Research date: September 14–15, 2026. Fifteen practical baselines, each anchored to the two citable floors — CISA's Cross-Sector Cybersecurity Performance Goals (CPG 2.0, released December 11, 2025) and CIS Controls v8.1 Implementation Group 1, the 56 safeguards defined as essential cyber hygiene.
CPG 2.0 is the better sequencing tool for resource-constrained organizations because it reorganized around CSF 2.0's six functions, merged IT and OT goals, added goals for third parties with deep system access such as MSPs, and ships with cost, impact, and ease ratings so an operator with one person and no budget can work in priority order.
The universal free-resource shelf
These apply to nearly every organization type below and deserve a standing page on the site:
- CISA Cyber Hygiene Services — free continuous external vulnerability scanning and web application scanning for US government, critical infrastructure, and eligible private organizations. Enroll via vulnerability@cisa.dhs.gov. CISA reports a typical 40% exposure reduction in the first year.
- CISA's no-cost tools catalog and Tabletop Exercise Packages (free, customizable scenarios with facilitator guides).
- Global Cyber Alliance toolkits for small businesses and for mission-based organizations — DMARC setup, DNS filtering via Quad9, password and MFA guidance.
- UK NCSC Small Business Guide and its Response and Recovery companion, which is the best plain-language IR guidance published anywhere.
- Sector ISACs — MS-ISAC for state, local, tribal, and territorial government and K-12; Health-ISAC; FS-ISAC; K12 SIX; WaterISAC; E-ISAC; MFG-ISAC.
- Nonprofit Cyber coalition members including GCA, the CyberPeace Institute and CyberPeace Builders, and Shadowserver.
- CISA SCuBA secure configuration baselines for Microsoft 365 and Google Workspace.
D1. Individuals
Top risks. Phishing and smishing; investment and romance scams, with crypto investment fraud alone exceeding $7.2B in reported 2025 US losses; account takeover through reused passwords and infostealers; tech-support scams at roughly $2.1B.
Priority controls. Unique passwords through a password manager. MFA on email, banking, and cloud storage first — email is the master key to everything else. Automatic OS and browser updates. Device encryption with screen locks. Credit freezes with all three bureaus, which are free and among the highest-value controls available to a consumer. A backup of phone and computer.
Budget and staffing. $0–$100 per year for a password manager and backup storage. No staff — habits are the control, and the highest-ROI items (updates, MFA, freezes, unique passwords) are free.
Free resources. CISA's Secure Our World basics; IdentityTheft.gov after fraud; IC3.gov to report; built-in browser and platform password managers.
D2. Families
Top risks. Everything in D1 plus child-targeted scams and sextortion, elder fraud including grandparent and tech-support scams, account bleed across shared devices, and home router and IoT compromise.
Priority controls. A family password manager. MFA on all shared finance, email, and streaming accounts. Router firmware updates and changed default passwords. Separate child accounts with parental controls. A family "call back to verify" rule for any money request, which counters voice-clone scams directly. Talk about sextortion reporting without shame — NCMEC's Take It Down service exists for this.
Budget. Under $150 per year.
Free resources. FBI and IC3 elder-fraud materials, NCMEC resources, Quad9 DNS filtering.
D3. Freelancers and solo practitioners
Top risks. Invoice fraud in both directions; takeover of the single email address the whole business runs on; ransomware on an unbacked-up laptop; client-data liability without contracts covering it.
Priority controls. Business email separated from personal, with phishing-resistant MFA. Password manager. Automatic cloud backup plus one offline copy. Full-disk encryption. Invoice-change callback verification with clients. Basic contract language on data handling. A separate bank account with transaction alerts.
Budget and staffing. $200–$600 per year; self-serve.
Free resources. GCA Small Business Toolkit; FTC small-business basics; free DMARC checkers.
D4. Small businesses (roughly 5–50 staff)
Top risks. BEC and invoice fraud; ransomware, in which SMBs are heavily over-represented; stolen credentials; and the absence of backups and an IR plan.
Priority controls — CIS IG1 core. Asset and software inventory. MFA everywhere, on email, remote access, administration, and banking. Automated patching. Managed EDR on all endpoints. Offline or immutable backups tested quarterly. Email authentication with SPF, DKIM, and DMARC at enforcement. A payment-change verification procedure. A one-page IR plan with the insurer's hotline on it.
Budget and staffing. A commonly cited target is 5–10% of the IT budget; concretely, roughly $5K–$25K per year for tools plus an MSP or MDR arrangement, with a fuller line-item build in 10-cybersecurity-economics.md landing at $10K–$30K. No dedicated staff — an IT generalist or MSP. Cyber insurance typically $1K–$5K per year for small firms.
