Article
What industry leaders need to know about the NIST Cybersecurity Framework 2.0
Our approach to applying the updates that bolster your cyber resilience
March 08, 2024

Article
Our approach to applying the updates that bolster your cyber resilience
March 08, 2024

In our digital age, keeping our systems safe is key to ensuring public safety and the smooth running of our society. Recent cyberattacks by groups like Volt Typhoon, backed by China, have shown how these attacks can have widespread effect—especially on organizations that maintain critical infrastructure, house sensitive data, or provide critical services. These attacks, along with a 50% increase in ransomware attacks in the industrial sector in 2023, stress the need for strong cybersecurity measures.
The National Institute of Standards and Technology (NIST) made significant updates to its Cybersecurity Framework (CSF) on February 26, 2024. These changes, especially in governance and supply chain security, are big steps forward from the 2018 version. They tackle long-standing issues by promoting better decision-making, clear communication, and proactive risk management.
There were two notable changes in the NIST CSF 2.0:
West Monroe has consistently applied the NIST framework as a pillar of our approach, integrating governance into our engagements since 2015. Utilizing the framework, we objectively measure risk, identify improvement opportunities, and track our clients’ progress toward achieving their security goals year over year. From our point of view, traditional industries grapple with governance challenges, insufficient investment, stakeholder fragmentation, and siloed operations. With our deep engagement across traditional sectors, the timing of the NIST 2.0 update couldn’t be more crucial. We’re at the forefront, leveraging NIST to address the unique challenges traditional industries face.
Today's businesses are navigating a rapidly changing digital landscape, where advancements like artificial intelligence in threat detection and the increasing use of real-time data demand a strong approach to managing risks. It's essential for companies to build a culture and strategy around security governance that aligns with their business goals, regulatory needs, and risk tolerance. Investing early in a comprehensive security governance program pays off by making responses more effective and aligned with the company's objectives.
Governance is crucial for security teams, especially when they're responsible for assets they don't fully control. A governance model that promotes shared responsibility across the organization is necessary to maintain an appropriate level of security. This model goes beyond just day-to-day operations, involving leadership, policies, and oversight to ensure that cybersecurity efforts are unified and integrated at every level.
In today's interconnected business environment, managing the security of the supply chain is crucial. This involves overseeing a network of third-party providers of software, hardware, and services that are vital to operations. Recognizing the risks these external parties can introduce, it's important to have a strategy that ensures the safety, privacy, and availability of critical services and infrastructure. At West Monroe, we're committed to leading the way in supply chain security, guided by several key principles:
The NIST Cybersecurity Framework 2.0 represents a pivotal advancement in the collective effort to fortify cyber resilience across industries. By introducing the Govern function and placing a renewed emphasis on supply chain risk management, this updated framework addresses critical vulnerabilities and aligns cybersecurity practices with the strategic objectives of organizations. West Monroe's proactive adoption and integration of these guidelines underscore the importance of governance and a security-first culture in navigating the complexities of today's digital landscape.
As businesses continue to evolve amid a backdrop of increasing cyber threats, the principles laid out in the NIST CSF 2.0 offer a comprehensive roadmap for enhancing security postures, fostering stakeholder engagement, and ensuring the continuous improvement of cybersecurity measures. Embracing these guidelines not only mitigates risks but also positions organizations to thrive in an era where digital resilience is synonymous with business success.