because the alert was ignored, misjudged or lost among false positives.
- What you can do
-
- Assign clear responsibility for reviewing alerts, and agree how critical alerts are handled outside working hours.
- Write triage procedures with clear criteria for escalating an alert to an incident.
- Train analysts in investigation, and tune detection rules to reduce false positives.
- Why we recommend this
- Detection tools only reduce risk when someone acts on what they find. Clear procedures and trained analysts shorten the time between an alert and a decision, which limits the damage an attacker can do.
-
DE.CM Detect
Out-of-hours monitoring
- Your answer
- The risk
- Attackers choose nights, weekends and holidays because they expect no one to react. An alert that waits hours or days for review gives them time to spread, steal data or encrypt systems.
- What you can do
-
- Decide which alerts must be handled out of hours, and how quickly each must be acted on.
- Choose how to cover them: an internal rota with clear authority and tools, or a provider that monitors and responds on your behalf.
- Write down what responders may do alone, such as isolating a device, and when to wake a decision maker.
- Why we recommend this
- Detection only helps if someone acts on it in time. A managed detection and response service lets you buy that coverage instead of staffing it, provided roles and response actions are agreed beforehand. We help you define the requirements and choose and onboard a provider.
-
RS.MA Respond Critical control
Incident response plan
- Your answer
- The risk
- Without a tested plan, the first hours of an incident are spent deciding who is in charge and what to do. Delays and mistakes, such as destroying evidence or restoring infected systems, increase the damage and the cost of recovery.
- What you can do
-
- Write an incident response plan with roles, decision rights, escalation criteria and external contacts.
- Prepare playbooks for likely scenarios, such as ransomware, account compromise and data leaks.
- Test the plan with management and technical teams in a tabletop exercise at least once a year.
- Why we recommend this
- An incident is the worst time to design a process. A rehearsed plan lets people act quickly and in the right order, and exercises reveal gaps in contacts, authority and tools before a real attack does.
- How we can help
-
RS.CO Respond
Incident communication
- Your answer
- The risk
- Poor communication can multiply the harm of an incident: regulators are informed late, customers learn about it from the media, and staff spread inaccurate information.
- What you can do
-
- Define who must be informed, by whom and how quickly: management, staff, regulators, customers and partners.
- Prepare contact lists and message templates in advance, and keep copies available offline.
- Agree who approves external statements, and practice communication in your exercises.
- Why we recommend this
- Clear, timely communication protects trust and helps you meet your notification obligations. Preparing it in advance lets the response team focus on the incident instead of drafting messages under pressure.
- How we can help
-
RS.MI Respond
Containment and investigation
- Your answer
- The risk
- An attack that is not contained quickly spreads to more systems. One that is not investigated may be followed by restoring systems while the attacker is still inside, so the incident repeats.
- What you can do
-
- Prepare containment steps for common scenarios, such as isolating devices, disabling accounts and blocking traffic.
- Train staff to preserve evidence, such as logs, memory and disk images, before systems are rebuilt.
- Arrange investigation support in advance, and consider a compromise assessment if you suspect a past intrusion.
- Why we recommend this
- Fast containment limits the damage, and a proper investigation finds the root cause so the attacker cannot return the same way. A compromise assessment also confirms whether attackers are already present before you invest in new defenses.
- How we can help
-
RS.MA Respond
Incident and request tracking
- Your answer
- The risk
- When incidents and requests arrive by phone and chat, work is lost, deadlines slip and nobody can show what was done. In a security incident, a missing record costs hours and weakens the evidence for auditors and regulators.
- What you can do
-
- Record every incident, request and change in one place, with an owner and a deadline.
- Add a security incident workflow with restricted access for sensitive cases.
- Connect your monitoring and security tools so that alerts create tickets for the right team.
- Why we recommend this
- A single record gives you ownership, a timeline and evidence for every incident, and shows which problems keep returning. Connecting alerts to tickets shortens the time between detection and action.
-
RC.RP Recover
Recovery plan
- Your answer
- The risk
- Without agreed priorities and tested procedures, recovery after a major incident is slow and improvised. Critical services can stay down longer than the business can tolerate, and systems may be restored with the attacker’s tools still in them.
- What you can do
-
- Agree recovery priorities, recovery time objectives (RTO) and recovery point objectives (RPO) with the business.
- Document how each critical system is restored, in what order and by whom.
- Test recovery regularly, including checks that restored systems are clean before they return to service.
- Why we recommend this
- Recovery planning turns backups and infrastructure into a working ability to restore the business. Agreeing targets with management sets the level of investment needed and avoids unrealistic expectations during a crisis.
- How we can help
-
RC.CO Recover
Recovery communication
- Your answer
- The risk
- During recovery, silence or conflicting updates erode the trust of customers, regulators and staff, and add pressure on the teams doing the work.
- What you can do
-
- Decide who communicates during recovery and how updates are approved.
