
Threat Talks · 2026-07-07 · 28 min
Ten years after its first release, the NIST Cybersecurity Framework got a full rebuild. Not because it failed, but because everyone started using it, and it was never built for everyone. In this episode, host Lieuwe Jan Koning talks with Amy Mahn, IT Standards Advisor at NIST, and Daniel Eliot, Lead for Small Business Engagement at NIST’s Applied Cybersecurity Division, about what CSF 2.0 actually changes and why it took a multi-year public process to get there. The original framework was written with critical infrastructure operators in mind. A decade later, hospitals, school districts, and small businesses were all using it too, often without the staff or budget the framework quietly assumed they had. NIST collected more than 4,000 comments from organizations across over 100 countries to find out what was missing.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.