NIST CSF 2.0

For Both Executive and Technical Readers

Every NIST CSF assessment tells you your Govern tier. Almost none tell you how much that governance gap is costing you in suppressed returns on every other control you’ve already bought, or which single investment would lift all of them.

The NIST CSF plug-in, vocabulary, structure, and the questions your leaders ask, already mapped. Nothing here starts from a blank page.

Executive Summary · NIST CSF

The QuestionHow much is a governance gap suppressing returns on controls you've already funded?

The MethodA causal model connecting the Govern tier to downstream control effectiveness.

The AnswerA single investment identified as lifting the return on every other control at once.

A REGIONAL HEALTH SYSTEM WAS ALIGNED TO CSF. Their CISO had $4.2M to allocate across Protect and Detect, two of the six CSF functions covering preventive controls and threat detection. The maturity assessment said both needed investment. The causal model said one would cut breach probability by 61%. The other by 11%.

A framework with six functions can’t tell you which one to fund first. The maturity assessment was accurate: Protect and Detect were both Tier 2, both needed investment, both were identified as priorities. What the assessment structurally could not produce was a causal answer: given that Govern is also at Tier 2, what is the return on a Detect investment versus a Protect investment for this specific system, in this specific posture, with this specific threat profile?

61%
breach reduction:
Protect investment
11%
breach reduction:
Detect investment
$4.2M
available
budget
Tier 2
both functions scored,
both “need investment”
Analysis Component Standard Approach Causal Approach
Return on Protect vs DetectBoth Tier 2; recommend raising both; no mechanism to compute differential impactdo(Protect): P(major breach) 34% → 13% (−61%). do(Detect): 34% → 30% (−11%). Mechanism: Govern at Tier 2 suppresses Detect’s return
Counterfactual on prior breachPost-mortem recommends investment across all contributing factors with equal weightdo(MFA deployed): P(breach) = 0.08, 91% reduction, dominant cause. do(Detect=Tier3): P(contained <4hrs) = 0.73, meaningful, but secondary
Insurance premium optimisationCannot answer, maturity scores do not encode underwriting logicProtect allocation produces $2.9M annual premium reduction
The maturity assessment gave the same score to two investments with a 5.5× difference in impact. The score measures current state. The causal model measures what changes if you act.

CSF 2.0 formalized what practitioners already knew: Govern is not one of six equal functions. It is the parent of all five others. A weak governance function degrades every downstream capability regardless of point-solution spending. The maturity assessment showed Govern at Tier 2. It did not show that Govern’s weakness was suppressing the return on every other investment. The causal model did.

The solution was to model the relationships between the variables that determine security posture, and to be explicit about which variables cause which. We recognised, for example, that Govern is not one of six equal functions, it is the upstream cause of all five others. A weak governance function suppresses the return on every downstream investment regardless of how much is spent on point solutions, which means observing poor detection performance tells you something about governance, not just about detection tooling. Budget allocation influences outcomes, but it is itself influenced by governance maturity, making it a mediator rather than a root cause. When you observe a variable in this model, you are effectively filtering the data to cases where that variable takes a particular value, and that filter ripples through the model, shifting related variables up and down accordingly. When you intervene on a variable, forcing it to a value regardless of what caused it, you break that ripple effect and get a cleaner answer: not what organisations that look like this tend to experience, but what would happen if this specific control were improved When you abduct, you extract a particular case from the averages, locking in its idiosyncratic circumstances before asking what would have happened if one or more things had been different.

Why Govern was the binding constraint

Govern has no direct edge to Security Incident, it works only through its children. A Tier 2 Govern function suppresses Detect return because threat monitoring findings have no clear escalation path. The maturity assessment cannot show this. A causal model with directed edges from Govern to Detect to breach probability can.