Free resources. CISA Cyber Hygiene scanning if eligible, CISA's free tools list, the GCA toolkit, the NCSC Small Business Guide, and the free CIS CSAT self-assessment.
D5. Startups
Top risks. Cloud and tenant compromise through exposed keys in repositories and permissive IAM; SaaS sprawl with no offboarding; founder-held root accounts; a customer-data breach killing enterprise deals; supply-chain exposure through dependencies.
Priority controls. SSO and MFA from day one — identity is the control plane. Secrets management with no keys in code and secret scanning enabled. A cloud security baseline using CIS Benchmarks, branch protection, and least-privilege IAM. Endpoint management and EDR even on an all-MacBook fleet. Audit logging on the control plane. SOC 2 readiness as a forcing function once you sell to enterprises.
Budget and staffing. Pre-seed and seed: founder-led with platform-native tools, largely free tiers. Series A/B: the first security hire — often a security-minded platform engineer — around 50 to 100 employees, or a vCISO at $2K–$8K per month. MDR when headcount cannot cover alerts.
Free resources. Cloud provider free security tooling, GitHub secret scanning and Dependabot, CIS Benchmarks, CISA's Secure by Design principles for the product team.
D6. Schools (K-12)
Trends. Schools remain soft targets, since budgets and staff data are public record. CISA's listed prevalent threats are data breaches, ransomware, BEC, DDoS, and system intrusions. Encouragingly, K-12 ransomware trended down in 2026 while higher education trended up; 34 ransomware attacks hit US education institutions in the first half of 2026, and incidents such as the Alamo Heights ISD breach (26,629 affected, a five-day shutdown, March 2026) show the operational stakes. Ed-tech vendor attacks — the PowerSchool breach of December 2024 and January 2025 being the canonical example — cascade to thousands of districts, so third-party risk is a K-12 problem too.
CISA released a new K-12 resource package on August 12, 2026 — a foundational program guide for school leaders plus a sustainment guide for K-12 security staff.
Priority controls. Protect student and staff credentials, with MFA for staff first and students where feasible. Safeguard devices. Perform, verify, and test backups. Develop and practice an IR plan. Use free training. Protect sensitive data by limiting collection and retention. Adopt the CPGs, with NIST CSF as the longer-term plan.
Budget and staffing. Chronically constrained; many districts have zero dedicated security staff. The realistic model is a technology director plus MS-ISAC membership plus E-Rate-eligible network security plus state programs.
Free resources. MS-ISAC membership, free for K-12; K12 SIX threat intelligence; CISA Cyber Hygiene scanning and the K-12 guides above; free tabletop packages; Cloudflare's Project Cybersafe Schools for small districts.
D7. Nonprofits
Top risks. BEC targeting donation and grant flows; ransomware; donor-data breaches; espionage against advocacy and human-rights organizations; tiny budgets guarding valuable data.
Priority controls. IG1 basics — MFA, patching, backups, EDR, often through donated licenses. DMARC, because donation-solicitation spoofing is common and damages the mission directly. Least privilege on donor CRMs. Callback verification for grant and payment changes. Volunteer and staff offboarding discipline.
Budget and staffing. Often under $10K per year; leverage donated and discounted technology through TechSoup and pro bono help.
Free resources. The GCA Mission-Based Toolkit; the Nonprofit Cyber coalition including CyberPeace Builders volunteer matching; Microsoft and Google nonprofit grants, whose donated Business Premium tiers include real security features; Cloudflare's Project Galileo for at-risk public-interest sites; CISA Cyber Hygiene.
D8. Healthcare organizations
Top risks. Ransomware with patient-safety impact — top variants including Akira and Qilin target healthcare, and IC3 logged 460 reported ransomware attacks against healthcare in 2025. Vendor and clearinghouse compromise, with Change Healthcare the canonical cascade. PHI breaches. Legacy and connected medical devices. Healthcare consistently posts the highest breach costs of any sector.
Priority controls. Offline backups plus downtime procedures — paper workflows — tested for 30-day outages, drilled with clinicians rather than written for auditors. MFA and encryption; note that the proposed HIPAA Security Rule update would make MFA, encryption at rest and in transit, asset inventories, and segmentation explicitly mandatory rather than addressable, so treating them as required now is both prudent and a head start. Network segmentation of clinical devices. A vendor risk program with business associate agreements and access inventories. 60-day breach-notification readiness. HHS OCR has settled multiple ransomware-specific HIPAA enforcement actions.
Budget and staffing. Small practices: MSP plus MDR plus compliance tooling, roughly $15K–$50K per year. Hospitals: a dedicated CISO and team, commonly 4–7% of the IT budget and rising since 2024.
Free resources. HHS 405(d) Health Industry Cybersecurity Practices, Health-ISAC, CISA Cyber Hygiene and healthcare advisories, the HHS HPH sector performance goals, ASPR TRACIE.
