CIS Controls IG1,
your security posture, measured honestly.
The globally trusted set of essential cyber-hygiene safeguards from the Center for Internet Security. I run the assessment with you, map where you align and where you don’t, and hand you a scored posture you own, doing the hands-on work alongside your team.
A practical baseline, not a paper exercise.
The CIS Controls are a globally recognised set of safeguards from the Center for Internet Security, prioritised so you fix what matters first. Implementation Group 1 is the essential-hygiene tier: the 56 safeguards every organisation should have in place to stop the most common attacks. Aligning to IG1 gives you a prioritised, defensible baseline: proof for partners, insurers and buyers that your fundamentals are sound, tackled in the order that cuts risk fastest.
This is an alignment and assessment engagement, not a certification. We measure where you stand against IG1, agree a prioritised plan to close the gaps, and leave you with a scored posture and an evidence pack you own, ready to share for insurers, tenders and due-diligence.
A sample of the safeguards IG1 asks you to get right.
Inventory of enterprise assets
Know every device on your network, so nothing connects that you can’t see or account for.
Inventory of software assets
Track the software you run and remove what is unsupported, unknown or no longer needed.
Data protection
Identify sensitive data, control where it lives, and protect it in line with its value.
Secure configuration
Set up devices and software to sensible, hardened defaults rather than out-of-the-box weaknesses.
Account & access management
Grant accounts and privileges on need, review them regularly, and revoke access the moment it lapses.
Three Implementation Groups. IG1 is where you start.
IG1
The baseline every organisation should meet, and the focus of this engagement. Achievable safeguards that stop the most common attacks.
- →The essential 56 safeguards
- →Achievable with limited resources and expertise
- →The right starting point for most organisations
- →A foundation the higher groups build on
IG2 & IG3
The next tiers, added once your fundamentals are solid and your risk profile calls for more.
- →IG2 · for organisations managing more sensitive data
- →IG3 · for mature, higher-risk organisations
- →Each builds on the group before it
- →A clear path once IG1 is in place
Thinking about CIS Controls IG1? Let’s map a realistic path in a free 20-minute call.
Start with an assessment→Done with you, not handed over a wall.
Know where you stand
We scope your systems and run the self-assessment together in CIS CSAT, so you see clearly where you align with IG1 and where you don’t.
Close the gaps together
I guide your team through each safeguard in plain English, prioritising the fixes that matter most and gathering the evidence as we go.
A posture you own
You walk away with a scored gap report, a prioritised roadmap and an evidence pack you keep, ready to show insurers and buyers.
More than a snapshot.
- ✓A scored assessment against CIS IG1
- ✓A prioritised remediation roadmap
- ✓An evidence pack you own and keep
- ✓Cross-mapping to NIST CSF, ISO 27001 and Essential Eight
- ✓A re-assessment reminder, so your posture stays current
- ✓The confidence to speak to your own security
The things buyers usually ask.
Is there a CIS certificate?
No. CIS Controls IG1 is an alignment and assessment engagement, not a certification. You come away with a documented, scored posture that insurers and auditors accept as evidence of due-diligence, which is what most buyers are really asking for.
How does IG1 relate to IG2 and IG3?
IG1 is the essential-hygiene baseline every organisation should meet. IG2 adds safeguards for organisations managing more sensitive data, and IG3 is for mature, higher-risk organisations. Each builds on the one before, so IG1 is the natural place to start and a foundation to grow from.
Does it map to other standards?
Yes. The CIS Controls map cleanly to NIST CSF and ISO 27001, and closely to the Essential Eight. Aligning to IG1 gives you a head start on those frameworks, and I include the cross-mapping so you can see exactly how the work carries across.
Do we need to buy anything?
No. Both the CIS Controls and the CIS CSAT self-assessment tool are free to use. My role is the assessment, the guidance and the evidence, so there is no licence to purchase to get started.
How long does it take?
Most organisations complete an IG1 assessment within three to six weeks. It depends on the size of your estate and how quickly your team can make the changes we agree. I keep the pace realistic and the plan prioritised.
Ready to see where you stand against CIS IG1?
Tell me a little about your business and I’ll map a realistic path to a scored, evidenced posture. A free 20-minute call, no obligation.