Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

LevelBlue Releases Updated 11 Essential Cybersecurity Controls, Now Built on More Than 9,000 Incident Response Investigations

Dallas, TX  September 9, 2026 –  LevelBlue, the world's largest pure-play managed security services provider, today released an updated edition of its 11 Essential Cybersecurity Controls, a practical, field-tested framework built on frontline experience from more than 9,000 incident response investigations.

Developed and validated by LevelBlue’s global experts in Digital Forensics and Incident Response (DFIR), cyber advisory, and security testing, this year’s edition incorporates the latest case data and new guidance on how artificial intelligence is reshaping both sides of the attack lifecycle.

The 11 Essential Cybersecurity Controls translate lessons from thousands of real-world investigations into the actions that most consistently reduce attack surfaces, strengthen detection and response, limit the impact of incidents, and build lasting cyber resilience. For each control, LevelBlue’s DFIR experts identify common implementation pitfalls and provide a “DFIR Perspective” explaining what effective implementation looks like during an actual incident, whether it results in faster recovery, a smaller blast radius, or an attacker being stopped before significant damage occurs.

The controls are also mapped to established standards, including CIS Controls v8.1, NIST Cybersecurity Framework 2.0, and NIST SP 800-171 Rev. 2. This helps security and risk leaders prioritize investments based not only on audit requirements, but also on the measures proven to reduce risk during real-world attacks.

“Plenty of organizations pass their audits and still get compromised," said Devon Ackerman, Global Services Leader, DFIR, at LevelBlue. "The controls that satisfy a framework and the controls that actually stop an attacker are not always the same. After leading and overseeing thousands of cyber investigations worldwide, I have seen firsthand which defenses work and which ones are routinely defeated. The 11 Essential Cybersecurity Controls distill those hard-earned lessons into clear, prioritized actions that any organization can take to meaningfully reduce their risk."

The updated edition also examines the growing role of AI in the threat landscape. Attackers are using AI to create more convincing phishing lures, identify exploitable vulnerabilities faster, and operate at a scale that once required an entire team. These capabilities do not diminish the importance of the 11 controls. Instead, they raise the cost of implementing them poorly. As the window between exposure and exploitation continues to shrink, getting the fundamentals right matters more than ever.

The release reinforces LevelBlue’s commitment to equipping organizations with the expertise, guidance, and capabilities needed to stay ahead of adversaries and build lasting resilience. By combining incident response expertise with EDR and XDR technology, managed detection and response, and AI-powered security operations, LevelBlue helps organizations strengthen defenses, improve compliance alignment, and respond more effectively when incidents occur.

The 11 controls covered in this year's update are:

  1. Phishing-resistant multi-factor authentication (MFA)
  2. Endpoint detection and response (EDR) deployment
  3. Privileged access management (PAM)
  4. Centralized logging and log retention through a SIEM or equivalent platform
  5. Regular patching and vulnerability management
  6. Email security filtering and phishing protection
  7. Asset inventory and visibility across IT, OT, and cloud environments
  8. Network segmentation and access controls
  9. Incident response plans and tabletop exercises
  10.  Data classification and structured data management
  11.  Offline, segmented, and tested backups with recovery time objective validation

Read the full 11 Essential Cybersecurity Controls report here or schedule a 1:1 session with a LevelBlue expert to benchmark your security program against the essential controls at https://www.levelblue.com/services/incident-readiness-and-response.

 

About LevelBlue

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world's most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.