Skip to content

Cyber resilience with NIST CSF in 2025

Master cyber resilience in 2025 with this expert guide to the NIST Cybersecurity Framework. Learn how to assess risk, improve security posture, and automate compliance with AI-powered solutions from 6clicks.

Group 193 (1)-1

Cyber resilience with NIST CSF in 2025


What are the core functions of the NIST CSF 2.0?

TL;DR: NIST CSF 2.0 includes six core functions—Identify, Protect, Detect, Respond, Recover, and the new Govern function—each representing a critical pillar of an effective, resilient cybersecurity program.

As presented in the 6clicks guide Cyber Resilience in 2025: Your Smart Guide to NIST CSF, the foundation of the framework is its Core Functions. These functions provide a high-level view of how cybersecurity activities are structured—from understanding risk to responding to and recovering from incidents.

In the 2023 update (version 2.0), NIST introduced a sixth function—Govern—highlighting the growing need for clear cybersecurity oversight and accountability.

The six core functions of NIST CSF 2.0

  1. Govern (new in 2.0)
    Establishes cybersecurity strategy, roles, responsibilities, and oversight.
    Focus: leadership, policies, governance structure, third-party risk.

  2. Identify
    Understands business context, assets, risk, and dependencies.
    Focus: risk assessments, asset management, supply chain.

  3. Protect
    Implements safeguards to limit or contain potential events.
    Focus: IAM, awareness training, data security, endpoint protection.

  4. Detect
    Enables timely discovery of cybersecurity events.
    Focus: monitoring, threat detection, logging.

  5. Respond
    Takes action during a detected incident to minimize impact.
    Focus: incident response, forensics, coordination, reporting.

  6. Recover
    Restores capabilities after an incident.
    Focus: recovery planning, improvements, communications.

Why these functions matter

  • Comprehensive coverage: Together, the functions span strategy to execution, from prevention through recovery.

  • Framework agnostic: They can be used with ISO, CIS Controls, COBIT, and others—ensuring flexibility.

  • Role clarity: Each function aligns with specific roles (e.g., IT, legal, executive) for clearer accountability.

  • Outcome-driven: Enables measurable progress and resilience building, not just checklist compliance.

In 2025 and beyond, these six functions help organizations manage risk holistically while staying prepared for ever-evolving cyber threats.

Need help aligning your team with the six core functions of NIST CSF 2.0?
Book a demo with 6clicks today to see how our platform operationalizes each function—governance, protection, detection, and more—through assessments, workflows, and compliance automation.

General thought leadership and news

6clicks renews UK Cyber Essentials Plus certification, reinforcing trusted GRC platform for government and defence

6clicks renews UK Cyber Essentials Plus certification, reinforcing trusted GRC platform for government and defence

London, United Kingdom – 27 February 2026. 6clicks, a global leader in AI-powered governance, risk, and compliance (GRC) software, has successfully...

Navigating Middle East cybersecurity compliance: A guide for GCC organisations

Navigating Middle East cybersecurity compliance: A guide for GCC organisations

The Gulf Cooperation Council (GCC) region has undergone a dramatic transformation in its approach to cybersecurity and data sovereignty. At the heart...

Achieving sovereign regulatory assurance in today’s threat and AI-driven world

Achieving sovereign regulatory assurance in today’s threat and AI-driven world

Cyber threats are escalating. AI systems are becoming more prevalent in regulated environments. Digital networks and critical infrastructure are...

6clicks brings cyber and GRC leaders together to advance sovereign AI assurance in the GCC

6clicks brings cyber and GRC leaders together to advance sovereign AI assurance in the GCC

Dubai, United Arab Emirates – 16 January 2026. 6clicks, a leading AI-powered governance, risk, and compliance (GRC) platform, hosts “The 2026...

6clicks reaffirms leadership in responsible AI with ISO 42001 recertification

6clicks reaffirms leadership in responsible AI with ISO 42001 recertification

Melbourne, Australia – 09 January 2026. 6clicks, the leading AI-powered governance, risk, and compliance (GRC) platform, has successfully attained...

Self-hosting for defense, critical infrastructure, and government

Self-hosting for defense, critical infrastructure, and government

Since founding 6clicks, we've maintained an unwavering commitment to a principle that sets us apart in the GRC landscape: one codebase. This isn't...