Platform
A shipped actasec feature — asset inventory, vulnerability scanning, risk register, ITSM incidents, vendor management, security training — satisfies the requirement outright.
We mapped all 133 individual requirements of the CyberFundamentals Framework — the self-assessment tool published by the Centre for Cybersecurity Belgium and used for NIS2 readiness at the IMPORTANT assurance level — against what actasec’s platform and advisory services actually deliver today.
Requirements addressed once the platform is paired with actasec’s advisory and managed services.
The specific requirements CyFun flags as priority, each independently scored to a ≥3/5 target.
Requirements a shipped actasec feature satisfies on its own — no services required.
A shipped actasec feature — asset inventory, vulnerability scanning, risk register, ITSM incidents, vendor management, security training — satisfies the requirement outright.
The platform covers part of it; an actasec service — CISO-as-a-Service, Programme Design, Security Assessments, Cloud Security, Penetration Testing, or SOC-as-a-Service — closes the rest.
A small number of requirements — mostly budget decisions, physical security, and backup infrastructure — stay with the client no matter which vendor they choose.
CyFun flags these as priority — each needs its own ≥3/5 maturity score, independent of the category average.
Roles, responsibilities & authorities for info/cyber security (staff, suppliers, customers, partners) documented, reviewed, authorized, updated, communicated, coordinated internally & externally.
Fully once combined — Resolver Groups alone only cover ticket-queue ownership, a narrow slice; Programme Design's RACI closes the rest.
OS and critical-component security patches and updates must be installed.
Fully — Vulnerability Management finds unpatched systems directly and ITSM tracks remediation to closure.
A vulnerability management plan established and implemented to identify, analyze, evaluate, mitigate and communicate all vulnerability types, including coordinated vulnerability disclosure (CVD).
Fully once combined — the internal lifecycle is already handled; Programme Design adds the missing external CVD intake.
Identities and credentials of authorized users, services and equipment must be managed.
Fully once combined — actasec covers its own identities directly; Cloud Security's IAM review extends coverage client-wide.
Multi-factor authentication (MFA) must be mandatory for remote access to organizational networks.
Fully once combined — actasec enforces its own MFA directly; Cloud Security validates/extends it client-wide.
Usage restrictions, connection requirements and authorization procedures defined, documented and implemented for remote access to critical systems.
Fully via Cloud Security's remote-access review and Programme Design's documentation.
Access permissions, rights and authorizations defined, managed, enforced and reviewed.
Fully once combined — platform RBAC covers actasec itself; Cloud Security extends it client-wide.
Established who needs access to critical information/technology and by what means they obtain it.
Fully via Cloud Security's IAM risk analysis.
Access rights, privileges and authorizations restricted to what's specifically needed for the role (least privilege).
Fully once combined — platform RBAC direct for itself; Cloud Security extends it client-wide.
No one should hold administrative privileges for routine, day-to-day tasks.
Partially — the review surfaces violations, but day-to-day enforcement remains the client's own operational discipline.
Backups of critical organizational data made and stored on a system different from the device holding the original data.
Not addressed — the one Key Measure that stays genuinely client-owned even combined with services; we can review the evidence, not run the backups.
A baseline configuration developed, documented and maintained for business-critical systems.
Fully via Cloud Security's CIS Benchmark hardening and IaC review.
Logs should be maintained, documented and monitored.
Fully via SOC-as-a-Service's SIEM deployment and management.
Log records include an authorized time source or internal clock timestamp compared/synchronized against an authorized time source.
Fully — a standard part of SOC-as-a-Service's SIEM configuration.
Firewalls installed, configured and actively updated across all networks used by the organization to protect against unauthorized access and cyber threats.
Fully via Cloud Security and Penetration Testing's direct firewall review/hardening.
Network segmentation and segregation implemented in line with trust boundaries and asset criticality to limit threat propagation.
Fully via Cloud Security's network security assessment.
Connections between critical system components identified, documented and controlled, without exception.
Fully via Cloud Security and Penetration Testing.
Adequate boundary-protection measures implemented to monitor/control communications at key external/internal system boundaries (IT and OT).
Fully via Cloud Security and Penetration Testing.
Antivirus, anti-spyware and other anti-malware programs must be installed and kept updated.
Fully via SOC-as-a-Service's EDR integration.
Unauthorized use of business-critical systems monitored and identified, through detection of unauthorized local, network, and remote connections.
Fully via SOC-as-a-Service's 24/7 monitoring.
Logging functionality of protection/detection tools enabled; logs saved, retained for a predefined period and periodically reviewed for unusual/harmful activity.
Fully via SOC-as-a-Service's SIEM/log management.
Cybersecurity incidents communicated to relevant external stakeholders within IR-plan-defined timelines, including reporting significant incidents to authorities per legal requirements.
Fully once combined — the platform tracks the clock, CISO-as-a-Service handles the regulatory notification itself.
Unauthorized access or data leaks detected and appropriately mitigated, including monitoring of critical systems at external boundaries and key internal points.
Fully via SOC-as-a-Service's monitoring and analyst-led containment.
Grouped by CyFun function, category, and subcategory. Expand a function to see how each of its requirements is addressed.
This is actasec’s own technical mapping against our shipped features and live service offerings — it is not a certified CyFun or NIS2 compliance audit, and coverage of a requirement does not by itself make an organization compliant. Most requirements also need organizational policy, procedure, and evidence that we can help produce but that the client must still own.
We’ll walk through where your organization stands today and what combination of platform and services gets you to a defensible CyFun®2025 assessment.
Request a Consultation →