Cyber security threats have grown not only in number but in complexity and precision. Ransomware, phishing, an external cyber attack and insider threats now form a persistent danger to organisations of all sizes. As digital transformation accelerates, so too must the defences that protect critical information assets.
Recent cyberattacks that have severely affected organisations include:
-
Marks and Spencer
-
The Coop
-
Harrods
These attacked have caused chaos, reportedly wiping £1 billion off the value of Marks and Spencer and putting Coop customers at risk of fraud. There is also the significant reputational impact on these organisations these attacks have caused.
What can organisations do to protect themselves from similar risks and issues?
Establishing a Cyber Security Framework
Effective cybersecurity begins with an overarching framework.
Whether following NIST, ISO/IEC 27001, or CIS Controls, adopting a structured approach ensures that defences are comprehensive, systematic, and measurable. A good framework aligns security efforts with organisational goals and facilitates better decision-making.
There are many different cybersecurity frameworks and organisations should choose the one that suits them best.
Different Cyber Security Frameworks
Here’s a discussion and comparison of several prominent cybersecurity frameworks:
Cyber security frameworks are sets of guidelines, best practices, and standards designed to help organisations manage their cybersecurity risks. They provide a structured approach to establishing, implementing, maintaining, and continually improving an organisation’s security posture. Choosing the right framework depends on various factors, including the organisation’s size, industry, regulatory requirements, risk appetite, and available resources.
Here are some widely adopted cybersecurity frameworks:
NIST Cybersecurity Framework (CSF)
-
Origin: Developed by the National Institute of Standards and Technology (NIST) in the United States.
-
Focus: Risk-based and flexible framework applicable to a wide range of organisations and industries, initially designed for critical infrastructure.
-
Structure: Organised around five core functions:
-
Identify: Developing an understanding of the organisation’s cyber security risk to systems, assets, data, and capabilities.
-
Protect: Developing and implementing appropriate safeguards to ensure the delivery of critical services.
-
Detect: Developing and implementing appropriate activities to identify the occurrence of a cybersecurity event.
-
Respond: Developing and implementing appropriate activities to take action regarding a detected cybersecurity incident.
-
Recover: Developing and implementing appropriate activities to maintain plans for resilience and to restore any capabilities or services that were8 impaired due to a cybersecurity incident.
-
-
Key Features: Voluntary, flexible, and adaptable; emphasises a common language for discussing and managing cybersecurity risk; provides a roadmap for improvement; aligns with other standards and frameworks.
-
Strengths: Comprehensive, flexible, widely recognised, promotes risk-based decision-making, good for organisations seeking a structured yet adaptable approach.
-
Weaknesses: Can be high-level and may require significant effort to tailor and implement specific controls; lacks formal certification.
ISO 27001
-
Origin: Developed by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC).
-
Focus: Establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
-
Structure: Based on a Plan-Do-Check-Act (PDCA) cycle, requiring organisations to:
-
Establish an ISMS.
-
Implement and operate the ISMS.
-
Monitor and review the ISMS.
-
Maintain and improve the ISMS.
-
ISO 27001 also includes a comprehensive list of security controls (organisational, people, physical, and technical). The latest version (2022) contains 93 controls across four categories.
-
-
Key Features: International standard, emphasises a holistic approach to information security management, requires formal certification for compliance, focuses on risk management.
-
Strengths: Globally recognised, provides a structured management system approach, strong emphasis on documentation and continuous improvement, certification demonstrates commitment to security.
-
Weaknesses: Can be bureaucratic and require significant documentation, the broad nature of controls may require interpretation for specific implementation.
CIS (Centre for Internet Security) Critical Security Controls
-
Origin: Developed and maintained by the Centre for Internet Security (CIS), a non-profit organisation. Formerly known as the SANS Top 20.
-
Focus: A prioritised set of actions (“Safeguards”) that organisations can take to improve their cyber security posture and mitigate the most prevalent cyber-attack vectors.
-
Structure: Currently consists of 18 Controls, each with specific Safeguards (153 in total in Version 8). Implementation Groups (IGs) help organisations prioritise controls based on their resources and risk profile (IG1: foundational cyber hygiene, IG2: greater operational complexity, IG3: sophisticated attacks).
-
Key Features: Actionable, prioritised, community-developed, focuses on practical implementation, maps to other frameworks and regulations.
-
Strengths: Practical and prescriptive guidance, easy to understand and implement incrementally, focuses on mitigating known threats, good starting point for organisations with limited resources.
-
Weaknesses: Less comprehensive in management system aspects compared to ISO 27001, may require integration with other frameworks for a complete security program.
Comparison Table
|
Feature |
NIST CSF |
ISO/IEC 27001 |
CIS Critical Security Controls |
|
Origin |
USA (NIST) |
International (ISO/IEC) |
Global Non-profit (CIS) |
|
Focus |
Risk Management, Improvement Roadmap |
Information Security Management System (ISMS) |
Prioritised Technical & Procedural Controls |
|
Approach |
Flexible, Outcome-Driven |
Process-Oriented, Certification-Based |
Prescriptive, Actionable |
|
Structure |
5 Functions, Categories, Subcategories |
PDCA Cycle, Annex A Controls |
18 Controls, Safeguards, Implementation Groups |
|
Formality |
Voluntary |
Requires Certification |
Voluntary |
|
Documentation |
Can be tailored to organisational needs |
High emphasis on documentation |
Focus on implementation steps |
|
Best For |
Wide range of organisations, adaptable use |
Organisations seeking formal certification |
Practical, threat-focused implementation |
|
Management System |
Integrated within the 5 Functions |
Core focus of the framework |
Less emphasis on overall management system |
Other Notable Frameworks
-
Cyber Essentials (UK): A UK government-backed scheme providing a baseline of cybersecurity controls for organisations to protect themselves against common online threats. Offers two levels: Cyber Essentials (self-assessment) and Cyber Essentials Plus (independent assessment).
