A Risk-Based Control Framework for Executives and High-Risk Organisations
By Navid Sobbi, Founder and CEO, NSI Global
PUBLISHED: 5 February 2024 SUBSTANTIVELY REVISED: 1 September 2026 RESEARCH CUT-OFF: 31 August 2026 (AEST)
This paper provides general risk-management guidance. Controls should be selected and configured for the organisation’s threat profile, systems, legal obligations and operating environment.
Executive Summary
Cybersecurity guidance fails when it becomes a long list of precautions with no relationship to authority, business impact or threat exposure. An organisation does not become secure because employees switch off Bluetooth, avoid one public charging outlet or recognise a poorly written phishing email. Those habits may be relevant in particular circumstances, but they cannot substitute for governed identity, device, data, monitoring and response controls.
This white paper presents NSI Global’s recommended cybersecurity guidelines as a risk-based organisational framework. It draws on the Australian Signals Directorate’s current guidance, the Essential Eight, the Australian Government Information Security Manual, the Office of the Australian Information Commissioner’s breach-response guidance and the NIST Cybersecurity Framework 2.0.
The framework has seven operating priorities:
- Govern the risk: assign accountable owners, understand critical systems and decide what level of residual risk the organisation will accept.
- Control identity and privilege: prioritise phishing-resistant authentication, separate administrative access and govern account recovery.
- Harden and manage devices: maintain supported systems, patch according to exposure, restrict execution and protect data on endpoints.
- Protect information and communications: classify sensitive information and use approved channels suited to its value and context.
- Detect abnormal activity: retain useful logs, establish alert ownership and monitor identities, endpoints, cloud services and critical transactions.
- Prepare for elevated-risk conditions: apply stronger controls to executives, privileged users, international travel and sensitive projects.
- Respond and recover deliberately: contain incidents without unnecessarily destroying evidence, assess obligations and restore from tested arrangements.
The objective is not to promise complete protection. It is to make compromise harder, detection faster, impact smaller and organisational decisions more defensible.
Purpose and Scope
This paper is intended for Australian boards, executives, legal and risk teams, technology leaders, security personnel and organisations responsible for sensitive commercial, personal or government-related information. It addresses organisational cybersecurity rather than consumer safety alone.
It is designed to support risk assessment and control prioritisation. It is not a substitute for the Essential Eight Maturity Model, the Australian Government Information Security Manual, sector-specific requirements or legal advice. A control should not be adopted merely because it appears in a checklist; its purpose, owner, coverage and evidence of operation should be understood.
Cybersecurity Is a Governance Problem Before It Is a Technology Problem
NIST Cybersecurity Framework 2.0 organises cybersecurity outcomes around six functions: Govern, Identify, Protect, Detect, Respond and Recover. The addition of Govern reflects a practical reality: technology teams cannot independently decide what information matters most, which disruption is intolerable, what legal duties apply or how much residual risk the organisation will accept.
Boards and executives should establish:
- The executive accountable for cybersecurity risk and the roles responsible for individual control domains
- The critical services, information assets, identities, suppliers and technology dependencies that require priority protection
- The risk scenarios against which controls will be designed and exercised
- The organisation’s target maturity, including where the Essential Eight applies as a baseline
- The thresholds for executive, legal, privacy, insurer and regulatory escalation
- The evidence required to demonstrate that controls operate, not merely that policies exist
Cybersecurity should be treated as a continuous management process. Acquisitions, cloud migrations, restructures, new suppliers, privileged appointments, overseas travel and emerging vulnerabilities can change the risk profile faster than an annual policy review.
