Protect
In cybersecurity governance, 'Protect' refers to the set of safeguards an organization puts in place to limit or contain the impact of a potential cybersecurity event. It covers the measures used to keep systems, data, and assets secure and resilient. The specific controls an organization adopts depend on its risk profile and are not dictated by a single universal standard.
Under the NIST Cybersecurity Framework, 'Protect' is one of the framework's core functions, encompassing the development and implementation of appropriate safeguards to support the delivery of critical services and to limit or contain the impact of a cybersecurity event. It includes categories such as Protective Technology (PR.PT), under which technical security solutions are managed to ensure the security and resilience of systems and assets consistent with related policies, procedures, and agreements. The NIST framework is a voluntary, non-binding set of guidance rather than a legal mandate, and its adoption and the selection of specific protective controls vary by organization, sector, and jurisdiction. This function is generally implemented and operated by management and technical security functions; it should be distinguished from other framework functions and from oversight responsibilities that may sit with the board or its committees.
Why it matters
The Protect function addresses one of the most consequential questions in cybersecurity governance: once an organization understands its assets and risks, what safeguards does it put in place to limit or contain the impact of a potential cybersecurity event? Under the NIST Cybersecurity Framework, Protect sits alongside other core functions and focuses specifically on the safeguards that support the delivery of critical services and keep systems, data, and assets secure and resilient. For boards, general counsel, and risk and compliance leaders, the state of an organization's protective measures is often a central indicator of how seriously cyber risk is being managed in practice rather than on paper.
Because the NIST framework is voluntary and non-binding guidance rather than a legal mandate, the specific controls an organization adopts under Protect are not dictated by a single universal standard. This creates both flexibility and responsibility: management and technical security functions must select and calibrate safeguards to the organization's own risk profile, while boards and their committees generally retain an oversight role in confirming that a reasonable approach exists and is being maintained. The distinction matters because gaps in protective controls can translate into operational disruption, loss of sensitive data, and downstream legal and regulatory exposure that vary by jurisdiction, sector, and entity type.
It is important to note that adopting the Protect function or the broader NIST framework does not by itself satisfy any particular legal requirement, and the framework's use should not be presented as universally mandatory. Whether a given set of safeguards is adequate is ultimately a matter of facts, applicable law, and professional judgment. This entry is educational and does not constitute legal, audit, or compliance advice.
Who it's relevant to
Inside Protect
Common questions
Answers to the questions practitioners most commonly ask about Protect.