- Prepare channels to reach staff, customers, regulators and the public, including when email or the website is unavailable.
- Give realistic timelines, and confirm when services are fully restored.
- Why we recommend this
- How you communicate during recovery shapes how the incident is remembered. Planned, honest updates keep stakeholders informed and reduce the volume of questions reaching your teams.
- How we can help
Further recommendations
The other gaps in your answers, in order of priority. Open each one to see the risk, what you can do and why we recommend it.
-
GV.RM Govern Cyber risk strategy
- Your answer
- The risk
- Without a strategy and an agreed risk appetite, security spending follows the latest incident or audit finding rather than the risks that matter most, and management cannot tell whether the organization is protected enough.
- What you can do
-
- Agree with management which services and data matter most and how much cyber risk the organization is willing to accept.
- Write a short cybersecurity strategy with a few clear objectives, owners and a two- to three-year roadmap.
- Record cyber risks in the enterprise risk register and review them alongside other business risks.
- Why we recommend this
- A strategy turns security from a list of purchases into a plan that management can approve, fund and measure. We recommend linking it to enterprise risk management because that is where decisions on budgets and priorities are already made.
- How we can help
-
GV.RR Govern Roles and accountability
- Your answer
- The risk
- When no one is clearly accountable, decisions on risk are delayed or never taken, security tasks fall between IT and the business, and incidents are handled without the authority to act quickly.
- What you can do
-
- Name one security leader who is accountable for cybersecurity and has direct access to senior management.
- Document security responsibilities across IT, risk, compliance and the business, for example in a RACI matrix.
- Give the security function a budget tied to its strategy, and review it every year.
- Why we recommend this
- Clear accountability is the condition for every other improvement: someone has to own the plan, report on it and escalate risks. Giving the security leader a line to senior management, separate from day-to-day IT operations, also reduces the conflict between keeping systems running and keeping them secure.
- How we can help
-
GV.PO Govern Security policies
- Your answer
- The risk
- Without approved policies, staff and suppliers have no clear rules to follow, controls are applied inconsistently, and the organization has little basis for holding anyone to account or for satisfying auditors and regulators.
- What you can do
-
- Approve a concise policy set covering acceptable use, access control, data protection, incident management and suppliers.
- Communicate the policies to every employee and contractor, and record their acknowledgment.
- Review the policies at least once a year, and check compliance through spot checks or internal audit.
- Why we recommend this
- Policies put management’s expectations in writing, which is the first thing auditors, regulators and frameworks such as ISO/IEC 27001 look for. We recommend a short policy set that is enforced over a long one that nobody reads.
- How we can help
-
GV.RM Govern Governance, risk and compliance tooling
- Your answer
- The risk
- When risks, policies and evidence live in scattered files, owners change without handover, reviews are missed and every audit becomes a search for documents. Management gets an out-of-date picture of where the organization stands.
- What you can do
-
- List the registers you maintain today: risks, policies, controls, audits and suppliers.
- Give each item an owner, a review date and a status in one shared place.
- Reuse evidence across frameworks such as ISO/IEC 27001 and NIST CSF 2.0 instead of collecting it again for each audit.
- Evaluate a GRC platform once your processes are stable enough to configure.
- Why we recommend this
- A single system of record keeps accountability visible and turns audits into a routine instead of a project. We recommend defining the processes first and choosing a platform second, because a tool cannot fix a process that nobody owns.
- How we can help
-
GV.OV Govern Management oversight
- Your answer
- The risk
- If management sees cybersecurity only after an incident, risks are accepted by default rather than by decision, and improvement work loses funding and priority.
- What you can do
-
- Agree a handful of measures that show your security position, such as MFA coverage, critical patch status and open high-risk findings.
- Report them to senior management at least every quarter, together with the top risks and the progress of improvement work.
- Record the decisions taken, and follow them up at the next review.
- Why we recommend this
- Regular oversight turns risk acceptance into a management decision and gives the security team the mandate and budget to act. Frameworks such as NIST CSF 2.0 and ISO/IEC 27001 expect evidence that management directs and reviews cybersecurity.
- How we can help
-
GV.SC Govern Supplier and third-party risk
- Your answer
- The risk
- Suppliers with remote access or with your data can become the way in. An attacker who compromises a supplier, or a supplier with weak security, can reach your systems through trusted access that is rarely monitored.
- What you can do
-
- List every supplier with access to your systems, networks or data, and rank them by risk.
- Add security requirements, a right to assess and a duty to report incidents to their contracts.
- Reassess critical suppliers regularly, and review and remove their access when it is no longer needed.
- Why we recommend this
- Supplier access is often broad, permanent and unmonitored, so it can undo the controls you apply to your own staff. A risk-based approach focuses your effort on the few suppliers that could cause the most harm.
