{"id":26029,"date":"2026-07-31T08:48:32","date_gmt":"2026-07-31T12:48:32","guid":{"rendered":"https:\/\/www.sherweb.com\/blog\/?p=26029"},"modified":"2026-07-31T08:49:10","modified_gmt":"2026-07-31T12:49:10","slug":"nist-csf-protect-identify-msps","status":"publish","type":"post","link":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/","title":{"rendered":"Why most MSP security stacks are stronger at Protect than Identify"},"content":{"rendered":"<p>Take five minutes and list every security tool you sell. Next to each one, write one of two labels:<\/p>\n<ul>\n<li><strong>Stops problems.<\/strong> This includes firewalls, endpoint detection and response, email filtering, patch automation, MFA.<\/li>\n<li><strong>Finds problems.<\/strong> Think asset discovery, vulnerability scanning, risk assessment, penetration testing.<\/li>\n<\/ul>\n<p>Most lists come back lopsided, and the weight sits on the \u201cstops problems\u201d side.<\/p>\n<p>The \u201cfinds problems\u201d side is what the <a href=\"https:\/\/www.nist.gov\/cyberframework\">NIST Cybersecurity Framework<\/a> calls Identify. It covers understanding your cybersecurity risk to systems, people, assets and data, and it&#8217;s the function most MSP security stacks cover least well. Here\u2019s why that happens, and what closing the gap looks like in practice.<\/p>\n<h2>Protect sells, Identify doesn&#8217;t<\/h2>\n<p>The imbalance starts as a commercial problem before it becomes a security issue.<\/p>\n<p><strong>\u201cProtect\u201d<\/strong> tools produce tangible results. Block counts. Quarantined attachments. Patch compliance percentages that move in the right direction month over month. All of it demos well in a sales conversation and fills a slide in a quarterly review.<\/p>\n<p><strong>\u201cIdentify\u201d<\/strong> work produces a document. An asset inventory is a spreadsheet. A risk assessment is a report. Neither gives a client the feeling that something was stopped on their behalf, so neither gets approved as easily.<\/p>\n<p>The same pressure shows up inside your own operation. When a technician&#8217;s week fills up, discovery work is the first thing to slide, because nothing breaks when it slips. No ticket gets opened. No alert fires. The inventory just quietly ages.<\/p>\n<p>The result is an MSP running a well-defended client environment that still can\u2019t answer two questions with confidence: what exactly are we protecting, and how much of it is exposed right now.<\/p>\n<h2>What the Identify function actually asks for<\/h2>\n<p>The NIST Cybersecurity Framework splits security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Identify comes second, and it asks for three things:<\/p>\n<ol>\n<li><strong>Asset management.<\/strong> Knowing every device, application, cloud service and data store across a client tenant.<\/li>\n<li><strong>Risk assessment.<\/strong> Knowing which of those carries real exposure, and how much.<\/li>\n<li><strong>Improvement.<\/strong> Doing both again next quarter and feeding what you learn back in.<\/li>\n<\/ol>\n<p>Most MSPs do the first two partially. Asset management happens once during onboarding, then decays as the environment changes. Risk assessment often means running a scan and forwarding the output. Improvement, the part that makes the other two continuous, rarely gets scheduled at all.<\/p>\n<p>In the NIST Framework, Identify is listed before Protect. When looking at another framework, the <a href=\"https:\/\/www.cisecurity.org\/controls\">CIS Critical Security Controls<\/a>, it makes the same point more bluntly.<\/p>\n<h2>CIS puts inventory first for a reason<\/h2>\n<p>CIS Controls organizes security into 18 controls, ordered by priority. Four of them carry most of the Identify work:<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Control<\/strong><\/td>\n<td><strong>What it covers<\/strong><\/td>\n<td><strong>Implementation group<\/strong><\/td>\n<\/tr>\n<tr>\n<td><strong>Control 1<\/strong><\/td>\n<td>Inventory and control of enterprise assets<\/td>\n<td>IG1<\/td>\n<\/tr>\n<tr>\n<td><strong>Control 2<\/strong><\/td>\n<td>Inventory and control of software assets<\/td>\n<td>IG1<\/td>\n<\/tr>\n<tr>\n<td><strong>Control 7<\/strong><\/td>\n<td>Continuous vulnerability management<\/td>\n<td>Begins at IG1<\/td>\n<\/tr>\n<tr>\n<td><strong>Control 18<\/strong><\/td>\n<td>Penetration testing<\/td>\n<td>IG3<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>IG1 is the baseline implementation group that CIS says every organization should meet, regardless of its size or budget. IG3 is the tier built for organizations that employ dedicated security specialists.<\/p>\n<p>Controls 1 and 2 sit ahead of secure configuration, account management, access control, malware defenses and every other protective measure in the set. The people who wrote the list put counting before defending, and they put it first for a reason.