D9. Financial companies
Top risks. Credential and identity attacks; BEC and wire fraud; third-party and fintech integration compromise; DDoS including hacktivist campaigns; and regulatory exposure. Financial services was the second most-targeted industry at 14.6% in M-Trends 2026.
Priority controls. Phishing-resistant MFA enterprise-wide. 24/7 monitoring, in-house or hybrid. Fusion of fraud, AML, and security functions. Tested wire-verification procedures with deepfake-resistant callbacks. Third-party risk management. Incident-reporting readiness for overlapping regimes: NYDFS Part 500 at 72 hours, GLBA Safeguards at 30 days to the FTC for 500+ consumers, SEC 8-K if public, and the banking regulators' 36-hour notification rule.
Budget and staffing. The highest sector spend, commonly above 10% of IT budget. Even small registered investment advisers and credit unions need MDR plus a vCISO; mid-size firms typically run five to twenty dedicated security staff.
Free resources. FS-ISAC, CISA Cyber Hygiene, Sheltered Harbor guidance for data vaulting. Note the FFIEC sunset its Cybersecurity Assessment Tool on September 1, 2025 — point readers to NIST CSF 2.0 and the CPGs as replacements.
D10. SaaS companies
Top risks. Tenant-isolation flaws and application-layer breaches; OAuth and API abuse; supply chain through dependencies and CI/CD; a single breach cascading to every customer — you are the third party in everyone else's DBIR statistic; credential stuffing against customer accounts.
Priority controls. Secure SDLC with dependency scanning. Secrets management and short-lived credentials in CI/CD. Per-tenant isolation testing. SSO and MFA for both workforce and product, with MFA defaulted on for customers. Comprehensive audit logging exposed to customers, which is a Secure by Design pledge item and increasingly a procurement requirement. A vulnerability disclosure program. SOC 2 or ISO 27001. And a customer-facing incident notification process with contractual SLAs — your incident is your customers' vendor-compromise playbook.
Budget and staffing. Security engineering embedded in product teams; first dedicated hire around 50 to 100 employees; a product-security and detection-response split around 300. MDR is common until then.
Free resources. CISA Secure by Design resources, OWASP ASVS and SAMM, GitHub Advanced Security free tiers for open source, CISA SCuBA for the back office.
D11. E-commerce
Top risks. Payment-page skimming; credential stuffing and account takeover; gift-card and refund fraud; DDoS during peak season; third-party plugin and platform compromise.
Priority controls. PCI DSS 4.0.1 compliance, with particular attention to the March 31, 2025 deadline that made script-integrity and payment-page change-detection requirements (6.4.3 and 11.6.1) mandatory — these exist precisely because of client-side skimming. Minimize scope through hosted payment fields and tokenization. Bot management and rate limiting on login and checkout. WAF and CDN with DDoS mitigation contracted before peak season. Plugin and theme patching discipline. MFA on the admin panel.
Budget and staffing. Small shops: platform-native, since Shopify-class platforms carry much of the PCI burden, plus $2K–$10K per year for WAF and bot tools. Mid-size self-hosted: a dedicated engineer plus MDR.
Free resources. PCI SSC free resources, CISA web application scanning, platform security guides, Have I Been Pwned domain monitoring.
D12. Manufacturers
Top risks. Ransomware causing production stoppage — manufacturing is perennially among the top-attacked sectors. IT/OT convergence exposing legacy control systems. IP theft. Supplier compromise propagating through just-in-time chains.
Priority controls. IT/OT segmentation with monitored conduits — CPG 2.0 now merges IT and OT goals, so apply them universally. Asset inventory including OT and ICS. Offline backups and manual-operation fallback procedures. Remote-access lockdown for vendors and integrators, eliminating shared always-on VPNs. EDR on IT and passive monitoring on OT. An incident plan that includes safety and production leaders, not only IT.
Budget and staffing. SMB manufacturers often have one IT generalist — use MDR plus an OT-aware integrator. Larger plants need a named OT security owner. Benchmark 3–7% of IT spend, rising with OT scope.
Free resources. CISA ICS advisories and free tools including Malcolm, CISA Cyber Hygiene, MFG-ISAC, NIST 800-82r3, and free OT tabletop scenarios.
D13. Enterprises
Top risks. Everything above at scale, plus identity-infrastructure compromise of AD and Entra; edge-device exploitation — the M-Trends 2026 "edge blind spot," where appliances without EDR harbored implants for roughly 400 days; third-party and M&A-inherited risk; SEC disclosure exposure; and shadow AI, which quadrupled per DBIR 2026 and added roughly $670K to average breach cost per IBM.
