Loading Reisen Cyber Institute…
Loading Reisen Cyber Institute…

NIST CSF
Six verbs. One conversation the board can follow.
The shared language for “are we actually managing cyber risk?”
Who it's for. Any org that needs a map, not just a tool list. Common in US federal supply chains and everywhere else that borrowed the picture.
01
Official-ish
Establish and monitor the organization’s cybersecurity risk management strategy, expectations, and policy.
Monday version
Who owns cyber risk, what “enough” looks like, and whether the program matches the business — not a graveyard of unused policies.
Do this
02
Official-ish
Understand current cybersecurity risks to assets, data, and capabilities.
Monday version
You cannot protect a mystery. Know the systems, data, and vendors that would ruin a quarter if they vanished.
Do this
03
Official-ish
Use safeguards to manage the organization’s cybersecurity risks.
Monday version
Identity, hardening, backups, training — the unglamorous work that keeps Tuesday from becoming an incident.
Do this
04
Official-ish
Find and analyze possible cybersecurity attacks and compromises.
Monday version
Assume something gets through. The question is how long it gets to live rent-free.
Do this
05
Official-ish
Take action regarding a detected cybersecurity incident.
Monday version
Contain, communicate, preserve evidence, and decide — without improvising a press release in Slack.
Do this
06
Official-ish
Restore assets and operations affected by a cybersecurity incident.
Monday version
Getting back to business is a plan, not a vibe. RTO/RPO only count if you have tested them.
Do this
Friendly translation, not legal advice. Always read the official text before you tell an auditor you “basically already do this.”