<\/p>\n<p>Control 7 is the one most MSPs already satisfy. Almost everybody scans. So if inventory is covered and scanning is covered, why does the Identify side still come up thin?<\/p>\n<h2>Scanning tells you what could be wrong, not what is<\/h2>\n<p>The answer is in what a scan actually produces. A scanner gives you a list, and every item on it carries a severity score.<\/p>\n<p>That score rates one thing: how damaging the flaw would be if somebody exploited it, judged against the software itself. It says nothing about the environment the software sits in.<\/p>\n<p>So, two clients can carry the same finding at the same score while one is genuinely exposed and the other is not, because of network position, configuration or controls already in place that the score never sees. Same number, different risk.<\/p>\n<p>The size of that gap is measurable. FIRST, the organization behind the Exploit Prediction Scoring System, estimates that <a href=\"https:\/\/connectsecure.com\/blog\/epss-scoring-a-quick-guide-for-msps-on-vulnerability-prioritization\">only 2-7% of published vulnerabilities<\/a> are ever exploited in the wild.<\/p>\n<p>For a technician, that means a severity-ranked list is a rough priority order at best, and a morning spent at the top of it may mean time spent on something nobody will ever use.<\/p>\n<div class=\"sherweb-callout\"><strong>Want a second opinion on your security stack?<\/strong><br \/>\nOur team of experts works with MSPs on building out security services, from which gaps to close first to how to package the result for clients.<br \/>\n<a href=\"https:\/\/info.sherweb.com\/sherweb-cloud-services-for-msps\/\">Schedule a call with the Sherweb team \u2192<\/a><\/div>\n<style>\n<!--.sherweb-callout { border-left: 4px solid #0078D4; background: #faddd7; padding: 1.25em 1.5em; margin: 2em 0; font-size: 1rem; border-radius: 6px; box-shadow: 0 0 0 1px rgba(0,0,0,0.05); } .sherweb-callout a { color: #0078D4; font-weight: 600; text-decoration: none; } .sherweb-callout a:hover {text-decoration: underline;}--><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\"><\/span><br \/><\/style>\n<h2>What closing the gap looks like in practice<\/h2>\n<p>Closing the gap comes down to four practices, and each has to work across an entire client base rather than one at a time.<\/p>\n<ol>\n<li><strong>Continuous discovery.<\/strong> Internal, external and cloud assets, refreshed on a schedule instead of captured once at onboarding. A new SaaS subscription, a forgotten test server, a subdomain nobody decommissioned. An inventory built in March is wrong by May.<\/li>\n<li><strong>Validation, not just detection.<\/strong> Testing whether a finding is really exploitable in that specific environment, running continuously rather than annually.<\/li>\n<li><strong>Prioritization by exploitability.<\/strong> Ranking by likelihood of attack rather than severity alone, so the remediation list is short enough that somebody actually finishes it.<\/li>\n<li><strong>Reporting a client can act on.<\/strong> A short list, evidence behind each item and a record of what changed since last quarter.<\/li>\n<\/ol>\n<p>That last one answers the commercial problem from earlier. A report that says &#8220;we tested this, here\u2019s what an attacker could reach, here\u2019s what we closed since March&#8221; shows work. It gives the client something to approve rather than something to file.<\/p>\n<h2>Building out the Identify side of your stack<\/h2>\n<p>Most of this is hard to do by hand across a client base, which is where tooling comes in. There are two tools in the Sherweb marketplace that handle the Identify side rather than the Protect side. They also cover different parts of it, which is why partners run them for different reasons.<\/p>\n<p><a href=\"https:\/\/www.sherweb.com\/security\/connectsecure\"><strong>ConnectSecure<\/strong><\/a> covers the management side. Continuous scanning across a multi-tenant client base, compliance assessment and a remediation workflow, giving you a current picture of what exists and what is outstanding.<\/p>\n<p><a href=\"https:\/\/www.sherweb.com\/security\/threatmate\"><strong>ThreatMate<\/strong><\/a> covers the validation side. Attack surface discovery, automated penetration testing and configuration audits, with findings ranked by whether they are actually exploitable rather than by severity score alone.<\/p>\n<p>An MSP running vulnerability management already has a program, and the tracking half of Identify is covered. Validation answers the second question, the one scanning was never designed to answer: out of everything on the list, what could somebody actually use?<\/p>\n<p>What you need first depends on the client. An SMB working toward the IG1 baseline needs the management side. A client with regulatory exposure, or one whose insurer has started asking specific questions at renewal, is where validation earns its place sooner.