Govern and identify
- Name an accountable business owner and define the organization's risk priorities.
- Inventory critical devices, applications, cloud services, administrators, data, and vendors.
- Record legal, contractual, insurance, customer, and operational requirements that affect security decisions.
Protect the obvious attack paths
- Require multifactor authentication, especially for email, finance, administration, remote access, and file storage.
- Use unique credentials and a managed password approach; remove stale accounts and excessive privileges.
- Install supported software updates, protect endpoints, train people to report phishing, and verify high-risk payment or account changes out of band.
- Maintain backups that are separated from ordinary access and test whether important data can actually be restored.
Detect, respond, and recover
Define how employees report suspicious activity, who makes containment decisions, how outside help is reached, which evidence must be preserved, and how critical operations continue. Test the plan with a short scenario at least after major business or system changes.
Use qualified security, legal, insurance, privacy, and regulatory support for the organization's specific risk and incident obligations.
