Practical guide ·

Our cybersecurity budget is limited: which controls should come first?

Start with the business services you cannot afford to lose and the credible scenarios that threaten them. Compare proposed measures by the risk they address, their dependencies and the effort needed to operate them. A useful priority list explains the decision and gives each action an owner and a verification method.

What are we protecting first?

Ask a business owner what interruption would stop delivery, payment or essential access. Identify the systems and external services supporting that operation. This often reveals a dependency that a technology inventory alone would not rank highly.

Use a small set of plausible scenarios rather than every imaginable attack. For each, record existing safeguards, remaining exposure and uncertainty. A decision can be useful without pretending that an unmeasured probability is precise.

How do we compare different proposals?

Consider an illustrative choice between buying a new dashboard and correcting an untested recovery process. The dashboard may improve visibility, but it does not repair a missing recovery dependency. Compare each proposal against the scenario and intended outcome before comparing features.

Include operating cost, skills, business disruption and dependencies. A product that nobody can configure or review creates continuing work. A less expensive measure can be the right first step when it enables several later improvements.

Illustrative comparison — adapt it to your organisation
ProposalDecision questionVerification
Improve recoveryWhich essential operation cannot be restored?Business transaction after a controlled restore
Tighten privileged accessWhich unnecessary rights enable the scenario?Reviewed rights and service check
Add monitoringWhich important event is currently invisible?Authorised scenario test
Introduce a policyWhich repeated decision lacks a usable rule?Observed use in the workflow

What makes the ranking defensible?

Record the basis for urgency: an exposed service, an unresolved incident finding, an important customer commitment or a statutory duty. Separate mandatory work from discretionary improvements and verify the actual deadline. Describe assumptions openly.

NIST’s small-business guidance provides a starting framework for organising risk work. Your priority order still depends on your environment. Use qualitative categories where the data does not support a calculation; scoring should aid discussion, not conceal the judgement behind it.

How do we turn the list into progress?

Choose a manageable first set of actions. Give each an owner, a target outcome, resources and a test of completion. “Improve access security” is vague; “remove the confirmed unnecessary privileges and verify the affected service still works” is reviewable.

At the next review, distinguish completed activity from achieved outcome. Record what remains at risk and who accepts it. Reprioritise when evidence changes. A roadmap is useful because it supports decisions over time, not because the first version predicted everything.

Explore in detail: CISO, vCISO or the IT manager? Who owns security.

How Dyasol can help

Dyasol can review the agreed risks and turn findings into a prioritised improvement plan. Technical implementation is separately scoped so you can decide what to commission and what your own team will do.

Plan the first practical improvements

Sources and context

Examples are illustrative. Practical recommendations should be adapted to the organisation.