-
SOC 2 (System and Organisation Controls 2): An auditing process that ensures service providers securely manage data to protect the interests of their organisation and the privacy of its clients. Focuses on five “Trust Services Criteria”: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
-
HIPAA (Health Insurance Portability and Accountability Act) Security Rule (USA): Specifically designed for organisations in the healthcare industry to protect Protected Health Information (PHI).
-
PCI DSS (Payment Card Industry Data Security Standard): A mandatory standard for organisations that handle credit card information.
Choosing the Right Framework
The best cybersecurity framework for an organisation depends on its specific needs and context. Organisations may even choose to adopt elements from multiple frameworks to create a hybrid approach that best suits their requirements. Key considerations include:
-
Business Goals and Objectives: What are the organisation’s priorities and how can cybersecurity support them?
-
Industry and Regulatory Requirements: Are there specific regulations or industry standards that the organisation must comply with?
-
Risk Appetite: What level of risk is the organisation willing to accept?
-
Resources and Expertise: What resources (financial, personnel) are available for implementing and maintaining a cybersecurity framework?
-
Organisational Culture: How receptive is the organisation to adopting new processes and controls?
By carefully evaluating these factors, organisations can select and implement a cybersecurity framework that effectively manages their risks and supports their overall business objectives.
Risk Assessment: Identifying Vulnerabilities
Before fortifying defences, it’s crucial to understand where the weak spots lie. A thorough risk assessment involves identifying assets, mapping data flows, evaluating potential threats, and scoring vulnerabilities based on likelihood and impact. This prioritisation enables efficient allocation of security resources.
Examples of information or cyber security risks include:
-
phishing attacks
-
insider threats, when employees or other stakeholders maliciously compromise data or information
-
software or hardware failures
-
poor records management and version control
-
network or hacking attempts, or another type of cyber attack
-
the accidental loss or corruption of data and information
-
a failure to maintain appropriate access rights
-
physical security of property like offices, and other repositories of data and information
-
not having an appropriate incident response plan
-
not being able to recognise and act on incidents speedily

Security Awareness and Training for All Staff
Humans remain the weakest link in most security chains. Regular, targeted training is essential to equip staff with the knowledge to detect phishing, handle data responsibly, and respond appropriately to security incidents. Real-world simulations can greatly enhance retention and readiness.
The GDPR for example discusses the need for both technical and organisational measures. Organisational measures include training, but also having the right kind of policies, procedures and support in place to help people fulfil their obligations.
Implementing Strong Access Controls
The principle of least privilege should govern access rights. Users should only have the minimum access required to perform their roles. Role-based access control (RBAC), coupled with user access reviews, reduces the scope of any potential security incident, and limits potential damage from compromised data and information.
Data Encryption: Safeguarding Information in Transit and at Rest
Encryption is non-negotiable in any modern security strategy. Data should be encrypted both in transit (e.g., using TLS) and at rest (e.g., using AES-256). Key management must be handled with precision, ensuring only authorised personnel can decrypt sensitive information.
Patch Management and System Updates
Unpatched software is one of the most common entry points for attackers. Organisations must adopt disciplined patch management procedures, including regular vulnerability scanning, timely updates, and testing of patches before deployment in critical systems.
Multi-Factor Authentication (MFA)
Passwords alone are no longer sufficient. MFA, which combines something the user knows (password), has (token), or is (biometrics), significantly reduces the risk of unauthorised access. Its implementation across all critical systems is now a baseline requirement. Without it network security cannot be complete or assured.
Secure Configuration of Hardware and Software
Default settings often prioritise ease of use over security. Devices and applications should be hardened by disabling unnecessary services, closing unused ports, and applying security baselines tailored to the organisation’s environment.
Monitoring, Logging, and Incident Detection
Continuous monitoring of systems, networks, and endpoints is essential to detect anomalies early. Logs should be centralised and retained in secure, tamper-evident storage, enabling rapid forensic analysis in the event of an incident.
Response and Recovery Planning
Even the best defences can fail. A well-documented incident response plan enables a swift, coordinated reaction to security breaches, reducing downtime and reputational harm. Recovery plans ensure data can be restored from secure backups with minimal disruption.
Vendor and Third-Party Risk Management
Outsourced services and supply chains introduce external risks. Organisations must vet vendors rigorously, require contractual security obligations, and conduct regular audits or assessments to ensure third-party compliance with security expectations.
Cloud Security Best Practices
Cloud environments often need specific protections. This includes securing API endpoints, managing identity and access through federated controls, encrypting cloud-stored data, and configuring services to prevent accidental exposure of assets.
Fortunately many cloud providers put cloud security or information and cyber security at the core of their service offer.
Regulatory Compliance and Industry Standards
Cyber security and wider information security cannot be decoupled from compliance. Regulations like the GDPR impose strict requirements around data security. Adhering to these not only mitigates legal risk but enhances stakeholder trust and operational discipline.
Creating a Culture of Security
Technology alone is insufficient. Security must be embedded into the organisational culture — a shared responsibility upheld by leadership and embraced by every employee. Open communication, transparency in incident reporting, and security champions across departments can help embed this mindset. As noted above, training and clear policies and procedures also play a key role.
Improving information and cyber security is not a one-off project but a continuous, evolving commitment. As threats mutate and technology advances, so too must defences — guided by insight, driven by policy, and reinforced by culture. Cyber criminals will not go away, but there are tools and techniques to prevent them causing harm.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: