{"id":3446,"date":"2024-08-01T11:33:00","date_gmt":"2024-08-01T11:33:00","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=3446"},"modified":"2024-07-30T16:18:12","modified_gmt":"2024-07-30T16:18:12","slug":"5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/","title":{"rendered":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/www.mcafee.com\/en-us\/consumer-corporate\/newsroom\/press-releases\/press-release.html?news_id=366ae340-1dd8-451a-b893-829eb146b43e\">61% of small businesses<\/a> victims of a cyberattack in 2023 lost over $10,000. Learn how to harden your digital defenses with these five NIST CSF 2.0 key points<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">According to the State of SMB Cybersecurity in 2024 report, <a href=\"https:\/\/www.connectwise.com\/globalassets\/media\/asset-docs\/executive-briefs\/the-state-of-smb-cybersecurity-in-2024.pdf\">94% of <\/a><a href=\"https:\/\/www.connectwise.com\/globalassets\/media\/asset-docs\/executive-briefs\/the-state-of-smb-cybersecurity-in-2024.pdf\">small businesses<\/a> (SMBs) have been victims of at least one cybersecurity attack in the past. This marks a 30% increase in just five years.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Too many business owners work hard to build their companies, only to hand over the fruits of their labors to cybercriminals. This is why you must take steps to protect your business in the face of growing cyber threats and increasingly complex technologies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don\u2019t fret. The NIST Cybersecurity Framework (or, more specifically, NIST CSF 2.0) is coming to the rescue. In this article, we&#8217;ll explore five key takeaways that SMB owners like you can learn from this new framework and discover how to implement them to protect your digital assets and infrastructure from the bad guys.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is the NIST Cybersecurity Framework (CSF) 2.0?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The National Institute of Standards and Technology (NIST) released its first major update to the Cybersecurity Framework (CSF) in a decade <a href=\"https:\/\/csrc.nist.gov\/news\/2024\/the-nist-csf-20-is-here\"><\/a><a href=\"https:\/\/csrc.nist.gov\/news\/2024\/the-nist-csf-20-is-here\">in February 2024<\/a>. Unlike its previous incarnation, NIST CSF 2.0 goes beyond <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors?trk=article-ssr-frontend-pulse_little-text-block\" target=\"_blank\" rel=\"noreferrer noopener\">critical infrastructure<\/a> to aid organizations of all sizes and industries in managing and mitigating security risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This new version was developed in response to the U.S. Congress\u2019s <a href=\"https:\/\/www.govinfo.gov\/content\/pkg\/PLAW-115publ236\/pdf\/PLAW-115publ236.pdf\">explicit request in 2018<\/a> to address small business concerns. Six years later, the NIST Cybersecurity Framework 2.0 was born.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The update throws a lifeline to the growing number of small and mid-size businesses in the crosshairs of cybercriminals due to their limited resources to invest in robust security protections. It\u2019s a new set of risk-based best practices aimed at all businesses, with a specific focus on SMBs, so they can effectively protect their data and reduce the risk of attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST CSF 2.0 is divided into six functions, providing organizations guidance for effectively managing their cybersecurity risk:<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"1\">\n<li><strong>Govern<\/strong>. Helps businesses to build and monitor a risk management strategy, expectations, and policy.<\/li>\n\n\n\n<li><strong>Identify<\/strong>. Explains how businesses should manage cybersecurity risks.<\/li>\n\n\n\n<li><strong>Protect<\/strong>. Details ways to minimize and contain security incidents.<\/li>\n\n\n\n<li><strong>Detect<\/strong>. Illustrates how to identify attacks and security issues.<\/li>\n\n\n\n<li><strong>Respond<\/strong>. Describes how to react to potential attacks promptly.<\/li>\n\n\n\n<li><strong>Recover<\/strong>. Provides guidance on how to recover in case the worst happens.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"786\" height=\"668\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-2_0-shadow.png\" alt=\"The NIST Cybersecurity Framework 2.0 wheel outlining the core functions\" class=\"wp-image-3451\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-2_0-shadow.png 786w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-2_0-shadow-300x255.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-2_0-shadow-560x476.png 560w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: The screenshot shows the Functions of the NIST CSF 2.0 Framework<\/em>.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/CSWP\/NIST.CSWP.29.pdf\">According to NIST<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe Functions should be addressed concurrently. Actions that support Govern, Identify, Protect, and Detect should all happen continuously, and actions that support Respond and Recover should be ready at all times and happen when cybersecurity incidents occur.