The CIS Critical Security Controls are a prioritized, prescriptive set of security safeguards maintained by the Center for Internet Security, designed to stop the most common attacks first. Where NIST CSF says what to think about, CIS says what to do, in order.
Key facts:
- Version 8.1 organizes 18 controls into safeguards, tiered by Implementation Groups (IG1 to IG3) so small organizations start with the essential subset.
- IG1 is positioned as "essential cyber hygiene", a floor every organization should reach.
- The controls map to NIST CSF and ISO 27001, making them a practical implementation layer under either.
The controls that run through email
Several controls hit the mailbox directly: email and web browser protections (an entire control of its own), malware defenses, account management (what phished credentials unlock), data protection (where sensitive data actually flows, including to unsanctioned apps), and incident response management. The email-and-browser control exists because that pair is how commodity attacks arrive, and phishing is the top vector the safeguards list addresses.
Where email security fits, honestly
Sentaro implements the email side of the email/browser protections control and contributes to malware defense, account monitoring and incident response with AI-native detection and OAuth visibility in Google Workspace and Microsoft 365. Asset inventories, configuration hardening, patching and the broader program remain yours. For UK organizations, Cyber Essentials covers similar hygiene ground with lighter formality.
This page is general guidance, not legal advice.