CIS
Put the CIS Critical Security Controls and CIS Benchmarks to work in your organisation. A prioritised plan, hardened systems and evidence you can reuse across audits.
Service Details
The CIS Controls give you a prioritised list of what to fix first, and Falx turns that list into a working plan for your organisation. You get a gap analysis against the 18 Controls, hardened systems built to CIS Benchmarks, and evidence you can reuse for Cyber Essentials, ISO 27001 and customer questionnaires.
Instead of guessing where your security budget should go, you work through safeguards in order of impact. You start with essential cyber hygiene and build towards more mature defences as your risk demands. This work sits within our governance services.
INFO
The CIS Controls are voluntary and there is no certification. Their value is a clear, defensible order of work, and evidence that supports the frameworks you do get audited against.
Why CIS works for UK organisations
Most frameworks tell you what good looks like. CIS tells you where to start. The first Implementation Group targets the attacks UK businesses face most: phishing, unpatched software, misconfigured cloud storage and weak credentials.
Because the Controls overlap with Cyber Essentials, ISO 27001 and the NIST Cybersecurity Framework, one programme of work produces evidence for several audits. You stop answering the same questions three different ways.

Who the CIS Controls apply to
The Center for Internet Security (CIS) is a US non-profit, and its Controls are voluntary guidance rather than law. They apply to any organisation in any sector, from a 20-person firm to a large enterprise. No regulator requires them by name, and there is no CIS certificate to hold.
You are most likely to use them if you want a practical baseline without a full certification programme, if customers or cyber insurers ask how you secure your systems, or if you need a technical layer under a management framework such as ISO 27001.
What the CIS Controls require
Version 8.1 contains 18 Controls, each broken into specific safeguards. Each safeguard is assigned to one of three Implementation Groups (IG), so you can scope the work to your size and risk:
- IG1, essential cyber hygiene — The baseline every organisation should meet, suited to smaller teams with limited security expertise.
- IG2 — Adds safeguards for organisations that handle sensitive data or run more complex IT.
- IG3 — The full set, for mature security functions facing targeted attacks.
In plain English, the 18 Controls cover knowing what hardware, software and data you have; configuring systems securely; managing accounts and access; finding and fixing vulnerabilities; keeping audit logs; protecting email, browsers and networks; defending against malware; backing up and recovering data; training staff; managing service providers; securing the software you build; responding to incidents; and testing your defences with penetration tests.
CIS Benchmarks vs CIS Controls
CIS Benchmarks
Detailed, platform-specific configuration settings for operating systems, cloud platforms, databases and network devices.
Applying a Benchmark gives you a hardened build and direct evidence for the secure configuration control.
CIS Controls
Eighteen prioritised controls in three Implementation Groups, setting what your organisation should achieve and in which order.
How Falx helps you implement CIS
Gap Analysis & Roadmap
We assess your estate against the Controls, agree your target Implementation Group and give you a prioritised roadmap with an owner for every gap.
Remediation & Hardening
We work alongside your internal team to close gaps, applying CIS Benchmarks to servers, endpoints and cloud services so systems are secure by default.
Evidence & Ongoing Assurance
We map each control to the other frameworks you answer to and keep the evidence current, so audits and questionnaires draw on one source.
What CIS implementation gives you
A prioritised programme rather than a vague maturity score. Every control is scoped to your estate, assigned an owner and tracked until it is live.
System Hardening
Benchmark-aligned builds for your servers, endpoints and cloud services, so every system ships secure by default.
Data Breach Prevention
Inventory, access control and monitoring that stop personal and card data leaking before it becomes a report to the ICO.
Log Monitoring
Centralised logging and alerting in line with Control 8, so suspicious activity is spotted and investigated quickly.
Vulnerability Management
Continuous scanning and patching that prioritises the weaknesses attackers exploit, not just what scanners flag.
Access Control
Least privilege, multi-factor authentication and privileged access reviews that give auditors clear evidence.
One set of evidence for every audit
CIS gives you the technical controls. Most organisations also answer to a certification, a regulator or a customer contract. We map each control to those requirements, so one piece of evidence serves several purposes.
You get a single view of your security posture, and fewer duplicated requests landing on your team every time an audit or questionnaire arrives.

CIS Controls implemented, not aspired to
We implemented the CIS controls for access, devices and accounts across more than 200 identities and devices. Rogue authentication attempts were eliminated and every endpoint is now managed. The result is a mapped, evidenced baseline rather than a spreadsheet of intentions.
Related frameworks and services
CIS often sits underneath another framework. Cyber Essentials is the natural UK certification for IG1 work, ISO 27001 adds the management system, and our NIST service covers the Cybersecurity Framework. If you handle card payments, see PCI DSS. Regulated firms should also look at NIS2, DORA, FCA requirements and UK GDPR. Comparing regimes? Read our NIS2, NIST, CIS and DORA comparison for financial services.
For the hands-on work, security posture reviews and risk management shape your roadmap, identity and access covers the account and access controls, and penetration testing meets Control 18. Our compliance support team pulls the evidence together, as part of our wider compliance programme.
We apply CIS across sectors including financial services, insurance, manufacturing, retail and not-for-profit organisations.
Frequently asked questions
Find out where you stand against CIS
Tell us about your estate and what your customers or insurers are asking for. You get a clear view of your Implementation Group, your biggest gaps and what to fix first.