preloader
Our new platform is here - start free at app.foundationcybersecurity.com.au

Foundation Cyber Security is built on 47 practical controls, organised into four pillars: Strategy, Protection, Response, and Recovery. Together they cover what a small to medium organisation needs to get right - the technical controls, and the strategy, governance, and planning that make them stick.

Each page below is the short version of a control: what it is, why it matters, the risk of leaving it, and where to start. Every control also maps to CIS Controls v8, NIST 800-53, the Essential Eight, and ISO 27001. The full detail - assessment questions, maturity levels, and recommendations matched to your score - is in the Foundation platform, free to start.

Strategy

Strategy is where most frameworks are weakest, and where Foundation starts. These controls cover your cybersecurity strategy, governance, asset management, and risk management - the things that get leadership on board and make every other control easier to land.

Assets

Governance

Preparation

Risk

Protection

The technical heart of the framework. These controls protect your applications, data, devices, network, and people - from multi-factor authentication and patching through to backups, access management, and staff training.

Apps

Data

Devices

Network

Users

Response

When something does happen, these controls determine how quickly you spot it and how well you respond - detection and logging, incident response, and business continuity.

Business Continuity

Detection

Incident Management

Recovery

Getting back to normal, and getting better. These controls cover recovery planning, disaster recovery testing, and managing the improvements that come out of incidents and assessments.

Improvement

Planning


If you’re not sure where to begin, take the free 5-question Quick Security Check for a 2-minute read on your posture, or create a free account and work through all 47 controls at your own pace.