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">What\u2019s Changed? A Look at NIST\u2019s CSF Version 1.1 to Version 2.0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While the biggest change in version 2.0 is the shift from mainly focusing on critical infrastructure to include other types of businesses, including SMBs, it wasn\u2019t the only notable change. Another critical adjustment was the inclusion of the new function category: Govern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, we aren\u2019t going to get too into the weeds here about what\u2019s changed from version 1.1 to 2.0. Instead, our goal is to provide a few examples of how this new version of the NIST Cybersecurity Framework can help SMBs boost their cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, if you\u2019re intrigued by the details and want to learn more about the changes from NIST CSF 1.1 to NIST CSF 2.0, check out the following video:<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"What Changed? - NIST Cybersecurity Framework 2.0\" width=\"940\" height=\"529\" src=\"https:\/\/www.youtube.com\/embed\/WrAecu8q82U?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">NIST CSF 2.0: 5 Small Businesses Takeaways<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the actual cybersecurity landscape, no one is too small to become the next cyber attack victim. When money is tight, and a report shows that attacks increased globally by <a href=\"https:\/\/blog.checkpoint.com\/research\/check-point-research-reports-highest-increase-of-global-cyber-attacks-seen-in-last-two-years-a-30-increase-in-q2-2024-global-cyber-attacks\/\">30% year-on-year<\/a> in Q4 2024, gearing up for the fight isn\u2019t easy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, we\u2019ve listed five NIST CSF 2.0 key takeaways that can help SMBs like yours dodge a few bullets in their uphill battle to ward off the bad guys. Are you a busy bee? Don\u2019t worry. We\u2019ve summarized the core concepts in the table below.&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>NIST CSF 2.0 SMBs Takeaways<\/strong><strong><\/strong><\/td><td><strong>NIST CSF 2.0 Examples<\/strong><strong><\/strong><\/td><\/tr><tr><td>1. Identify, Understand, and Prioritize Your Risks<\/td><td>Run risk assessments. Analyze the risks you\u2019ve identified. Hash out a plan of action.<\/td><\/tr><tr><td>2. Protect Sensitive Data and Access<\/td><td>Protect data in transfer. Implement strong authentication and restrict access. Prevent data loss.<\/td><\/tr><tr><td>3. Prioritize Your Supply Chain Risk Management<\/td><td>Put security at the heart of your software development process. Take steps to mitigate vendor-related risks. Implement a supply chain risk management framework.<\/td><\/tr><tr><td>4. Embed Security Into All Your Processes<\/td><td>Sign your codes using a code signing certificate (and install only signed software). Protect your containers with an SSL\/TLS certificate. Scan your software and websites.<\/td><\/tr><tr><td>5. Have Robust Response and Recovery Plans<\/td><td>Create an incident response plan. Set up a recovery plan. Implement both to use when things go south.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">NIST CSF 2.0 Takeaway #1. Identify, Understand, and Prioritize Your Risks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Understanding and prioritizing risks is paramount for organizations with limited budgets that cannot afford to splash out on each threat. The govern and identify functions of the NIST Cybersecurity Framework help you pick the right strategy for your business and identify and prioritize the most critical threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use NIST CSF\u2019s tailored pathways and numerous <a href=\"https:\/\/www.nist.gov\/document\/csf-20-implementations-pdf\">implementation examples<\/a> to draft a cybersecurity strategy and policies that align with your company\u2019s mission. To do so:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Run Risk Assessments<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2024-01\/22_1201_safecom_guide_to_cybersecurity_risk_assessment_508.pdf\">cyber risk assessment<\/a> allows you to examine the risks to your organization\u2019s operations, IT and digital assets, and people. Businesses take risks every day \u2014 this is just part of how business works. But for SMBs, a <em>faux pas<\/em> (misstep) can mean the end of it. Proactively detecting and assessing potential risks that could negatively impact your operations, finances, and reputation will help you make the right decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, SMB malware infections <a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2024_smb-cyber-infections-rising-amid-resurgence-of-attacks-leveraging-microsoft-excel-kaspersky-reports\">r<\/a><a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2024_smb-cyber-infections-rising-amid-resurgence-of-attacks-leveraging-microsoft-excel-kaspersky-reports\">ose<\/a><a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2024_smb-cyber-infections-rising-amid-resurgence-of-attacks-leveraging-microsoft-excel-kaspersky-reports\"> by 5%<\/a> in Q1 2024. Is this something that could happen to you? Hopefully not, but it\u2019s always a possibility. These days, employees often use their personal devices for work. This increases the risk of <a href=\"https:\/\/sectigostore.com\/blog\/malware-analysis-what-it-is-how-it-works\/\"><\/a><a href=\"https:\/\/sectigostore.com\/blog\/malware-analysis-what-it-is-how-it-works\/\">introducing<\/a> malware to your larger network<a href=\"https:\/\/sectigostore.com\/blog\/malware-analysis-what-it-is-how-it-works\/\"><\/a>, which can quickly spread across your entire organization like wildfire.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"555\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow-1024x555.png\" alt=\"A basic diagram illustrating how personal device (BYOD) pose network threats\" class=\"wp-image-3453\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow-1024x555.