- How we can help
-
ID.AM Identify Critical control Asset inventory
- Your answer
- The risk
- Systems you don’t know about are not patched, monitored or backed up. Forgotten servers, unmanaged devices and unknown cloud services are a common way in for attackers.
- What you can do
-
- Combine data from your directory, endpoint management, network scans and cloud accounts into one inventory.
- Record an owner and a criticality rating for every system, application and important data set.
- Automate discovery, including of internet-facing assets, so new or unknown assets are found and reviewed quickly.
- Why we recommend this
- Every other control depends on knowing what you have: you can’t protect, patch or monitor what isn’t on the list. We recommend automated discovery because manual lists quickly go out of date.
-
ID.AM Identify Laptop, desktop and mobile device management
- Your answer
- The risk
- Unmanaged devices miss updates, hold company data with no protection and cannot be locked or wiped if lost. Attackers look for the weakest device that can still reach email and files.
- What you can do
-
- List every type of device that reaches company data, including personal phones and tablets.
- Enroll them in a management platform that applies security settings, updates and applications automatically.
- Separate work data from personal data on staff-owned devices, and enable remote lock and wipe.
- Why we recommend this
- You cannot enforce a security baseline on devices you do not manage. Unified endpoint management and mobile device management give you one place to apply settings and to act when a device is lost, instead of relying on each user.
- How we can help
-
ID.AM Identify Security tool coverage
- Your answer
- The risk
- Each security tool sees only part of the estate, and no two asset lists agree. Systems without endpoint protection or logging, or with no owner, stay invisible until an attacker or an auditor finds them.
- What you can do
-
- Choose the controls every asset must have, for example endpoint protection, patching and log collection.
- Combine the asset lists from your directory, endpoint, cloud, vulnerability and network tools into one view.
- Report assets that miss a control or have no owner, and track each gap to closure.
- Why we recommend this
- Owning a tool is not the same as having coverage. Comparing your tools against each other shows where protection is missing without buying anything new, so you can close the gaps in priority order.
-
ID.RA Identify Internet-facing exposure
- Your answer
- The risk
- Attackers start by listing what you expose. Forgotten test servers, open administration pages and expired certificates are easy to find from outside and are often missed from inside.
- What you can do
-
- Start from your domains and address ranges, and discover what is actually reachable from the internet.
- Compare the result with your asset list, and assign an owner to every unknown or forgotten system.
- Monitor continuously, and review new exposures every month.
- Why we recommend this
- Seeing your organization as an outsider does shows risks that internal tools miss. Continuous discovery catches new exposures as they appear, before an attacker does.
- How we can help
-
ID.RA Identify Risk assessment
- Your answer
- The risk
- Without a structured risk assessment, security effort is spread evenly or driven by vendors and headlines, while the threats most likely to harm your critical services may go unaddressed.
- What you can do
-
- Assess the risks to your critical services, considering realistic threats, their likelihood and their business impact.
- Record each risk in a register with an owner, a treatment decision and a target date.
- Repeat the assessment at least yearly and after major changes, such as new systems, services or suppliers.
- Why we recommend this
- A risk assessment tells you where to spend first and gives management a defensible basis for accepting or treating each risk. It is also a core requirement of ISO/IEC 27001.
- How we can help
-
ID.RA Identify Threat intelligence
- Your answer
- The risk
- Without threat intelligence, you learn about campaigns against your sector, leaked staff credentials or fake websites using your name only after they have been used against you or your customers.
- What you can do
-
- Define what you need to know: the threats, fraud types and assets that matter most to your organization.
- Follow national and sector sources, such as CERT advisories and industry groups, and make someone responsible for reviewing them.
- Monitor for leaked credentials, look-alike domains and fake social media accounts, and act on what you find.
- Why we recommend this
- Intelligence tells you which threats are likely, so you can prioritize defenses and detection rules instead of reacting to everything. Monitoring for leaks and brand abuse also protects your customers from fraud that happens outside your network.
- How we can help
-
ID.RA Identify Critical control Vulnerability management
- Your answer
- The risk
- Unpatched vulnerabilities, especially on internet-facing systems, are one of the most common ways attackers get in, and known flaws are often exploited soon after they are published.
- What you can do
-
- Scan all systems regularly, starting with internet-facing services, and include cloud assets.
- Set fix deadlines by severity and exposure, with the shortest deadlines for critical flaws on internet-facing systems.
- Track every finding to closure, and report overdue fixes to management.
- Why we recommend this
- Vulnerability management closes known doors before attackers use them, which makes it one of the most cost-effective controls. We recommend prioritizing by real exposure and exploitability, not by severity score alone, so your teams fix what matters first.
-
ID.RA Identify Cloud infrastructure posture
- Your answer
- The risk
- Cloud resources are created in minutes and are reachable from anywhere. A public storage bucket, an account with too many permissions or a container with a known flaw can expose data before anyone notices.
- What you can do
-
- List every cloud account and subscription, and who is responsible for each.