1. Establish a Risk-Tiered Control Baseline
Not every user, device or project warrants the same controls. Applying one low baseline to everyone underprotects high-value targets. Applying maximum restrictions indiscriminately can create operational friction and encourage workarounds.
| Risk tier | Typical exposure | Control objective |
| Organisational baseline | Ordinary users, managed devices and standard business information | Reduce common compromise pathways and establish recoverability |
| Elevated | Executives, finance, legal, HR, administrators, sensitive projects and frequent travellers | Resist targeted phishing, account takeover, data theft and transaction manipulation |
| High assurance | Government-related work, critical infrastructure, strategic transactions, hostile-environment travel and credible targeting | Minimise accessible data, strengthen isolation and communications, and increase active monitoring |
Risk tiering should influence authentication, device configuration, log retention, communications platforms, travel devices, monitoring and incident-response arrangements. It should not create permanent exemptions from the organisational baseline.
2. Control Identity, Authentication and Privilege
Identity is now a primary security boundary. Cloud applications, remote work and outsourced services allow a valid account to reach information without first crossing a traditional office network perimeter.
Prefer Phishing-Resistant Authentication
Multi-factor authentication should be enabled for business systems, particularly email, remote access, cloud administration, finance and accounts able to reset other users. However, authentication methods do not provide equal protection. ASD notes that public-key methods using a physically separate security key provide stronger resistance than several code-based approaches.
Where supported, use passkeys, FIDO2 security keys or another phishing-resistant method for privileged and high-risk users. SMS codes may still be better than single-factor authentication when stronger methods are unavailable, but they should not be represented as the preferred high-assurance control.
Authentication design should also address:
- Enrolment of new authentication methods and recovery channels
- Alerts and approval for changes to MFA, passkeys and recovery details
- Session duration, token theft and revocation after suspected compromise
- Legacy protocols or applications that can bypass modern authentication
- Emergency access accounts, including how their use is monitored
Use Unique Credentials and Govern Recovery
Password managers can generate and store unique credentials, reducing reuse across services. Where a password or passphrase remains necessary, it should be long, unique and resistant to guessing. Routine password rotation should not be treated as a universal substitute for compromise-driven resets, strong authentication and monitoring.
Security questions based on biographical details are weak recovery mechanisms for public figures and executives. Recovery should use controlled, auditable processes rather than information discoverable through corporate profiles or social media.
Separate Administrative Access
Administrators should not use privileged accounts for ordinary email and web activity. Privileged access should be limited, time-bound where practicable, reviewed and monitored. Departures, role changes and supplier offboarding should trigger prompt access review. Shared credentials weaken accountability and should be replaced with individually attributable access wherever possible.
3. Manage and Harden Devices
Devices should be treated as managed assets, not merely purchased equipment. The organisation needs to know what devices exist, who is responsible for them, whether they are supported and what information they can access.
Maintain Supported and Patched Systems
Enable managed updates and define patching priorities according to vulnerability exposure, exploitation and business criticality. Internet-facing systems, identity infrastructure and security products warrant particular attention. The Essential Eight provides maturity-based guidance for patching applications and operating systems; its implementation should be assessed for effectiveness, not inferred from policy settings.
Unsupported devices and software should be removed, isolated or covered by an approved risk treatment. A device that cannot receive security updates accumulates exposure regardless of whether it continues to function operationally.
Restrict What Can Execute
Application control, hardened user applications and restrictions on administrative privileges reduce the opportunities available to malicious code. Controls should extend beyond traditional antivirus. Depending on risk, they may include endpoint detection and response, mobile-device management, macro controls, browser hardening, controlled software installation and removable-media restrictions.
Software should be obtained through approved sources. This is not because every unapproved application is malicious, but because the organisation otherwise loses assurance over provenance, licensing, updates, permissions and support.
Encrypt, Lock and Manage Endpoints
Use device encryption, automatic screen locking and remote-management capabilities appropriate to the platform and risk. Recovery keys should be protected and accessible to authorised personnel. Lost or stolen devices should be reported immediately so access, sessions and corporate data can be assessed and, where appropriate, remotely contained.
Personal devices should not be assumed to provide the same controls as managed work devices. If bring-your-own-device access is permitted, the organisation should explicitly define the applications, information, management controls and privacy boundaries involved.
