Learn more about our phishing simulations and awareness training.
Discover how your business can benefit

Nikolas Rösener
Security Expert
- cyber-security@ohb-ds.de
- 0421220950
When we talk aboutcybersecurity risks, most people first think of large-scale, targeted hacker attacks on major corporations and governments. We hear aboutadvanced persistent threats (APTs),zero-day vulnerabilities,spear-phishing, andCEO fraud.
In fact,cybersecuritysimply means that the risk is not limited to IT, but affects the entire company and originates in the cyber domain—primarily the internet. Thus, every small and medium-sized enterprise (SME) is exposed to a significantcybersecurity riskon a daily basis, simply because it owns systems and employs staff who interact with the internet. The greatest risk for these companies, however, is not targeted attacks (motivated by national interests) exploiting unknown vulnerabilities, but rather global malware, phishing, and ransomware campaigns carried out by profit-driven cybercriminals. These criminals use simple scams and known vulnerabilities to cause rapid, widespread damage and extort money.
The consequences can be devastating. The damage caused by a malware or ransomware attack often threatens the very survival of small and medium-sized businesses alike. It is therefore essential for every business leader to understand the risks to which their employees and resources are exposed and to know what options are available to effectively mitigate those risks.
The first and most important step is to analyze the threats and challenges to cybersecurity. Security frameworks can facilitate a systematic assessment, but they are often—such as the BSI’s IT-Grundschutz in Germany—too extensive for small and medium-sized enterprises (SMEs) to manage. With theCIS Controls, the Center for Information Security (CIS) provides a framework that can be scaled to suit the needs of small and medium-sized enterprises.
The 20 critical control points of the CIS Controls Framework are divided into three categories:
TheBasiccategoryincludesessential control points for managing hardware and software, as well as for access control, configuration, and vulnerability management.
TheFoundationalcategorycoverskey security measures for data, software, firewalls, routers, switches, and both mobile and stationary devices.
The "Organizational" categorycoversorganizational measures such as awareness training, incident response, and the conduct of penetration tests.

There is no “one-size-fits-all” solution for adequate security. The CIS recognizes this as well and divides the measures for assessing and addressing risks into threeimplementation groups.
The first group,IG1, includessolutions for companies with limited resources and little experience in cybersecurity. The goal here is to establish an appropriate baseline level of controls upon which further controls and measures can be built.
IG2includes controls for medium-sized companies and those that have already taken steps and gained experience in the area of cybersecurity. Among other things, this involves efficient and pragmatic protection against malware, phishing, and ransomware.
IG3is ultimately intended for companies that have sufficient expertise and resources to protect themselves against theAPTs andzero-day hacksmentioned earlier.

In practice, this works as follows: Toensure, in accordance with Control Number 6 (Maintenance, Monitoring, and Analysis of Audit Logs), that the necessary log files are available for a post-mortem analysis following an IT incident,IG1requires that audit logs be enabled for all relevant systems. This typically involves a one-time effort. InIG2, a centralized log management system with analysis capabilitiesshouldbe implemented so that security personnel can quickly detect new threats, such as a malware infection or a DDoS attack, and track them retroactively. Finally, to protect large infrastructures and detect novel attacks exploiting zero-day vulnerabilities,IG3calls for consolidatinginformationin aSIEMand partially automating the response.
For organizations of all sizes, theImplementation Groupsalso provide a useful guide for prioritizing security measures. This ensures that core issues are addressed first, thereby minimizing cybersecurity risk from the outset. More information on the Implementation Groups is available in the accompanyingCIS white paper.
For anyone who wants a quick overview of their current cybersecurity posture, the CISofferstheCIS Controls Self-Assessment Tool (CSAT). With this free tool, anyone who has a clear understanding of the measures currently in place can assess their cyber risk.
TheCIS Controlsprovide a quick and effective starting point for analyzing cybersecurity risks. However, anyone who runs the CSAT and takes a look at the sub-controls will notice that this is not an“out-of-the-box” checklist. For each control point, the generically formulated requirement must be adapted to the technological and organizational realities of the company’s IT infrastructure, and any unsuitable requirements must be revised or appropriately replaced.
In particular, companies that have made the switch to the Microsoft Cloud already have all the necessary technological prerequisites to implement the core controls ofImplementation Groups1 and 2. However, they often lack the expertise and guidelines needed to actually achieve the objectives of these controls.
For example, the sub-controls inIG1require ongoing inventory of all hardware and selective software approval; inIG2, they require trackingof the software actually installed; and inIG3, they require integrationthat consolidates this information.Allthree controls are technically addressed for endpoints through the use ofMicrosoft Intune. However, it must also be ensured operationally that all devices are registered and that a software blacklist or whitelist is maintained and enforced!
We therefore offer a cybersecurity assessment fully tailored to the Microsoft 365 cloud platform. Using our questionnaire on the implementation status and usage patterns of various Microsoft security tools—such asMicrosoft Intune,Microsoft Information Protection, orAzure AD Security Defaults—youcanclearly visualize your addressed and unaddressed risks and, in consultation with us, develop a concrete action plan for your company’s cybersecurity strategy.

CIS Controls also offer small and medium-sized businesses the opportunity to quickly assess their cybersecurity risk and identify opportunities for improvement through generic measures.
Our cybersecurity analysis also allows you to demonstrate the specific implementation status of technological measures in Microsoft 365 and clearly visualize the cybersecurity risks addressed by these measures.

You are currently viewing placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing a placeholder content from reCAPTCHA. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More Information