NIST Cybersecurity Framework 2.0, released in February 2024, introduces a sixth core function called Govern. This function establishes organizational leadership—boards, chief executives, general counsel and senior risk officers—as the accountable parties for cybersecurity strategy, risk appetite and resource allocation. Where version 1.1 embedded governance considerations within other functions, CSF 2.0 makes executive accountability explicit and primary.
For boards and executive leadership across regulated sectors, this change creates both clarity and obligation. The Govern function defines what organizational leadership is responsible for, separate from what IT or security operations execute. It answers the question: who owns the cybersecurity outcome?
What the Govern Function Establishes
According to NIST's published materials, the Govern function addresses the organizational context, strategic direction, expectations and policies that inform how cybersecurity risk will be managed. It sits above the other five functions—Identify, Protect, Detect, Respond and Recover—as the decision-making layer that determines priorities, acceptable risk levels and accountability structures.
The Govern function does not describe technical controls or incident response procedures. It describes the leadership decisions that determine which controls matter, how much to invest, what risks to accept and who carries authority when those decisions conflict with other business priorities.
This elevation of governance reflects a decade of regulatory enforcement, breach litigation and board-level scrutiny. Leadership cannot delegate accountability for an outcome while remaining uninformed about the decisions that shape it. The Govern function formalizes that principle in a framework used across industries and regulatory regimes.
How This Differs From CSF 1.1
CSF 1.1 included governance activities within the Identify function, alongside asset management and risk assessment. That structure implied governance was preparatory work, a precursor to implementing controls. In practice, it allowed governance to become a checkbox exercise completed by security teams rather than a continuous leadership responsibility.
CSF 2.0 makes Govern a separate, equal function because governance is not preparation for cybersecurity—it is the ongoing authority that directs it. Leadership sets strategy, defines risk appetite, allocates resources, establishes accountability and monitors performance. Those activities do not happen once; they operate continuously as the business and threat environment change.
For boards and executives, this structural change means cybersecurity governance is no longer something the IT department handles. It is a board and C-suite responsibility, analogous to financial controls or legal compliance, where leadership remains accountable even when execution is delegated.
Why This Matters to the Business
Regulators, insurers and counterparties increasingly expect boards and executives to demonstrate informed oversight of cybersecurity risk. The FTC, state attorneys general, banking regulators and securities regulators have all pursued enforcement actions where leadership failed to establish adequate governance over data protection and cyber risk management.
When a material breach occurs, the question is no longer whether the firewall was configured correctly. The questions are: Did the board understand the risk? Did leadership allocate sufficient resources? Were accountability and escalation paths clear? Did the organization have a strategy, or only a collection of tools?
The Govern function provides a common language for answering those questions. It defines what adequate governance looks like: clear roles, documented risk decisions, regular reporting to leadership, integration with enterprise risk management, and a cybersecurity strategy that aligns with business objectives. Organizations that cannot demonstrate those elements face regulatory exposure, insurance exclusions and reputational consequences that extend beyond the immediate cost of a breach.
What Adequate Ownership Looks Like
Adequate ownership of cybersecurity governance requires a named executive with the authority to make risk decisions, the access to report directly to the board, and the resources to translate strategy into execution. This is not a technical role. It is a strategic leadership function that connects cyber risk to business risk.
In larger organizations, this role is typically a Chief Information Security Officer (CISO) who reports to the CEO, board or a risk committee—not to the CIO or IT leadership. In smaller or mid-sized organizations, the same function may be performed by a general counsel, chief risk officer or external advisor, provided they have direct access to decision-makers and the mandate to act on cybersecurity governance.
The common failure is treating cybersecurity as an IT problem that leadership monitors from a distance. When governance is delegated to technical staff without executive participation, the result is reactive spending, misaligned priorities and no clear owner when something goes wrong. The Govern function makes explicit that leadership cannot remain at arm's length.
The Connection to Cyber Risk Management
Cyber risk management is the process of identifying, assessing, treating and monitoring risks to information and systems. The Govern function establishes who makes those risk decisions and how they integrate with the organization's broader risk management framework.
Without governance, cyber risk management becomes a technical exercise that produces reports no one acts on. With governance, cyber risk management becomes a decision-making process where leadership evaluates trade-offs, accepts or mitigates specific risks, and adjusts the approach as the business changes. The Govern function provides the structure for that decision-making process to occur at the right level, with the right authority.
For regulated organizations, this integration is not optional. Regulatory expectations—whether from banking supervisors, health information privacy rules, or FTC enforcement—increasingly require that cyber risk be managed within the same governance structures as financial, operational and legal risk. The Govern function aligns CSF 2.0 with that regulatory reality.
What Leadership Should Do
First, confirm that someone with the authority to act owns cybersecurity governance in your organization. If no one can articulate your cybersecurity strategy, your risk appetite or your accountability structure, you have a governance gap, not a technical one.
Second, establish how cyber risk reporting reaches the board and executive leadership. Effective governance requires regular, structured reporting that presents risks in business terms, highlights decisions that require leadership input, and tracks progress against strategic objectives. If your board receives only technical status updates or compliance checklists, the reporting does not serve a governance function.
Third, document your risk decisions. When you choose to accept a risk, defer an investment or prioritize one control over another, record the rationale and the decision-maker. This documentation is not ceremonial. It demonstrates informed oversight, establishes accountability and provides the evidence regulators and insurers will request if something goes wrong.
Fourth, integrate cybersecurity governance into your enterprise risk management process. Cyber risk should be evaluated using the same frameworks, reporting structures and escalation paths as other material risks to the business. The Govern function provides the structure for that integration; leadership must ensure it happens in practice.
When Executive Leadership Is Missing
Many organizations lack the internal capacity to fulfill the Govern function adequately. A full-time CISO may not be economically viable or strategically necessary. The general counsel or CFO may lack the cybersecurity-specific expertise to translate regulatory expectations into operational decisions. IT leadership may lack the business perspective or organizational authority to own governance.
This is the gap that [virtual CISO (vCISO) leadership](/vciso/) addresses. A vCISO provides the executive-level cybersecurity governance that the Govern function defines: strategy development, risk decision-making, board reporting, regulatory interpretation and accountability oversight. The role is strategic, not operational. It exists to give boards and executives the informed ownership they are accountable for, without requiring a full-time executive hire.
Heights provides vCISO leadership to organizations that need governance clarity, regulatory confidence and strategic direction, but do not need to build an internal security department. The service is structured to close the governance gap that CSF 2.0 makes explicit.
Next Steps
If your organization lacks clear ownership of cybersecurity governance, or if your board and executive leadership are uncertain about their accountability under the new framework, the appropriate next step is to evaluate how the Govern function applies to your specific regulatory and risk environment.
Heights offers a confidential consultation for boards and executive leadership who want to understand their governance obligations, assess their current accountability structure and determine what adequate ownership looks like for their organization. The consultation is a single conversation, without obligation, designed to clarify the governance gap and the options for closing it.
Contact Heights to schedule that conversation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Cyber Risk Management
One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.