Article
Where to start a cybersecurity governance program
Before choosing controls or tools, there are three questions that order all the work. A practical approach based on the CGF cycle.
Many cybersecurity programs start in the wrong place: a tool to implement or a standard to comply with. The result is usually the same: a lot of activity, little clarity about whether the organization is really more protected.
At i-Prot we propose reversing the order. Before talking about controls, it’s worth answering three questions that order all the work that follows. They are the basis of the Assess stage of the CGF cycle.
1. What do we need to protect?
Every governance program starts by knowing the assets: information, processes, services and systems that sustain the business. Without that inventory, any security investment is a blind bet. It’s not about listing everything, but identifying what, if it failed, would have a real impact.
2. Which risks must we reduce?
With the assets clear, the next step is to understand which threats they’re exposed to and with what likelihood and impact. This allows prioritization: not all risks deserve the same attention and resources are always limited. Risk management turns intuition into defensible decisions.
Governance doesn’t start by asking which standard to comply with, but what the organization needs to protect and which risks to reduce.
3. Which capabilities must we govern?
Only then does it make sense to talk about controls, processes and technology. Capabilities are designed to treat the prioritized risks, not the other way around. That way, each control has a reason for being that is traceable to a specific risk and asset.
From assessment to operation
Answering these three questions produces a map: assets, risks and capabilities connected to each other. That map lets you prioritize the roadmap, justify the investment to leadership and measure progress over time.
A program that starts this way doesn’t depend on a tool or a one-off certification: it holds as a business capability, which is exactly the goal of cybersecurity governance.