Most companies don't end up with a security incident for lack of tools. They get there for lack of order: a firewall here, an antivirus there, a password policy nobody reviews, an incident response plan that exists only in a forgotten document.
Each piece on its own seems sufficient. Together, they don't make a strategy.
Cybersecurity improves when it stops being a collection of tools and becomes a practice of governance, protection and recovery.
That's exactly the logic behind the NIST Cybersecurity Framework (CSF) 2.0 — and why more and more organizations and consultancies in Colombia are using it as a roadmap.
What NIST CSF 2.0 is
The NIST CSF is a cybersecurity risk management framework developed by the U.S. National Institute of Standards and Technology (NIST), designed for organizations of any size and sector — industry, government, academia and nonprofits.
It's a voluntary framework, not a mandatory certification, which makes it applicable regardless of sector or country.
Version 2.0, published in 2024, introduced a sixth core function: Govern.
This function didn't exist as a separate category before. The change reflects something practice had already been showing: cybersecurity can't be sustained with technical controls alone if there's no decision structure, roles and accountability behind them.
The 6 core functions: a roadmap, not a list
What makes CSF 2.0 useful isn't that it lists best practices — it's that it organizes them into a logical sequence any organization can follow, regardless of its maturity level.
Govern
GovernDefines the cybersecurity strategy, roles, policies and oversight. It's the starting point: without it, the other five functions run without direction or clear owners.
Identify
IdentifyUnderstand what assets, systems, suppliers and risks the organization really has. You can't protect what isn't inventoried.
Protect
ProtectImplement the safeguards needed to reduce the likelihood of an incident: access control, encryption, training and vulnerability management.
Detect
DetectIdentify security events and anomalies as they happen, not afterward.
Respond
RespondAct during and after an incident with a defined plan instead of improvising in real time.
Recover
RecoverRestore systems and services after an incident, and apply lessons learned to reduce the next risk.
The six functions work together.
They aren't a checklist you tick once. They operate continuously and simultaneously.
Sustains and guides the other five functions.
Constantly feeds back into protection decisions.
Protect, detect, respond and recover evolve with the risk.
Why it matters in the Colombian context
CSF 2.0 doesn't replace the regulatory frameworks that already govern public entities in Colombia, such as MinTIC's Information Security and Privacy Model (MSPI), based on ISO 27001.
It complements them: while the MSPI defines compliance guidelines for the public sector, CSF 2.0 provides a common language and a risk management structure that works just as well in the private sector.
Translating cybersecurity into business decisions.
The value of CSF 2.0 also lies in enabling senior management to understand, prioritize and make decisions about cybersecurity risk — not just the technical team.
This is particularly relevant for Colombian organizations that currently handle cybersecurity as a series of isolated IT decisions, without a structured conversation at the executive level about the real risk the business faces.
How to apply it: a practical roadmap
Adopting CSF 2.0 doesn't mean implementing all six functions at once or starting from scratch.
The practical path has three steps:
Assess
Assess the organization's current maturity against each of the six functions: what exists, what's informal and what doesn't exist.
Prioritize
Prioritize gaps according to the real business risk, not according to what's easiest to implement first.
Implement in phases
Build a phased implementation plan, typically starting with Govern and Identify, which are the foundation everything else rests on.
The starting point at ECOMIL
At ECOMIL, this is the starting point of our cybersecurity consulting and integration work: not selling standalone tools, but helping organizations build that complete roadmap.
A maturity assessment turns the organization's current state into a concrete, measurable first step.
Understand where the organization stands.
Risks, assets, responsibilities, existing controls and priority gaps.
A roadmap to bring order to cybersecurity
NIST CSF 2.0 isn't just another standard to add to the list of cybersecurity acronyms.
It's a framework that organizes what most organizations already have scattered around — tools, policies, good intentions — into a clear roadmap of governance, protection and recovery.
Find out your organization's maturity level.
At ECOMIL we help assess your organization's cybersecurity maturity against the six functions of NIST CSF 2.0 and build an implementation plan prioritized according to your real risk.
Assess my organization's maturity →