<\/p>\n<h2>Go back to your tool list<\/h2>\n<p>If almost everything on your list stops problems and almost nothing finds them, you\u2019re defending an environment that nobody has fully mapped. That\u2019s a solvable problem, and NIST and CIS agree on where to start.<\/p>\n<p>Count what&#8217;s actually there, then test which of it is genuinely exposed. Neither step means tearing up the rest of your stack, and both make everything already in it easier to defend in front of a client.<\/p>\n<h2>Ready to update the Identify side of your stack?<\/h2>\n<p>ThreatMate handles attack surface discovery, automated penetration testing and configuration audits across every client environment from one place. It ranks what it finds by whether an attacker could actually use it, so your team gets a short list worth working through and your clients get evidence behind every recommendation.<\/p>\n<p>Learn more about <a href=\"https:\/\/www.sherweb.com\/security\/threatmate\">ThreatMate<\/a> in the Sherweb marketplace.<\/p>\n<h2>Frequently asked questions (FAQs)<\/h2>\n<h3>What are the functions of the NIST Cybersecurity Framework?<\/h3>\n<p>CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond and Recover.<\/p>\n<h3>What is the Identify function in NIST CSF?<\/h3>\n<p>Identify covers understanding your cybersecurity risk to systems, people, assets and data. In CSF 2.0 it contains three categories: asset management, risk assessment and improvement.<\/p>\n<h3>How do CIS Controls map to NIST CSF?<\/h3>\n<p>CIS publishes a mapping between Controls v8.1 and CSF 2.0. Controls 1 and 2, covering enterprise asset and software inventory, align to the asset management category under Identify.<\/p>\n<h3>What is the difference between vulnerability scanning and penetration testing?<\/h3>\n<p>Scanning finds and reports potential weaknesses. Penetration testing attempts to exploit them to establish whether they are usable in a given environment. CIS treats them as separate controls, 7 and 18.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Take five minutes and list every security tool you sell. Next to each one, write one of two label","protected":false},"author":177,"featured_media":26030,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[753],"tags":[919,1116,1211],"class_list":["post-26029","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cybersecurity","tag-connectsecure","tag-threatmate"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb<\/title>\n<meta name=\"description\" content=\"Most MSP security stacks over-invest in Protect and skip Identify. Here&#039;s how to close the visibility gap using CIS Controls and NIST CSF 2.0.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb\" \/>\n<meta property=\"og:description\" content=\"Most MSP security stacks over-invest in Protect and skip Identify. Here&#039;s how to close the visibility gap using CIS Controls and NIST CSF 2.0.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/\" \/>\n<meta property=\"og:site_name\" content=\"Sherweb\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Sherweb\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-31T12:48:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-31T12:49:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.sherweb.com\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"480\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"The Sherweb Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:site\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"The Sherweb Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/\"},\"author\":{\"name\":\"The Sherweb Team\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\"},\"headline\":\"Why most MSP security stacks are stronger at Protect than Identify\",\"datePublished\":\"2026-07-31T12:48:32+00:00\",\"dateModified\":\"2026-07-31T12:49:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/\"},\"wordCount\":1453,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Threatmate_1200x480.jpg\",\"keywords\":[\"Cybersecurity\",\"ConnectSecure\",\"ThreatMate\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/\",\"name\":\"NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Threatmate_1200x480.jpg\",\"datePublished\":\"2026-07-31T12:48:32+00:00\",\"dateModified\":\"2026-07-31T12:49:10+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\"},\"description\":\"Most MSP security stacks over-invest in Protect and skip Identify. Here's how to close the visibility gap using CIS Controls and NIST CSF 2.0.