Assess against NIST CSF 2.0
We built a current profile across all six functions, starting with Govern — new in version 2.0 — which surfaced that nobody at leadership level formally owned cyber risk.
Penspy is an independent security firm, testing web applications and auditing against the frameworks you answer to.
A credit union’s board asked a simple question — how secure are we? — and received three vendor reports that answered it three different ways.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
A regional credit union.
Over two years the credit union had collected a managed-services report, an insurer’s questionnaire and an internal IT review. Each used its own scoring, and none of them agreed on what to fix first.
The new CEO wanted one picture, in one framework, that could be repeated each year and compared.
We built a current profile across all six functions, starting with Govern — new in version 2.0 — which surfaced that nobody at leadership level formally owned cyber risk.
Interviews were verified against evidence: MFA coverage, backup restore tests and patch timelines were checked rather than taken on trust, using the CIS Controls v8.1 safeguards as the yardstick.
Twenty-two gaps were grouped into four quarters of work, each with an owner, a rough cost and the CSF outcome it moves.
| Severity | Finding | Maps to | Status at retest |
|---|---|---|---|
| High | Backups were taken nightly, but no restore had been tested in 19 months. | CSF RC.RP · CIS 11.5 | Closed |
| High | MFA was enforced for staff email but not for the core banking administrator console. | CSF PR.AA · CIS 6.5 | Closed |
| High | No named executive owner for cyber risk; not on the board agenda. | CSF GV.RR | Closed |
| High | Two vendors held standing domain administrator access with no review. | CSF GV.SC · CIS 5.4 | In progress |
| Medium | Incident response plan last updated before the move to cloud email. | CSF RS.MA · CIS 17.4 | Closed |
What changed.
The board received a one-page CSF 2.0 profile showing current and target tiers per function, and a quarterly roadmap. The CEO now presents progress against the same profile at each board meeting.
Six months later the follow-up review showed three functions moved up a tier, and the insurer’s renewal questionnaire was answered from the same evidence.
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.