The Fractional CFO’s Guide to IT Risk: Leveraging the NIST CSF for Enterprise Oversight
Introduction
In your everyday life, how do you decide which risks to take?
Whether choosing a health insurance plan or deciding whether to ride the newest roller coaster at an amusement park, you face a host of decisions every day, with some being tougher to quantify than others.
When it comes to working with clients as a fractional CFO, risk plays a role, too. You need to help clients navigate risk and ensure they’re taking a thorough approach commensurate with the risk levels they face.
These days, your fractional CFO role is no longer exclusively focused on finance; instead, you’re becoming increasingly responsible for enterprise risk oversight.
It makes sense. With system outages and cyberattacks leading to significant business disruption, your clients can face major financial losses.
To help clients improve their approach to cybersecurity, you need a recognized, structural framework like the NIST CSF. As the National Institute of Standards and Technology’s Cyber Security Framework, it serves as a guideline that organizations can use to ascertain where they stand when it comes to their security posture.
In this guide, you’ll learn core concepts of IT risk and how to use the NIST CSF as a starting point to measure, monitor, and manage risk effectively.
The CFO’s Evolving Role in IT Risk Management
In recent years, the CFO’s role has grown to include more than just finance and accounting.
95% of CFOs in North America say that their role has increasingly broadened to include a plethora of other tasks, including cybersecurity, corporate strategy, and IT.
Today, technology investments and cybersecurity measures are intertwining more with financial risk, making IT a critical knowledge base for fractional CFOs.
The Link Between Technology and Financial Risk
As Deloitte explains, business risks increase as technology becomes increasingly ingrained in the fabric of our daily lives.
Technology risk is an inherent financial risk, due to the costly consequences of system outages, data breaches, and compliance penalties.
Recent research quantifies these costs to show exactly how devastating these threats can be.
For instance, SolarWinds found that downtime costs average $427 per minute for small businesses and $9,000 per minute for enterprises.
Based on these statistics, a small business that had 5 hours of downtime would lose over $100,000.
Additionally, if your clients are impacted by a data breach, they could face costs upwards of $4.4M, according to 2025 research.
With technology incidents leading to major expenses for your clients, you’ll want to do everything you can to help them minimize those risks.
And with your role as a trusted leader and strategic advisor, you have the decision-making authority to guide your clients in the right direction.
Common Misconceptions About Risk

Before exploring the NIST CSF, let’s review and refute typical assumptions that organizations tend to make about risk.
Having a strong comprehension of risk concepts will be valuable when navigating these conversations with your clients.
Misconception #1: “We can completely fix or eliminate all risks.”
As much as we’d like to believe that there’s a silver bullet that will eliminate all threats, you and your clients will have to accept that you can’t eradicate all risks entirely.
Contrary to popular belief, risk is not an all-or-nothing, binary concept that a business either has or doesn’t have.
Instead, risk is represented as a continuum. Your clients’ businesses will fall into a specific place on that continuum based on their controls and risk tolerance.
Truth: Risk Is Everywhere
You can never completely remove all aspects of risk. Consider this everyday example. Let’s say you need to go to the grocery store. You may decide to walk instead of driving to reduce the risk of getting in a car accident.
However, walking to the grocery store could open up other risks like getting hit by a car or tripping and falling on the pavement.
Although compensating controls (using crosswalks and avoiding uneven pavement) can significantly reduce residual risk, there is still the chance that something could happen.
Though it’s possible to lower threat levels, you can’t eliminate all risk. That’s why the goal of the NIST CSF is to help manage risk, as the creators recognized that you can’t simply erase all risk.
Truth: The Likelihood of Risk Matters
Quantifying risk isn’t only about naming the risk. It’s also about understanding its likelihood of occurring.
Consider an event that would have a devastating impact on your clients’ business, like a volcano eruption. However, if your client isn’t located anywhere near a volcano, you wouldn’t need to worry because that threat is highly unlikely to occur.
This is an example of a high-impact, low-probability risk.
Truth: Your Clients Choose Their Risk Tolerance
It’s up to your clients, with guidance from trusted experts, to determine how much risk they’re willing to accept, or tolerate.
Consider company office locations. For some businesses, having an office in midtown Manhattan is a risk they’re willing to accept.
Despite the threats associated with living and working in a major city, it may be worth it because of the proximity to clients & employees and company visibility. The business may implement controls to defend against threats.