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow-300x163.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow-560x304.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow-940x510.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/uncontrolled-personal-devices-nist-csf-2_0-shadow.png 1210w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: The screenshot shows an example of a business risk.<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">Analyze the Risks You\u2019ve Identified<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Once you\u2019ve compiled a comprehensive list of potential risks, analyze their probability of occurring and any possible impacts. <a href=\"https:\/\/www.lastpass.com\/resources\/reports\/smb-commercial-cybersecurity-report\">47% of U.S.-based SMBs<\/a> polled by LastPass in 2024 suffered a data breach due to a compromised password. How likely is it that something like this will happen to you?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Analyze your situation and <a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/protecting-personal-information-guide-business#takestock\">in<\/a><a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/protecting-personal-information-guide-business#takestock\">ventory the sensitive data<\/a> (e.g., credit card numbers, passwords), critical hardware, systems, and software you need to protect. <a href=\"https:\/\/www.geeksforgeeks.org\/risk-ratio-formula-calculation-examples-benefits\/\">Assign a ratio to each risk<\/a> (e.g., =1; &gt;1; &lt;1). It\u2019ll help you prioritize efforts and focus on the right threats.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Hash Out a Plan of Action<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Involve key stakeholders in the <a href=\"https:\/\/www.ibm.com\/topics\/risk-management\">risk management<\/a> plan&#8217;s development activities. This will help you minimize the chances of a security incident, reduce its impact should the worst happen, and get their buy-in. So, what does all this look like from a high-level perspective?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Set up policies and processes,<\/li>\n\n\n\n<li>Determine who will monitor the identified risks, and<\/li>\n\n\n\n<li>Figure out how these crucial tasks will be achieved.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, no matter how small, SMBs must abide by industry and country regulations and requirements. The <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\">European Union\u2019s General Data Protection Regulation<\/a> (GDPR) and the global <a href=\"https:\/\/sectigostore.com\/blog\/what-to-know-about-pci-dss-4-0-and-4-0-1\/\">Payment Card Industry Data Security Standards<\/a> (PCI DSS) version 4.0.1 are just two examples of key regulations and standards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ensure your employees understand them and set up a process to track compliance. It&#8217;ll keep you out of trouble and avoid <a href=\"https:\/\/www.enforcementtracker.com\/\">costly fines<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sounds complicated? It doesn\u2019t have to be. Once again, the NIST Cybersecurity Framework 2.0 comes to the rescue by pointing to some of NIST&#8217;s additional resources:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>NIST SP 800-37: <a href=\"https:\/\/doi.org\/10.6028\/NIST.SP.800-37r2\">Risk Management Framework for Information Systems and Organizations<\/a>.<\/li>\n\n\n\n<li>NIST SP 800-30: <a href=\"https:\/\/doi.org\/10.6028\/NIST.SP.800-30r1\">Guide for Conducting Risk Assessments from the NIST Risk Management Framework<\/a> (RMF).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">NIST CSF 2.0 Takeaway #2. Protect Sensitive Data and Access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Data is your most valuable asset if your company is like most businesses. Securing that data and controlling who has access to it is paramount to its value and integrity.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cyberreadinessinstitute.org\/news-and-events\/small-and-medium-sized-businesses-face-major-obstacles-in-achieving-cyber-readiness-the-state-of-smb-cyber-readiness-2024\/\">Over half of the survey respondents<\/a> in the Cyber Readiness Institute\u2019s 2024 report (\u201cThe State of Cyber Readiness Among Small and Medium-Sized Businesses\u201d) consider <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-phishing-email-5-examples-of-phishing-emails-and-how-to-avoid-them\/\">phishing<\/a>, <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/security\/what-is-business-email-compromise-bec.html\">business <\/a><a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/security\/what-is-business-email-compromise-bec.html\">email <\/a><a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/security\/what-is-business-email-compromise-bec.html\">compromise<\/a> (BEC) attacks, and <a href=\"https:\/\/sectigostore.com\/blog\/what-is-ransomware-and-how-does-it-work\/\">ransomware<\/a> the top threats for SMBs. All these attacks can result in bad guys getting their hands on your most valuable asset. So, what can you do to protect your data?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some examples of the NIST Cybersecurity Framework 2.0\u2019s suggested measures to boost the security of your sensitive data and access.