The levels and key measures
To respond to the severity of the threat an organization is exposed to, in addition to the starting level Small, 3 assurance levels are provided: Basic, Important and Essential.
Based on our historical data, retro-fitting was done on successful cyber-attacks using anonymized data. The conclusion is that:
- measures in assurance level Basic are able to cover 82% of the attacks,
- measures in assurance level Important are able to cover 94 % of the attacks,
- measures in assurance level Essential are able to cover 100% of the attacks.
Based on these attacks, key measures were identified at each level to prioritize the countermeasures to protect against the known cyberattacks relevant for that assurance level.