- Check configuration against a baseline such as the CIS Benchmarks, and fix public exposure and excessive permissions first.
- Scan workloads, containers and infrastructure code, and send findings to the team that owns the resource.
- Why we recommend this
- Cloud risk changes daily, so a one-time review goes out of date quickly. A cloud-native protection platform keeps checking and ranks findings by real exposure, so teams fix what matters first.
-
ID.IM Identify Independent security testing
- Your answer
- The risk
- Controls that have never been tested may not work as intended. Without independent testing, weaknesses in configurations, applications and processes stay hidden until an attacker finds them.
- What you can do
-
- Commission an independent penetration test of your internet-facing systems and critical applications.
- Repeat it at least yearly and after major changes, and retest every fix.
- Feed the findings into your risk register and security roadmap.
- Why we recommend this
- Independent testing shows how an attacker would actually get in and whether your controls stop them. It also gives management and regulators objective evidence that a self-assessment cannot provide.
- How we can help
-
PR.AA Protect Identity and access management
- Your answer
- The risk
- Accounts that keep their rights after people change roles or leave are easy targets. When access is granted informally, nobody can show who can reach what, and an attacker who steals one account inherits all of its rights.
- What you can do
-
- Define roles and the access each role needs, and base access requests on them.
- Run joiner, mover and leaver steps so access changes the day a role changes, and disable accounts as soon as people leave.
- Review who has access to critical systems at least twice a year, with the business owner signing off.
- Introduce single sign-on so users and administrators manage fewer separate accounts.
- Why we recommend this
- Controlling the identity lifecycle removes the forgotten access that attackers rely on, and gives auditors a record of who approved what. Single sign-on reduces password reuse and makes access easier to withdraw.
- How we can help
-
PR.AA Protect Critical control Multi-factor authentication
- Your answer
- The risk
- With passwords alone, one phished, guessed or reused password is enough to access email, remote access or cloud services. Stolen credentials are one of the most common ways attackers get in.
- What you can do
-
- Enforce MFA first on email, remote access, cloud services and every administrator account.
- Extend it to all users, and remove exceptions and legacy sign-in methods that bypass it.
- Move administrators and other high-risk users to phishing-resistant methods, such as FIDO2 security keys or passkeys.
- Why we recommend this
- MFA means a stolen password is no longer enough on its own, which closes one of the most common attack paths for a modest cost. We recommend managing it centrally, with conditional access, so the same rules apply to every application and exceptions are visible.
- How we can help
-
PR.AA Protect Critical control Privileged access
- Your answer
- The risk
- Administrator accounts give full control of your systems. If one is compromised, an attacker can disable security, steal data or deploy ransomware across the organization, and shared accounts make their actions impossible to trace.
- What you can do
-
- Reduce administrator accounts to the minimum, and separate them from everyday user accounts.
- Keep privileged passwords in a vault, rotate them, and protect privileged access with MFA.
- Grant administrator rights only when needed, record privileged sessions, and review privileged accounts every quarter.
- Why we recommend this
- Ransomware and data theft usually depend on gaining administrator rights, so controlling those rights limits the damage of any intrusion. A privileged access management (PAM) platform enforces this consistently and gives auditors a record of every privileged action.
- How we can help
-
PR.AT Protect Security awareness
- Your answer
- The risk
- Phishing and social engineering target people rather than systems. Untrained staff are more likely to click a malicious link, give away a password or approve a fraudulent payment, and less likely to report it quickly.
- What you can do
-
- Run short, regular awareness training, tailored to roles such as finance, IT and executives.
- Run phishing simulations, and use the results to target further training rather than to blame individuals.
- Give every user a simple way to report suspicious messages, and acknowledge the reports.
- Why we recommend this
- No technology stops every deceptive message, so staff who recognize and report attacks become an extra layer of detection. Measuring reporting rates over time shows management whether the program is working.
- How we can help
-
PR.PS Protect Critical control Email security
- Your answer
- The risk
- Email is one of the most common ways attacks begin: phishing steals credentials, attachments deliver malware and ransomware, and fake messages from executives or suppliers lead to fraudulent payments. Without DMARC, criminals can also send email that appears to come from your domain.
- What you can do
-
- Enable advanced filtering that analyzes links and attachments, including after delivery.
- Publish SPF and DKIM for every domain you send from, then move DMARC to enforcement in stages.
- Add a report-phishing button, and a process to remove malicious emails from every mailbox quickly.
- Why we recommend this
- Stopping malicious email before it reaches people removes the starting point of many attacks, and DMARC protects your customers and partners from emails that impersonate you. We recommend combining email protection with awareness training, because neither is enough on its own.
- How we can help
-
PR.DS Protect Data protection
- Your answer
- The risk
- If you don’t know where sensitive data is or who can access it, it can be copied, leaked or encrypted by ransomware without anyone noticing. Data breaches bring regulatory, legal and reputational consequences that last long after the incident.