CSF Function Current Target Assessment Rationale
GovernTier 2Tier 3Risk strategy documented; needs stronger board oversight and supply chain risk integration
IdentifyTier 3Tier 3Asset inventory mature; maintain current practices
Protect −61% breachTier 2Tier 3MFA incomplete across clinical systems; endpoint hardening below benchmark
Detect −11% breachTier 2Tier 3No 24/7 SOC coverage; SIEM coverage gaps on medical devices
RespondTier 3Tier 3Playbooks current; tabletop exercises completed Q2
RecoverTier 2Tier 3Backup testing frequency below policy; DR plan not tested against ransomware scenario

A maturity assessment scores nodes. A causal model connects them. Detection without governance is a siren with no one listening. Recovery without containment is rebuilding on fire. Those connections change the return on every investment.

3 Questions, 3 Rungs
  1. Would MFA have prevented the prior breach: or would Tier 3 detection have contained it?: Rung 3. Abduct to actual event conditions, apply each intervention independently.
  2. If we invest $4.2M in Protect, what does breach probability become vs the same investment in Detect?: Rung 2. do() separates the causal effect from the Govern confound.
  3. What is our current exposure: and given Severe Business Impact, what does the graph tell us about upstream Govern maturity?: Rung 1. Evidence propagates in both directions.
Rung 2: The budget decision
Scenario Major Breach Annual Loss Insurance
Status quo34%$8.1M62% Adverse
$4.2M → Detect30% (−11%)$6.4M58% Adverse
$4.2M → Protect13% (−61%)$3.2M31% Adverse
$2.8M Protect + $1.4M Govern Chosen9% (−74%)$2.2M22% Adverse
Rung 3: Post-incident counterfactuals
Contributing Factor Post-Mortem Counterfactual Model
MFA not deployed“Root cause”P(breach|MFA) = 0.08, 91% reduction. Dominant cause.
SIEM alert not actioned 38 hrs“Contributing”P(contained<4hrs) = 0.73, meaningful, but only if breach occurs.
Vendor credentials not rotated“Contributing”P(breach|rotated) = 0.21, material but not dominant.
DR untested for ransomware“Contributing”P(recovery>72hrs) = 0.68 vs 0.15, affects cost, not whether breach occurs.

Investing in DR to prevent the next breach would have been a category error. The post-mortem gave equal weight to all four. The model did not.

A language model can speak fluently about any domain. It cannot know one. The .bayes file is the knowledge the LLM is missing: a causal map of the domain, auditable, versioned, and wrong in specific correctable ways.

Optionally open NIST-CSF-gaussian.bayes in Bayes Server. 15 nodes, 22 edges. The model is the thing; the software that runs it is a commodity. Govern fans out to all five operational functions. Incident pathway: Security Incident → Incident Detection → Incident Response. Consequence nodes: Business Impact, Regulatory Exposure, Insurance Outcome.

Nodes show Gaussian distributions on a 0–100 scale. Black checkmark = observed evidence. Red checkmark = do() intervention.

Rung 3, Counterfactual: would MFA have prevented the breach?

NIST CSF 2.0 BN prior state
Prior, no evidence set

Prior marginals. Major incident probability: 18.9%. All nodes at prior.

Rung 2, Intervention: Protect vs Detect investment

NIST CSF 2.0 BN prior state before investment intervention
Prior, no intervention

Baseline before any investment intervention. Major breach probability: 34%. Expected annual loss: $8.1M.

Rung 1, Association: diagnostic and predictive inference

NIST CSF 2.0 BN prior state before diagnostic evidence entry
Prior, no evidence set

Prior marginals. Major incident probability: 18.9%.

The model is a file. Any capable LLM can load its XML and answer NIST CSF budget and post-incident questions in plain English.

