News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Business of Tech | Cybersecurity Framework 2.0 Unveiled: NIST Addresses Supply Chain Risks

The National Institute for Standards and Technology (NIST) has released Cybersecurity Framework 2.0, which expands its recommendations to include organizations beyond critical infrastructure. The updated framework adds a sixth function, Govern, and addresses supply chain risks. It provides a reference tool, a searchable catalog, and references to help organizations implement the framework.

The new “Govern” function focuses on establishing, communicating, and monitoring an organization’s cybersecurity risk management strategy. This addition complements the existing pillars: “identity,” “protect,” “detect,” “respond,” and “recover.”

According to the 2024 SonicWall Annual Cyber Threat Report, the increasing depth of cyberattacks has led to a growing need for managed service providers (MSPs). Cybercriminals are increasing their attacks on critical infrastructure, with a 27% rise in ransomware activity in the second half of 2023. Despite an overall annual decline, ransomware volumes hit a record high in Asia, especially targeting the financial sector. SonicWall recorded 6.06 billion malware attacks in 2023, marking the highest global attack volume since 2019, with healthcare, retail, and government sectors being heavily targeted. Intrusion attempts also increased by 20%, with a significant rise in the finance, government, and healthcare sectors. IoT exploits also saw a 15% global increase.

Why do we care?

The headline is all about the NIST Cybersecurity Framework.  This is a significant update to guide organizations in enhancing their cybersecurity postures, and like software updates, you have work to do.   IT service providers should assist organizations in integrating the “Govern” function into their cybersecurity strategies. This involves helping them to define clear cybersecurity policies, implement governance structures that ensure accountability and oversight, and establish metrics for monitoring cybersecurity effectiveness. 

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories