The CIS Controls: Offense Informs Defense
The CIS Controls are 18 families of safeguards based on real-world attack data. Each safeguard asks for one specific action. The framework uses implementation groups IG1 through IG3 to adapt to risk. IG1 is the baseline. IG3 fits high-risk environments. The Secret Service uses the same offense-informs-defense approach for bank robberies. The controls use data from IC3, Verizon DBIR, and other sources to stop the attacks that actually happen.
Hot Take: CentOS 6 with Fail2ban
A post from October 2025 claimed disabling password authentication and using fail2ban made a server secure. Amelia mapped it to Control 4 (secure configuration) and Control 5 (account management). But the server ran CentOS 6, a 15-year-old operating system with massive unpatched vulnerabilities. Control 7 requires patching. CentOS 6 is end-of-life. No patches exist. The controls expose the gap: good authentication cannot fix an unpatchable OS.
Hot Take: VMware is Bulletproof
A post with 688 upvotes claimed VMware is bulletproof. Amelia pointed to Control 14 (security awareness training) and Control 17 (incident response). Lawrence added Control 12 (infrastructure management) and Control 6 (access control). Shodan shows thousands of internet-facing ESXi hosts with known vulnerabilities. VMware is critical infrastructure, not bulletproof. The controls provide a path to reduce exposure through proper management and training.
Hot Take: Just Turn Off Web Security
A Chrome update broke an EMR system. The advice: disable web security and replace the Chrome icon with a flag that disables CORS. Amelia identified Control 16 (application software security) as the root cause. The vendor failed to test. Control 9 (email and browser protections) and Control 15 (service provider management) apply. Disabling CORS in a clinical environment opens the door to adversary-in-the-middle attacks. The controls demand the vendor maintain modern security standards.
Recap: CIS Controls Beat Improvisation
The CIS Controls are not a fixed checklist. They are a risk-informed decision path. IG1 covers 74% of common TTPs with basic safeguards. For sysadmins, the controls reduce trial and error. For developers, Control 16 provides a progressive guide to secure software development. Frameworks beat improvisation. The controls filter bad advice and deliver better outcomes.
Q&A
How do you implement CIS Controls in an organization that already has many tools? Start with executive buy-in using the data that IG1 mitigates 74% of commodity attacks. Most organizations already have the tooling for IG1. βΆ 22:07
What are your opinions on mandatory compliance regulations? Mandatory compliance is necessary, but it does not always enforce meaningful cybersecurity. Organizations that want to do the right thing will exceed minimum standards. βΆ 24:01
Notable Quotes
CentOS 6 has massive vulnerabilities. Amelia Cruciana Β· βΆ 12:04
VMware looks like a security nightmare. Amelia Cruciana Β· βΆ 14:29
just disable web security Lawrence Cruciana Β· βΆ 17:15
The controls are a set of 18 prioritized, real-world informed, risk-sized defensive strategies Lawrence Cruciana Β· βΆ 20:57
IG1 taking care of largely 74% of common TTPs Lawrence Cruciana Β· βΆ 21:13
Key Takeaways
- The CIS Controls filter bad advice by grounding decisions in real-world attack data.
- IG1 covers 74% of common TTPs with basic, low-cost safeguards.
- Use the controls to evaluate social media claims before adopting them.
About the Speaker(s)
Lawrence Cruciana, CISSP, CISM, CISA, GCCC, CCP, CCA is the founder and President of Corporate Information Technologies (CorpInfoTech), a cybersecurity-centric Managed Service Provider that he has led and grown for more than two decades. CorpInfoTech delivers secure IT services toβ¦
Amelia is a cybersecurity and privacy student & researcher with a focus on practical, privacy-preserving security. She advocates security-first, security-by-default design to reduce real-world risk. Her focus applies the CIS Controls in ways non-traditional practitioners and early-careerβ¦