Business Core · Technology · Module

Security

Protecting the estate as a capability: knowing what is worth attacking, holding a baseline of controls, managing who can get in, and being able to recover.

The idea

How it works

Security is often presented as a technical specialism and decided as a budget line, which leaves the middle — what the organisation is protecting, from whom, and to what standard — unanswered. The six functions of the NIST Cybersecurity Framework (govern, identify, protect, detect, respond, recover) are a useful checklist because they make that middle explicit, and because they give recovery the same standing as prevention.

Security risk is operated here and reported upward. The appetite for it is set in Governance, alongside the organisation’s other risks; the regulatory handling of a breach, including notification, sits with Compliance under incident response; and the assets themselves are listed once, in Business Assets. What this module holds is the capability: the threat picture, the controls, access, and the ability to restore.

Working with it

In practice

  1. 01

    Start from what an attacker would want

    Customer data, payment flows, credentials, and systems whose loss would stop trading. The registers say what exists; this says what to protect first.

  2. 02

    Adopt a recognised baseline

    ISO/IEC 27001 Annex A or the CIS Controls give a starting set that others have tested. Tailor it; there is little to gain from inventing one.

  3. 03

    Treat identity as the perimeter

    With most systems rented and reached over the internet, who can sign in, with what, and to what, is where a large share of breaches begin.

  4. 04

    Test the restore, not the backup

    A backup that has never been restored is a hypothesis. Recovery time is known only once it has been measured.

One level in

The components of security

A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.

  1. Threat model

    What is worth protecting, who might want it, and the plausible routes by which harm could arrive.

    Learn
  2. Security control baseline

    The recognised set of controls adopted, tailored to the threats, with the honest status of each.

    Learn
  3. Identity and access arrangements

    How people and systems sign in, what privileged accounts exist, and how access follows people as they join, move and leave.

    Learn
  4. Backup and recovery plan

    What is backed up, how quickly each critical system must return, and dated evidence that restoring works.

    Learn

A large share of breaches begin with a credential, and many recoveries fail at the restore. Put the effort where both are decided.