How to Improve Information and Cyber Security

Cyber security threats have grown not only in number but in complexity and precision. Ransomware, phishing, an external cyber attack and insider threats now form a persistent danger to organisations of all sizes. As digital transformation accelerates, so too must the defences that protect critical information assets.

Recent cyberattacks that have severely affected organisations include:

  • Marks and Spencer

  • The Coop

  • Harrods

These attacked have caused chaos, reportedly wiping £1 billion off the value of Marks and Spencer and putting Coop customers at risk of fraud. There is also the significant reputational impact on these organisations these attacks have caused.

What can organisations do to protect themselves from similar risks and issues?

 

Establishing a Cyber Security Framework

Effective cybersecurity begins with an overarching framework.

Whether following NIST, ISO/IEC 27001, or CIS Controls, adopting a structured approach ensures that defences are comprehensive, systematic, and measurable. A good framework aligns security efforts with organisational goals and facilitates better decision-making.

There are many different cybersecurity frameworks and organisations should choose the one that suits them best.

 

Different Cyber Security Frameworks

Here’s a discussion and comparison of several prominent cybersecurity frameworks:

Cyber security frameworks are sets of guidelines, best practices, and standards designed to help organisations manage their cybersecurity risks. They provide a structured approach to establishing, implementing, maintaining, and continually improving an organisation’s security posture. Choosing the right framework depends on various factors, including the organisation’s size, industry, regulatory requirements, risk appetite, and available resources.

Here are some widely adopted cybersecurity frameworks:

 

NIST Cybersecurity Framework (CSF)

  • Origin: Developed by the National Institute of Standards and Technology (NIST) in the United States.

  • Focus: Risk-based and flexible framework applicable to a wide range of organisations and industries, initially designed for critical infrastructure.

  • Structure: Organised around five core functions:

    • Identify: Developing an understanding of the organisation’s cyber security risk to systems, assets, data, and capabilities.

    • Protect: Developing and implementing appropriate safeguards to ensure the delivery of critical services.

    • Detect: Developing and implementing appropriate activities to identify the occurrence of a cybersecurity event.

    • Respond: Developing and implementing appropriate activities to take action regarding a detected cybersecurity incident.

    • Recover: Developing and implementing appropriate activities to maintain plans for resilience and to restore any capabilities or services that were8 impaired due to a cybersecurity incident.

  • Key Features: Voluntary, flexible, and adaptable; emphasises a common language for discussing and managing cybersecurity risk; provides a roadmap for improvement; aligns with other standards and frameworks.

  • Strengths: Comprehensive, flexible, widely recognised, promotes risk-based decision-making, good for organisations seeking a structured yet adaptable approach.

  • Weaknesses: Can be high-level and may require significant effort to tailor and implement specific controls; lacks formal certification.

ISO 27001

  • Origin: Developed by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC).

  • Focus: Establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

  • Structure: Based on a Plan-Do-Check-Act (PDCA) cycle, requiring organisations to:

    • Establish an ISMS.

    • Implement and operate the ISMS.

    • Monitor and review the ISMS.

    • Maintain and improve the ISMS.

    • ISO 27001 also includes a comprehensive list of security controls (organisational, people, physical, and technical). The latest version (2022) contains 93 controls across four categories.

  • Key Features: International standard, emphasises a holistic approach to information security management, requires formal certification for compliance, focuses on risk management.

  • Strengths: Globally recognised, provides a structured management system approach, strong emphasis on documentation and continuous improvement, certification demonstrates commitment to security.

  • Weaknesses: Can be bureaucratic and require significant documentation, the broad nature of controls may require interpretation for specific implementation.

CIS (Centre for Internet Security) Critical Security Controls

  • Origin: Developed and maintained by the Centre for Internet Security (CIS), a non-profit organisation. Formerly known as the SANS Top 20.

  • Focus: A prioritised set of actions (“Safeguards”) that organisations can take to improve their cyber security posture and mitigate the most prevalent cyber-attack vectors.

  • Structure: Currently consists of 18 Controls, each with specific Safeguards (153 in total in Version 8). Implementation Groups (IGs) help organisations prioritise controls based on their resources and risk profile (IG1: foundational cyber hygiene, IG2: greater operational complexity, IG3: sophisticated attacks).

  • Key Features: Actionable, prioritised, community-developed, focuses on practical implementation, maps to other frameworks and regulations.

  • Strengths: Practical and prescriptive guidance, easy to understand and implement incrementally, focuses on mitigating known threats, good starting point for organisations with limited resources.

  • Weaknesses: Less comprehensive in management system aspects compared to ISO 27001, may require integration with other frameworks for a complete security program.

Comparison Table

Feature

NIST CSF

ISO/IEC 27001

CIS Critical Security Controls

Origin

USA (NIST)

International (ISO/IEC)

Global Non-profit (CIS)

Focus

Risk Management, Improvement Roadmap

Information Security Management System (ISMS)

Prioritised Technical & Procedural Controls

Approach

Flexible, Outcome-Driven

Process-Oriented, Certification-Based

Prescriptive, Actionable

Structure

5 Functions, Categories, Subcategories

PDCA Cycle, Annex A Controls

18 Controls, Safeguards, Implementation Groups

Formality

Voluntary

Requires Certification

Voluntary

Documentation

Can be tailored to organisational needs

High emphasis on documentation

Focus on implementation steps

Best For

Wide range of organisations, adaptable use

Organisations seeking formal certification

Practical, threat-focused implementation

Management System

Integrated within the 5 Functions

Core focus of the framework

Less emphasis on overall management system

Other Notable Frameworks

  • Cyber Essentials (UK): A UK government-backed scheme providing a baseline of cybersecurity controls for organisations to protect themselves against common online threats. Offers two levels: Cyber Essentials (self-assessment) and Cyber Essentials Plus (independent assessment).

