Skip to main content
Language Translation
  Close Menu

Detect is the third function of NIST. What the Detect function reveals is that relying too much on the Protect function will cause your organization to not know when a cyberthreat is occurring that will negatively affect the organization. This function’s main job is to help you discover cybersecurity events in a timely fashion because the average time it takes to detect a breach in 2019 is 206 days (“Cost of a Data Breach Report 2019”, IBM Security, Ponemon). The important thing to remember about Detect is that not only does it deal with making sure your organization has the technology to detect attacks on every device, system, and service, but also your organization is making sure that the processes you have in place to protect your organization are following best practices, documented, and being continuously improved. Since most attacks are stealthy and not obvious, organizations must be able to detect anomalies or events that may seem insignificant by themselves, but when happening together, they are dangerous to your organization.

Low – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score to from Low to Medium will be to 1) Ensure that you are patching all of your digital assets as soon as possible because this will stop 90% of attacks before they ever begin (Panda Security), 2) Ensure all staff receive frequent cyber awareness training so they are able to avoid phishing attacks and malicious websites, 3) Ensure you are using a next generation anti-virus (NGAV) solution and research if an endpoint detection and response (EDR) solution makes sense for your organization’s continuous monitoring needs, 3) Setup and document which threats you want to receive alerts for so you know when significant attacks are occurring, and 4) research whether a managed security service provider is right for your organization.

The following are additional resources to help you level up your game from Low to Medium:

Medium – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Medium to High will be to 1) Ensure that you are patching all of your digital assets as soon as possible because this will stop 90% of attacks before they ever begin (Panda Security), 2) Ensure all staff receive frequent cyber awareness training so they are able to avoid phishing attacks and malicious websites, 3) Ensure you are using a next generation anti-virus (NGAV) solution and research if an endpoint detection & response (EDR) solution makes sense for your organization’s continuous monitoring needs, 3) Begin identifying which systems, software, services, and network that need improved detection capabilities, such as “smart” IoT devices (Internet if Things), printers, etc… to ensure all devices and services are being monitored, and 4) begin adding additional layers of cybersecurity solutions that increase the protections of your organization, such as behavior analytics, intrusion detection/prevention system, firewalls, and/or threat intelligence platform.

The following are additional resources to help you level up your game from Medium to High:

High – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score and continue at High will be to 1) Implement advanced detection capabilities such as machine learning, 2)Expand your detection capabilities with user and entity behavior analytics, 3) Research if an endpoint detection & response (EDR) solution makes sense for your organization’s continuous monitoring needs, 4) Ensure you are regularly testing and improving your detection processes that include threat intelligence and capabilities to include external service provider activities, and 5) Vulnerability scans are being performed as part of your detection strategy.

The following are additional resources to help you level up your game and keep it at High: