Environment Protection Scorer (EPS)
With today’s modern ways of working, organisations worldwide focus on reducing capital expenditures and operational costs to support their business model while actively pushing to increase customer value and innovation.
This significantly increases cloud service adoption and distributed technology environments, enabling highly available products and services and rapid scalability while decreasing the total cost of ownership (TCO).
At a high level, we can categorise these business environments into four main areas, as shown below.
External Environment where customers, remote workers, contractors, and anyone can access your externally-facing applications, systems and networks.
Cloud Environment public cloud services are hosted externally using one or more major cloud service providers (CSPs). Infrastructure can be shared or dedicated (or a mix of the two) depending on your business needs and security requirements.
Data Centre Environment (also known as “private cloud”): where internal systems, applications, and data are hosted and stored. It is often located in the same city/state as your head office and uses dedicated infrastructure to host internal company resources.
On-premises Environment where users, systems and applications are hosted on-site in the exact physical location as your organisation’s head office.
Business Operating Environments - High Level Concept (Deployment Models)
The Environment Protection Scorer (EPS) simplifies identifying the cybersecurity controls needed to protect your business environment.
Cyber threats evolve daily, so understanding the level of protection your environment requires is crucial. The EPS does exactly that—simplifying the complexity of cybersecurity into a single, actionable score.
By weighing seven key attributes—confidentiality, integrity, availability, possession, deployment model, supply chain dependency, and attack vector—the EPS delivers a straightforward protection score with industry-standard control recommendations aligned to the NIST cybersecurity framework (CSF) version 2 to meet your environment’s protection level.
Key Benefits:
Focused Security Investment: The calculator helps you allocate your cybersecurity resources (time, people, and money) more efficiently by recommending a mix of fundamental and industry-leading security controls for the areas that need the most attention based on your environment's specific characteristics.
Adaptable to Any Environment: Whether your environment is cloud-based, on-premises, or a mix of both, the EPS provides relevant control insights that can be applied across different deployment models.
Proactive Defence Strategy: Understand your attack vectors and the level of control needed to maintain possession of sensitive information. This will enable you to strengthen your defences against potential threats before they materialise.
Environment Protection Score
Low: Public information, generally not sensitive, and minimal impact/harm if disclosed.
Medium: Data is somewhat sensitive and should be protected from unauthorised access.
High: Data is highly sensitive, and unauthorised access could lead to serious harm, including financial loss, legal penalties, or severe damage to reputation.
Low: Data integrity is not critical, and minor inaccuracies or modifications would have little to no impact.
Medium: Data integrity is important, and some inaccuracies could cause issues, but they would be manageable.
High: Data must remain accurate and trustworthy at all times. Unauthorised changes could lead to significant harm.
Low: Occasional downtime is acceptable. The system or data does not need to be highly available.
Medium: Availability is important, and downtime would cause some inconvenience or moderate disruption to operations. Limited downtime is tolerable.
High: Continuous availability is crucial and any downtime could lead to serious consequences, including financial loss, reputational damage, or disruption of critical operations.
Low: The environment contains non-sensitive data or systems where possession control is less critical. The impact of a loss would be minimal.
Medium: The environment holds moderately sensitive data or systems. While possession control is necessary, the impact of a loss would be moderate and manageable.
High: The environment has sensitive data or important systems that need strong possession controls.
Very High: The environment contains highly sensitive data or critical systems that require stringent possession controls.
Public: Cloud resources are hosted on shared infrastructure. Accessible over the internet, highest risk.
Private: Dedicated cloud environment, offering enhanced control and security, either on-premises or hosted by a third-party. Moderate risk.
Hybrid: Mix of public and private cloud environments, offers greater flexibility, balanced risk.
On-premises: Locally hosted and managed within an organisation’s own physical infrastructure, lowest risk.
Low: Low dependency on external suppliers; mostly self-sufficient.
Medium: Balanced risk with moderate outsourcing of services and software.
High: High dependency on third parties; significant risk if disrupted.
Network: Exploitable remotely over the internet or a network connection.
Adjacent: Requires access through a shared physical or logical network, such as Wi-Fi or Bluetooth, but not over the internet.
Local: Requires direct access to the local device or system.
Physical: Requires physical access to the device or system.