Where do you even start?

Cybersecurity readiness can feel overwhelming for firms outside the tech sector. The terminology is dense, the frameworks are long, and the pressure to "do something" often leads companies to buy a security tool before they have even mapped out what they are actually trying to protect. The result is a patchwork of purchased solutions that don't add up to a coherent security posture — and a firm that still cannot answer basic questions when a client, auditor, or regulator asks about its readiness.

A more effective starting point is to think in terms of a small number of core domains that most cybersecurity frameworks converge on. Getting a firm's basics right across these six areas builds a genuine foundation — one that technical tools can then support, rather than substitute for.

1. Cybersecurity governance and policy

Before any technical control matters, a firm needs clear ownership: who is responsible for cybersecurity decisions, what the firm's written policies actually require of employees, and how those policies get enforced and updated. Without this, technical measures tend to exist in isolation, with no one accountable for whether they are actually working.

2. Asset and risk management

You cannot protect what you haven't identified. This domain covers building an accurate inventory of the systems, data, and devices the firm relies on, and then assessing which of those assets carry the greatest risk if compromised. A firm that knows exactly where its sensitive data lives is in a completely different position than one that is guessing.

3. Identity and access management

This domain governs who can access what, and under what conditions — strong authentication practices, role-based access limits, and prompt removal of access when an employee's role changes or ends. A large share of real-world security incidents trace back to access that should have been restricted or revoked long before the incident occurred.

4. Network and systems protection

This is the more familiar, technical layer: firewalls, secure configurations, patching schedules, and protections against malware and unauthorized network access. It matters, but it is far more effective when it sits on top of the governance and asset-management work above rather than standing in for it.

5. Incident response

No security program prevents every incident. What separates a firm that recovers quickly from one that suffers lasting damage is whether it has a documented, rehearsed plan for detecting, containing, and reporting a security incident before one actually happens. Building this plan under pressure, in the middle of a live incident, is the worst possible time to start.

6. Business continuity and disaster recovery

This domain covers a firm's ability to keep operating, or recover quickly, when systems are disrupted — whether by a cyberattack, technical failure, or other disruption. Regular backups, tested recovery procedures, and a clear plan for maintaining critical operations all fall here.

How a firm assesses where it actually stands

The practical way to move from these six domains to an action plan is a gap assessment: reviewing your current practices against each domain, honestly, and identifying where the biggest gaps sit relative to your firm's actual risk profile. This produces a prioritized list rather than an overwhelming one — a small number of concrete next steps instead of a vague sense that "we should do more on cybersecurity."

The firms that struggle most with cybersecurity are rarely the ones with no budget for tools — they're the ones who bought tools before they had a policy telling them what those tools were supposed to protect.

Why policy comes before technology

It is tempting to treat cybersecurity as a shopping list of software to install. But a firewall configured without a clear policy on what traffic should be allowed, or an access control system deployed without a defined ownership structure, tends to underperform its cost. Starting with governance and policy — even before any new technical purchase — ensures that every subsequent investment in tools is actually solving a defined problem, not just adding another dashboard nobody reviews.