A meeting in a bright meeting room

Cybersecurity strategy and governance from a maturity assessment

Turn a maturity assessment into a load-bearing strategy and a governance that holds in daily operations.

After a maturity assessment against the CIS Controls, an industrial company needed a solid cybersecurity strategy and a governance that holds in daily operations. ODCUS built both, holistically across the infrastructure on Zero-Trust principles.

Starting point

The maturity was measured, but the translation into a prioritized strategy and a governance with clear roles was missing. Security decisions ran without a shared target picture.

Approach

  • Developed a cybersecurity strategy based on Zero Trust and a holistic view of the infrastructure
  • Established governance with roles, responsibilities and decision paths
  • Documented the strategy and communicated it across all levels
  • Involved team leads and C-level stakeholders
  • Derived a cybersecurity roadmap with priorities from the CIS control gaps

Result

  • A strategy people carry instead of a set of loose measures
  • A governance with clear roles and decision paths
  • A prioritized roadmap along the biggest gaps
  • A shared target picture across business units and management

Frameworks and tools used

NIST CSF 2.0CIS ControlsZero TrustGovernance