I recently read a LinkedIn post discussing the usefulness or lack thereof regarding the use frameworks in developing your cybersecurity roadmap. The author discussed implementing controls that they felt were going to give the organization the best cost to benefit ratio, but the author never really discussed what they did to come up with what those missing controls nor what risks they were mitigating through implementing them. Now I certainly agree there are some controls which will give you a much bigger bang for your buck, like multifactor authentication, endpoint detection and response or additional network segmentation. All three of those controls will certainly reduce your risk more than some of the policies and procedures that any cyber framework will recommend you implement, but does that mean you shouldn’t implement these policies and procedures?