3 year generic cybersecurity roadmap
Matthijs van der Wel-ter Weel
Strategic Advisor on cybersecurity @ Orange Cyberdefense
I'm reaching out to our community of cybersecurity professionals for your insights and feedback on a crucial topic:
Can we define a generic 3-year roadmap for cybersecurity for a mid size company?
In my client engagements, I discuss defining a tailored strategy, guidelines, target operating model etc. However, I find that some clients ask me to provide them with a roadmap and tell them what to do. You can argue that there is no such thing as a standard/generic approach that fits all. Yet I'm triggered to see if there is something generic that can be used as a starting point in our dialog.
Here's a preliminary outline I've been working on:
Year 1: Foundation and Immediate Priorities
Year 2: Strengthening and Expansion
领英推荐
Year 3: Optimization and Future-Proofing
What do you think? Is this roadmap comprehensive enough? Are there other crucial elements we should consider? Can organizations implement these elements in 3 years time or is it way too much for them to handle? How would you prioritize and structure these initiatives?
Are there already generic roadmaps available that ideally link to a framework? For example, https://www.cisecurity.org/insights/blog/align-to-a-framework-plan-a-cybersecurity-roadmaps-route
Your expertise and experiences are invaluable. Let's discuss, refine, and collaborate to create a robust, adaptable roadmap that can benefit the entire cybersecurity community.
Comment below or connect with me directly to share your thoughts! ????
Cyber Resilience Manager
4 个月It’s a good guideline, but we have to open our eyes also on the Post Quantum periode that stands before the door, the 4the technical (r)evolution we are in, AI impact and… the fact that we are moving towards Zero Trust Networks, the switch from IT security towards Network Security. What really missing for me is what will be the ROI on those investments? ??
Assistant Professor Cyber Security at University of Applied Sciences Utrecht (HU)
4 个月I think the key aspects are well covered but what I miss is the embedding in continuous improvements Matthijs van der Wel-ter Weel . A roadmap gives the false impression you are 'done' after 3 years, but as we all know we need to keep up to date within cyber security both in strategy as well as technical measures