Another business may decide the risks of having an office in a big city isn’t worth it. To combat those risks, they might shift to another location or work from home instead.
As mentioned earlier, though, remember that changing risk factors may open up a new host of risks.
“Risk is just a feeling or a guess.”
Many organizations operate on an assumption that they are secure. However, risk is actually a calculated mathematical equation that takes a variety of different factors into consideration.
Aggregated factors include likelihood, impact, and criticality. Together, they form an objective metric that allows clients to prioritize the threats that need the most immediate attention.
As a result, your clients can’t simply say that they “feel” they are secure and well-defended from risk.
In order to be an accurate statement, they’ll need proof—clear results from a risk or security posture assessment.
“Moving to the cloud eliminates risk.”
A major misconception among business owners is that switching from on-premises infrastructure to cloud infrastructure removes risk entirely.
The cloud is just somebody else’s computer.
Moving to the cloud is an example of trading one type of risk for another. Though this switch would eliminate risks associated with a physical facility, it creates other threats, like vendor or user account compromise.
Moving to the cloud also expands the organizational attack surface by making data more accessible.
And, like on-premises systems, cloud data still needs to be backed up and managed.
With the right controls, these risks can be properly mitigated. Still, it’s important to remember that moving to the cloud requires careful risk assessment and management.
“Disaster recovery planning should focus on the absolute worst-case scenarios, no matter how likely they are to occur.”
Although it’s important to prepare your clients for worst-case scenarios, like a ransomware attack that renders their business inoperable, that doesn’t mean you should spend time planning for events that have a low likelihood of occurring.
Consider the volcano example from earlier.
Say your clients’ business is located in New Jersey. It’s incredibly unlikely (almost impossible) that a volcano will suddenly erupt in NJ and cause damage to your clients’ business. As a result, it doesn’t make sense to spend time and costs defending against this threat.
On the other hand, a snowstorm or hurricane would be relevant threats to a NJ business and would need appropriate preparations.
If your clients opened up an additional business location in Hawaii, that would be the time to consider the risks associated with volcanic activity.
A risk assessment should not result in ensuring safeguards for every single threat in existence.
Instead, it should result in a thoughtful plan that defends against the most relevant threats; the ones with higher probabilities of occurring and larger impacts if they come to fruition.
Understanding the NIST Cyber Security Framework (CSF)

Now that you have a stronger understanding of fundamental risk concepts, you can learn how the NIST CSF fits into your clients’ risk management processes.
The NIST Cyber Security Framework v1/1.1
The NIST Cyber Security Framework is a guideline that organizations can use to build a baseline understanding of their security posture.
Over the years, the NIST CSF has evolved in both the controls it references and its target audience.
First created as a result of a 2013 US executive order, the NIST CSF was intended to protect critical infrastructure.
Ultimately, the goal of the NIST CSF is the management of risk. This is the same objective as other frameworks and regulatory standards (like HIPAA, PCI, GLBA, and CMMC).
Scope & Methodology
The NIST CSF took the 108 most reasonable controls from the NIST 800-53 framework that are relevant to the widest range of organizations, regardless of their industry or customers.
Some items within this first iteration were specific to critical infrastructure.
The NIST CSF is not a binary standard like HIPAA or PCI regulations; instead, it represents a continuum of risk, leaving some items open to interpretation.
For instance, instead of telling organizations how a certain process should be executed, it highlights the expected outcome. This approach means that organizations can decide for themselves how to meet a specific control.
Flexibility & Practicality
Unlike other types of assessments, the NIST CSF was created to be flexible, repeatable, and cost-effective, making it appealing to a wide variety of organizations.
In addition, the framework is technologically neutral, allowing organizations to apply the guidelines to their unique technology stack in a way that makes sense.
The original iteration also championed collaboration, encouraging agencies to share details with each other about their controls and resulting effects on overall operations.
In a sense, this framework considers a core cybersecurity concept from the start, as explained in this quote from Jeh Johnson: “Cybersecurity is a shared responsibility…the more systems we secure, the more secure we all are.”

The NIST CSF v.2
In its second version, the NIST CSF aimed to help all organizations, not only those with critical infrastructure.
The resulting framework incorporated these changes:
- Took a more generalized approach
- Included updates that reflected changes in the technological landscape
- Increased the number of controls from 108 to 134
With the updated second version, the NIST CSF became more relevant to all organizations—including your clients.
