Business Core · Technology · Module
Security
Protecting the estate as a capability: knowing what is worth attacking, holding a baseline of controls, managing who can get in, and being able to recover.
The idea
How it works
Security is often presented as a technical specialism and decided as a budget line, which leaves the middle — what the organisation is protecting, from whom, and to what standard — unanswered. The six functions of the NIST Cybersecurity Framework (govern, identify, protect, detect, respond, recover) are a useful checklist because they make that middle explicit, and because they give recovery the same standing as prevention.
Security risk is operated here and reported upward. The appetite for it is set in Governance, alongside the organisation’s other risks; the regulatory handling of a breach, including notification, sits with Compliance under incident response; and the assets themselves are listed once, in Business Assets. What this module holds is the capability: the threat picture, the controls, access, and the ability to restore.
Working with it
In practice
- 01
Start from what an attacker would want
Customer data, payment flows, credentials, and systems whose loss would stop trading. The registers say what exists; this says what to protect first.
- 02
Adopt a recognised baseline
ISO/IEC 27001 Annex A or the CIS Controls give a starting set that others have tested. Tailor it; there is little to gain from inventing one.
- 03
Treat identity as the perimeter
With most systems rented and reached over the internet, who can sign in, with what, and to what, is where a large share of breaches begin.
- 04
Test the restore, not the backup
A backup that has never been restored is a hypothesis. Recovery time is known only once it has been measured.
One level in
The components of security
A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.
Threat model
What is worth protecting, who might want it, and the plausible routes by which harm could arrive.
LearnSecurity control baseline
The recognised set of controls adopted, tailored to the threats, with the honest status of each.
LearnIdentity and access arrangements
How people and systems sign in, what privileged accounts exist, and how access follows people as they join, move and leave.
LearnBackup and recovery plan
What is backed up, how quickly each critical system must return, and dated evidence that restoring works.
Learn
A large share of breaches begin with a credential, and many recoveries fail at the restore. Put the effort where both are decided.
The other modules in technology
The technology estate
What systems the organisation runs, how they connect, and the few principles that decide what may be added to them.
LearnBuild, buy or subscribe
Deciding, for each capability, whether to build it, license it or rent it as a service — and recording why, so the reasoning can be revisited.
LearnAI and automation
Where AI and automation are used, who remains accountable for what they do, how well they are shown to work, and what risk each use carries.
LearnTechnical debt and renewal
What the estate owes to decisions made earlier, which of those debts are worth repaying, and how ageing systems are replaced without stopping the business.
Learn