NIST Cybersecurity Framework 2.0 Addresses Growing Cyberattack Threats

NIST Cybersecurity Framework 2.0 Addresses Growing Cyberattack Threats

The News: The National Institute of Standards and Technology (NIST) releases the first draft of its Cybersecurity Framework (CSF) 2.0. Comments on the document are open to the public until November 4, 2023 and the final version is slated to be released in early 2024. Additional information is available on NIST’s website.

NIST Cybersecurity Framework 2.0 Addresses Growing Cyberattack Threats

Analyst Take: The NIST CSF was first released in 2014 as a set of voluntary best practices designed to guide industries with critical infrastructure, such as banking, energy, and healthcare, on understanding, communicating about, and, ultimately, mitigating cybersecurity risk. Effectively, it provides guidelines for developing, integrating, and measuring the success of cybersecurity programs for organizations through facilitating not only systematic methodologies, but also common language to aid communication between technical and nontechnical staff. The document has since become widely regarded as the de facto industry standard, having been downloaded more than 2 million times across more than 185 countries, according to NIST.

Naturally, much has developed since the NIST CSF’s inception. Cyber-crime has risen to an immediate, board-level priority that must be addressed ubiquitously, across industries – vastly broadening the NIST CSF’s applicability and its importance, from small businesses and local schools to large government organizations. Against this backdrop, more guidance is required on how to implement framework recommendations and best practices.

At the same time, the threat landscape is constantly evolving and more difficult than ever for organizations to keep pace with. To name just a few factors, supply chain risks have emerged, and new variants and tactics for ransomware and other malware attacks are continuing to increase.

Version 2.0 of the NIST CSF includes a number of key updates and additions that respond to these new requirements:

  • Arguably most notably, it adds a sixth pillar, “Govern,” to the previously existing five (“Recover,” “Identify”, “Respond,” “Detect,” and “Protect”). This new pillar reflects the criticality of cybersecurity from the standpoint of risk to the business or organization. It adds additional context regarding individual roles and responsibilities for managing cyber-threats, while providing additional context on formulating and executing cybersecurity frameworks from an organizational perspective. Specifically, the Governance pillar covers:
    • Organizational context
    • Risk management strategy
    • Roles and responsibilities
    • Policies and procedures
  • To help streamline adoption of the framework, Version 2.0 adds “Framework Profiles” that provide guidance on implementing CSF best practices, within the context of organizations’ specific resources. While preserving the framework’s flexibility, which allows it to be tailored to organizations’ unique requirements, these profiles add examples specific to industries and use cases that help organizations from the standpoint of implementation.
  • Finally, another important update with Version 2.0 is additional clarity around how the organization’s cybersecurity posture is assessed and measured.

Along with these updates, NIST will be launching a reference tool that will allow CSF 2.0 data to be browsed, searched and exported. The objective is to help organizations utilize the framework in conjunction with other industry guidelines and standards.

For IT Operations teams, the takeaway is that, if they are not yet being held to NIST recommendations from the standpoint of technology implementations and day-to-day policies and procedures, they should be prepared to be. Collaboration with security and line of business (LOB) leaders will continue to increase, and while these conversations may not always be easy, the NIST CSF Version 2.0 represents a tool that can help to facilitate discussions, conceptual development of cybersecurity policies, and their implementation.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

Tech Giants and White House Join Forces on Safe AI Usage

NIST Launches the Trustworthy & Responsible Artificial Intelligence Resource Center

Network Resilience Coalition Debuts to Boost Data and Network Security

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market
August 22, 2026

Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market

Thales positioned cybersecurity as a core growth pillar at its November 2024 Capital Markets Day, targeting a market expanding from $195B to $338B by 2029 at 11.6% CAGR, driven by...
FPT IS Bets on Vietnam's Data Privacy Law as a Platform Moment
August 22, 2026

FPT IS Bets on Vietnam’s Data Privacy Law as a Platform Moment

Vietnam's strict new data protection laws drive enterprise urgency. FPT IS launches a four-layer Data Privacy Management Platform to meet compliance demands and position itself as a strategic infrastructure partner....
DigiCert's PQC Event Franchise Shifts from Awareness to Action
August 21, 2026

DigiCert’s PQC Event Franchise Shifts from Awareness to Action

DigiCert's third annual World Quantum Readiness Day on September 17, 2026, marks a strategic shift from quantum awareness to active post-quantum cryptography deployment, addressing enterprises' top challenge: cryptographic agility....
OPSWAT's OTCEP Invitation: OT Security Credibility or Contract Pipeline?
August 21, 2026

OPSWAT’s OTCEP Invitation: OT Security Credibility or Contract Pipeline?

OPSWAT's CTO presentation at Singapore's OTCEP Forum signals peer-level recognition in OT Security, positioning the vendor to convert high-visibility relationships into durable contracts....
Can NXP MCX A5 MCUs Secure the Industrial Edge Before Agentic Attackers Arrive?
August 20, 2026

Can NXP MCX A5 MCUs Secure the Industrial Edge Before Agentic Attackers Arrive?

Brendan Burke and Olivier Blanchard, Research Directors at Futurum, share their insights on why NXP's MCX A5, the first MCU to combine a 10BASE-T1S digital PHY, topology discovery, and post-quantum...
Thales-Systematic Deal: Interoperability Is Now a Sovereign Imperative
August 20, 2026

Thales-Systematic Deal: Interoperability Is Now a Sovereign Imperative

Thales and Systematic's partnership integrates command-and-control software with SAMP/T NG air defence systems for Denmark, showing that integration capabilities now outrank feature innovation in enterprise cybersecurity....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.