---
title: Critical security controls for businesses | Bawn
description: There are many resources available for SMB owners to begin the process of reducing their cyber risk with cybersecurity controls.
image: https://bawn.com/hubfs/Imported_Blog_Media/shutterstock_1558664219-2048x1536-1.jpg
---

[Skip to main content](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/critical-security-controls#main)

[![Logo Transparency-1 (1)](https://bawn.com/hs-fs/hubfs/Logo%20Transparency-1%20(1).png?width=230&height=66&name=Logo%20Transparency-1%20(1).png)](https://bawn.com)

- Show submenu for Cyber Risk Engineering Cyber Risk Engineering 
  
    - [What is Cyber Risk Engineering](https://bawn.com/what-is-cyber-risk-engineering)
    - [Cybersecurity vs Cyber Risk Engineering](https://bawn.com/cybersecurity-vs-cyber-risk-engineering)
    - [The Bawn Risk Engineering Framework](https://bawn.com/cyber-risk-engineering-framework)
    - [Cyber Risk Assessment](https://bawn.com/get-your-cyber-risk-score)
    - [Cyber Liability Exposure](https://bawn.com/understand-liability-exposure)
- Show submenu for Services Services 
  
    - Show submenu for Cyber Risk Services Cyber Risk Services 
      
          - [Risk Assessment](https://bawn.com/cybersecurity-risk-assessment-service)
          - [Security Strategy Development](https://bawn.com/cyber-security-strategy-development-services)
          - [Cyber Risk Mitigation](https://bawn.com/risk-mitigation-services)
          - [vCISO](https://bawn.com/vciso-virtual-chief-information-security-officer)
          - [Incident Response Planning](https://bawn.com/incident-response-planning-services)
    - Show submenu for Managed Services Managed Services 
      
          - [A Different Kind of MSP](https://bawn.com/bawn-is-a-different-msp)
          - [Full Service Secure IT](https://bawn.com/msp-services)
    - [Cyber Warranty](https://bawn.com/cyber-warranty)
    - Show submenu for Sectors Sectors 
      
          - [Energy and Utilities](https://bawn.com/energy-and-utilities)
          - [Manufacturing](https://bawn.com/manufacturing)
          - [Startups](https://bawn.com/cyber-services-for-startups)
          - [SMBs](https://bawn.com/smb-cybersecurity)
          - [Financial Services](https://bawn.com/financial-services-cybersecurity)
- [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)

Open main navigation

Close main navigation

- Show submenu for Cyber Risk Engineering Cyber Risk Engineering 
  
    - Cyber Risk Engineering
    - [What is Cyber Risk Engineering](https://bawn.com/what-is-cyber-risk-engineering)
    - [Cybersecurity vs Cyber Risk Engineering](https://bawn.com/cybersecurity-vs-cyber-risk-engineering)
    - [The Bawn Risk Engineering Framework](https://bawn.com/cyber-risk-engineering-framework)
    - [Cyber Risk Assessment](https://bawn.com/get-your-cyber-risk-score)
    - [Cyber Liability Exposure](https://bawn.com/understand-liability-exposure)
- Show submenu for Services Services 
  
    - Services
    - Show submenu for Cyber Risk Services Cyber Risk Services 
      
          - Cyber Risk Services
          - [Risk Assessment](https://bawn.com/cybersecurity-risk-assessment-service)
          - [Security Strategy Development](https://bawn.com/cyber-security-strategy-development-services)
          - [Cyber Risk Mitigation](https://bawn.com/risk-mitigation-services)
          - [vCISO](https://bawn.com/vciso-virtual-chief-information-security-officer)
          - [Incident Response Planning](https://bawn.com/incident-response-planning-services)
    - Show submenu for Managed Services Managed Services 
      
          - Managed Services
          - [A Different Kind of MSP](https://bawn.com/bawn-is-a-different-msp)
          - [Full Service Secure IT](https://bawn.com/msp-services)
    - [Cyber Warranty](https://bawn.com/cyber-warranty)
    - Show submenu for Sectors Sectors 
      