- What you can do
-
- Identify and classify sensitive data, such as customer, financial and personal data, and record where it is stored.
- Encrypt sensitive data at rest and in transit, and keep the keys in a managed key store or a hardware security module (HSM).
- Limit access to those who need it, and monitor or block unusual copying and transfers with data loss prevention (DLP).
- Why we recommend this
- Protecting the data itself, not only the systems around it, means that a breach of one system does not automatically expose your most valuable information. Classification comes first because it tells you which data needs the strongest controls, so you don’t pay to protect everything at the same level.
- How we can help
-
PR.DS Protect Encryption and key management
- Your answer
- The risk
- Unencrypted data is readable by anyone who copies it, and keys left in files or shared between teams make strong encryption weak. If a key is lost without a backup, the data it protects is lost too.
- What you can do
-
- Encrypt sensitive data at rest and in transit, starting with databases, laptops, backups and remote access.
- Move keys into a managed key store or a hardware security module (HSM), and name an owner for each key.
- Rotate keys on a schedule, back them up securely and test recovery.
- Log every use of a key, so that you can answer an auditor.
- Why we recommend this
- Encryption only protects data as well as its keys are protected. Central key management gives clear ownership, rotation and an audit trail, and tested recovery means encryption cannot become the cause of data loss.
- How we can help
-
PR.DS Protect Critical control Backups
- Your answer
- The risk
- Ransomware deliberately looks for backups to encrypt or delete. If your backups sit on the same network, share the same credentials or have never been restored, you may be unable to recover your systems or data at all.
- What you can do
-
- Keep at least one copy of critical data offline or immutable, so that it cannot be changed or deleted.
- Protect backup systems with separate credentials, MFA and their own network segment.
- Test restores of critical systems on a schedule, and measure them against your recovery targets.
- Why we recommend this
- After a ransomware attack, a clean and tested backup is often the difference between a disruption and a crisis. We recommend immutable copies and regular restore tests, because a backup that has never been restored is only an assumption.
- How we can help
-
PR.PS Protect Critical control Secure configuration and patching
- Your answer
- The risk
- Default settings, unnecessary services and missing updates give attackers easy footholds. Inconsistent configurations also make it hard to know which systems are exposed when a new vulnerability is announced.
- What you can do
-
- Adopt secure baselines, such as CIS Benchmarks, for servers, endpoints, network devices and directories.
- Apply critical security updates within set deadlines, and record and review every exception.
- Check configurations against the baseline automatically, and correct any drift.
- Why we recommend this
- Hardening removes weaknesses before anyone can exploit them, and a standard baseline makes every system easier to protect, monitor and audit. Automated checks show where configurations have drifted without reviewing every device by hand.
- How we can help
-
PR.PS Protect Cloud and workplace security
- Your answer
- The risk
- Cloud services can be reached from anywhere, so one weak setting, such as legacy sign-in, open external sharing or excessive administrator rights, can expose email and files to the internet. Default settings often favor convenience over security.
- What you can do
-
- Review your cloud tenant against a security baseline, such as the CIS Microsoft 365 Foundations Benchmark.
- Block legacy authentication, require MFA, and allow access to company data only from managed, compliant devices.
- Control external sharing, label sensitive files, and monitor administrator and configuration changes.
- Why we recommend this
- Under the shared responsibility model, the provider secures its platform, but the settings, identities and data in your tenant are yours to protect. We recommend a governed design and baseline from the start, because correcting settings after users and data have moved is much harder.
-
PR.IR Protect Network protection
- Your answer
- The risk
- In a flat network, an attacker who compromises one computer can reach every server, including your most critical systems. Internet-facing applications without dedicated protection are also open to direct attack.
- What you can do
-
- Separate critical systems into their own network zones, such as servers, management, backup and operational technology (OT).
- Allow only the traffic each zone needs, deny everything else by default, and review firewall rules regularly.
- Protect internet-facing applications and APIs with a web application firewall (WAF), and give remote users secure, controlled access.
- Why we recommend this
- Segmentation contains an intrusion to one part of the network and limits how far ransomware or an attacker can spread. A web application firewall adds a layer of protection for the applications that must stay open to the internet, while weaknesses in their code are fixed.
-
PR.IR Protect Control of devices on the network
- Your answer
- The risk
- Anyone who connects to the network starts inside your perimeter. Unknown laptops, forgotten printers and cameras, and visitors’ devices often share a network with servers, and attackers use them as a way in.
- What you can do
-
- Find out what is connected today, including printers, cameras and other devices that cannot run security software.
- Authenticate users and devices with 802.1X, and give guests and contractors separate, limited access.
- Place each type of device in its own network segment, and restrict devices that fail compliance checks.
