This NIST NCCoE guide provides practical recommendations to help Managed Service Providers (MSPs) design, maintain, and test backup files to reduce the impact of ransomware and other data loss events (e.g., hardware failure, accidental or malicious deletion). It supports implementation of the NIST Cybersecurity Framework subcategory PR.IP-4 by outlining considerations for backup planning, selecting backup services/products, ensuring backup availability and integrity, and strengthening disaster recovery readiness. The guidance is adaptable—MSPs can apply only the recommendations relevant to their operational context.
Risk Management
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Risk Management
Guide for Conducting Risk Assessments
- Published date:
- Author: National Institute of Standards and Technology (NIST)
NIST Special Publication 800-30 Rev. 1 provides structured guidance for conducting cybersecurity risk assessments across information systems and organizations. It supports decision-making at all levels of the risk management hierarchy by outlining methodologies to identify threats, vulnerabilities, impacts, and residual risks. The guide complements NIST SP 800-39 and serves as a foundational reference for integrating risk assessment into enterprise-wide risk management and security control selection.
- Risk Management
#StopRansomware Guide: Prevention and Response Best Practices
- Published date:
- Author: Cybersecurity and Infrastructure Security Agency (CISA)
This guide from CISA, MS-ISAC, NSA, and the FBI provides actionable best practices for preventing and responding to ransomware and data extortion attacks. It includes two core parts: (1) Prevention guidance based on common attack vectors, including credential compromise and social engineering, and (2) A detailed response checklist with detection and threat hunting steps. The guide aligns recommendations with CISA’s Cross-Sector Cybersecurity Performance Goals and highlights the evolving tactics of ransomware actors, including double extortion. Ideal for IT and cybersecurity professionals across sectors.
- Risk Management
A Critical Guide to Closing Your Exposure Management Gaps
- Published date:
- Author: Bitsight
As CISOs transform their position in the enterprise from technical managers to business risk leaders, they need better visibility and data about cyber risks in order to credibly advise the business. As digital footprints keep expanding and cybersecurity threats keep snowballing, prioritize action around the biggest risks to the business.
Download this guide to get details on why leading CISOs credit exposure management as one of the top tools and practices that will help them drive better prioritization of action, better transparency to the board and CEOS and better accountability from their direct reports.
- Risk Management
5 Ways to Evaluate the ROI of Your Cybersecurity Program
- Published date:
- Author: Bitsight
Cybersecurity ROI isn’t about cost savings. It’s about how your cybersecurity program helps you achieve your goals while managing risk to a level that your executive team is comfortable with. So if you shouldn’t measure success in cost savings, how do you measure it?
Bitsight is providing five steps that help CISOs and executive teams evaluate their company’s cybersecurity performance.
Download the eBook to learn how to:
– Frame success
– Establish & understand your cyber risk appetite
– Assess & quantify risk
– Benchmark to gain perspective
– Facilitate continuous improvement
- Risk Management
EU Risk Management Toolbox
- Published date:
- Author: ENISA
The EU RM Toolbox, developed by ENISA, addresses interoperability issues in information security risk management (RM) methods. It facilitates the integration of diverse RM approaches within or across organizations, aiming to standardize risk understanding and reporting. This tool helps stakeholders achieve a unified view of risks and enables the consistent communication of risk assessment outcomes to relevant communities and authorities.