          - Sectors
          - [Energy and Utilities](https://bawn.com/energy-and-utilities)
          - [Manufacturing](https://bawn.com/manufacturing)
          - [Startups](https://bawn.com/cyber-services-for-startups)
          - [SMBs](https://bawn.com/smb-cybersecurity)
          - [Financial Services](https://bawn.com/financial-services-cybersecurity)
- [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)
- Search
- [Get Started](https://bawn.com/contact-bawn)

[Get Started](https://bawn.com/contact-bawn)

Search

# Critical security controls for businesses

May 10, 2023

**Tags:** 

[Cybersecurity](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/tag/cybersecurity)

For many small and medium-sized businesses (SMBs) the concept of a comprehensive cybersecurity program can be a difficult process to initiate. Fortunately, there are many resources available for SMB owners to begin the process of reducing their cyber risk.

One such resource is the Center for Internet Security (CIS) Critical Security Controls (CSC). A set of 18 guidelines for improving cybersecurity. They are designed to prioritize the most essential security measures and provide a framework for effective cybersecurity defense. Here are some of the key points to understand from the CIS 18 Critical Security Controls:

1. **The CIS CSCs are a prioritized set of guidelines**: The controls are numbered 1 through 18, and each control is designed to build on the previous one. 
2. **The controls are adaptable**: The CIS CSCs are not meant to be a one-size-fits-all solution. They are adaptable to different organizations’ needs and priorities.  
   Organizations can implement the controls in a way that works best for them. 
3. **The CSCs are designed to be measurable**: Each control has specific criteria that can be used to assess an organization’s implementation of the control. This allows organizations to measure their progress and identify areas that need improvement. 
4. **The CSCs are designed to be effective**: The controls are based on real-world threats and are designed to be effective at mitigating those threats. Implementing the CSCs can significantly improve an organization’s cybersecurity posture. 
5. **The first six controls are foundational**: The first six controls are considered foundational because they provide a solid base for an organization’s cybersecurity defense. These controls focus on basic cybersecurity hygiene, such as inventorying hardware and software, controlling administrative privileges, and maintaining secure configurations. 
6. **The CSCs cover a wide range of cybersecurity areas**: The controls cover areas such as vulnerability management, incident response, access control, and network security. By implementing the CSCs, organizations can improve their security posture across multiple areas. 
7. **The CSCs are regularly updated**: The CIS CSCs are updated regularly to reflect changes in the threat landscape and advances in cybersecurity technology. This ensures that the controls remain relevant and effective. 
8. **The CSCs are widely recognized**: The CIS CSCs are widely recognized as a best practice framework for cybersecurity. Many organizations, including government agencies, use the controls as a benchmark for their cybersecurity programs. 
9. **The CSCs are not a comprehensive cybersecurity solution**: While the CIS CSCs are a valuable tool for improving cybersecurity, they are not a comprehensive solution.

Organizations should also consider other cybersecurity frameworks and best practices to create a holistic cybersecurity program.

The CIS 18 Critical Security Controls are a good starting point for business owners to begin the process of adding extra layers of protection to their cybersecurity posture. They can be viewed at [https://www.cisecurity.org/controls/cis-controls-list](https://www.cisecurity.org/controls/cis-controls-list). Contact BAWN if you need assistance in understanding or implementing these controls to protect your company’s network infrastructure.

![Critical security controls for businesses](https://bawn.com/hs-fs/hubfs/Imported_Blog_Media/critical-cybersecurity-controls-300x233-2.png?width=300&height=233&name=critical-cybersecurity-controls-300x233-2.png)

### Related Articles

##### [![Why Startups Should Care About Cybersecurity Even If They Don't Handle Sensitive Information](https://bawn.com/hs-fs/hubfs/shutterstock_1028126971_edited.jpeg?width=520&height=294&name=shutterstock_1028126971_edited.jpeg) Cybersecurity for Small Businesses and Startups • April 29, 2024 Why Startups Should Care About Cybersecurity Even If They Don't Handle Sensitive Information 2 min read](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/why-startups-should-care-about-cybersecurity-even-if-they-dont-handle-sensitive-information)

