HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Topic · Enterprise

Business solutions

Frameworks and practices to secure an organisation, without leaving it to chance.

Dossiers in this section

6 dossiers

The topic in brief

Start from a framework

Enterprise security isn't improvised: it's structured on recognised frameworks. The NIST Cybersecurity Framework 2.0 organises the work around six functions — Govern, Identify, Protect, Detect, Respond, Recover — and is designed for organisations of any size. ISO/IEC 27001 is the international standard for information security management systems, certifiable by a third party.

Zero Trust: trust is not a strategy

The Zero Trust model starts from a simple principle: don't implicitly trust any request, inside or outside the perimeter, and always verify. CISA publishes a maturity model that helps move from the idea to a concrete, staged path, without impractical upheavals.

The few things that make the difference

Frameworks aside, the evidence is consistent: asset inventory, timely patch management, multi-factor authentication everywhere, verified backups, least privilege. These are ordinary measures that stop the majority of real attacks — the ones that fill our dossiers.

FAQ

Which framework should I choose?
The NIST CSF 2.0 is an excellent flexible starting point; ISO/IEC 27001 is the certifiable standard. They're often used together.
What is Zero Trust?
A model that grants no implicit trust to any request and always verifies identity and context, inside and outside the perimeter.