Treat Cables, Peripherals and Removable Media by Risk
Unknown removable media and peripherals can create risk, particularly in high-assurance environments. Organisations should define whether USB storage is blocked, permitted only when encrypted and issued by the organisation, or scanned through an approved workflow.
Public USB charging should not dominate an enterprise cybersecurity programme. For travellers and targeted personnel, carrying a trusted charger and cable is a sensible precaution. The broader control objective is to prevent untrusted data-capable accessories and physical access to devices, not to suggest that every public charging point represents an active compromise.
4. Protect Information and Communications
The correct communication channel depends on the sensitivity of the information, participants, devices, jurisdictions and threat profile. “Encrypted” is an important property, but it is not a complete security assessment.
Classify Information Before Selecting the Channel
Organisations should define what information may be sent through ordinary corporate email, approved collaboration tools, encrypted messaging, secure portals or specialised communications systems. Sensitive legal, strategic, government-related or crisis communications may require stronger controls than routine business coordination.
NSI Global’s corporate communications security services can support organisations that require communications designed for an elevated threat environment. The appropriate platform depends on the use case and should not be selected solely from a consumer application’s marketing claim.
Use Approved Work Channels
Work information should remain within authorised accounts and devices unless an approved exception exists. Separate work and personal identities reduce accidental disclosure, loss of organisational records and uncontrolled access after employment ends.
For meetings:
- Distribute invitations through controlled channels and restrict entry to expected participants
- Verify unfamiliar attendees before sensitive discussion begins
- Share only the required application or window rather than the entire screen
- Establish whether recording, transcription or AI meeting assistants are permitted
- Consider the physical surroundings, visible documents and people within hearing range
- Review recurring links, guest access and external collaboration settings
Understand What Encryption Does and Does Not Protect
End-to-end encryption can protect message content in transit between endpoints when correctly implemented. It does not protect information displayed on a compromised device, copied by an authorised participant, exposed through backups or accessed after an account takeover. High-risk communications therefore require endpoint security, identity verification and participant governance as well as encryption.
Statements based on interface colours or icons can become obsolete as messaging standards and platform behaviour change. Organisations should maintain an approved-platform standard and validate current security settings rather than relying on a static visual cue.
5. Detect Activity That Preventive Controls Miss
Prevention will not stop every intrusion, misuse or configuration error. Detection depends on collecting useful signals, retaining them for an appropriate period and assigning people who can interpret and act on them.
ASD’s security-assurance guidance identifies event logs as a core data source for detecting cybersecurity events. Useful logging should capture sufficient context, including time, relevant user or process, affected equipment and an event description.
Monitoring priorities commonly include:
- High-risk authentication, impossible or unusual access, new devices and changes to MFA
- Privileged-role assignment, emergency-account use and administrative configuration changes
- Mailbox forwarding, delegation, transport rules and suspicious application consent
- Endpoint malware, persistence, unusual process execution and security-control tampering
- Cloud storage sharing, bulk downloads and access to sensitive repositories
- Changes to backup configuration, log retention and security alerts
- Finance, payroll or supplier changes that could indicate business email compromise
Alert coverage is not the same as detection capability. Every material alert should have an owner, triage path, escalation threshold and expected response time. Log retrieval should be tested before an incident, including the impact of platform licensing and retention settings.
6. Apply Elevated Controls to Executives, Travel and Sensitive Work
Executives, senior advisers, finance personnel, administrators and employees involved in strategic projects may be targeted because of the decisions, access and relationships attached to their roles. Their protection should be proportionate and discreet, not dependent on generic rules applied to the entire workforce.
Executive and Privileged-User Measures
Elevated controls may include phishing-resistant hardware authentication, separately managed administrative identities, enhanced mailbox and cloud monitoring, tighter application permissions, protected recovery processes and briefing for executive assistants or family offices that handle sensitive logistics.
Publicly available information should be reviewed for its value to impersonation, password recovery, travel prediction or social engineering. The objective is not to remove every public reference, but to avoid unnecessary exposure of details that can strengthen an attack.