Our CISO wants to put the full $4.2M into Detect, SIEM and 24/7 SOC. Protect is also Tier 2. Which investment should we make?
AnyChatRung 2 · do(Detect), do(Protect)
Running both interventions. do($4.2M → Detect): major breach probability 34% → 30%: an 11% reduction. do($4.2M → Protect): 34% → 13%: a 61% reduction. The mechanism is the Govern → Detect edge. Your Govern is at Tier 2, so detection investments produce a well-instrumented environment with unclear escalation paths. MFA and endpoint hardening close the attack surface independent of governance maturity, the Protect edge doesn’t pass through Govern. Your CISO’s recommendation would spend $4.2M for an 11% reduction when 61% was available for the same price.
Last year we had a ransomware incident. 11-day dwell time, MFA not deployed on the clinical VPN. Post-mortem listed four contributing factors with equal weight. Which one would actually have prevented it?
AnyChatRung 3 · abduct → counterfactual
I abduct the incident conditions from the observed evidence, then apply each intervention independently. MFA was the dominant preventive cause: P(breach|MFA) = 0.08, a 91% reduction. Tier 3 detection would have contained it in under four hours with 73% probability, meaningful, but only after the breach occurs. The DR finding was a different category: it doesn’t prevent the breach, it reduces recovery time. Funding DR to prevent the next breach would have been a category error. The post-mortem gave equal weight to all four. The model did not.
How do you know all this?
AnyChatRung 1 · provenance
I don’t know it, the model does. The graph was built on CSF 2.0 structure with CPTs parameterized from your incident history, published healthcare breach data, and expert elicitation from your CISO and security architects. Every number I gave you comes from NIST-CSF-gaussian.bayes. Open it, change the CPTs, watch the recommendation move. The model is auditable. I’m just the interface.
Our CISO says we should just follow the NIST CSF prioritization guidance and invest proportionally across functions.
AnyChatRung 3 · but-for prevention
NIST CSF prioritization is a population-level framework. It does not tell you which control gap, in your environment, on your incident timeline, would have prevented your specific ransomware event. The but-for query here, would MFA on the clinical VPN have stopped the 11-day dwell?, requires modelling your specific attack path, the credential abuse mechanism, and the detection window that MFA would have closed. Framework proportionality cannot answer that. The causal model can, and the answer is why the post-mortem’s equal-weight attribution was wrong.

Same model, three rungs. The audit trail is the .bayes file, not a PowerPoint that recommends everything and prioritizes nothing.

Is that all this simple model can answer?
AnyChat
A more sophisticated model can answer more complex questions. Still, even this intentionally simple model can answer more, like these:
  • Maturity roadmap. What is the next-highest-value tier improvement after this one?
  • Audit prioritization. Which control's ROI is most sensitive to the current governance gap?
  • Benchmark comparison. How does our tier-to-ROI relationship compare to sector peers?
  • Budget defense. What is the expected loss if this investment is deferred another year?
  • Cascading return. Does improving this tier reduce risk in a control we have not directly funded?
Same file, same audit trail, different questions asked.

Build the causal model on your CSF posture. Parameterize it from your incident history, sector breach data, and your security team’s expert judgment. Deliver a model that tells the board which investment, not just that investment is needed.

  • Insurance underwriters already think causally. Protect investments reduce premium; Detect investments reduce claims. The model quantifies the difference before your renewal conversation, $2.9M annual premium reduction in this case.
  • Regulators are converging on CSF. SEC disclosure, CIRCIA, NIS2, DORA, all align with or reference the framework. “We funded Protect because the model showed 61% vs 11% given our governance maturity” survives scrutiny. “Both were Tier 2 so we split the budget” does not.
  • Post-incident review requires counterfactuals. A maturity assessment cannot answer “what should we have done differently?” A causal model answers it with probabilities, not opinions.
NIST-CSF-gaussian.bayes

This case study is a composite drawn from published healthcare cybersecurity assessments and NIST CSF implementation patterns. Specific figures are representative. No individual organisation, incident, or regulatory proceeding is described.

The Deeper Trade

The model does not replace the expert who built it. It frees her from being the bottleneck for every routine version of this question, so she can spend her judgment on the cases that actually need it, and keep making the model better.