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Protect Data Transfers via Encrypted Connections<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The bad news: <a href=\"https:\/\/news.sophos.com\/en-us\/2024\/03\/12\/2024-sophos-threat-report\/\">90% of attacks<\/a> reported to Sophos in 2023 involved data theft. The good news: You can protect the confidentiality and integrity of communications and sensitive information transmitted over the internet (e.g., credit card details during online payment transactions, emails, and <a href=\"https:\/\/www.ibm.com\/topics\/api\">API connections<\/a>) with <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/end-to-end-encryption-E2EE\">end-to-end encryption<\/a>. This is possible by installing trusted <a href=\"https:\/\/sectigostore.com\/ssl-certificates\">secure socket layer\/<\/a><a href=\"https:\/\/sectigostore.com\/ssl-certificates\">transport layer security (SSL\/TLS) certificate<\/a>s on your web servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you encrypt your data transmissions between a client and a server with an <a href=\"https:\/\/sectigostore.com\/blog\/ssl-vs-tls-decoding-the-difference-between-ssl-and-tls\/\">SSL\/TLS protocol<\/a>, the browser confirms to the user that the connection is secure by replacing &#8220;http&#8221; with the secure &#8220;<a href=\"https:\/\/sectigostore.com\/blog\/port-443-everything-you-need-to-know-about-https-443\/\">https<\/a>\u201d protocol. This creates a secure communication channel between the two parties where everything is encrypted. This means that unless the attacker gets hold of the user\u2019s private key, all he\u2019ll see is gibberish nonsense when he tries to intercept the data.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"557\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow-1024x557.png\" alt=\"NIST Cybersecurity Framework 2.0 graphic: An illustration showing how SSL\/TLS protects data in transit\" class=\"wp-image-3454\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow-1024x557.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow-300x163.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow-560x305.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow-940x511.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/ssl-tls-data-protection-shadow.png 1342w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: SSL\/TLS certificates enable the use of SSL\/TLS protocols to secure sensitive data in transit.<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">Implement Strong Authentication and Restrict Access<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In 2023, IBM reported a <a href=\"https:\/\/www.ibm.com\/reports\/threat-intelligence\">71% increase<\/a> in the attacks that used stolen or compromised credentials. It\u2019s no secret that bad guys are after your passwords. Thus, relying only on one solution isn&#8217;t enough. Use a multi-layered approach instead.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enable <a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/guidance-topic\/multi-factor-authentication\">multi-factor authentication<\/a> (MFA) and use a password manager to generate <a href=\"https:\/\/www.cisa.gov\/secure-our-world\/use-strong-passwords\">strong passwords<\/a> and shield them from crooks.<\/li>\n\n\n\n<li>Take authentication security one step further with <a href=\"https:\/\/sectigostore.com\/blog\/what-is-pki-a-laymans-guide-to-public-key-infrastructure\/\">public key infrastructure<\/a> (PKI)-based <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-digital-identity-why-does-it-matter\/\">digital identity<\/a>. This <a href=\"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/\">passwordless approach<\/a> shields users&#8217; accounts against <a href=\"https:\/\/www.kaspersky.com\/resource-center\/definitions\/brute-force-attack\">brute-force attacks<\/a> by letting users automatically authenticate with a <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-pki-certificate\/\">client certificate<\/a> and a <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-private-key-in-cybersecurity\/\">private key<\/a>.<\/li>\n\n\n\n<li>Stay away from default passwords.<\/li>\n\n\n\n<li>Give users access to data, resources, and systems they need to do their work (i.e., the <a href=\"https:\/\/www.paloaltonetworks.com\/cyberpedia\/what-is-the-principle-of-least-privilege\">principle of least privilege<\/a>).<\/li>\n\n\n\n<li>Patch your software and systems regularly. Check your <a href=\"https:\/\/sectigostore.com\/blog\/how-to-perform-a-website-security-check\/\">website for vulnerabilities<\/a> and fix them before the attackers find them.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Prevent Data Loss<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Data is one of your most precious assets. However, considering that the 2024 Black Kite report shows that <a href=\"https:\/\/blackkite.com\/wp-content\/uploads\/2024\/05\/BlackKite_Report_Ransomware-2024.05.14.pdf\">31% of ransomware attacks analyzed impacted<\/a><a href=\"https:\/\/blackkite.com\/wp-content\/uploads\/2024\/05\/BlackKite_Report_Ransomware-2024.05.14.pdf\"><\/a><a href=\"https:\/\/blackkite.com\/wp-content\/uploads\/2024\/05\/BlackKite_Report_Ransomware-2024.05.14.pdf\"> SMBs with revenues of &lt;$20 million,<\/a> it&#8217;s also one of the assets that&#8217;s most at risk. What makes things worse is that Veeam&#8217;s 2024 Ransomware Trend survey reports that businesses hit by such an attack lose an average of <a href=\"https:\/\/www.veeam.com\/blog\/announcing-rw24.html\">18% of their data<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protect \u201cyour precious,\u201d as Gollum in <em>The Lord of the Rings<\/em> would say. Back up your data. For instance, if you have an online shop, use an automated backup tool like <a href=\"https:\/\/sectigostore.com\/codeguard\/backup\">CodeGuard Backup<\/a>. This handy solution will even scan your website for malware. Moreover, don\u2019t forget to enable <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/full-disk-encryption-FDE\">full-disk encryption<\/a> on your devices and <a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/training\">t<\/a><a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/training\">rain your employees<\/a> to recognize and properly respond to cyber threats.