Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

NIST CSF 2.0’s Identify, Protect, Detect, Respond, and Recover Functions, Explained

August 11, 2026
hero-nist-csf-2-0-functions-explained-1.png

NIST CSF 2.0 organizes cybersecurity risk management into six Functions. Five of them, Identify, Protect, Detect, Respond, and Recover, run the day-to-day security work every business actually does.

The sixth Function, Govern, sets the strategy behind the other five. We cover Govern in depth in our guide to the NIST CSF Govern function. This page walks through the remaining five.

If you’re brand new to the framework, start with our plain-English overview of what NIST CSF 2.0 is first. Everything below assumes you already know CSF 2.0 exists and want each Function explained.

The Six Functions at a Glance

Each Function breaks down into Categories and Subcategories. These are specific outcomes, not a list of tools you’re told to buy (NIST’s CSF Core reference lays this out in full). NIST’s official CSF 2.0 text defines all six Functions below.

FunctionWhat It Covers
Govern (GV)Strategy, roles, policy, and oversight for the whole program. Covered separately in our Govern function guide.
Identify (ID)Understanding your assets, data, systems, and risk.
Protect (PR)Safeguards that secure assets and limit an event’s impact.
Detect (DE)Finding and analyzing a possible attack or compromise.
Respond (RS)Actions taken once an incident is confirmed.
Recover (RC)Restoring assets and operations after an incident.

Identify: Knowing What You Have and What’s At Risk

Identify is the foundation. You can’t protect what you don’t know you have.

This Function covers building an inventory of your assets, data, systems, and the risks tied to each. That means knowing which devices connect to your network, which software runs on them, where sensitive data lives, and which vendors touch your systems.

A business that skips Identify usually finds out the hard way: a server nobody tracked, a departed employee’s account nobody disabled, a vendor with more access than anyone remembered granting.

Identify typically includes:

  • An inventory of hardware, software, and cloud services in use
  • A map of where sensitive data lives and who can reach it
  • A list of vendors and third parties with system or data access
  • A basic understanding of which risks matter most to your business

None of this needs to be exotic. Most small and mid-sized businesses can build a workable Identify picture with a spreadsheet and a few hours of discovery, then keep it current as things change.

Protect: The Safeguards That Limit the Damage

Protect is where most people’s mental image of “cybersecurity” actually lives. It covers the safeguards that secure your assets and limit how much damage an event can do.

This is the Function that includes access controls, multifactor authentication (MFA), endpoint protection, encryption, employee security training, and patch management. It also covers backups, though Recover is where you actually use them.

Protect isn’t about buying every security product available. It’s about matching safeguards to the assets and risks Identify already surfaced.

Common Protect controls include:

  • Multifactor authentication on email, VPN, and admin accounts
  • Endpoint protection on every device that touches company data
  • A regular patching and update schedule
  • Access limited to what each role actually needs
  • Security awareness training so staff can spot phishing attempts
  • Backups that are tested, not just scheduled

A business that’s strong on Protect but weak on Identify often protects the wrong things well. That’s why the Functions build on each other rather than standing alone.

Detect: Catching an Attack Before It Spreads

Detect covers finding and analyzing a possible cybersecurity attack or compromise. Protect reduces how often something bad happens. Detect is what tells you when something bad is happening anyway, because eventually, something will get through.

Diagram of how the Detect function works: centralized logging, alerts on unusual activity, regular review, and confirming real incidents

This Function is about monitoring: log review, alerting on unusual activity, and having someone (in-house or outsourced) actually watching for signs of trouble. A locked-down network still needs eyes on it, because attackers who slip past Protect controls rely on nobody noticing for as long as possible.

Detect capabilities usually include:

  • Centralized logging across servers, endpoints, and network devices
  • Alerts for unusual login attempts, data transfers, or privilege changes
  • Regular review of security alerts, not just automated collection
  • A defined process for confirming whether an alert is a real incident

The gap between Protect and Detect is where a lot of small businesses get hurt. They install security tools, then nobody is watching what those tools flag. An unmonitored alert is functionally the same as no alert at all.

Respond: Acting Once You Know It’s Real

Respond covers what happens once you’ve confirmed an incident is real, not a false alarm.

This Function is about containing the damage, communicating clearly, and following a plan instead of improvising under pressure. A written incident response plan turns a crisis into a checklist.