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#primaryimage\",\"url\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Threatmate_1200x480.jpg\",\"contentUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Threatmate_1200x480.jpg\",\"width\":1200,\"height\":480,\"caption\":\"NIST CSF for MSPs: Why Identify matters as much as Protect\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/nist-csf-protect-identify-msps\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Why most MSP security stacks are stronger at Protect than Identify\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\",\"name\":\"Sherweb\",\"description\":\"More than a cloud marketplace\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/42a19dccace310904575a5656cc20976\",\"name\":\"The Sherweb Team\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/author\\\/the-sherweb-team\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb","description":"Most MSP security stacks over-invest in Protect and skip Identify. Here's how to close the visibility gap using CIS Controls and NIST CSF 2.0.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/","og_locale":"en_US","og_type":"article","og_title":"NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb","og_description":"Most MSP security stacks over-invest in Protect and skip Identify. Here's how to close the visibility gap using CIS Controls and NIST CSF 2.0.","og_url":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/","og_site_name":"Sherweb","article_publisher":"https:\/\/www.facebook.com\/Sherweb","article_published_time":"2026-07-31T12:48:32+00:00","article_modified_time":"2026-07-31T12:49:10+00:00","og_image":[{"width":1200,"height":480,"url":"https:\/\/www.sherweb.com\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg","type":"image\/jpeg"}],"author":"The Sherweb Team","twitter_card":"summary_large_image","twitter_creator":"@SherWeb","twitter_site":"@SherWeb","twitter_misc":{"Written by":"The Sherweb Team","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#article","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/"},"author":{"name":"The Sherweb Team","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976"},"headline":"Why most MSP security stacks are stronger at Protect than Identify","datePublished":"2026-07-31T12:48:32+00:00","dateModified":"2026-07-31T12:49:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/"},"wordCount":1453,"commentCount":0,"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg","keywords":["Cybersecurity","ConnectSecure","ThreatMate"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/","url":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/","name":"NIST CSF for MSPs: Why Identify matters as much as Protect | Sherweb","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#primaryimage"},"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg","datePublished":"2026-07-31T12:48:32+00:00","dateModified":"2026-07-31T12:49:10+00:00","author":{"@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976"},"description":"Most MSP security stacks over-invest in Protect and skip Identify. Here's how to close the visibility gap using CIS Controls and NIST CSF 2.0.","breadcrumb":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#primaryimage","url":"\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg","contentUrl":"\/blog\/wp-content\/uploads\/Threatmate_1200x480.jpg","width":1200,"height":480,"caption":"NIST CSF for MSPs: Why Identify matters as much as Protect"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sherweb.com\/blog\/security\/nist-csf-protect-identify-msps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sherweb.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.sherweb.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Why most MSP security stacks are stronger at Protect than Identify"}]},{"@type":"WebSite","@id":"https:\/\/www.sherweb.com\/blog\/#website","url":"https:\/\/www.sherweb.com\/blog\/","name":"Sherweb","description":"More than a cloud marketplace","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sherweb.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/42a19dccace310904575a5656cc20976","name":"The Sherweb Team","url":"https:\/\/www.sherweb.com\/blog\/author\/the-sherweb-team\/"}]}},"tag_names":["Cybersecurity","ConnectSecure","ThreatMate"],"_links":{"self":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/26029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/users\/177"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/comments?post=26029"}],"version-history":[{"count":4,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/26029\/revisions"}],"predecessor-version":[{"id":26035,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/26029\/revisions\/26035"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/media\/26030"}],"wp:attachment":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/media?parent=26029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/categories?post=26029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/tags?post=26029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}