Priority controls. A full CIS IG2-to-IG3 or CSF 2.0 program with Govern-function board reporting. In-house or hybrid 24/7 SOC with detection engineering and threat hunting. Identity-first zero trust: phishing-resistant MFA, PAM, ITDR. KEV-prioritized vulnerability management — only 26% of organizations fully remediate KEV entries, so beating that is a defensible goal. Tested enterprise IR: retainers, a breach coach, an SEC materiality process, crisis communications. An AI governance policy, which 63% of organizations still lack.
Budget and staffing. Commonly 6–14% of IT budget. A headcount rule of thumb is roughly one security FTE per 100–250 employees depending on sector, with a CISO plus functional leads for security operations, GRC, product and application security, and identity.
D14. Government (federal, state, local, tribal, territorial)
Top risks. Ransomware against municipalities and counties; election-adjacent interference; legacy systems; tiny local IT teams; hacktivist DDoS.
Priority controls. CPG 2.0 adoption as the baseline checklist. MFA on all remote access and email. Offline backups for critical services — courts, 911-adjacent systems, utility billing. Migration to .gov domains, which is free. Centralized logging. Participation in MS-ISAC and EI-ISAC monitoring including Albert sensors. IR plans coordinated with state National Guard and state CISO programs. Federal agencies additionally follow CISA Binding Operational Directives and FISMA.
Budget and staffing. Severely constrained at the local level, where many counties have zero security staff. Leverage the State and Local Cybersecurity Grant Program while funding lasts, state-shared SOC services, and free federal services.
Free resources. MS-ISAC, free for SLTT, with 24/7 SOC support and incident response assistance; CISA Cyber Hygiene, regional advisors, and the free tools catalog; free .gov domains; tabletop packages.
D15. Critical infrastructure
Top risks. State-sponsored pre-positioning in OT using living-off-the-land techniques, which remains the headline concern in CISA advisories. Ransomware with cascading physical impact. Edge and VPN appliance exploitation — the UK NCSC's top 2025 incident drivers were Ivanti, FortiManager, and SharePoint vulnerabilities. Small utilities, especially water systems, with minimal staff.
Priority controls. CPG 2.0 in full, since it was designed for exactly this audience with ratings to sequence work. OT asset inventory and segmentation. Remove OT from the public internet — this remains the single most consequential finding in water-sector advisories. MFA on all remote OT access. CIRCIA readiness for 72-hour incident and 24-hour ransom-payment reporting once the final rule is effective. Manual-operations drills. Vendor remote-access governance. Sector ISAC membership and KEV-driven patching.
Budget and staffing. Varies enormously: investor-owned utilities run full SOCs while small municipal water systems may have a single operator. The CPGs exist precisely to give the resource-poor end a prioritized minimum.
Free resources. CISA Cyber Hygiene plus free regional Cybersecurity Advisors and Protective Security Advisors, the EPA/CISA water-system scanning program, WaterISAC and E-ISAC, free OT tabletop scenarios, and the Shields Up guidance page for heightened-threat postures.
A single comparison table for the site
| Organization | Top-priority control | Realistic annual budget | Staffing | Biggest free resource |
|---|---|---|---|---|
| Individual | MFA on email; credit freeze | $0–$300 | None | CISA Secure Our World |
| Family | Callback rule for money requests | <$150 | None | NCMEC, Quad9 |
| Freelancer | Separated business email with MFA | $200–$600 | Self | GCA toolkit |
| Small business | MFA plus tested backups | $10K–$30K | MSP | CISA Cyber Hygiene |
| Startup | SSO/MFA and secrets management | $250K–$500K | 1 hire at 50–100 staff | Cloud free tiers |
| School (K-12) | Staff MFA plus tested backups | Constrained | Tech director | MS-ISAC (free) |
| Nonprofit | MFA plus DMARC | <$10K | Volunteer/donated | GCA Mission-Based Toolkit |
| Healthcare | Downtime procedures drilled | $15K–$50K (small); 4–7% IT (hospital) | MSP → CISO team | HHS 405(d), Health-ISAC |
| Financial | Phishing-resistant MFA plus 24/7 monitoring | >10% of IT | 5–20+ | FS-ISAC |
| SaaS | Customer-facing incident SLAs | Embedded | 1 hire at 50–100 | OWASP ASVS |
| E-commerce | PCI script-integrity controls | $2K–$10K (small) | Platform/MSP | PCI SSC resources |
| Manufacturer | IT/OT segmentation | 3–7% of IT | MDR plus integrator | CISA ICS advisories |
| Enterprise | Identity-first zero trust | 6–14% of IT | 1 per 100–250 staff | MITRE ATT&CK, ISACs |
| Government (SLTT) | CPG 2.0 plus MFA | Grant-dependent | Often zero | MS-ISAC (free) |
| Critical infrastructure | OT off the internet | Highly variable | Variable | CISA advisors (free) |