Frameworks
The NIST Cybersecurity Framework (CSF 2.0)
The NIST Cybersecurity Framework (CSF 2.0) is an internationally recognised way to structure and measure a security programme. Its six core functions — Govern, Identify, Protect, Detect, Respond and Recover — give organisations of any size a common language for managing cyber risk.
The NIST Cybersecurity Framework (CSF 2.0) is an internationally recognised way to structure and measure a security programme. Its six core functions — Govern, Identify, Protect, Detect, Respond and Recover — give organisations of any size a common language for managing cyber risk.
The six functions
How CSF 2.0 is structured
- Govern — roles, risk appetite, oversight and accountability
- Identify — understand your assets, data and risks
- Protect — safeguards like identity, hardening and training
- Detect — spot events and anomalies (EDR/MDR)
- Respond — contain and manage incidents
- Recover — restore and learn
How our services map to it
CSF in practice
- Identify → our Cyber Security Audit & Analysis
- Protect & Detect → the Cyber Resilience Programme and MDR
- Respond & Recover → Incident Response and backups
- Govern → our governance, vCISO and policy work
FAQ
Common questions
Is NIST CSF only for large organisations?
No. CSF 2.0 is designed to scale to organisations of any size. It's one of the most practical frameworks for SMEs because it prioritises outcomes over paperwork.
What's new in CSF 2.0?
The 2024 update added 'Govern' as a sixth core function, putting leadership accountability and risk management at the heart of the framework.
Do we get certified in NIST CSF?
No — CSF is a framework for structuring and measuring your programme, not a certification. If you need formal certification, ISO/IEC 27001 is the usual route.
Related pages
Let’s talk
Every good plan starts with a conversation, and there’s no obligation in having one.