Skip to content

"Too small for NIST?" Here's how to right-size a security framework.

"Too small for NIST?" Here's how to right-size a security framework.
"Too small for NIST?" Here's how to right-size a security framework.
7:18

We hear this on partner and prospect calls: "We're too small for NIST."

Usually that means someone opened a framework, counted the controls, compared the total to the size of their IT team, got overwhelmed, and closed it.

But NIST wrote CSF 2.0 to help organizations of all sizes and sectors, and states plainly that it’s not a one-size-fits-all approach. Overwhelm comes in when a small IT team treats every control as equally urgent.

We asked practitioners about this on our podcast. Three of them (across banking, manufacturing and vCISO advisory) described the same dilemma in different words. Each podcast episode is linked where their comments come up.

What does "too small for NIST" actually mean?

It usually means the framework looks like a shopping list. It isn't.

CSF 2.0 is organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover. It describes outcomes, not products. It never tells a 200-person company to buy a network access control system. NIST even publishes a Small Business Quick-Start Guide meant to help organizations with modest or no cybersecurity plans in place.

If you’d prefer a prescriptive start point, CIS Controls can do that for you. Implementation Group 1 is 56 safeguards that CIS defines as essential cyber hygiene, the ones every organization, regardless of size or cyber sophistication, should apply against the most common attacks.

So the framework is rarely the problem. Scoping the work is the problem.

How does a lean security team choose a framework?

The CISO of a mid-market bank holding company had this decision forced on him. The FFIEC retired its Cybersecurity Assessment Tool, the self-assessment many banks and credit unions had relied upon for years, on August 31, 2025. Regulators pointed institutions to several alternatives without mandating one.

He moved to the Cyber Risk Institute Profile, a NIST-based framework built for financial services, and chose it "for our size and complexity."

Note what he didn't do. He didn't drop the framework when the old one went away, and he didn't adopt the largest one available. He picked one scoped for institutions like his.

He was equally direct about the budget: "We're not going to invest half of our budget in information security because it just doesn't make business sense."

That’s not resistance. It's a design constraint that belongs at the start of the exercise, not the end. A framework plan that ignores budget isn't a plan, it's a wish list.

What does 80/20 look like in practice?

The IT manager at a manufacturer put it in Pareto terms. Take a framework and get to 80 percent. Don't build your plan around the exotic attack chain, like one that worms its way from a printer to a server to someone's iPhone.

That chain is certainly possible. It's just not where a small team's next dollar or next hour should go.

Look, the 80 percent is unglamorous, and that's exactly the point here. CIS IG1 leans heavily on inventory, secure configuration, account management, backups and training. You need to know what you own. You need to have good controls around who can log in to a given server, application or database. You need to keep it patched. You need to be able to restore it. Most of the incidents that hurt mid-market organizations start with a gap in at least one of these, not with a novel technique from North Korea.

Where does compliance fit?

The CRO of a vCISO firm summed it up well: "Compliance is a byproduct of good security."

His advice to clients is to pick a framework, NIST, ISO or CIS, and follow through on it. Compliance requirements usually cover one slice of a broader framework, such as privacy or a specific type of data. They aren't a security program on their own. Implementing a full, industry-vetted framework is what gives the program credibility.

And the order matters. Build for an audit and you get a binder. Build for security outcomes and audit evidence is a derivative of the right work.

Which parts of a framework are hardest to do yourself?

Most of IG1 is work you should own. Asset inventory, accounts, configurations and backups are specific to your environment. Nobody outside your organization knows which systems can go offline mid-shift or which vendor has access to what.

The Detect and Respond functions are different. In CIS terms that's Control 8 (Audit Log Management), Control 13 (Network Monitoring and Defense) and Control 17 (Incident Response Management). These outcomes depend on continuous coverage and correlation across sources, which is exactly where a two- or three-person team runs out of gas. We covered this in a separate blog, what "someone watching" misses.

They also outsource well, because these techniques generalize. An attacker moving laterally through Active Directory looks the same at a bank as at a manufacturer.

Where does Gradient Cyber fit?

Quorum AI operationalizes the monitoring and response portions of frameworks like NIST CSF and PCI DSS. It correlates telemetry across endpoint, network, identity, SaaS and cloud. What reaches you is a SitRep: the supporting evidence, a severity, and prioritized actions. SitReps document incident handling, and reporting supports audits.

What we don't do: replace your GRC program, write your policies, or own your controls. For gap assessments and policy work, we coordinate with vCISO partners.

How do you start this quarter?

  1. Pick the framework your stakeholders speak. CSF 2.0 for boards and insurers. The CRI Profile if you're a bank. CIS IG1 as the implementation checklist under either.
  2. Set your budget ceiling. Then scope to it.
  3. Score yourself against IG1 and chase the 80. Inventory, identity, configuration, backups, training.
  4. Decide what you own and what you buy. Environment-specific work stays in house. Continuous detection and response is the strongest candidate for outsourcing.
  5. Make evidence a byproduct. If your monitoring and response produce documentation as they run, audit prep becomes collection, not reconstruction.

Frequently asked questions

Do regulators require a specific framework?

For banks and credit unions, not since the CAT sunset. The FFIEC pointed institutions to NIST CSF 2.0, the CRI Profile, CISA's Cybersecurity Performance Goals and the CIS Controls without mandating any one of them. Other sectors have their own requirements, so check yours.

NIST or CIS?

Both. CSF 2.0 gives you outcome language for boards, auditors and insurers. CIS IG1 gives a lean IT team a prioritized list of what to do first. They map to each other, so one effort serves both.

Does an MXDR service make us compliant?

No. It covers the detect and respond outcomes and produces evidence for them. Control ownership, policy and the rest of the framework stay with you.

We're a three-person IT team. Where do we start?

IG1, scored honestly. Get the 80 on inventory, identity and backups before you spend a dollar on the long tail.


You aren't too small for a framework. You're too small to treat every control equally.

Blog comments