Boards ask a simple question — how secure are we? — and usually receive an answer in somebody else’s vocabulary. A managed service provider’s dashboard, an insurer’s questionnaire, a vendor’s maturity score. None of them line up, and none of them can be compared year on year.
What changed in version 2.0
NIST published the Cybersecurity Framework 2.0 in February 2024. It kept the five familiar functions — Identify, Protect, Detect, Respond, Recover — and added a sixth, Govern, which covers strategy, roles and responsibilities, policy, oversight and supply-chain risk. It also widened its intended audience from critical infrastructure to organisations of every size.
“Govern answers the question every board is really asking: who owns this, and how would we know if it was going wrong?”
Profiles and tiers, in plain terms
A current profile describes what you do today against each outcome in the framework. A target profile describes what you want to do. The gap between them is your roadmap. Tiers describe how rigorous your approach is overall, from partial to adaptive. None of this requires a big programme; for a smaller organisation, it can fit on one page.
Related engagement A maturity baseline the board could actually read →How to report it
Show the six functions, current and target tier for each, and the three things that will move the most in the next quarter, each with an owner. Repeat it every quarter in the same format. The value is not the score; it is the comparison.
For the technical detail underneath, the CIS Controls v8.1 give concrete safeguards that map onto CSF outcomes. Implementation Group 1 is a practical first target for most smaller organisations.