---
title: Cyber Fundamentals
description: FS-ISAC's fundamentals of cybersecurity are essential to financial services firms’ security and business operations and are appropriate for all levels of cyber maturity.
---

# Cyber Fundamentals

Critical baseline security practices for today’s threat landscape

 featured

 FS-ISAC Explained

[Become a Member ](https://www.fsisac.com/membership-2024?hsLang=en)

## **Robust cyber hygiene is the bedrock of cyber defense and resilience**

The fundamentals of cybersecurity are essential to financial services firms’ security and business operations. FS-ISAC developed these 15 recommendations appropriate for all levels of cyber maturity, using a risk-based approach and [Defense-in-Depth principles](https://www.fsisac.com/hubfs/Knowledge/HardeningFileTransferSoftware.pdf?hsLang=en). Though some fundamentals are regulatory requirements, all are necessary, and will help financial services institutions at any level of cyber maturity remain secure and resilient. Click on the title for basic guidance and use the arrows for more advanced insights.

[01

Know your network

** 

](https://www.fsisac.com/cyber-fundamentals#know-your-network) [02

Regularly update and patch software

** 

](https://www.fsisac.com/cyber-fundamentals#regularly-update-and-patch-software) [03

Encrypt data at rest and in transit

** 

](https://www.fsisac.com/cyber-fundamentals#encrypt-data-at-rest-and-in-transit) [04

Use strong passwords for every employee, device, and account

** 

](https://www.fsisac.com/cyber-fundamentals#use-strong-passwords-for-every-employee-device-and-account) [05

Require MFAs

** 

](https://www.fsisac.com/cyber-fundamentals#require-mfas) [06

Use a zero-trust, least privilege policy with MFA

** 

](https://www.fsisac.com/cyber-fundamentals#use-a-zero-trust-least-privilege-policy-with-mfa) [07

Use VPNs

** 

](https://www.fsisac.com/cyber-fundamentals#use-vpns) [08

Use backup systems to duplicate data and system configurations

** 

](https://www.fsisac.com/cyber-fundamentals#use-backup-systems-to-duplicate-data-and-system-configurations) [09

Develop an incident response plan specific to attack type

** 

](https://www.fsisac.com/cyber-fundamentals#develop-an-incident-response-plan-specific-to-attack-type) [10

Use firewalls, configured closed by default, with active blocking

** 

](https://www.fsisac.com/cyber-fundamentals#use-firewalls-configured-closed-by-default-with-active-blocking) [11

Train employees on their role in cybersecurity

** 

](https://www.fsisac.com/cyber-fundamentals#train-employees-on-their-role-in-cybersecurity) [12

Keep a log of system activity

** 

](https://www.fsisac.com/cyber-fundamentals#keep-a-log-of-system-activity) [13

Use secure configuration management

** 

](https://www.fsisac.com/cyber-fundamentals#use-secure-configuration-management) [14

Incorporate application security controls

** 

](https://www.fsisac.com/cyber-fundamentals#incorporate-application-security-controls) [15

Harden your API controls

** 

](https://www.fsisac.com/cyber-fundamentals#harden-your-api-controls)

 5

 of 15

Resources

[CPG 3.3](https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf)  
[Key rotation](https://cloud.google.com/kms/docs/key-rotation#:~:text=Automatic%20key%20rotation%20at%20a,to%20a%20stronger%20key%20algorithm)  
[NIST SP 800-57](https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final)  
[Digital Identity Guidelines: Authentication and Lifecycle Management (nist.gov)](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf)  
[NIST SP 800-63 Digital Identity Guidelines](https://pages.nist.gov/800-63-3/)   
[CPG 3.4](https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf)  
[NIST Password Guidelines 2024 | AuditBoard](https://www.auditboard.com/blog/nist-password-guidelines/)  
[ Configure the MFA registration policy - Microsoft Entra ID Protection](https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-mfa-policy)   
[Block legacy authentication - Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/conditional-access/block-legacy-authentication#moving-away-from-legacy-authentication)   
[ CPG 7.3](https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf)  
[NIST SP 800-41, Revision 1, Guidelines on Firewalls and Firewall Policy](https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf)  
[ How to Recognize and Avoid Phishing Scams | Consumer Advice (ftc.gov)](https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams#recognize)  
[4 Things You Can Do To Keep Yourself Cyber Safe | CISA ](https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe)  
[ NIST Basics ](https://www.nist.gov/itl/smallbusinesscyber/cybersecurity-basics)  
[ NSA Basics ](https://media.defense.gov/2019/Jul/16/2002158046/-1/-1/0/CSI-NSAS-TOP10-CYBERSECURITY-MITIGATION-STRATEGIES.PDF)   
[NCP | Checklist Repository](https://ncp.nist.gov/repository)  
[ISO 10007:2017(en), Quality management](https://www.iso.org/obp/ui/en/#iso:std:70400:en)

Previous

Next

Related Reports

Back to Top

[![Become a Member](https://no-cache.hubspot.com/cta/default/5442200/5fb1208d-bf34-4986-a35b-862cf810fc2f.png)](https://cta-redirect.hubspot.com/cta/redirect/5442200/5fb1208d-bf34-4986-a35b-862cf810fc2f)

[![fs-isac-greyscale](https://www.fsisac.com/hubfs/fs-isac-greyscale.svg "fs-isac-greyscale")](https://www.fsisac.com/?hsLang=en)

- [About Us](https://www.fsisac.com/about-us) 
    - [Careers](https://www.fsisac.com/careers)
    - [Contact Us](https://www.fsisac.com/contact-fsisac)
    - [Events](https://www.fsisac.com/events-archive)
    - [FAQ](https://www.fsisac.com/who-we-are/faq)
    - [Newsroom](https://www.fsisac.com/newsroom)
- [Privacy Notice](https://www.fsisac.com/privacy-notice) 
    - [Responsible Disclosure](https://www.fsisac.com/responsible-disclosure)
    - [Scholarship Program](https://www.fsisac.com/scholarships)
    - [Subsidiaries](https://www.fsisac.com/who-we-are/sheltered-harbor)
    - [Terms](https://www.fsisac.com/terms)

Follow Us

[![Twitter](https://www.fsisac.com/hubfs/Icons/Twitter.svg) ](https://twitter.com/FSISAC) [![LinkedIn](https://www.fsisac.com/hubfs/Icons/Linkedin.svg) ](https://www.linkedin.com/company/fs-isac/)

© Copyright 1999 -  FS-ISAC, Inc. All Rights Reserved.

[Terms and Policies

](https://www.fsisac.com/terms?hsLang=en)

```json
{
  "@context" : "https://schema.org",
  "@type" : "VideoObject",
  "contentUrl" : "https://5442200.fs1.hubspotusercontent-na1.net/hubfs/5442200/Videos/CorporateExplainer-FSISAC-ShortVersion.mp4",
  "dateModified" : "2025-05-30T16:27:59.558Z",
  "description" : "About FSISAC Video",
  "duration" : "PT1M43.061S",
  "height" : 1080,
  "name" : "Corporate Explainer FSISAC",
  "thumbnailUrl" : "https://5442200.fs1.hubspotusercontent-na1.net/hubfs/5442200/Videos/CorporateExplainer-FSISAC-ShortVersion.mp4/medium.jpg?t=1748622479558",
  "uploadDate" : "2023-01-10T14:07:11.346Z",
  "width" : 1920
}
```