Who Does the NIST CSF Apply To?
In its current form, CSF applies to any type of operational business. Your clients don’t have to be in critical infrastructure to benefit. The goal is to help all organizations manage and reduce risk.
It is not an audited standard, nor is it enforced by any regulatory organization.
This means it’s up to your clients or your clients’ partners to define the specific control and determine what successful implementation looks like.
What is Included in the NIST CSF?

The NIST CSF includes a number of guiding principles for understanding and defining cybersecurity controls.
Supply Chain and Vendor Risk Management
The Core Concept: You inherit the risks of the people you hire.
This section of the NIST CSF ensures vendors are aligned with your clients’ controls and that vendor risks are continually understood, prioritized, assessed, and monitored.
Over time, this can help your clients in the vendor evaluation process. This section of the framework moves beyond just trusting your partners to actively verifying them.
Vendor Risk Assessments
Critical suppliers must be assessed before your clients sign any contracts.
It’s essential to know if vendors’ security practices align with your clients’ risk tolerance before sharing access to any data.
Continuous Monitoring
Just like other aspects of cybersecurity and risk management, vendor management is not a “set it and forget it” activity. Your clients must actively monitor risks posed by suppliers throughout the partnership.
Just because a vendor was secure when your clients hired them doesn’t mean they are secure today. If a vendor begins to indicate that they no longer align with your clients’ security controls, it may be time to evaluate different vendors.
Asset Management
The Core Concept: If you don’t know what you have, you cannot secure it.
Asset management is often treated as a long inventory list, but it is the foundation of all security. If you don’t know a server, laptop, or software license exists, you cannot patch, monitor, or secure it.
The Lifecycle Approach
Your clients must manage assets (hardware, software, services, and data) throughout their entire life cycles, from purchase to disposal.
Data Flow Mapping
It is not enough for your clients to share a list of their servers; they need to understand traffic. Who is sending data to whom? What data is being shared?
Understanding the flow of sensitive information can help secure communication channels so that only authorized systems are connected to each other.
Vulnerability Assessments
The Core Concept: Find your own security gaps before an attacker does.
Vulnerabilities in assets should be properly identified and recorded. Similarly, risk responses should be carefully chosen, prioritized, tracked, and communicated.
Identifying & Resolving Vulnerabilities
You need a process to identify gaps and a disciplined procedure to resolve them. This can come in the form of vulnerability scanning and patch management.
Unpatched operating systems and third-party applications are a primary threat vector.
Continuous Strategic Oversight
A secure system can become vulnerable overnight if a new flaw is found.
Frequent scanning and improvements help your clients pay attention to emerging threats and update their systems as needed.
Creating a Strong Security Posture
Your clients should aim to move their organizations from weak, improperly managed security practices to proactive, adaptive security practices where vulnerabilities are actively identified and resolved.
Protective Controls
The Core Concept: Follow Defense in Depth principles.
While many people simplify protection to just “encryption,” NIST CSF v2.0 recommends protecting confidentiality, integrity, and availability across all three states of data existence (store, process, and transmit):
- Data-at-Rest: Protecting files stored on hard drives, databases, or backups.
- Data-in-Use: Protecting data while it is currently open and being processed by an application.
- Data-in-Transit: Protecting data while it is moving across the internet or your network.
Organizations should also properly manage access to physical assets, access permissions, and credentials.
Detection Controls
The Core Concept: You need proper visibility if you want to identify, contain, and remove threats quickly.
Your clients’ goal should be to detect malicious activity immediately, rather than finding out six months later when it’s too late.
Comprehensive Tools
Your clients need tools that analyze all of their systems such as email systems, servers, and firewalls together, in order to spot patterns that individual tools would miss.
Monitor Vendors
You should monitor your service providers’ activity just as closely as your own employees. If a provider starts acting strangely, like accessing files they shouldn’t need to, your clients need to be able to detect and respond immediately.
Triaged and Validated Incident Reports
Security tools can generate thousands of alerts. Your clients need a process to quickly separate false alarms from real incidents.
Preserve Forensic Evidence
If your clients’ systems come under attack, you cannot just fix or delete the activity and move on.
You need to ensure that any actions that have been taken to contain the threat have been documented. When working with your cyber insurance provider, it may be necessary to involve a third-party computer forensics specialist and/or incident response (IR) firm.
The malware and tooling used today cannot be simply “cleaned” away from existence. In many cases, after working to collect forensics or working with an IR firm, the affected assets will need to be wiped clean and redeployed.
