In our previous article of this GRC series, we explored the IDENTIFY function within the Cyberfundamentals (CyFyn®) framework: understanding what assets exist, which systems are critical, and where risks may emerge.
But visibility alone does not reduce risk. Knowing which assets are critical is valuable, yet it does little if no measures are taken to protect them. Once an organisation understands what matters most, the next challenge becomes keeping those assets secure.
That is where the PROTECT function comes in.
PROTECT focuses on the safeguards, controls, and processes that reduce the likelihood and impact of cybersecurity incidents. It answers a simple but crucial question: How do we keep our most important assets safe?
Whether it is a user's identity, a critical business application, sensitive customer data, or an operational technology environment, protection is about ensuring these assets remain secure, available, and resilient.
Table of contents: |
One of the most common misconceptions in cybersecurity is that every asset should receive the same level of protection.
In reality, that approach is neither practical nor effective: The visibility gained through IDENTIFY allows organizations to prioritize. Critical systems require stronger safeguards than low-risk assets. Business impact, threat exposure, and regulatory requirements all influence how protection measures are deployed.
This is why cybersecurity is fundamentally risk-based, as organizations do not protect everything equally, but mainly protect what matters most.
No security control is perfect: A strong password can be stolen. Multi-factor authentication can be bypassed. A user may still click a phishing link. Software vulnerabilities may remain undiscovered.
That is why PROTECT relies on the principle of defence in depth. Rather than depending on a single security measure, multiple layers work together to reduce risk.
A modern protection strategy typically combines:
If one layer fails, another remains in place. The objective is not to create an impenetrable fortress. The objective is to make successful attacks significantly more difficult and less impactful.
Under NIS2, protection is not merely a best practice. It is a regulatory requirement.
Several obligations map directly to the PROTECT function, including:
Organizations must not only implement these controls, but also be able to demonstrate that they are effective and consistently applied.
This is where governance and documentation become essential. NIS2 increasingly focuses on proving security maturity rather than simply claiming it exists.
PROTECT consists of six building blocks that work together to reduce risk and improve resilience.
Access should be limited to the right people, at the right time, for the right reasons.
This includes:
Strong identity controls remain one of the most effective security measures available.
Technology alone cannot stop every attack. Employees remain a frequent target for cybercriminals, making awareness a critical layer of protection.
Organizations should establish:
Security culture is not built through annual presentations, but rather developed through continuous engagement.
Data is often the asset attackers are ultimately trying to reach.
Organizations should focus on:
The goal is to ensure information remains protected even when systems are compromised.
Security should be embedded into daily operations.
This includes:
Consistency often matters more than complexity.
Security deteriorates when systems are not maintained.
Organizations should ensure:
Many successful attacks exploit weaknesses for which fixes already exist.
Technology provides the technical safeguards that reinforce all other protection layers.
Examples include:
Technology is important, but it is most effective when supported by people and processes.
Where IDENTIFY helps organizations understand what they have, PROTECT ensures those assets are safeguarded.
Together, these functions form the foundation of a mature cybersecurity program. Without visibility, protection efforts are often misdirected. Without protection, visibility alone provides little value.
Organizations that succeed are not necessarily those with the most security tools.
They are the organizations that consistently apply the right protections to the assets that matter most.
⏭️ Up Next: DETECTEven the strongest protection strategy assumes that incidents can still occur. In the next article of our GRC in Belgium series, we will explore the DETECT function within the Cyberfundamentals (CyFyn®) framework and examine how organizations identify suspicious activity, recognize threats early, and gain the visibility needed to respond before minor issues become major incidents. You cannot respond to what you cannot see... |