Security leaders should start with a clear assessment of current security posture. That means reviewing staffing, training, systems, incident response, and business continuity, then comparing those controls against today’s threat environment. The goal is to find gaps before they become failures, because a plan without an honest baseline often looks stronger on paper than it is in practice.
What security leaders should do first
The first job is to establish an honest baseline of the current security posture. That baseline should cover people, process, and technology together, because cyber safety breaks down when leaders fix one layer while assuming the others are already sound. The goal is not a perfect scorecard, but a decision-ready view of where the business is exposed.
A useful baseline is operational, not theoretical. It should tell leaders what is staffed, what is trained, what is monitored, what is recoverable, and where the organisation is depending on informal workarounds. That is the difference between a programme that sounds mature and one that can actually absorb pressure.
How to build a baseline that leadership can trust
Start by checking whether the organisation can answer four questions without guessing: who owns the control, what evidence proves it works, when it was last tested, and what happens if it fails. That forces the review away from slideware and toward observable reality. A strong baseline usually includes incident response readiness, backup and recovery confidence, access governance, and the state of critical systems.
This is also where current threat conditions matter. A baseline is only useful if it is compared with the threats the business faces now, not last year’s assumptions. Teams should ask whether the current control set matches today’s attack paths, business dependencies, and recovery expectations, then separate true capability from assumed capability.
What leaders should look for once the baseline is set
The first pass should identify gaps that create immediate business fragility: understaffed functions, training that does not match actual responsibilities, controls that exist on paper but are not exercised, and recovery arrangements that have never been tested under realistic conditions. Security leaders should also look for single points of failure in operations, because those often become the fastest route from a local issue to a business-wide outage.
That review should lead to prioritisation, not a long wish list. A baseline only helps if it shows where the organisation can reduce exposure fastest, where resilience is weakest, and which failures would have the broadest operational impact. For practical response planning, teams can anchor this work in CISA cyber threat advisories to keep the baseline aligned with active threat patterns, and use NCSC UK Advice and Guidance for operational control checks and board-level framing.
Risk and Threat Considerations
An incomplete baseline creates a false sense of safety, which is often more dangerous than openly known weakness. If leaders do not understand current exposure, they may underinvest in the controls that matter most, miss weak recovery assumptions, or discover too late that an apparently solid control fails under real attack or outage conditions.
Failure mechanism: The business treats untested controls, stale training, and undocumented dependencies as evidence of protection, so gaps remain hidden until an incident forces them into the open.
Impact: The likely result is avoidable disruption, slower response, and a wider blast radius when a security event or operational failure occurs.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | A current baseline is the foundation of business cyber risk prioritisation. |
| ID.RA-01 — Asset Vulnerabilities are Identified and Documented | The answer centers on reviewing current posture to find gaps before they fail. | |
| RC.RP-01 — Recovery Plan is executed during or after an incident | Business continuity and recovery testing are part of the baseline leaders must assess. | |
| Recommendation — Define a current risk baseline before selecting security priorities. Inventory current gaps and document where exposure exists. Validate recovery assumptions through tested response and continuity plans. | ||
| NIST SP 800-53 Rev 5 | RA-3 — Risk Assessment | The question asks leaders to assess current posture against today’s threats. |
| CP-2 — Contingency Plan | Business continuity is explicitly part of the baseline leaders should review. | |
| Recommendation — Perform a current risk assessment before setting security priorities. Review and test contingency plans for critical business functions. | ||
| CIS Controls v8 | CIS-17 — Incident Response Management | Incident response readiness is a core part of the first posture assessment. |
| CIS-11 — Data Recovery | Recovery capability is part of the baseline needed for cyber safety. | |
| Recommendation — Validate incident response roles, playbooks, and escalation paths. Test restoration capability and confirm recovery objectives are realistic. | ||
| ISO/IEC 27001:2022 | A.5.24 — Information security incident management planning and preparation | The answer includes incident response preparedness as a baseline element. |
| Recommendation — Prepare and test incident response arrangements before relying on them. | ||
Practitioner Guidance
What to prioritise: Put the first review effort into the systems and processes that would most quickly stop the business from operating if they failed, especially recovery, response, and critical access paths. If the organisation cannot demonstrate that those controls work under test, treat them as open risk rather than established protection.
What to verify: Verify that every major control has an accountable owner, a recent test, and evidence that the result changed something operational. If the answer is only narrative, the baseline is not yet decision-ready.
Practitioner takeaway: The safest first move is not to launch more controls, but to make existing exposure visible enough that leadership can prioritise where failure would hurt the business most.
Related resources from NHI Mgmt Group
- How should security teams make NHI best practices usable across the business?
- How should security leaders build executive support for cyber hygiene programmes across the business?
- What should security teams do first if they want to improve cyber insurance readiness?
- What should security leaders in education do first to improve resilience against cyber incidents?