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">NIST CSF 2.0 Takeaway #3. Prioritize Your Supply Chain Risk Management<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST Cybersecurity Framework 2.0 update emphasizes the focus on <a href=\"https:\/\/www.synopsys.com\/glossary\/what-is-software-supply-chain-security.html\">supply chain<\/a> risk management. This is particularly important for SMBs relying heavily on third-party vendors, suppliers, and partners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what if they aren\u2019t as reliable as they seem? Disaster is just around the corner. In January 2024, an attacker stole more than <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/email-addresses-of-15-million-trello-users-leaked-on-hacking-forum\/\">15 million<\/a><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/email-addresses-of-15-million-trello-users-leaked-on-hacking-forum\/\"> <\/a><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/email-addresses-of-15-million-trello-users-leaked-on-hacking-forum\/\">profiles<\/a> (including info on users\u2019 email addresses) from an unsecured Trello API. Due to the popularity of this online project management tool, the number of businesses impacted was massive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, what does NIST CSF 2.0 suggest in these situations?<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Put Security at the Heart of Your Software Development Process<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Follow <a href=\"https:\/\/codesigningstore.com\/secure-coding-practices-to-implement\">secure coding best practices<\/a>, perform vulnerability assessments from the design to the release stage, and implement <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/authentication\">secure authentication<\/a>. This approach will help you identify and fix flaws earlier, ensure that only verified and <a href=\"https:\/\/sectigostore.com\/blog\/the-difference-between-authentication-and-authorization-explained-in-detail-by-a-security-expert\/\">authorized users<\/a> can access data, and save you money, time, and resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automate security testing with <a href=\"https:\/\/www.synopsys.com\/glossary\/what-is-sast.html\">static (SAST) and dynamic (DAST)<\/a> application testing tools, and include risk management processes into your <a href=\"https:\/\/aws.amazon.com\/what-is\/sdlc\/\">software development lifecycle<\/a> (SDLC). It\u2019ll enable you to identify and effectively manage supply chain risks in a timely manner.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Take Steps to Mitigate Vendor-Related Risks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.synopsys.com\/software-integrity\/resources\/analyst-reports\/open-source-security-risk-analysis.html#UXsectionVulnerabilities\">96% of the code base<\/a> analyzed by Synopsys contained open-source materials. A single application had an average of 526 open-source components. Request a <a href=\"https:\/\/www.thesslstore.com\/blog\/sbom-an-up-close-look-at-a-software-bill-of-materials\/\">software bill of materials<\/a> (SBOM) from your suppliers and create one for your software. An SBOM will list every bit of your code so that you can quickly identify dependencies, vulnerabilities, and fixes.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same report shows that 49% of open-source components analyzed weren&#8217;t updated in the last two years. An unmaintained project is a vulnerable project. Knowing this, use a <a href=\"https:\/\/www.synopsys.com\/glossary\/what-is-software-composition-analysis.html\">software composition analysis<\/a> (SCA) tool to scan your software for vulnerable third-party components automatically. Last but not least, follow <a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/guidance-topic\/choosing-vendorservice-provider\">the NIST CSF 2.0 guide<\/a> to learn how to choose a reliable service provider\/vendor.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Implement a Supply Chain Risk Management Framework<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The latest Verizon DBIR report shows that <a href=\"https:\/\/www.verizon.com\/business\/resources\/infographics\/2024-dbir-infographic.pdf\">15% of breaches<\/a> involved a third party causing direct or indirect software supply chain security issues. We get it: As an SMB, you must take the risk of collaborating with third-party suppliers and vendors, or you can\u2019t survive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The solution? Adhere to a <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.1305.ipd.pdf\">supply chain risk management framework<\/a> to outline the policies, procedures, controls, and recovery plans to mitigate these risks. Does it sound familiar? Yup, it has a similar structure to the NIST CSF 2.0. The best of it? You can easily integrate the two frameworks for ultimate protection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">NIST CSF 2.0 Takeaway #4. Embed Security into All of Your Processes<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.connectwise.com\/resources\/smb-research-2024\">78% of SMBs<\/a> admitted to ConnectWise that a severe cybersecurity incident could put them out of business for good. And rightly so, considering that IBM reports the average global cost of a data breach reached <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\">$4.45 million<\/a> in 2023.