Travel Security
Travel risk varies by destination, role, information held and credible targeting. ASD recommends updating devices, enabling MFA, securing devices with a strong PIN or passphrase and considering encryption and backups before travel.
For elevated-risk travel, consider:
- Taking only the information and devices required for the trip
- Using a dedicated travel device or account with restricted access
- Recording device condition and configuration before departure
- Using a trusted mobile connection or approved VPN according to organisational policy
- Keeping devices under personal control and reporting any unexplained loss of control
- Reviewing accounts, sessions, applications and devices on return
- Resetting or rebuilding travel assets when the assessed risk justifies it
Public Wi-Fi should not be described as uniformly unsafe in every circumstance. Modern encrypted applications can reduce interception risk, but an untrusted network may still support impersonation, manipulation or tracking attempts. A managed mobile connection is generally preferable when available, particularly for sensitive work.
7. Prepare to Respond and Recover
An incident plan should identify who can contain systems, preserve evidence, engage legal advisers, assess privacy obligations, notify insurers, communicate with stakeholders and authorise recovery. Contact details and escalation paths must be accessible when ordinary systems are unavailable.
The First Response Priorities
- Move coordination to a trusted channel. Do not organise the response through an account or platform that may be compromised.
- Contain ongoing access and harm. Actions may include revoking sessions, isolating affected devices, disabling accounts or blocking malicious infrastructure.
- Preserve the available record. Capture relevant logs, messages, configuration, volatile information and a chronology before avoidable changes destroy context.
- Establish scope and impact. Identify affected identities, systems, information, transactions and third parties.
- Assess obligations. Legal, privacy, contractual, insurance and sector-specific requirements depend on the facts and should be considered early.
- Recover from trusted arrangements. Restore services only after the access pathway and persistence risk have been addressed.
The OAIC’s June 2026 quick-reference guidance describes four general data-breach steps: contain, assess, notify where required, and review. Whether an incident is an eligible data breach under the Notifiable Data Breaches scheme requires a fact-specific assessment.
Do not instruct personnel to delete suspicious material, factory-reset devices or “clean up” accounts before the response team determines what must be preserved. Containment and preservation need to be coordinated; neither should be treated as an excuse for avoidable delay.
Where compromise is suspected, NSI Global’s digital forensic incident response and BEC forensics capability can support authorised investigation, containment planning and evidence preservation. The engagement scope should reflect the incident rather than assume that every device or data source requires examination.
An Implementation Roadmap
First 30 Days: Establish Visibility and Authority
- Nominate executive and operational owners for cybersecurity risk and incident response
- Identify critical systems, information, privileged accounts and external dependencies
- Confirm MFA coverage and prioritise high-risk accounts for phishing-resistant methods
- Check whether unsupported internet-facing systems or critical devices remain in use
- Validate backups, log availability and incident contact details
- Define the trusted channel to use if corporate email is suspected of compromise
Days 31–60: Close Priority Control Gaps
- Review privileged access, dormant accounts, shared credentials and account recovery paths
- Apply managed patching, endpoint protection and device-encryption requirements
- Review mailbox forwarding, cloud consent, external sharing and administrative alerts
- Establish approved communications and meeting controls for sensitive information
- Define travel-security tiers for executives and high-risk personnel
- Map legal, privacy, contractual, insurance and reporting obligations
Days 61–90: Test Operation Under Pressure
- Exercise an identity compromise or data-breach scenario with executive participation
- Test log retrieval, session revocation, endpoint isolation and trusted communications
- Measure whether critical controls are deployed and functioning across the intended scope
- Record accepted exceptions, owners, expiry dates and compensating controls
- Establish a board or risk-committee reporting cycle focused on exposure and remediation
Measures That Demonstrate Control Effectiveness
Useful reporting connects control coverage to risk. Depending on the organisation, measures may include:
- Percentage of privileged and high-risk accounts using phishing-resistant authentication
- Supported-device and critical-patch coverage, with overdue exposure by business owner
- Number and age of privileged, dormant, shared and third-party accounts
- Coverage and tested retrieval of required security logs
- Time to triage high-severity identity, endpoint and cloud alerts
- Backup restoration success against agreed recovery objectives
- Completion and closure of actions from incident exercises
- Number of security exceptions without an owner, compensating control or expiry date
A single percentage can conceal material gaps. Ninety-nine per cent MFA coverage is not reassuring if the unprotected one per cent includes cloud administrators. Metrics should show where the remaining exposure sits and who owns its treatment.