Respond activities typically include:

  • Containing affected systems to stop the spread
  • Following a predefined incident response plan
  • Notifying the right people, internally and externally
  • Documenting what happened and when it happened
  • Coordinating with your IT provider, insurer, or legal counsel as needed

A business without a Respond plan doesn’t avoid the incident. It just handles the incident badly, in real time, with no plan to fall back on.

Recover: Getting Back to Normal

Recover covers restoring the assets and operations an incident affected.

This is where backups stop being a line item and start being the reason a business survives an incident intact. A backup nobody has tested is a hope, not a plan.

Recover typically includes:

  • Restoring systems and data from tested backups
  • Confirming restored systems are clean before reconnecting them
  • Communicating recovery status and timelines to stakeholders
  • Reviewing what happened and updating the plan for next time

How the Five Functions Work as a Cycle

Identify, Protect, Detect, Respond, and Recover aren’t five separate boxes to check once. They work as a loop, and each one feeds the next.

  1. Identify: know what you have and what’s actually at risk.
  2. Protect: put safeguards around what Identify found.
  3. Detect: watch for signs something got through anyway.
  4. Respond: act on a confirmed incident using a plan, not improvisation.
  5. Recover: restore operations, then roll what you learned back into Identify.
NIST CSF Security Cycle

Govern sits above this cycle rather than inside it. It’s where your risk strategy, policies, and accountability get set, and where the other five Functions get checked against that strategy. We cover it in full in our Govern function guide.

Where Small and Mid-Sized Businesses Usually Have the Biggest Gaps

Most small and mid-sized businesses aren’t starting from zero on these five Functions. They usually have some Protect controls in place already: antivirus, maybe MFA on a few systems.

Icon grid showing where SMB security gaps cluster: no tested response plan, unconfirmed backups, unwatched alerts, no asset inventory

The gaps tend to cluster in the same spots:

  • Respond: no written incident response plan, or one that’s never been tested
  • Recover: backups are scheduled, but nobody has confirmed they actually restore
  • Detect: security tools are installed, but no one is watching what they flag
  • Identify: no current inventory of assets, data, or vendor access

Notice where those gaps sit. They’re concentrated in the Functions that only matter once something has already gone wrong, which is exactly why they get skipped until it’s too late.

The fastest way to see where your own business stands across all five, plus Govern, is our NIST CSF 2.0 self-assessment checklist. If you’d rather work from a static reference, we also have a downloadable NIST CSF 2.0 checklist, and if you’re specifically sizing this for a smaller operation, see NIST CSF 2.0 for small business.

See Where You Stand

Want a faster read on where your business stands than working through this page function by function? Our free NIST CSF 2.0 Risk-Check asks a few plain-English questions across all six Functions and gives you an instant snapshot of where your gaps likely are. It’s a simplified starting point, not an official NIST assessment, and there’s no sign-up required to see your result.

Take the free NIST CSF 2.0 Risk-Check

Frequently Asked Questions

CSF 2.0 also broadened its scope beyond critical infrastructure to any organization, of any size or sector.

No. NIST CSF 2.0 is voluntary guidance, not a law, and there’s no regulator that fines a business for skipping it. Its influence comes indirectly, through contracts, cyber insurance applications, and how regulators judge “reasonable” security after a breach.

Identify. You can’t protect assets, data, or systems you haven’t inventoried yet. Most businesses find their Protect controls are already ahead of their Identify picture, which means some of what they’re protecting is the wrong thing, or protected inconsistently.

A Profile describes your cybersecurity posture in terms of the Functions, Categories, and Subcategories. A Current Profile shows where you actually are today. A Target Profile shows where you want to be, based on your risk tolerance and priorities. Comparing the two is what turns CSF 2.0 into an action plan.

Tiers describe how rigorously an organization manages cybersecurity risk overall, not how many controls it has. There are four: Partial, Risk Informed, Repeatable, and Adaptive. A higher Tier isn’t automatically the right goal for every business; it depends on your risk tolerance and resources.

Yes. Most of what CSF 2.0 asks for, asset inventory, access controls, monitoring, incident response, tested backups, is work a managed IT provider already handles day to day. LeadingIT also helps build the Govern-function paperwork, like a written risk strategy and policy set, that insurers and banks ask to see.

Ready to See Where Your Business Actually Stands?

Reading through these five Functions is a solid start, but running all of them consistently takes more bandwidth than most internal IT teams have to spare. LeadingIT helps Chicagoland businesses build and run a NIST CSF 2.0-aligned security program through our NIST CSF 2.0 compliance and cybersecurity services, done for you instead of added to your team’s plate.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.