2023 Verizon DBIR Report Actionable CIS Controls

Scott Kuffer
June 6, 2023
Industry
Verizon DBIR 2023 CIS Controls One Sheet (1)

2023 Verizon DBIR Report: Actionable CIS Controls

Verizon’s highly anticipated 2023 Data Breach Investigation Report (DBIR) was released today, unveiling a valuable addition to the report—the mapping of CIS controls to Verizon’s incident classifications. This inclusion provides organizations with an actionable and comprehensive list of controls that directly align with high-impact areas that have historically led to confirmed incidents and breaches.

By mapping the CIS controls to Verizon’s incident classifications, organizations gain a strategic advantage in their auditing and risk assessment processes. This mapping allows businesses to prioritize their security efforts by focusing on controls that address specific incident types and potential vulnerabilities identified in the report.

The CIS controls serve as a starting point for organizations to build out their risk assessments and implement safeguards to protect against system intrusions, social engineering attacks, basic web application attacks, miscellaneous errors, and lost and stolen assets—categories that have proven to be critical factors in previous security incidents.

With the actionable list of CIS controls now incorporated into the DBIR, organizations can proactively assess their security posture by evaluating their controls with the incident classifications outlined by Verizon. This empowers businesses to evaluate and mitigate risks against the evolving threat landscapes, leveraging the valuable insights provided by Verizon’s extensive research and analysis.

Here is the assembled list of CIS controls, categorized based on their incident classifications, as outlined in the 2023 DBIR:


Click Here to Download the One Sheet: Incident Classifications Mapped to CIS Controls

Scott Kuffer
Scott is the co-founder and COO of Nucleus Security, a leading provider of risk-based vulnerability management solutions. With a wealth of experience in cybersecurity, SaaS, and business strategy, he has been at the forefront of driving innovation in vulnerability management, helping some of the world’s most complex enterprises tackle their biggest security challenges.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.