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Integrating security into every aspect of a business will minimize the chances of joining the SMBs and <a href=\"https:\/\/startupgraveyard.io\/\">start-ups graveyard<\/a>. <a href=\"https:\/\/www.smith-howard.com\/how-smbs-can-take-advantage-of-the-nist-cybersecurity-framework-2-0\/\">NIST <\/a>Cybersecurity Framework 2.0\u2019s structured approach facilitates this integration process without breaking the bank.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Sign Your Codes Using a Code Signing Certificate (and Install Only Signed Software)<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In March 2023, a software supply chain attack started by an infected software application <a href=\"https:\/\/www.mandiant.com\/resources\/blog\/3cx-software-supply-chain-compromise\">set the stage<\/a> for a second attack. If you are a software development company, <a href=\"https:\/\/codesigningstore.com\/how-to-sign-an-exe-with-a-digital-certificate\">signing your code<\/a> with a <a href=\"https:\/\/sectigostore.com\/code-signing\">trusted code signing certificate<\/a> will help protect you and your customers on the other end of the supply chain from malware and data breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do you use third-party software? Before you download or install it, <a href=\"https:\/\/codesigningstore.com\/how-to-create-and-verify-windows-authenticode-signature\">ensure it\u2019s signed<\/a>, too. This way, if a malicious actor has modified the app since it was signed, your company\u2019s users will get a security warning and the installation will stop.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Protect Your Containers With an SSL\/TLS Certificate<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Did you know that the humble <a href=\"https:\/\/sectigostore.com\/ssl-types\/ev-ssl-certificates\">SSL\/TLS certificate<\/a> can also help protect <a href=\"https:\/\/www.datadoghq.com\/knowledge-center\/containerized-applications\/\">container apps<\/a> (i.e., a standalone, executable package including everything needed to run an application) by securing their connections? Yup, you can secure the communication between Docker clients, daemons, hosts, and containers with an <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/sectigo-ssl\">SSL\/TLS certificate<\/a>. Ask the vendors you work with that use containers to do the same.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This step is crucial because containers often share a common operating system. A single vulnerable container can affect the whole infrastructure and, consequently, your entire software supply chain.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"562\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow-1024x562.png\" alt=\"An illustration showing how SSL\/TLS protects Docker-related data in transit\" class=\"wp-image-3455\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow-1024x562.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow-300x165.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow-560x307.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow-940x516.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/docker-secure-connections-shadow.png 1079w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: The screenshot shows how SSL\/TLS certificates protect the containers\u2019 communications, too. The Ubuntu logo came from the Ubuntu.com\/resources page.<\/em><\/figcaption><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">Scan Your Software and Websites<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.balbix.com\/resources\/ponemon-report-cyber-risk-in-the-age-of-ai\/?utm_source=website&amp;utm_medium=topbar\">54% of organizations<\/a> polled by Ponemon Institute for Balbix\u2019s 2024 State of Enterprise Cyber Risk in the Age of AI report consider unpatched vulnerabilities their most important concern. However, only 49% of respondents run vulnerability scans once a week.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adopt a <a href=\"https:\/\/www.entrust.com\/cybersecurity-institute\/reports\/2024-state-of-zero-trust-exec-summary\">zero-trust<\/a> mindset. Trust no one. Did you download a new software or a critical update? Check if it has been digitally signed by a verified company and scan the executable file with a reputable antivirus before installing it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do you own a website? Use an <a href=\"https:\/\/sectigostore.com\/blog\/how-to-perform-a-website-security-check\/\">automated website security checker tool <\/a>to scan it for malware, vulnerabilities, and viruses regularly. Software like <a href=\"https:\/\/sectigostore.com\/sitelock.aspx\">SiteLock<\/a> and <a href=\"https:\/\/sectigostore.com\/website-security\/hacker-guardian-pci-scan-control-center\">HackerGuardian<\/a> come with a <a href=\"https:\/\/sectigostore.com\/website-security\">plethora of features<\/a> that\u2019ll keep your website and data secure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">NIST CSF 2.0 Takeaway #5 Have Robust Response and Recovery Plans<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber incidents and supply chain attacks happen all the time. Just open a news website and you&#8217;ll likely find one that is making headlines. Attackers are even <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-crowdstrike-fixes-target-companies-with-malware-data-wipers\/\">hiding malware in phony patches and updates<\/a> that promise to fix the CrowdStrike update glitch that impacted millions of Microsoft hosts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While most SMB attacks don&#8217;t make news headlines, today&#8217;s threat landscape can&#8217;t be ignored. Effective and well-thought-out response and recovery plans can be the difference between life and death, above all for an SMB.