How-To / Governance

A Framework Is Not a Control Set

Use NIST CSF 2.0 as a common decision language. Score current and target profiles, weight gaps by business criticality, and work a short, owned priority list.

The short answer

NIST CSF 2.0 is a common language for describing cyber risk, not a product checklist. A small business should score a current profile, choose a realistic target, weight each gap by business criticality, assign owners to the top three priorities, and rescore annually so the framework drives decisions instead of documentation.

The most common way a small business encounters a security framework is as a list of things to buy. Somebody produces a spreadsheet of controls, maps them to products, and the exercise becomes a procurement plan wearing a governance costume.

That misreads what a framework is for. The Cybersecurity Framework does not tell you what to buy. It gives a company, its insurer, its largest customer, its auditor, and its IT provider a way to describe the same environment using the same words. That sounds modest. It is the entire value.

Consider what happens without it. Your provider describes your posture in terms of the tools deployed. Your insurer describes it in terms of application answers. Your customer describes it in terms of their questionnaire. Your CFO describes it in terms of the budget line. Four descriptions of one environment, none of which reconcile, and no way to tell whether the thing being described is adequate.

What changed in version 2.0

The framework gained a sixth function, GOVERN, which sits alongside IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER rather than underneath them.

For a small business, this is the most useful thing that has happened to the framework, because GOVERN names the thing that is actually missing in most environments we assess. Organizational context. Risk management strategy. Roles and authorities. Policy. Oversight. Supply chain risk.

Read that list against a typical fifty-person company. There is endpoint protection, backup, MFA, and a firewall, all of which live under PROTECT. There is often nothing under GOVERN at all, because nobody sold it to them. PROTECT is where the products are, so PROTECT is where the money went.

This is not a criticism of the company. It is a description of how the market works. Cybersecurity is sold as products, so buyers accumulate products, and the accumulation is mistaken for a program. Then something happens, and the absence of decisions rather than the absence of tools is what makes the event expensive.

Current profile and target profile

The mechanic that makes the framework useful is that you score twice.

The current profile is where you are. The target profile is where you have decided to be. The gap between them is your plan, and the discipline is in the second number rather than the first.

Not everything needs to reach the top tier. A sixty-person distribution business does not need adaptive continuous monitoring, and pretending otherwise produces a plan nobody funds and everybody ignores. Deciding that a category stays at tier two, deliberately, with the reason written down, is a legitimate governance act. It may be the most valuable output of the whole exercise, because a documented decision to accept a risk is worth more than an undocumented aspiration to eliminate it.

We add a third number, business criticality, because a gap of two tiers in a category that barely affects the business is not the same as a gap of one tier in a category the company cannot operate without. Ranking by gap alone sends you to work on the largest number rather than the most consequential one.

Where small businesses actually score

Patterns repeat enough to be worth stating, with one important boundary: these are AEGITz field observations from assessments, not published industry benchmarks.

PROTECT scores highest, for the reason above. The tools got bought.

IDENTIFY scores lower than people expect, and it is the one that blocks everything else. Asset inventory in particular. A company that cannot list its systems, its data, and its third-party connections cannot meaningfully assess risk, cannot answer a questionnaire, and cannot scope an incident. Visibility precedes governance. Governance without visibility is mostly policy.

DETECT tends to have a specific shape: adequate during business hours, absent after them. Which is a problem, given when incidents tend to run.

RECOVER is where the gap between belief and reality is widest. Backups exist. Recovery has never been timed. Almost every company scores itself higher here than a test would support, and the first honest restore measurement is the moment that becomes obvious.

GOVERN is usually the lowest and it is usually the one that, once addressed, improves the others without buying anything.

Doing this without turning it into a project

The objection to frameworks in a small business is that they consume time the company does not have and produce documents nobody reads. That objection is often correct, and it is a failure of scoping rather than of the framework.

A profile for a company under two hundred people is a conversation, not an engagement. Twenty-two categories, scored current and target, with criticality, in a couple of hours with the right three or four people in the room. The output is a ranked list.

Then the discipline is in what happens next. Take the top three by priority score and give each an owner and a date. Not the top fifteen. Three. Review at the quarterly technology review and rescore annually.

A profile that gets rescored annually is worth more than a perfect one produced once. The trend line is the actual product.

What it gives you commercially

Three things, and they are the reason to do this even if security is not currently keeping anyone awake.

It answers the questionnaire. Enterprise customers increasingly ask which framework you align to, and a current profile is a better answer than a list of products.

It changes the insurance conversation from an annual scramble into a review of a document you already maintain.

And it gives leadership a way to make a decision about security spending that is not driven by whichever vendor presented most recently. The profile turns the question from should we buy this into which gap does this close, and how does that gap rank against the others. That is a materially better question, and it is the one a CFO can actually engage with.

The profile workbook

Twenty-two categories across all six functions, each described in terms of what it means inside a small business rather than in framework language, with current, target, criticality, and an automatic priority ranking.

Score it honestly. The value is in the gaps, and a profile that flatters you produces a plan that protects nothing.

Put this into practice

AEGITz NIST CSF 2.0 Small Business Profile

Use the working resource connected to this guide. No sales gate and no dead-end file link.

Download Excel workbookView resource details

Related reading

Keep following the decision.

Need help applying it?

Bring the real operating problem.

Build a practical security profile