A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient protection three years ago has changed.
Fortunately, the NIST CSF 2.0 (the newest version of the NIST Cybersecurity Framework, updated in 2024) is the closest thing to a universal standard for what a solid cybersecurity posture means. In this blog, I’ll explore how you use it to measure where you actually stand.
NIST CSF 2.0: what it is and what changed

The framework has 6 functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
Each one covers a critical area of security.
The 2024 update added Govern as a new function. It sits underneath everything else, acknowledging that security governance has to come first. After all, you can't defend what nobody's actually managing.
Want the full breakdown of all six functions? Check out our complete NIST Framework guide.
How organizations should assess cybersecurity posture
According to the NIST CSF 2.0, here are the vulnerabilities you should be looking for:
1. Govern: Is someone actually in charge?
Someone needs to own security — a person or a team that's actually responsible.
Look for:
- Does your organization have a documented security policy? And does anyone actually know it exists?
- When something goes wrong, who escalates it? Is there a clear chain of command, or does it just become chaos?
- Does your board or executive team understand what your actual security risks are? Or is it just an IT thing?
- Are there documented roles and responsibilities for security decisions?
If nobody can answer these questions cleanly, you need to address that.
2. Identify: Do you know what you have?
You can't protect what you don't know exists. This sounds obvious until you walk into a business and find servers nobody documented or data living in places nobody knew about.
Look for:
- Can you list every system, application, and data repository your business runs?
- Do you know which systems talk to each other?
- Do you know where your most sensitive data actually lives?
- When you buy new software or hardware, is it tracked somewhere?
If you're guessing at any of these, your “identify” category is weak.
3. Protect: Are your defenses even?
You might have strong authentication in one department and reused, weak passwords in another. Similarly, you might have hardened one system and completely neglected another.
Look for:
- Are access controls consistent across the business?
- How often are patches actually applied? Are they sitting in a queue for months?
- Do you have a baseline security standard that every system meets?
- Are endpoints as protected as your network, or are they an afterthought?
Uneven protection is protection that fails.
4. Detect: Can you see when something's wrong?
If you don't have monitoring and alerting in place, you're operating blind. Attackers can sit in your systems for months before you realize they're there. And honestly, sometimes you don't catch it yourself — you find out because someone external notices and tells you about it.
Look for:
- Are you monitoring for suspicious activity on your network?
- If an account gets compromised, would you know in hours or months?
- Do you have alerting set up when things look unusual?
- Is anyone actually watching the logs, or do they just pile up?
If you're operating blind, detection is broken.
5. Respond: Do you have a plan?
This is usually where I find the biggest gaps, even in businesses that have everything else nailed down. But if something goes terribly wrong, you don’t want to suddenly be thinking through incident response from scratch.
Look for:
- Do you have a documented incident response plan?
- Has your team actually practiced it, or does it just sit in a folder?
- Do you know who calls whom when something happens?
- Can you contain a breach before it spreads?
A solid plan means faster containment, less damage, and quicker recovery. Not having a plan can make a bad situation worse.
6. Recover: Can you actually restore?
A lot of businesses have backups in place, but have never actually tested whether they work. They don't know how long recovery takes. They've never practiced the process. That leaves you completely exposed if something goes wrong.
Look for:
- Are your critical systems being backed up regularly?
- Have you actually tested restoring from those backups? Not just once — recently?
- Do you know how long it would take to get back online if your data disappeared?
- Is there a disaster recovery plan, or are you just hoping?
FAQs about assessing your cybersecurity posture
Here are a few common questions I hear.
What is cybersecurity posture?
Cybersecurity posture is the overall strength of your organization's defenses against cyberattacks. It includes all your security policies, tools, training programs, and systems working together. A strong posture means multiple layers of protection. A weak one means gaps that attackers can exploit.
What's the difference between cybersecurity posture and cybersecurity risk?
Cybersecurity posture is how strong your defenses are. Cybersecurity risk is the vulnerability that exists despite those defenses. As your posture improves, your risk decreases. You need both assessments: One tells you what defenses you need, the other tells you where you're exposed.
How often should I assess my cybersecurity posture?
I’d recommend doing it annually at a minimum. But the security landscape changes faster than that. Many organizations do quarterly checks to catch new vulnerabilities and verify that improvements are working.
The bigger and more exposed your organization is, the more frequently you should assess.
Can I measure cybersecurity posture without hiring outside help?
We offer a free online diagnostic tool that can help you get a gut check on your current cybersecurity.
A self-assessment is useful for identifying obvious problems, but an independent assessment from someone who's seen thousands of businesses can catch vulnerabilities you won't spot yourself. An outsider’s perspective is often very valuable in this area.
How to improve your company's cybersecurity posture based on what you find

After you get a sense of where your biggest gaps are, you have options:
- If your team already has cybersecurity skills, you can make a plan to address gaps internally, prioritized according to risk
- If you don’t have the time or the skills on your team, you can partner with a provider for a one-time assessment
- You could also consider working with a provider to offer targeted cybersecurity support or consulting services
Unless your internal team has the time and the skills to handle it in-house, the fastest way to add protection on a budget is typically to get a cybersecurity posture assessment from a provider — one that already knows exactly what they’re looking for.
Getting a cybersecurity posture assessment through Marco
The goal of our assessments is to get everyone on the same page about what needs to happen, when, and why.
Our assessments involve interviews with your team and thorough investigations into your actual systems to catch things that quick scans miss, including:
- misconfigurations hiding in your environment
- policies that look good on paper but don't work in practice
- gaps in how your tools are actually configured
Then, our findings are framed clearly in language that non-IT people can understand. You don't just get a list of vulnerabilities. You get context: What does this actually mean for your business? What's the real risk if something goes wrong? Then you get a clear roadmap that tells you what to prioritize and what can wait, based on your actual budget and business needs.
If you want a real assessment of your security posture — one that's independent, thorough, and backed by 50+ years of experience inside thousands of businesses — reach out.