It combines governance, people, processes, architecture, and technical safeguards to reduce the likelihood and impact of unauthorized access, disruption, manipulation, destruction, or disclosure.
Cybersecurity is not a state in which attacks never occur. Organizations use it to understand what matters, protect important assets and services, detect adverse activity, respond effectively, and restore operations. The appropriate measures depend on business objectives, threat exposure, legal duties, safety needs, and risk tolerance.
In practice, a cybersecurity program runs as a loop rather than a project: inventory and risk assessment set priorities, controls are implemented and tested, incidents feed lessons back into governance, and leadership reviews risk acceptance explicitly. Maturity is usually judged by how repeatable and measured this loop is — not by the number of tools deployed.
Key points
Primary purposeSupport the organization’s mission while managing harmful digital events and conditions.
NIST CSF 2.0 functionsGovern, identify, protect, detect, respond, and recover.
ScopePeople, data, applications, identities, devices, networks, cloud services, operational technology, suppliers, and business processes.
Important limitationMore security products do not automatically create better cybersecurity; disconnected controls can add cost and complexity without reducing material risk.