Practical guide ·
Our cybersecurity budget is limited: which controls should come first?
Start with the business services you cannot afford to lose and the credible scenarios that threaten them. Compare proposed measures by the risk they address, their dependencies and the effort needed to operate them. A useful priority list explains the decision and gives each action an owner and a verification method.
What are we protecting first?
Ask a business owner what interruption would stop delivery, payment or essential access. Identify the systems and external services supporting that operation. This often reveals a dependency that a technology inventory alone would not rank highly.
Use a small set of plausible scenarios rather than every imaginable attack. For each, record existing safeguards, remaining exposure and uncertainty. A decision can be useful without pretending that an unmeasured probability is precise.
How do we compare different proposals?
Consider an illustrative choice between buying a new dashboard and correcting an untested recovery process. The dashboard may improve visibility, but it does not repair a missing recovery dependency. Compare each proposal against the scenario and intended outcome before comparing features.
Include operating cost, skills, business disruption and dependencies. A product that nobody can configure or review creates continuing work. A less expensive measure can be the right first step when it enables several later improvements.
| Proposal | Decision question | Verification |
|---|---|---|
| Improve recovery | Which essential operation cannot be restored? | Business transaction after a controlled restore |
| Tighten privileged access | Which unnecessary rights enable the scenario? | Reviewed rights and service check |
| Add monitoring | Which important event is currently invisible? | Authorised scenario test |
| Introduce a policy | Which repeated decision lacks a usable rule? | Observed use in the workflow |
What makes the ranking defensible?
Record the basis for urgency: an exposed service, an unresolved incident finding, an important customer commitment or a statutory duty. Separate mandatory work from discretionary improvements and verify the actual deadline. Describe assumptions openly.
NIST’s small-business guidance provides a starting framework for organising risk work. Your priority order still depends on your environment. Use qualitative categories where the data does not support a calculation; scoring should aid discussion, not conceal the judgement behind it.
How do we turn the list into progress?
Choose a manageable first set of actions. Give each an owner, a target outcome, resources and a test of completion. “Improve access security” is vague; “remove the confirmed unnecessary privileges and verify the affected service still works” is reviewable.
At the next review, distinguish completed activity from achieved outcome. Record what remains at risk and who accepts it. Reprioritise when evidence changes. A roadmap is useful because it supports decisions over time, not because the first version predicted everything.
Explore in detail: CISO, vCISO or the IT manager? Who owns security.
How Dyasol can help
Dyasol can review the agreed risks and turn findings into a prioritised improvement plan. Technical implementation is separately scoped so you can decide what to commission and what your own team will do.
Sources and context
Examples are illustrative. Practical recommendations should be adapted to the organisation.