Skip to main content

CIS implementation by Neo Security

From loose measures to a working security approach

CIS critical Security controls

With the CIS Controls (an international framework of security measures) you build a strong defense against cyberattacks step by step. We address the biggest risks first, so you see results quickly.

Our engineers help you implement the CIS Controls in phases. We align this with your organization: how large you are, which sector you work in and which risks you face. This way CIS doesn't remain theory, but delivers noticeable improvements every month.

You get practical measures, clear priorities and clear growth in your security level.

At a glance

  • Up to 95% of common attacks covered

    The CIS Controls target the most common types of attacks. By implementing them properly you prevent the majority of everyday threats.

  • We start with the biggest risks

    We prioritize the measures that have the most impact for your organization.

  • Results you can measure

    You receive clear security metrics that show how your security posture is improving.

  • Globally recognized framework

    CIS is an internationally recognized framework that is regularly updated with the latest insights.

Why CIS?

The CIS framework is not a book full of theory, but a practical list of proven controls (security measures). We use CIS as the backbone of your security approach. We link each control to a concrete risk and a clear measure: what do we enable, who is responsible and when is it done.

Up to 95% of common attacks covered

The CIS Controls target the most common types of attacks. By implementing them properly you prevent the majority of everyday threats.

We start with the biggest risks

We prioritize the measures that have the most impact for your organization.

Results you can measure

You receive clear security metrics that show how your security posture is improving.

Globally recognized framework

CIS is an internationally recognized framework that is regularly updated with the latest insights.

Implementation Groups

The CIS Controls are divided into Implementation Groups (IG1, IG2, IG3). These are levels that match the maturity and risks of your organization.

IG1

Basic cyber hygiene

The baseline measures every organization needs.

56 safeguards

Controls 1-6, 10, 12, 14

Asset management (system overview)
Secure configurations (safe settings)
Account management
Malware defense (antivirus)
IG2

Enhanced security

For organizations with sensitive or confidential data.

74 safeguards

All IG1 + additional controls

Vulnerability management
Audit log management
Network monitoring
Incident response
IG3

Advanced security

For organizations with critical processes (healthcare, finance, infrastructure).

23 safeguards

All IG1, IG2 + penetration testing

Penetration testing (ethical hacking)
Red team exercises (attack simulations)
Advanced threat detection
Zero trust architecture

Our approach for CIS implementation

1

Phase 1: assessment & risk prioritization

Week 1–2

We start with a CIS maturity assessment: we compare your current security against the CIS Controls. Our engineers map out the key gaps (gap analysis) and create a clear roadmap. The plan specifies which measures we tackle first and why.

Features:

CIS maturity assessmentGap analysis (overview of gaps)Risk-based roadmap
2

Phase 2: IG1 – fundamentals in order

Week 3–8

We implement the measures from Implementation Group 1. These are the baseline measures every organization needs. We set up: Asset inventory (overview of devices/systems), Secure configurations (safe settings) and Access management.

Features:

Asset inventorySecure configurationsAccess management
3

Phase 3: IG2 – deepening

Week 9–16

For organizations with sensitive data we expand to IG2. We set up: Vulnerability management (structural scanning for vulnerabilities), Log monitoring (checking logs) and an Incident response plan (action plan for incidents).

Features:

Vulnerability managementLog monitoringIncident response plan
4

Phase 4: continuous improvement

Week 17+

If your organization has critical processes, we grow towards IG3. We set up Penetration testing as a check, establish security metrics and start a cycle of continuous improvement.

Features:

Penetration testingSecurity metricsContinuous improvement

The 18 Critical Security controls of the CIS framework

1Inventory of enterprise assets (overview of all devices and systems)
IG1
2Inventory of software assets (overview of all software)
IG1
3Data protection
IG1
4Secure configuration of assets
IG1
5Account management
IG1
6Access control management
IG1
7Continuous vulnerability management
IG2
8Audit log management
IG2
9Email and web browser protection
IG2
10Malware defense
IG1
11Data recovery
IG2
12Network infrastructure management
IG1
13Network monitoring and defense
IG2
14Security awareness training
IG1
15Service Provider Management
IG2
16Application software security
IG2
17Incident response management
IG2
18Penetration Testing
IG3

Start today with CIS controls

With the CIS Controls you strengthen your digital resilience with measures we know work. Our engineers guide you step by step through implementation and ensure security that fits your organization, without unnecessary complexity.