NIST Cybersecurity Framework
The NIST Cybersecurity Framework organises cyber-risk work into six functions - Govern at the centre, with Identify, Protect, Detect, Respond and Recover around it - so an organisation can see which part of its defence is actually weak instead of just buying more tools.
Picture a wheel: Identify, Protect, Detect, Respond and Recover as spokes around the Govern hub in the middle.
Reach for this when…
- You've bought security tools but can't say which risk each one addresses.
- A near-miss happened and nobody agreed on who should have caught it.
- A customer, insurer or regulator is asking for your cybersecurity posture in a common format.
How to run it
- Govern: set the cyber-risk strategy, policy and accountability that shapes everything else.
- Identify: catalogue your critical assets, data, and the risks to them.
- Protect: put safeguards, access controls, and training around what matters most.
- Detect: build monitoring that catches an incident while it's still small.
- Respond: have a tested plan for containing and communicating a breach.
- Recover: restore operations and feed what you learned back into Govern and Identify.
A worked example
Situation. Martin Fernandez ran Fernandez Cargas, a mid-sized logistics firm in Cordoba, Argentina, and got badly rattled when a key supplier was hit by ransomware.
Applied. Mapping his own operation against the functions, he found Identify and Protect were reasonable but Detect was almost nonexistent: nobody would know about an intrusion until something visibly broke.
Result. He put basic monitoring and alerting in place. Three months later it caught a phishing-driven login attempt on the dispatch system before it reached anything critical.
The catch
The framework tells you where to look, not how good 'good enough' is for your size of business, so smaller firms can drown trying to implement it as if they were a bank. It's also a snapshot exercise unless someone owns keeping it current, and Recover is the function most often skipped until the year it's needed.
A framework you've mapped once and never revisited is documentation, not defence.
Origin: National Institute of Standards and Technology (NIST)