Building a Simple Security Roadmap Using NIST CSF 2.0

Many small and mid-size care organizations know they need to improve cybersecurity but do not know where to begin or how to explain priorities to leadership. The NIST Cybersecurity Framework gives a common structure for that conversation. Version 2.0 was published in February 2024 and is designed to be useful to organizations of all sizes. As the new year approaches, it is a good moment to turn it into a plan.

The six functions

CSF 2.0 organizes cybersecurity outcomes into six functions. They are easy to explain to non-technical leaders.

Govern

New in version 2.0. This covers how leadership sets direction: roles and responsibilities, policies, risk strategy and oversight of suppliers.

Identify

Know what you have and what could go wrong: assets, data, vendors and risks.

Protect

Safeguards that reduce risk: access control, training, data security, secure configurations and maintenance.

Detect

Finding problems quickly through monitoring and alerts.

Respond

Taking action when an incident occurs: response plans, communication and analysis.

Recover

Restoring operations and learning from the event.

The framework is voluntary and not a replacement for HIPAA, but it complements it well. The HIPAA Security Rule says what to address, while the framework provides a way to organize and measure the work.

Step 1: Take stock honestly

For each function, list what you have today. A simple self-assessment might use plain ratings such as not started, partially in place or in place. Examples:

Govern: Is there a named security officer? Are policies current and approved?

Identify: Do you have an inventory of devices, software and vendors? Has a risk analysis been done in the past year?

Protect: Is multifactor authentication on email and remote access? Are laptops encrypted? Is staff training documented?

Detect: Does anyone review alerts from firewalls, endpoint protection and email?

Respond: Is there a written incident response plan with contact numbers?

Recover: Are backups tested, with an isolated copy?

Be honest and avoid blame. The goal is to find gaps.

Step 2: Choose priorities by risk

You cannot fix everything at once. Rank gaps by the harm they could cause and how easy they are to exploit. Many organizations find the same high-value starting points:

Multifactor authentication on email, remote access and administrator accounts

Tested backups with an isolated copy

Patching of internet-facing systems

A written, rehearsed incident response plan

Security awareness training and phishing reporting

An accurate inventory of systems and vendors

The HHS 405(d) Health Industry Cybersecurity Practices publication offers healthcare-specific guidance for small, medium and large organizations that can help you pick specific practices.

Step 3: Turn priorities into a roadmap

Split work into quarters with an owner, a deliverable and a way to confirm completion.

Quarter 1

Complete the risk analysis, inventory devices and vendors and deploy multifactor authentication on email.

Quarter 2

Expand multifactor authentication, test restore procedures and write or update the incident response plan.

Quarter 3

Segment the network, strengthen monitoring and run a tabletop exercise.

Quarter 4

Review vendor agreements, conduct an access review and update the roadmap for the next year.

Adjust the plan to your size, budget and current gaps.

Step 4: Report in plain terms

Give leadership a one-page update each quarter. Use the six functions as headings, show progress and highlight the next decisions or budget needs. Boards and owners respond better to a clear picture of risk reduction than a list of technical tasks.

Step 5: Review and repeat

Treat the roadmap as a living document. Revisit it after incidents, new systems, acquisitions and regulatory changes.

Getting help

UnityCare IT helps healthcare organizations assess their current security posture and build realistic, budget-aware roadmaps. If you would like a framework-based assessment to start the year, we are glad to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034