Environment Protection Scorer (EPS)

 

With today’s modern ways of working, organisations worldwide focus on reducing capital expenditures and operational costs to support their business model while actively pushing to increase customer value and innovation.

This significantly increases cloud service adoption and distributed technology environments, enabling highly available products and services and rapid scalability while decreasing the total cost of ownership (TCO).

At a high level, we can categorise these business environments into four main areas, as shown below.

  • External Environment where customers, remote workers, contractors, and anyone can access your externally-facing applications, systems and networks.

  • Cloud Environment public cloud services are hosted externally using one or more major cloud service providers (CSPs). Infrastructure can be shared or dedicated (or a mix of the two) depending on your business needs and security requirements.

  • Data Centre Environment (also known as “private cloud”): where internal systems, applications, and data are hosted and stored. It is often located in the same city/state as your head office and uses dedicated infrastructure to host internal company resources.

  • On-premises Environment where users, systems and applications are hosted on-site in the exact physical location as your organisation’s head office.

High Level Architecture - Deployment Models

Business Operating Environments - High Level Concept (Deployment Models)

The Environment Protection Scorer (EPS) simplifies identifying the cybersecurity controls needed to protect your business environment.

Cyber threats evolve daily, so understanding the level of protection your environment requires is crucial. The EPS does exactly that—simplifying the complexity of cybersecurity into a single, actionable score.

By weighing seven key attributes—confidentiality, integrity, availability, possession, deployment model, supply chain dependency, and attack vector—the EPS delivers a straightforward protection score with industry-standard control recommendations aligned to the NIST cybersecurity framework (CSF) version 2 to meet your environment’s protection level.

Key Benefits:

  • Focused Security Investment: The calculator helps you allocate your cybersecurity resources (time, people, and money) more efficiently by recommending a mix of fundamental and industry-leading security controls for the areas that need the most attention based on your environment's specific characteristics.

  • Adaptable to Any Environment: Whether your environment is cloud-based, on-premises, or a mix of both, the EPS provides relevant control insights that can be applied across different deployment models.

  • Proactive Defence Strategy: Understand your attack vectors and the level of control needed to maintain possession of sensitive information. This will enable you to strengthen your defences against potential threats before they materialise.

Environment Protection Score

Environment Protection Score

Confidentiality Requirement (CR)
Confidentiality refers to limits on who can get what kind of information in this environment.
Low: Public information, generally not sensitive, and minimal impact/harm if disclosed.
Medium: Data is somewhat sensitive and should be protected from unauthorised access.
High: Data is highly sensitive, and unauthorised access could lead to serious harm, including financial loss, legal penalties, or severe damage to reputation.
Integrity Requirement (IR)
Integrity refers to being accurate or consistent with the intended state of information. Unauthorised modification of data, whether deliberate or accidental, is a breach of data integrity.
Low: Data integrity is not critical, and minor inaccuracies or modifications would have little to no impact.
Medium: Data integrity is important, and some inaccuracies could cause issues, but they would be manageable.
High: Data must remain accurate and trustworthy at all times. Unauthorised changes could lead to significant harm.
Availability Requirement (AR)
Availability ensures that systems and data are consistently accessible and resilient, maintaining operational continuity even during disruptions.
Low: Occasional downtime is acceptable. The system or data does not need to be highly available.
Medium: Availability is important, and downtime would cause some inconvenience or moderate disruption to operations. Limited downtime is tolerable.
High: Continuous availability is crucial and any downtime could lead to serious consequences, including financial loss, reputational damage, or disruption of critical operations.
Possession Requirement (PR)
Possession in this context is about the level of control you require over the system(s) and/or data in your environment.
Low: The environment contains non-sensitive data or systems where possession control is less critical. The impact of a loss would be minimal.
Medium: The environment holds moderately sensitive data or systems. While possession control is necessary, the impact of a loss would be moderate and manageable.
High: The environment has sensitive data or important systems that need strong possession controls.
Very High: The environment contains highly sensitive data or critical systems that require stringent possession controls.
Deployment Model (DM)
Deployment models define how resources are structured and managed across cloud and on-premises environments, offering varying levels of control, security, and flexibility.
Public: Cloud resources are hosted on shared infrastructure. Accessible over the internet, highest risk.
Private: Dedicated cloud environment, offering enhanced control and security, either on-premises or hosted by a third-party. Moderate risk.
Hybrid: Mix of public and private cloud environments, offers greater flexibility, balanced risk.
On-premises: Locally hosted and managed within an organisation’s own physical infrastructure, lowest risk.
Supply Chain Dependency (SCD)
Supply Chain Dependency gauges the organisation's reliance on third-party suppliers and the severity of the business impact in the event of a disruption to (or via) third-party services.
Low: Low dependency on external suppliers; mostly self-sufficient.
Medium: Balanced risk with moderate outsourcing of services and software.
High: High dependency on third parties; significant risk if disrupted.
Attack Vector (AV)
Attack vector is the method or pathway through which an attacker gains unauthorised access to data, a system or network to exploit vulnerabilities.
Network: Exploitable remotely over the internet or a network connection.
Adjacent: Requires access through a shared physical or logical network, such as Wi-Fi or Bluetooth, but not over the internet.
Local: Requires direct access to the local device or system.
Physical: Requires physical access to the device or system.

Recommended Cybersecurity Controls