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Create an Incident Response Plan<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Are you among the <a href=\"https:\/\/www.huntress.com\/resources\/the-state-of-cybersecurity-for-mid-sized-businesses-in-2023\">47% of organizations<\/a> lacking an incident response plan? If so, it\u2019s time to act. After you&#8217;ve identified a business champion responsible for keeping the plan up to date, build an <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/incident-response-team\">incident<\/a><a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/incident-response-team\"> response team<\/a>, and list their contact details, roles, and responsibilities. Don&#8217;t forget to describe what will be reported, when, and how.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We won\u2019t get into the nitty-gritty here as the NIST Cybersecurity Framework 2.0 already includes an extensive list of resources and guides such as the:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/Incident-Response-Plan-Basics_508c.pdf\">NIST Incident Response Plan Basics<\/a>,<\/li>\n\n\n\n<li><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-61r2.pdf\">NIST Computer Security Incident Handling Guide<\/a>, and<\/li>\n\n\n\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/resources\/data-breach-response-guide-business\">Data Breach Response: A Guide for Businesses<\/a>.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Set Up a Recovery Plan<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">After you\u2019ve tested your new incident response plan, offer your business a present. OK, it ain&#8217;t Christmas, but having a thorough <a href=\"https:\/\/www.ready.gov\/business\/emergency-plans\/recovery-plan\">incident recovery <\/a><a href=\"https:\/\/www.ready.gov\/business\/emergency-plans\/recovery-plan\">plan<\/a> is a gift for all occasions and seasons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pinpoint potential threats and their impact(s) on your company and an incident recovery team. Next, determine possible recovery strategies. For example, if an <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/sectigo-multi-domain-ucc-ssl\">SSL\/TLS certificate<\/a>\u2019s private key gets compromised, there should be a process in place to immediately revoke and replace it to limit any potential data exposure.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check the NIST CSF 2.0 and the <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-184.pdf\">NIST Guide for Cybersecurity Event Recovery<\/a> for additional tips and links. You won&#8217;t regret it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Looking for More NIST CSF 2.0 SMB Resources? Check Out These Links<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST Cybersecurity Framework 2.0 is a goldmine of templates, examples, and useful information to help SMBs successfully implement it. Here we\u2019ve listed a few.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Get an overview of the NIST CSF 2.0 with the <a href=\"https:\/\/www.nist.gov\/blogs\/cybersecurity-insights\/take-tour-nist-cybersecurity-framework-20-small-business-quick-start\">SMBs dedicated quick guide<\/a> and the <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.1299.pdf\">NIST CSF 2.0 resource and overview guide<\/a>.<\/li>\n\n\n\n<li>Share and discuss insights, perspectives, and challenges with other SMBs like you. Join the <a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/get-engaged\">NIST&#8217;s Small Business Cybersecurity Community of Interest <\/a>(COI).<\/li>\n\n\n\n<li>Discover more about actual SMB threats by watching the entertaining videos published on the <a href=\"https:\/\/www.nist.gov\/itl\/smallbusinesscyber\/videos\">Small Business Cybersecurity Corner<\/a>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts About 5 SMB Takeaways from the NIST Cybersecurity Framework 2.0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We hope you\u2019ve found this article and its linked resources useful. It\u2019s clear to see how NIST CSF 2.0 makes cybersecurity accessible to any business, including cash-strapped SMBs. The new framework&#8217;s structured approach empowers small and mid-sized businesses to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Easily identify focus areas and weaknesses,<\/li>\n\n\n\n<li>Develop a comprehensive cybersecurity strategy,<\/li>\n\n\n\n<li>Seamlessly embed security in all processes, and<\/li>\n\n\n\n<li>Boost customer trust and loyalty, showing them that security is at the heart of your business.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Prepare your business for cybersecurity attacks before they occur by taking action today. Strengthen your defenses by securing your web transactions with <a href=\"https:\/\/sectigostore.com\/ssl-certificates\">trusted SSL\/TLS certificates<\/a>, protecting the integrity and authenticity of your software apps with code signing digital signatures. This will also help you comply with industry regulations that require you to protect your data at rest and in transit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>61% of small businesses victims of a cyberattack in 2023 lost over $10,000. Learn how to harden your digital defenses with these five NIST CSF 2.0 key points According to&#8230;<\/p>\n","protected":false},"author":23,"featured_media":3449,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13],"tags":[299,298],"class_list":["post-3446","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-nist-csf-2-0","tag-nist-cybersecurity-framework","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small &amp; medium businesses.