To defend against these threats and reduce risk, organizations implement security controls—measures that prevent, detect, respond to, or recover from cybersecurity incidents. These controls can be grouped by type (what they do) and category (how they are applied). Understanding these distinctions is key to building a layered and comprehensive security strategy.
A company should be witty enough to identify which part of their cybersecurity posture needs to be enhanced. This is achieved via what is called a gap analysis.