Questions the Board Should Ask
- Which business services and information would cause the greatest harm if unavailable, altered or disclosed?
- Which identities can administer systems, recover accounts or approve material transactions?
- Where is phishing-resistant authentication not yet deployed, and why?
- Which critical systems are unsupported, unpatched or exposed to the internet?
- What activity can the organisation detect today, and how long are the required logs retained?
- Can the response team coordinate securely if email and collaboration platforms are unavailable?
- When were backups last restored and the incident plan last exercised?
- Which suppliers can access critical systems or sensitive information, and how is that access monitored?
- What exceptions have been accepted, by whom, and when will they be reviewed?
In Sum
Effective cybersecurity is not a collection of warnings about individual behaviour. It is a governed system of controls that reflects the organisation’s assets, identities, operating environment and credible threats.
The strongest programme combines baseline resilience with targeted protection for the people and information that attract greater risk. It makes authority explicit, limits privilege, manages devices, protects communications, detects abnormal activity and prepares decision-makers to respond without compounding the incident.
NSI Global can assess these controls through its cyber posture consulting services and develop recommendations aligned to the organisation’s actual risk profile. Where an incident may already have occurred, the priority changes from general hardening to controlled containment, scoping and evidence-led investigation.
For a confidential discussion, contact NSI Global.
Frequently Asked Questions
What Cybersecurity Controls Should an Organisation Prioritise First?
Start with critical asset and identity visibility, phishing-resistant authentication for high-risk accounts, supported and patched systems, managed endpoints, tested backups, useful logging and an executable incident-response plan. The order should be adjusted for the organisation’s exposure and business impact.
Is the Essential Eight a Complete Cybersecurity Programme?
No. The Essential Eight provides prioritised mitigation strategies and a maturity model. Organisations may also need governance, cloud, identity, monitoring, communications, supplier, privacy, physical-security and incident-response controls based on their environment and obligations.
Should Employees Avoid All Public Wi-Fi?
A managed mobile connection is preferable for sensitive work. Modern encrypted applications may reduce some interception risk, but public networks remain outside the organisation’s control and can support impersonation, tracking or manipulation attempts. The decision should reflect the device, activity and travel risk.
Are Encrypted Messaging Applications Sufficient for Sensitive Communications?
No. Encryption can protect content in transit, but it does not protect a compromised endpoint, an unauthorised participant, insecure backups or information copied by a legitimate recipient. Sensitive communications require suitable devices, verified identities, controlled participants and an approved platform.
What Should Staff Do if They Suspect a Device or Account Is Compromised?
Report the concern immediately through the organisation’s approved incident channel. Avoid deleting messages, uninstalling suspected software or factory-resetting the device unless directed by the response team. The priority is to contain harm while preserving enough information to establish what occurred.
Sources and Further Reading
The evidence base below draws principally on authoritative Australian cyber and privacy guidance, supplemented by NIST’s organisation-wide risk framework current at the research cut-off.
- NIST Cybersecurity Framework 2.0
- ASD: Practical cybersecurity tips for business leaders
- ASD: Essential Eight
- ASD: Essential Eight assessment process guide
- ASD: Implementing multi-factor authentication
- ASD: Passkeys
- ASD: Guidelines for security assurance, June 2026
- ASD: Security tips for travelling
- ASD Annual Cyber Threat Report 2024–25
- OAIC: Quick reference guide for responding to data breaches, June 2026
- OAIC: Guide to securing personal information