NIST CSF 2.0: No CISO, No Excuse

Threat Talks infographic

Find Threat Talks on

The framework changed, but the question did not: what do I do tomorrow?

NIST released version 2.0 of the Cybersecurity Framework, and for most teams the hard part is not the document, it is the first move. This episode is about that first move.

Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Amy Mahn, IT standards advisor at NIST, and Daniel Elliott, lead for small business engagement in NIST’s Applied Cybersecurity Division. Together they take CSF 2.0 off the page: the new Govern function, the profiles that map where you are against where you need to be, and the free Quick Start Guides built for teams that do not have a security department.

What you’ll learn

  • Govern is now its own function. Cyber risk moved out of “Identify” and onto the board’s agenda as a strategic business risk.
  • Profiles build your roadmap. Score your current state against your target state, then close the gap on purpose.
  • Map once, report many. CSF lines up with ISO 27001, SOC 2, and HIPAA so one effort covers several obligations

Your cybersecurity experts

Lieuwe Jan Koning

Co-Founder and CTO
ON2IT

Amy Mahn

Amy Mahn

IT Standards Advisor NIST Office

Daniel Eliot

Daniel Eliot

Lead for Small Business Engagement NIST

Episode details

The headline change in CSF 2.0 is structural. Governance, previously folded inside the Identify function, is now its own function with its own color in the famous wheel. Daniel Elliott frames why that matters: cybersecurity is no longer a technology issue parked in IT, it is a strategic business risk that sits alongside financial, competitive, and environmental risk. Boards are starting to ask better questions, and the framework now reflects that reality.

The practical engine is the profile. Amy Mahn walks through how an organizational profile lets you describe your current cybersecurity posture in terms of outcomes, set a target state, and run a gap analysis between the two. The output is a roadmap, not a grade. A community profile does the same thing for a whole sector, manufacturers or hospitals or finance, sharing priorities without going through NIST at all.

The part most teams miss is how practical 2.0 became. It is no longer a single PDF. It is Quick Start Guides, tables, checklists, spreadsheets, a search tool, and community-submitted mappings to ISO 27001, SOC 2, and HIPAA. For a CISO juggling five compliance regimes, those mappings turn repeated reporting into one effort. For an IT manager with no CISO and limited time, the small business guide is about 15 pages with concrete steps: enable MFA here, change the default passwords there, know your legal obligations.

The takeaway is permission to start small. Elliott’s advice for the under-resourced is direct: do not try to do everything at once, prioritize your most critical assets, and let the framework help you sequence the work. It is free, it is voluntary, and as Lieuwe Jan puts it, there is no excuse not to look, because there is almost certainly something in it for you.

Threat Talks infographic

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

8 + 8 =

Christmas Hacker