- Why we recommend this
- Network access control turns an open network into a controlled one and gives you a live list of what is connected. Starting in monitor mode avoids blocking legitimate devices by surprise.
- How we can help
-
PR.IR Protect Segmentation between applications
- Your answer
- The risk
- Attackers who gain a foothold move from server to server looking for data and administrator rights. Where servers can reach each other freely, one compromise can spread across the whole data center.
- What you can do
-
- Map how your critical applications communicate with each other and with their data.
- Allow only the connections each application needs, starting with the most critical ones, and test the rules in monitor mode first.
- Log and review blocked connections, and update the rules when applications change.
- Why we recommend this
- Limiting movement inside the network keeps one intrusion small. Micro-segmentation applies the rule at workload level, so protection stays in place when servers move or scale.
- How we can help
-
PR.IR Protect Secure access for remote users and branches
- Your answer
- The risk
- When staff work outside the office, web browsing and cloud applications bypass the controls built around the head office. Broad VPN access also lets one stolen account reach far more than it needs.
- What you can do
-
- Map where users, branches and applications are, and how their traffic reaches the internet and the cloud.
- Apply the same web, cloud and data protection policies to every location.
- Give access to private applications per user, device and application, instead of broad VPN access to the whole network.
- Why we recommend this
- SASE and SSE move security to where users and applications are, so policy follows the user. Per-application access limits what a stolen account can reach.
- How we can help
-
PR.IR Protect Protection of internet-facing services
- Your answer
- The risk
- Internet-facing applications face constant automated attacks, and a flood of traffic can take a payment or customer service offline within minutes. Even a short outage costs customers, income and trust.
- What you can do
-
- List the websites, portals and APIs that must stay online, and rank them by business importance.
- Protect them with a web application and API firewall tuned to your applications, while weaknesses in the code are fixed.
- Add DDoS protection sized for those services, and rehearse the response with your teams and your internet provider.
- Why we recommend this
- A web application firewall blocks common attacks while code is fixed, and DDoS protection keeps services reachable when attackers try to flood them. Testing the two together shows how the service behaves under realistic conditions.
-
PR.IR Protect DNS, DHCP and IP address management
- Your answer
- The risk
- Malware and phishing rely on DNS to reach their servers and websites. Without DNS filtering and logging, these connections go unnoticed, and unmanaged IP addressing makes it hard to trace which device was involved in an incident.
- What you can do
-
- Bring DNS, DHCP and IP address management onto a central DDI platform with change control.
- Enable protective DNS to block known malicious and newly registered domains.
- Log DNS queries and send them to your security monitoring, so investigations can see which device contacted what.
- Why we recommend this
- Every device already uses DNS, so filtering it protects users, servers and unmanaged devices without installing anything on them. Central DDI also gives you an accurate, auditable record of which device used which address.
- How we can help
-
PR.IR Protect Infrastructure resilience
- Your answer
- The risk
- A single hardware failure, a power or cooling problem, or an attack on an exposed management interface can stop critical services for hours or days. Ageing platforms that no longer receive security updates add to the risk.
- What you can do
-
- Identify the services that need high availability and the single points of failure they depend on.
- Design redundancy, capacity and a disaster recovery site to match the availability each service needs.
- Isolate and harden the management interfaces of hypervisors and storage, and replace platforms that no longer receive updates.
- Why we recommend this
- Availability is part of security: customers and regulators judge you on whether services stay up, whatever caused the outage. We recommend designing resilience around business requirements, so that you invest most where downtime costs most.
- How we can help
-
DE.CM Detect Critical control Log monitoring
- Your answer
- The risk
- Without central logs, attacks can go unnoticed for a long time, and when an incident is discovered there is no record of how the attacker got in, what they accessed, or whether they are still present.
- What you can do
-
- Collect logs from identities, critical servers, firewalls, remote access, email and cloud services in a central platform such as a SIEM.
- Keep logs long enough to investigate incidents, and protect them from being changed or deleted.
- Build detection rules around your main risks, tune them to reduce false positives, and review alerts every day.
- Why we recommend this
- Logs are the evidence trail for detecting and investigating attacks, and many regulations and standards require them. We recommend starting with the sources that matter most for your risks rather than collecting everything, so that detection is useful from the start.
- How we can help
-
DE.CM Detect Identity threat detection
- Your answer
- The risk
- Attackers increasingly log in instead of breaking in. With one stolen password they can reach the directory, raise their privileges and move through the network while looking like a normal user.
- What you can do
-
- Collect sign-in and directory logs from Active Directory and your cloud identity providers.
- Alert on password spraying, impossible travel, new privileged accounts and unusual access to sensitive systems.
- Agree response actions, such as forcing a sign-out or a password reset, and who may take them.
- Why we recommend this
- Identity is the new perimeter, and endpoint tools see little of what happens inside a directory. Identity threat detection and response adds that visibility and links it to your other alerts.
