Resources

NIST CSF 2.0 for Companies with 20 to 500 Employees

The Framework still applies at fifty people. The binder written for a bank does not. A proportional read is a way to decide what to do next, not a way to look finished.

Why the bank’s binder fails at fifty people

NIST CSF 2.0 was written so that a great many kinds of organizations could describe a cybersecurity program in the same language. That is its value, and it is also how it gets misused. A mid-market firm downloads an enterprise control set, or inherits one from a former employer, and tries to perform it. The performance fails. The principles did not fail. Access still needs an owner. An incident still needs a plan. A vendor who holds your data is still your problem.

The firms this practice serves are law firms, advisers, and SaaS companies between roughly 20 and 500 people, usually in the week a questionnaire, a renewal, or an exam asks them to describe the program. The Framework is a way to organize that description. It is not a binder written for a bank.

Six Functions, plus the two subjects clients now add

The Functions are Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the one teams skip, and it is the one examiners, customers, and carriers have started to ask about first: who is accountable, and how does the firm decide. Identify is the inventory: systems, data, vendors. Protect is access, configuration, and the ordinary hygiene that is still where incidents start. Detect is whether you would notice. Respond and Recover are the plan and the restore, which are different documents and are often confused.

Two subjects sit beside that list in the way this firm assesses a company. Supply chain, because your clients have started treating your vendors as theirs. AI governance, because the same clients have started asking what tools see their data. Neither requires a research program. Both require a list and a rule.

Scoring is for priority

A score is useful when it changes the order of work. It is theater when it is a number on a slide and the next quarter looks like the last one. The point of scoring a thin team is to say, out loud, which three gaps will block a deal, a renewal, or an exam, and which gaps can wait without pretending they are closed.

The gaps that block are rarely exotic. They are multi-factor authentication that does not cover the accounts that matter, backups nobody has restored, an incident plan with no names, a vendor list that is a memory, and policies the staff have not seen. A maturity assessment, fixed scope at $3,000 to $8,000, exists to rank those against the firm in front of us, not against a hypothetical enterprise.

From a score to a year, and to a page a board will read

The output that earns its keep is a 12-month roadmap and a board summary short enough to be read. The roadmap says what will be done, by whom, and what “done” looks like. The summary says where the firm is exposed and what the next two quarters will change. Remediation and documentation, $3,500 to $7,500, is how the top of that roadmap becomes policies, an incident response plan, and an evidence set. A retainer is how it stays true after the project ends. Most firms do not need the retainer on day one.

Services lists those engagements in the order a firm should actually buy them. The order matters more than the menu.

Take the directional assessment

The free readiness assessment is the same frame, answered by you, in about five minutes, across 41 questions from Govern through Recover, including supply chain and AI governance. It is directional. It will not satisfy a customer, a carrier, or an examiner. It will stop a leadership meeting from spending an hour on a gap that is not the one blocking the quarter. If the result and the conversation in the room disagree, believe the disagreement. That is the useful part.

Next step

If this is the request on your desk.

The assessment is free and takes about five minutes. The intro is fifteen minutes if you want the work scoped to a date. The document link is there if this week you only need the paper.

TRM Solutions is an independent advisory practice not affiliated with, endorsed by, or sponsored by any current or former employer. Employer names describe professional experience only. Engagements are conducted in a personal capacity and do not involve employer systems, data, clients, vendors, or confidential information. Client engagements are covered by NDA. Assessments and templates provide directional guidance and are not a penetration test, audit, certification, or guarantee of security.