##### [![Your Essential Cyber Security Risk Assessment Checklist: Is Your Business Protected?](https://bawn.com/hs-fs/hubfs/shutterstock_2231879513.jpg?width=520&height=294&name=shutterstock_2231879513.jpg) Cybersecurity for Small Businesses and Startups • September 10, 2024 Your Essential Cyber Security Risk Assessment Checklist: Is Your Business Protected? 3 min read](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/your-essential-cyber-security-risk-assessment-checklist-is-your-business-protected)

### Comments

![ancient-scroll (1)](https://bawn.com/hs-fs/hubfs/ancient-scroll%20(1).png?width=110&height=110&name=ancient-scroll%20(1).png)

### Cyber Knowledge Awaits

Stay ahead of cyber threats and gain valuable insights by subscribing to Bawn's blog today!

First Name

Last Name

Email \*

###### Recent Posts

- [Responsible AI Isn’t Optional: Why the Next Few Years Matter More Than Ever](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/responsible-ai-isnt-optional-why-the-next-few-years-matter-more-than-ever)
- [Why Insurance Innovation Is Really About Understanding Risk—Not Avoiding It](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/why-insurance-innovation-is-really-about-understanding-risk-not-avoiding-it)
- [Navigating Compliance in the Age of Cybersecurity: Insights from Kate Williams](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/navigating-compliance-in-the-age-of-cybersecurity-insights-from-kate-williams)
- [Why Your Business Continuity Plan Should Be Part of Your Cyber Risk Strategy](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/why-your-business-continuity-plan-should-be-part-of-your-cyber-risk-strategy)
- [A Cyber Playbook for Non-Tech Executives](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/a-cyber-playbook-for-non-tech-executives)

[![Logo Transparency-2 (1)](https://bawn.com/hs-fs/hubfs/Logo%20Transparency-2%20(1).png?width=300&height=87&name=Logo%20Transparency-2%20(1).png)](https://bawn.com/placeholder)

- Company 
    - [About Bawn](https://bawn.com/about-us)
    - [Our Approach to Cyber Risk](https://bawn.com/cyber-services-for-startups-4)
    - [Our Services](https://bawn.com/cyber-services-for-startups)
    - [Career](https://bawn.com/careers)
    - [Our Partners](https://bawn.com/partners)
    - [Privacy Policy](https://bawn.com/privacy-policy)
    - [Terms and Conditions](https://bawn.com/terms-and-conditions)
    - [Master Services Agreement](https://bawn.com/master-services-agreement)
- Get Help 
    - [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)
    - [CPA Toolkit](https://bawn.com/cpa-trusted-advisor)
    - [FAQ](https://bawn.com/frequently-asked-questions)
    - [Contact Us](https://bawn.com/contact-bawn)
- Affiliate Program 
    - [For Insurance Agents & Brokers](https://bawn.com/insurance-agent-affiliate-program)
    - [Affiliate Program Terms and Conditions](https://bawn.com/bawn-affiliate-terms-and-conditions-program-)
- Crushing It 
    - [Podcast Episodes](https://bawn.com/crushing-it)
    - [Guest Signup](https://bawn.com/crushing-it/guest-signup)

©2026 Bawn, Inc. All rights reserved.

 

- <https://www.linkedin.com/company/bawn>
- <https://www.twitter.com/BawnHQ>
- <https://www.youtube.com/@BawnCyber>
- <https://www.facebook.com/bawncyber>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Darren Mott",
    "url" : "https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/author/darren-mott"
  },
  "dateModified" : "2023-11-09T05:14:39.999Z",
  "datePublished" : "2023-05-10T21:31:50.000Z",
  "headline" : "Critical security controls for businesses | Bawn",
  "image" : [ "https://bawn.com/hubfs/Imported_Blog_Media/shutterstock_1558664219-2048x1536-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/critical-security-controls",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://bawn.com/hubfs/Logo%20Transparency-1%20(1)-1.png"
    },
    "name" : "Bawn"
  }
}
```