Part II · Chapter 9

Building a cybersecurity strategy

A cybersecurity strategy nobody takes decisions from is a document, not a strategy. This chapter works through what a strategy has to achieve, the seven components it needs to contain, how the requirement areas of the Cybersecurity Act can give it structure, and what the path from current state to roadmap looks like when it works. Zero Trust is treated as a principle rather than a product.

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

Most organisations have some form of security plan. Fewer have a strategy, meaning a document that says what will be deprioritised. A plan listing everything that would be good to do is a wish list, and it gives no guidance the day the budget covers half of it. That difference is what this chapter is about.

It opens with the purpose of a strategy, which is to make prioritisation possible when resources do not stretch to everything. Then follow the seven components, the backbone of the chapter, describing what a complete document has to cover, from target picture and risk appetite to measurement and ownership. One section shows how the ten requirement areas of the Cybersecurity Act can be used as a structuring framework, which has the practical advantage that the strategy then speaks the same language as the supervision and that follow up becomes comparable over time. Zero Trust is treated as a shift from network boundaries to continuous verification, as a principle rather than a product. After that comes the process from current state to roadmap in eight steps, the most practical part and the one that turns the strategy into something you can actually work from. The closing sections deal with the strategy as a living document with a set revision cadence, with the most common mistakes, and with a worked example strategy for a mid sized municipality. The current state the strategy builds on comes out of chapter 14 on risk and gap analysis, and leadership responsibility is covered in chapter 8.

The question has become more concrete since the Cybersecurity Act entered into force. In a review it is not enough to describe ambitions. What is asked for is how the organisation prioritised, on what basis and who took the decision. A strategy without traceable choices does not answer that, however well it is written. The practical consequence is that the strategy has to be written so it can be followed up, not merely read.

This page shows what the chapter covers and why a strategy has to contain choices that deprioritise. The seven components, the eight step process and the example strategy are in chapter 9 of the book.

A strategy without a roadmap is a wish. A roadmap without ownership is a document.

Key insights

  • A strategy without ownership and dated steps is a statement of intent, however well it is written.
  • The ten requirement areas of the Cybersecurity Act are a useful structure, because they are already what you are reviewed against.
  • Zero Trust is a principle of verification, not a product you can buy ready made.
  • The strategy should be a living document with a set revision cadence, or it will soon describe an organisation that no longer exists.
  • Risk analysis comes before strategy. Without a current state, prioritisation is arbitrary.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

  • Control mapping

    ISO 27001 against the requirement areas of the Cybersecurity Act, as structuring material.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.