-
DE.CM Detect Endpoint detection
- Your answer
- The risk
- Traditional antivirus misses many modern attacks, such as fileless malware, misuse of legitimate administration tools and hands-on intrusions. Without endpoint detection, this activity leaves no alert and little evidence.
- What you can do
-
- Deploy endpoint detection and response (EDR) on every workstation and server, including those in branches and remote sites.
- Monitor it centrally, and agree who investigates alerts and who may isolate a device.
- Consider extended detection and response (XDR) to correlate endpoint, identity, email and cloud alerts in one place.
- Why we recommend this
- Workstations and servers are where attacks run, so visibility there gives the earliest and most detailed evidence of an intrusion. EDR also lets you isolate a compromised device remotely, which can stop an attack from spreading.
- How we can help
-
DE.CM Detect Network threat detection
- Your answer
- The risk
- Once inside, attackers move between systems and send data out over the network. Without visibility of internal traffic, lateral movement, command-and-control traffic and data theft can continue unnoticed, especially on systems that cannot run security agents, such as OT and legacy devices.
- What you can do
-
- Identify the network segments and choke points that carry traffic to and from your critical systems.
- Deploy network sensors at those points to analyze traffic, including the metadata of encrypted traffic.
- Send network alerts to your SIEM or XDR, and train analysts to investigate them.
- Why we recommend this
- Network traffic is hard for an attacker to hide, so NDR detects intrusions that endpoint tools miss and covers devices where no agent can be installed. It also provides evidence of what was accessed or sent out when you investigate an incident.
- How we can help
-
DE.CM Detect Ransomware readiness
- Your answer
- The risk
- Ransomware attackers spend days inside a network gaining access and looking for backups before they encrypt anything. If detection, containment and recovery have not been planned and tested, an attack can stop the organization for days.
- What you can do
-
- Review how ransomware would enter, spread and reach your backups in your environment.
- Enable detection of ransomware behavior and the ability to isolate a device quickly.
- Protect backups with immutable copies and separate credentials, and test a full restore.
- Rehearse a ransomware scenario with management and technical teams.
- Why we recommend this
- Ransomware is a chain of steps, and breaking any of them limits the damage. Combining detection, containment and tested recovery means you do not depend on the attacker to get your data back.
- How we can help
-
DE.CM Detect Service health monitoring
- Your answer
- The risk
- Without end-to-end monitoring, customers notice outages and slowdowns first, root causes take longer to find, and unusual behavior that may signal an attack or a failing control goes unnoticed.
- What you can do
-
- Map each critical business service to the applications and infrastructure it depends on.
- Monitor the availability, performance and user experience of those services, and define what healthy looks like for each.
- Route alerts to the responsible teams based on user impact, and review recurring problems.
- Why we recommend this
- Monitoring at the level of business services lets you fix problems before customers notice and provides evidence for service-level reporting. It also supports security, because unexpected changes in behavior can be an early sign of an attack.
- How we can help
-
DE.AE Detect Alert analysis
- Your answer
- The risk
- Alerts that no one reviews give no protection. An attack can be detected by your security tools and still succeed because the alert was ignored, misjudged or lost among false positives.
- What you can do
-
- Assign clear responsibility for reviewing alerts, and agree how critical alerts are handled outside working hours.
- Write triage procedures with clear criteria for escalating an alert to an incident.
- Train analysts in investigation, and tune detection rules to reduce false positives.
- Why we recommend this
- Detection tools only reduce risk when someone acts on what they find. Clear procedures and trained analysts shorten the time between an alert and a decision, which limits the damage an attacker can do.
-
DE.CM Detect Out-of-hours monitoring
- Your answer
- The risk
- Attackers choose nights, weekends and holidays because they expect no one to react. An alert that waits hours or days for review gives them time to spread, steal data or encrypt systems.
- What you can do
-
- Decide which alerts must be handled out of hours, and how quickly each must be acted on.
- Choose how to cover them: an internal rota with clear authority and tools, or a provider that monitors and responds on your behalf.
- Write down what responders may do alone, such as isolating a device, and when to wake a decision maker.
- Why we recommend this
- Detection only helps if someone acts on it in time. A managed detection and response service lets you buy that coverage instead of staffing it, provided roles and response actions are agreed beforehand. We help you define the requirements and choose and onboard a provider.
-
RS.MA Respond Critical control Incident response plan
- Your answer
- The risk
- Without a tested plan, the first hours of an incident are spent deciding who is in charge and what to do. Delays and mistakes, such as destroying evidence or restoring infected systems, increase the damage and the cost of recovery.
- What you can do
-
- Write an incident response plan with roles, decision rights, escalation criteria and external contacts.
- Prepare playbooks for likely scenarios, such as ransomware, account compromise and data leaks.
- Test the plan with management and technical teams in a tabletop exercise at least once a year.
