Taking action to implement the Framework
The NIST Cybersecurity Framework represents a tipping point in the evolution of
cybersecurity, one that emphasizes and encourages a proactive risk-management
approach that builds on standards and compliance. While the Framework is voluntary,
we believe that organizations—across industries—should adopt the guidelines as a
key tool to manage and mitigate cyber risk to their business, in combination with
other risk-management tools and processes such as cyber insurance.