  • SOC 2 (System and Organisation Controls 2): An auditing process that ensures service providers securely manage data to protect the interests of their organisation and the privacy of its clients. Focuses on five “Trust Services Criteria”: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

  • HIPAA (Health Insurance Portability and Accountability Act) Security Rule (USA): Specifically designed for organisations in the healthcare industry to protect Protected Health Information (PHI).

  • PCI DSS (Payment Card Industry Data Security Standard): A mandatory standard for organisations that handle credit card information.

Choosing the Right Framework

The best cybersecurity framework for an organisation depends on its specific needs and context. Organisations may even choose to adopt elements from multiple frameworks to create a hybrid approach that best suits their requirements. Key considerations include:

  • Business Goals and Objectives: What are the organisation’s priorities and how can cybersecurity support them?

  • Industry and Regulatory Requirements: Are there specific regulations or industry standards that the organisation must comply with?

  • Risk Appetite: What level of risk is the organisation willing to accept?

  • Resources and Expertise: What resources (financial, personnel) are available for implementing and maintaining a cybersecurity framework?

  • Organisational Culture: How receptive is the organisation to adopting new processes and controls?

By carefully evaluating these factors, organisations can select and implement a cybersecurity framework that effectively manages their risks and supports their overall business objectives.

 

Risk Assessment: Identifying Vulnerabilities

Before fortifying defences, it’s crucial to understand where the weak spots lie. A thorough risk assessment involves identifying assets, mapping data flows, evaluating potential threats, and scoring vulnerabilities based on likelihood and impact. This prioritisation enables efficient allocation of security resources.

Examples of information or cyber security risks include:

  • phishing attacks

  • insider threats, when employees or other stakeholders maliciously compromise data or information

  • software or hardware failures

  • poor records management and version control

  • network or hacking attempts, or another type of cyber attack

  • the accidental loss or corruption of data and information

  • a failure to maintain appropriate access rights

  • physical security of property like offices, and other repositories of data and information

  • not having an appropriate incident response plan

  • not being able to recognise and act on incidents speedily

 

Caldicott principles

 

 

Security Awareness and Training for All Staff

Humans remain the weakest link in most security chains. Regular, targeted training is essential to equip staff with the knowledge to detect phishing, handle data responsibly, and respond appropriately to security incidents. Real-world simulations can greatly enhance retention and readiness.

The GDPR for example discusses the need for both technical and organisational measures. Organisational measures include training, but also having the right kind of policies, procedures and support in place to help people fulfil their obligations.

 

Implementing Strong Access Controls

The principle of least privilege should govern access rights. Users should only have the minimum access required to perform their roles. Role-based access control (RBAC), coupled with user access reviews, reduces the scope of any potential security incident, and limits potential damage from compromised data and information.

 

Data Encryption: Safeguarding Information in Transit and at Rest

Encryption is non-negotiable in any modern security strategy. Data should be encrypted both in transit (e.g., using TLS) and at rest (e.g., using AES-256). Key management must be handled with precision, ensuring only authorised personnel can decrypt sensitive information.

 

Patch Management and System Updates

Unpatched software is one of the most common entry points for attackers. Organisations must adopt disciplined patch management procedures, including regular vulnerability scanning, timely updates, and testing of patches before deployment in critical systems.

 

Multi-Factor Authentication (MFA)

Passwords alone are no longer sufficient. MFA, which combines something the user knows (password), has (token), or is (biometrics), significantly reduces the risk of unauthorised access. Its implementation across all critical systems is now a baseline requirement. Without it network security cannot be complete or assured.

 

Secure Configuration of Hardware and Software

Default settings often prioritise ease of use over security. Devices and applications should be hardened by disabling unnecessary services, closing unused ports, and applying security baselines tailored to the organisation’s environment.

 

Monitoring, Logging, and Incident Detection

Continuous monitoring of systems, networks, and endpoints is essential to detect anomalies early. Logs should be centralised and retained in secure, tamper-evident storage, enabling rapid forensic analysis in the event of an incident.

 

Response and Recovery Planning

Even the best defences can fail. A well-documented incident response plan enables a swift, coordinated reaction to security breaches, reducing downtime and reputational harm. Recovery plans ensure data can be restored from secure backups with minimal disruption.

 

Vendor and Third-Party Risk Management

Outsourced services and supply chains introduce external risks. Organisations must vet vendors rigorously, require contractual security obligations, and conduct regular audits or assessments to ensure third-party compliance with security expectations.

 

Cloud Security Best Practices

Cloud environments often need specific protections. This includes securing API endpoints, managing identity and access through federated controls, encrypting cloud-stored data, and configuring services to prevent accidental exposure of assets.

Fortunately many cloud providers put cloud security or information and cyber security at the core of their service offer.

 

Regulatory Compliance and Industry Standards

Cyber security and wider information security cannot be decoupled from compliance. Regulations like the GDPR impose strict requirements around data security. Adhering to these not only mitigates legal risk but enhances stakeholder trust and operational discipline.

 

Creating a Culture of Security

Technology alone is insufficient. Security must be embedded into the organisational culture — a shared responsibility upheld by leadership and embraced by every employee. Open communication, transparency in incident reporting, and security champions across departments can help embed this mindset. As noted above, training and clear policies and procedures also play a key role.

Improving information and cyber security is not a one-off project but a continuous, evolving commitment. As threats mutate and technology advances, so too must defences — guided by insight, driven by policy, and reinforced by culture. Cyber criminals will not go away, but there are tools and techniques to prevent them causing harm.