Final Thought
As a fractional CFO, your role now includes managing technology risk as one aspect of financial risk.
A disciplined, structured approach is essential to guide your clients beyond common misconceptions and toward operational resilience.
The NIST Cyber Security Framework is one way to help you and your clients better understand, manage, and mitigate common risks. From asset management to vulnerability assessments, there are a number of areas your clients should take into account.
Often, working with an experienced external provider can be the right next step to help gain a better understanding of your clients’ current security posture.
One trusted IT and cybersecurity partner is Miles IT, a nationwide organization that helps clients across all industries improve their risk profiles and implement strong security measures.
Interested in learning how we can help your clients reduce risk and improve security?
Reach out to us today to set up your no-cost consultation.
FAQs
-
How does the NIST Cyber Security Framework (NIST CSF) help fractional CFOs translate technical security measures into understandable risk management goals?
+
The NIST CSF provides a structured framework that organizations can use to build a baseline understanding of their security posture and controls. The goal of the framework is to enable better risk management.
This structure supports data-driven conversations about a company’s risk profile and the effectiveness of their current security controls.
Ultimately, this aligns IT metrics with the fractional CFO’s expanding responsibility for risk management and oversight.
-
Is the NIST CSF an audited and enforced regulatory standard?
+
No, the NIST CSF is not an audited standard and is not enforced by any regulatory organization. It is a guideline that organizations can use to understand and improve their security posture.
However, organizations will sometimes use it for vendor risk management to understand how a business meets the control expectations.
Unlike binary standards like HIPAA or PCI, the NIST CSF represents a continuum of risk. It leaves some items open to interpretation by sharing expected outcomes instead of detailing how a process must be carried out.
-
What types of organizations is the NIST CSF primarily designed for to help manage and reduce risk?
+
In its current form, the NIST CSF applies to any type of operational business.
While the NIST CSF’s original iteration (v1/1.1) was intended to protect critical infrastructure, the controls could easily be applied to a wide range of organizations. The second version (v2) aimed to help all organizations manage and reduce risk, resulting in a more generalized framework.
-
What are common misconceptions about risk that businesses should know?
+
You should be aware of these common misconceptions about risk so you can properly advise your clients:
- “We can completely fix or eliminate all risks.”
Risk is a continuum, and you can never entirely remove all aspects of risk. The goal of the NIST CSF and risk management is to better manage risk.
- “Risk is just a feeling or a guess.”
Risk is a calculated mathematical equation based on factors like likelihood, impact, and criticality. It is an objective metric that allows clients to properly prioritize threats.
- “Moving to the cloud eliminates our risk.”
Moving to the cloud merely trades one type of risk for another. The cloud can be thought of as somebody else’s computer, and still requires consistent backups and oversight.
- “Disaster recovery testing should focus on the absolute worst-case scenarios, no matter how likely they are to occur.”
It doesn’t make sense to plan safeguards for every single threat, especially if that threat has an incredibly low likelihood of coming to fruition. Instead, risk assessments should focus on defending against the most relevant threats—those with higher probabilities of occurring and larger potential impacts.
- “There are no risks to my business.”
This is not true; there are risks associated with every business. You may not choose to acknowledge these risks, but they still exist.
-
What are the core components or sections of the NIST Cyber Security Framework (CSF), and what is the primary focus of each?
+
The NIST CSF contains key guidelines designed to help organizations understand and implement cybersecurity controls. The sections include:
- Asset Management: “If you don’t know what you have, you cannot secure it.” This ensures all assets (hardware, software, services, and data) are managed throughout their entire life cycles.
- Supply Chain and Vendor Risk Management: “You inherit the risks of the people you hire.” This area recommends continuous monitoring, assessment, and prioritization of risks posed by vendors.
- Vulnerability Assessments: “Find your own security gaps before an attacker does.” This section involves identifying and recording vulnerabilities, then prioritizing and resolving them, often through patch management.
- Protective Controls: “Follow Defense in Depth principles.” This section recommends protecting confidentiality, integrity, and availability across all three states of data existence: data-at-rest, data-in-transit, and data-in-use.
- Detection Controls: “You need proper visibility if you want to identify, contain, and remove threats quickly.” This section suggests using comprehensive tools to analyze systems and spot malicious activity more quickly, along with processes to separate false alarms from real incidents.