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small &amp; medium businesses.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-01T11:33:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nadia Bonini\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nadia Bonini\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/\"},\"author\":{\"name\":\"Nadia Bonini\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/f4ce6500b99e7563f71f0d1d6394f135\"},\"headline\":\"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0\",\"datePublished\":\"2024-08-01T11:33:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/\"},\"wordCount\":3308,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/nist-cybersecurity-framework-feature-v1.jpg\",\"keywords\":[\"NIST CSF 2.0\",\"NIST Cybersecurity Framework\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/\",\"name\":\"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/nist-cybersecurity-framework-feature-v1.jpg\",\"datePublished\":\"2024-08-01T11:33:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/f4ce6500b99e7563f71f0d1d6394f135\"},\"description\":\"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small & medium businesses.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/nist-cybersecurity-framework-feature-v1.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/nist-cybersecurity-framework-feature-v1.jpg\",\"width\":1600,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/f4ce6500b99e7563f71f0d1d6394f135\",\"name\":\"Nadia Bonini\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g\",\"caption\":\"Nadia Bonini\"},\"description\":\"Nadia is a technical writer with more than 15 years of experience in IT, software development projects, email and cybersecurity. She has worked for leaders in the IT industry and Fortune 500 companies. A Certified CSPO mail application security product owner and a former application security engineer, she also works as a professional translator. She is a big fan of Ubuntu, traveling and Japan.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights","description":"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small & medium businesses.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/","og_locale":"en_US","og_type":"article","og_title":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights","og_description":"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small & medium businesses.","og_url":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/","og_site_name":"InfoSec Insights","article_published_time":"2024-08-01T11:33:00+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg","type":"image\/jpeg"}],"author":"Nadia Bonini","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Nadia Bonini","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/"},"author":{"name":"Nadia Bonini","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/f4ce6500b99e7563f71f0d1d6394f135"},"headline":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0","datePublished":"2024-08-01T11:33:00+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/"},"wordCount":3308,"image":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg","keywords":["NIST CSF 2.0","NIST Cybersecurity Framework"],"articleSection":["Cyber Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/","url":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/","name":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0 - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg","datePublished":"2024-08-01T11:33:00+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/f4ce6500b99e7563f71f0d1d6394f135"},"description":"Take your cybersecurity posture to the next level with these top 5 NIST Cybersecurity Framework 2.0 takeaways for small & medium businesses.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2024\/07\/nist-cybersecurity-framework-feature-v1.jpg","width":1600,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/5-smb-takeaways-from-the-nist-cybersecurity-framework-2-0\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"5 SMB Takeaways from the NIST Cybersecurity Framework 2.0"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/f4ce6500b99e7563f71f0d1d6394f135","name":"Nadia Bonini","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/871770d58b7b0abd48f90fb2f9643895c766b7ab6c1d4fa58e3651941cdc9e63?s=96&d=mm&r=g","caption":"Nadia Bonini"},"description":"Nadia is a technical writer with more than 15 years of experience in IT, software development projects, email and cybersecurity. She has worked for leaders in the IT industry and Fortune 500 companies. A Certified CSPO mail application security product owner and a former application security engineer, she also works as a professional translator. She is a big fan of Ubuntu, traveling and Japan."}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/3446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=3446"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/3446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/3449"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=3446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=3446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=3446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}