- Why we recommend this
- An incident is the worst time to design a process. A rehearsed plan lets people act quickly and in the right order, and exercises reveal gaps in contacts, authority and tools before a real attack does.
- How we can help
-
RS.CO Respond Incident communication
- Your answer
- The risk
- Poor communication can multiply the harm of an incident: regulators are informed late, customers learn about it from the media, and staff spread inaccurate information.
- What you can do
-
- Define who must be informed, by whom and how quickly: management, staff, regulators, customers and partners.
- Prepare contact lists and message templates in advance, and keep copies available offline.
- Agree who approves external statements, and practice communication in your exercises.
- Why we recommend this
- Clear, timely communication protects trust and helps you meet your notification obligations. Preparing it in advance lets the response team focus on the incident instead of drafting messages under pressure.
- How we can help
-
RS.MI Respond Containment and investigation
- Your answer
- The risk
- An attack that is not contained quickly spreads to more systems. One that is not investigated may be followed by restoring systems while the attacker is still inside, so the incident repeats.
- What you can do
-
- Prepare containment steps for common scenarios, such as isolating devices, disabling accounts and blocking traffic.
- Train staff to preserve evidence, such as logs, memory and disk images, before systems are rebuilt.
- Arrange investigation support in advance, and consider a compromise assessment if you suspect a past intrusion.
- Why we recommend this
- Fast containment limits the damage, and a proper investigation finds the root cause so the attacker cannot return the same way. A compromise assessment also confirms whether attackers are already present before you invest in new defenses.
- How we can help
-
RS.MA Respond Incident and request tracking
- Your answer
- The risk
- When incidents and requests arrive by phone and chat, work is lost, deadlines slip and nobody can show what was done. In a security incident, a missing record costs hours and weakens the evidence for auditors and regulators.
- What you can do
-
- Record every incident, request and change in one place, with an owner and a deadline.
- Add a security incident workflow with restricted access for sensitive cases.
- Connect your monitoring and security tools so that alerts create tickets for the right team.
- Why we recommend this
- A single record gives you ownership, a timeline and evidence for every incident, and shows which problems keep returning. Connecting alerts to tickets shortens the time between detection and action.
-
RC.RP Recover Recovery plan
- Your answer
- The risk
- Without agreed priorities and tested procedures, recovery after a major incident is slow and improvised. Critical services can stay down longer than the business can tolerate, and systems may be restored with the attacker’s tools still in them.
- What you can do
-
- Agree recovery priorities, recovery time objectives (RTO) and recovery point objectives (RPO) with the business.
- Document how each critical system is restored, in what order and by whom.
- Test recovery regularly, including checks that restored systems are clean before they return to service.
- Why we recommend this
- Recovery planning turns backups and infrastructure into a working ability to restore the business. Agreeing targets with management sets the level of investment needed and avoids unrealistic expectations during a crisis.
- How we can help
-
RC.CO Recover Recovery communication
- Your answer
- The risk
- During recovery, silence or conflicting updates erode the trust of customers, regulators and staff, and add pressure on the teams doing the work.
- What you can do
-
- Decide who communicates during recovery and how updates are approved.
- Prepare channels to reach staff, customers, regulators and the public, including when email or the website is unavailable.
- Give realistic timelines, and confirm when services are fully restored.
- Why we recommend this
- How you communicate during recovery shapes how the incident is remembered. Planned, honest updates keep stakeholders informed and reduce the volume of questions reaching your teams.
- How we can help
Detailed results
Every answer, by function. Each answer scores from 0 to 3.
Govern
- Cyber risk strategy
- Roles and accountability
- Security policies
- Governance, risk and compliance tooling
- Management oversight
- Supplier and third-party risk
Identify
- Asset inventory
- Laptop, desktop and mobile device management
- Security tool coverage
- Internet-facing exposure
- Risk assessment
- Threat intelligence
- Vulnerability management
- Cloud infrastructure posture
- Independent security testing
Protect
- Identity and access management
- Multi-factor authentication
- Privileged access
- Security awareness
- Email security
- Data protection
- Encryption and key management
- Backups
- Secure configuration and patching
- Cloud and workplace security
- Network protection
- Control of devices on the network
- Segmentation between applications
- Secure access for remote users and branches
- Protection of internet-facing services
- DNS, DHCP and IP address management
- Infrastructure resilience
Detect
- Log monitoring
- Identity threat detection
- Endpoint detection
- Network threat detection
- Ransomware readiness
- Service health monitoring
- Alert analysis
- Out-of-hours monitoring
Respond
- Incident response plan
- Incident communication
- Containment and investigation
- Incident and request tracking
Recover
- Recovery plan
- Recovery communication
Next steps
This report reflects your own view of your organization. An independent assessment based on evidence confirms where you stand and which gaps to close first.
Oyoon Altaqnya for Information Technology & Cybersecurity · Tripoli, Libya · sales@techeyes.ly · www.techeyes.ly