Hackers are not going anywhere, anytime soon. The burgeoning new wave of hackers is tech-savvy and hell-bent on causing maximum damage. Virtually all organisations face constant threat from cyber-attack; unfortunately, it’s a matter of when, not if, someone tries to hack your data. Times have changed, and responding to attacks as they happen is simply not enough. The most effective way to strengthen cyber security is to plan ahead for a digital defence that covers all aspects of your business.
Traditionally, organisations have taken a reactive approach to cyber security – responding to threats as they occur, rather than pro-actively protecting and managing cyber risk. Today’s sophisticated hackers are always finding new opportunities for attack, which makes it mission-critical to stay on the offence with cyber security. Managing compliance for multiple security standards has also proven challenging, with cyber security not visible at the board level or even considered to be a business priority. That is, of course, until a data breach occurs and it becomes everybody’s problem.
This fragmented approach is ineffective – and dangerous. The consequences of a cyber-attack can be devastating, such as loss of customer confidence, ruined reputation, and costly legal ramifications. Not to mention the potential destruction of your entire business.
To be fully effective, cyber security must be owned at the board level, and not just managed by the IT department or a board member with tech expertise. ‘Ready for a Hack,’ an article in the April 2016 issue of Company Director, is a case in point. It tells the story of Distribute.IT – a now non-existent Australian website hosting business – which was forced to close its doors after a hacker attacked its systems in 2011 and deleted thousands of its clients’ websites. The hacker targeted a specific employee who was deemed to be ‘vulnerable’, bypassing all security measures and locking out the IT team who could only watch on, defenceless. The message is clear. Cyber security needs to be broad in scope, and senior management needs to recognise that it’s a whole-of-business challenge.
That advice still stands. In their Cyber security priorities for boards of directors 2025-26, the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD) say boards should treat cyber security as a core governance and enterprise risk.
The US Government recognised the urgency of protecting critical infrastructure from cyber attacks. In 2013 President Barack Obama ordered the National Institute of Standards and Technology (NIST) to create a cyber security framework. The NIST Framework was based on input from more than 3,000 workshop attendees. StickmanCyber’s own Ajay Unni participated in NIST’s Cybersecurity Framework workshop held in Gaithersburg, Maryland, US in April 2016.
NIST released CSF 2.0 in February 2024 and widened its scope to organisations of all sectors and sizes. Its six core Functions are: Govern, Identify, Protect, Detect, Respond and Recover. Govern is new in version 2.0 and covers how an organisation’s cyber security risk management strategy, expectations and policy are set, communicated and monitored. The diagram below shows the five original Functions of CSF 1.1 and their categories.
The NIST Framework shifts the balance from reactive compliance to proactive cyber risk management. Being proactive improves communication and collaboration on cyber security issues across divisional, management, and board levels, putting the organisation in the best position to comply with current and future regulatory standards.
Adopting the framework can also serve as evidence of implementing appropriate measures to prevent cyber-attack, which may help your legal position in the event of a breach.
A proactive, company-wide approach is the key to long-term cyber security. StickmanCyber’s approach to cyber security by design provides a dynamic, cost-effective, and customised framework that helps safeguard your business from cyber attack:
Instead of one-size-fits-all, we customise cyber security to meet your specific needs, risk tolerance, and resources available, with the focus firmly on risk minimisation.
The lack of visibility of cyber security at the board level and senior management is a common problem for security professionals within large organisations. Our methodology promotes external and internal collaboration and buy-in. Cyber security is quickly integrated into more business functions, such as new product development and infrastructure design, meaning your business is more fully protected.
Cyber security is constantly changing. With new technology and smarter cybercriminals, a dynamic approach enables rapid evolution to keep security steps ahead of hackers. Our methodology is designed to be flexible, always keeping you on the front foot.
Our methodology adapts the industry gold standard NIST Cyber Security Framework, alongside standards such as ISO 27001 and Australia’s Essential Eight, to bring you a proactive, broad-scale, and customised approach to managing cyber risk.
Remember – hacking will happen at some point. It really does pay to be proactive. To find out more about safeguarding your business now and into the future please contact us.
Secure by design means building security into the design, development and operation of products, services and systems from the outset, rather than fixing problems after release. Secure by default means a product is secure out of the box, with strong security settings already turned on, so customers don’t have to configure it themselves. ASD and the AICD encourage boards to check whether the technology their organisation uses or provides is both.
Everyone has a role, but accountability sits with the board and senior management. ASD and the AICD advise boards to treat cyber security as a core governance and enterprise risk, set clear accountability and reporting, and build a strong security culture. Day-to-day controls are usually run by IT or security teams, a managed security provider, or both, under that oversight.
No. The NIST Cybersecurity Framework is voluntary, and many Australian organisations use it as a structure for managing cyber risk. Some Australian requirements are mandatory for certain organisations: for example, the Protective Security Policy Framework requires non-corporate Commonwealth entities to implement all Essential Eight strategies to at least Maturity Level Two, and APRA-regulated entities must meet CPS 234.
Start by identifying your most critical systems and information – the ‘crown jewels’ ASD recommends protecting first – and assessing your current controls against a recognised framework such as NIST CSF 2.0, ISO 27001 or the Essential Eight. Turn the gaps into a prioritised roadmap, give the board regular reporting on progress, and build security requirements into new projects from the start.
Yes. NIST designed CSF 2.0 for organisations of all sectors and sizes, and ASD publishes cyber security advice written specifically for small business. A smaller organisation may not implement every control a large enterprise would, but it can still plan security into its systems, suppliers and processes from the start and focus first on its biggest risks.