Creating Small Business On-Ramps to NIST Cybersecurity Guidance

No ratings

Presented at CyberCON 2025 by

he road to a secure and resilient business in the face of increasing cyber risks is not a straight path and can sometimes be bumpy. Sometimes, just getting onto the road to a more secure and resilient business is challenging—many small and medium-sized businesses (SMB) often don't know where or how to enter. Here is where the NIST small business quick start guides come into play. These guides, written specifically for the small business community, create on-ramps to enhanced security using NIST guidance. These guides provide high level overviews of some of our foundational frameworks and publications and go beyond a summary to ask important strategic questions, link to additional resources, and connect the dots across NIST publications—all in a graphic format much different from our core publications. This session will cover some of our new NIST small business cybersecurity quick start guides, such as the Cybersecurity Framework 2.0 Small Business Quick Start Guide and the Risk Management Framework for Small Enterprises. We’ll also discuss other quick start guides planned and will solicit audience input on other guides they would like to see NIST produce. We’ll also reserve time to highlight other new NIST small business cybersecurity resources, how people can get involved in our SMB efforts, and will share NIST SMB cybersecurity programmatic goals for 2025. (Reviewer Note: If accepted, I will update this when 800-171,R3 SMB Quick Start Guide is published this fall)