connecteddale

Strategy Coach = Clarity + Alignment

NIST Cybersecurity Framework

The NIST Cybersecurity Framework organises cyber-risk work into six functions - Govern at the centre, with Identify, Protect, Detect, Respond and Recover around it - so an organisation can see which part of its defence is actually weak instead of just buying more tools.

Picture a wheel: Identify, Protect, Detect, Respond and Recover as spokes around the Govern hub in the middle.

Govern Identify Protect Detect Respond Recover
Govern sits at the centre, shaping the five operational functions around it.

Reach for this when…

How to run it

  1. Govern: set the cyber-risk strategy, policy and accountability that shapes everything else.
  2. Identify: catalogue your critical assets, data, and the risks to them.
  3. Protect: put safeguards, access controls, and training around what matters most.
  4. Detect: build monitoring that catches an incident while it's still small.
  5. Respond: have a tested plan for containing and communicating a breach.
  6. Recover: restore operations and feed what you learned back into Govern and Identify.

A worked example

Situation. Martin Fernandez ran Fernandez Cargas, a mid-sized logistics firm in Cordoba, Argentina, and got badly rattled when a key supplier was hit by ransomware.

Applied. Mapping his own operation against the functions, he found Identify and Protect were reasonable but Detect was almost nonexistent: nobody would know about an intrusion until something visibly broke.

Result. He put basic monitoring and alerting in place. Three months later it caught a phishing-driven login attempt on the dispatch system before it reached anything critical.

The catch

The framework tells you where to look, not how good 'good enough' is for your size of business, so smaller firms can drown trying to implement it as if they were a bank. It's also a snapshot exercise unless someone owns keeping it current, and Recover is the function most often skipped until the year it's needed.

A framework you've mapped once and never revisited is documentation, not defence.

Origin: National Institute of Standards and Technology (NIST)