CYBERSECURITY · CONSULTING AND INTEGRATION

NIST CSF 2.0 in practice: a cybersecurity roadmap for Colombian companies

What NIST CSF 2.0 is, its 6 core functions explained in executive language, and how to apply it as a practical cybersecurity roadmap in Colombian companies and public entities.

August 19, 2026 • 8 min read

Most companies don't end up with a security incident for lack of tools. They get there for lack of order: a firewall here, an antivirus there, a password policy nobody reviews, an incident response plan that exists only in a forgotten document.

Each piece on its own seems sufficient. Together, they don't make a strategy.

Cybersecurity improves when it stops being a collection of tools and becomes a practice of governance, protection and recovery.

That's exactly the logic behind the NIST Cybersecurity Framework (CSF) 2.0 — and why more and more organizations and consultancies in Colombia are using it as a roadmap.

01 · THE FRAMEWORK

What NIST CSF 2.0 is

The NIST CSF is a cybersecurity risk management framework developed by the U.S. National Institute of Standards and Technology (NIST), designed for organizations of any size and sector — industry, government, academia and nonprofits.

It's a voluntary framework, not a mandatory certification, which makes it applicable regardless of sector or country.

THE KEY CHANGE IN 2.0

Version 2.0, published in 2024, introduced a sixth core function: Govern.

This function didn't exist as a separate category before. The change reflects something practice had already been showing: cybersecurity can't be sustained with technical controls alone if there's no decision structure, roles and accountability behind them.

02 · THE ROADMAP

The 6 core functions: a roadmap, not a list

What makes CSF 2.0 useful isn't that it lists best practices — it's that it organizes them into a logical sequence any organization can follow, regardless of its maturity level.

01

Govern

Govern

Defines the cybersecurity strategy, roles, policies and oversight. It's the starting point: without it, the other five functions run without direction or clear owners.

02

Identify

Identify

Understand what assets, systems, suppliers and risks the organization really has. You can't protect what isn't inventoried.

03

Protect

Protect

Implement the safeguards needed to reduce the likelihood of an incident: access control, encryption, training and vulnerability management.

04

Detect

Detect

Identify security events and anomalies as they happen, not afterward.

05

Respond

Respond

Act during and after an incident with a defined plan instead of improvising in real time.

06

Recover

Recover

Restore systems and services after an incident, and apply lessons learned to reduce the next risk.

A CONTINUOUS LOGIC

The six functions work together.

They aren't a checklist you tick once. They operate continuously and simultaneously.

GOVERN

Sustains and guides the other five functions.

IDENTIFY

Constantly feeds back into protection decisions.

CONTINUOUS CYCLE

Protect, detect, respond and recover evolve with the risk.

03 · COLOMBIAN CONTEXT

Why it matters in the Colombian context

CSF 2.0 doesn't replace the regulatory frameworks that already govern public entities in Colombia, such as MinTIC's Information Security and Privacy Model (MSPI), based on ISO 27001.

It complements them: while the MSPI defines compliance guidelines for the public sector, CSF 2.0 provides a common language and a risk management structure that works just as well in the private sector.

THE DIFFERENCE

Translating cybersecurity into business decisions.

The value of CSF 2.0 also lies in enabling senior management to understand, prioritize and make decisions about cybersecurity risk — not just the technical team.

This is particularly relevant for Colombian organizations that currently handle cybersecurity as a series of isolated IT decisions, without a structured conversation at the executive level about the real risk the business faces.

04 · FROM THEORY TO PRACTICE

How to apply it: a practical roadmap

Adopting CSF 2.0 doesn't mean implementing all six functions at once or starting from scratch.

The practical path has three steps:

01

Assess

Assess the organization's current maturity against each of the six functions: what exists, what's informal and what doesn't exist.

02

Prioritize

Prioritize gaps according to the real business risk, not according to what's easiest to implement first.

03

Implement in phases

Build a phased implementation plan, typically starting with Govern and Identify, which are the foundation everything else rests on.

OUR APPROACH

The starting point at ECOMIL

At ECOMIL, this is the starting point of our cybersecurity consulting and integration work: not selling standalone tools, but helping organizations build that complete roadmap.

A maturity assessment turns the organization's current state into a concrete, measurable first step.

BEFORE DEFINING THE TECHNOLOGY

Understand where the organization stands.

Risks, assets, responsibilities, existing controls and priority gaps.

05 · CONCLUSION

A roadmap to bring order to cybersecurity

NIST CSF 2.0 isn't just another standard to add to the list of cybersecurity acronyms.

It's a framework that organizes what most organizations already have scattered around — tools, policies, good intentions — into a clear roadmap of governance, protection and recovery.

Does your organization know where it stands on that roadmap today?
CYBERSECURITY ASSESSMENT

Find out your organization's maturity level.

At ECOMIL we help assess your organization's cybersecurity maturity against the six functions of NIST CSF 2.0 and build an implementation plan prioritized according to your real risk.

Assess my organization's maturity →

Legal Pages

FAQs

Privacy Policy

Contact Support

Cookie Policy