What Is CIS? Understanding the Center for Internet Security

An explainer on the Center for Internet Security, the 18 CIS Controls, and what a CIS Benchmark Assessment actually tells a South African business about its own environment.

In this video

  • What the Center for Internet Security is, and why South African insurers and auditors keep referring to it
  • The difference between CIS Benchmarks (prescriptive settings for a specific technology) and the 18 CIS Controls (prioritised safeguards at an organisational level)
  • Implementation Groups IG1, IG2 and IG3 — and why IG1 is the realistic baseline for most South African SMEs
  • Why "we have antivirus and a firewall" no longer satisfies a cyber insurance questionnaire
  • What ROI Technologies hands over at the end of an assessment

Why this matters commercially

South African cyber insurance has hardened considerably. Brokers and underwriters increasingly ask for evidence rather than assurances: MFA enforced across every user including administrators and service accounts, limits on the number of Domain Admin accounts, EDR deployed on servers and workstations, tested backups that are offline or immutable, and a documented security baseline.

A benchmark report answers those questions with a pass or fail against each control, rather than an opinion. That is the difference between a renewal conversation and a renewal argument.

Configuration, not products

The line that sums up the video: attackers don't break in, they log in. And they log in through misconfigurations rather than through the products themselves. A firewall left with its management interface reachable from the internet, an Active Directory with weak password policy, a Microsoft 365 tenant still permitting legacy authentication — in each case the product is present and working as designed.

Frequently asked questions

Is CIS a certification?

No. CIS publishes consensus-developed benchmarks and controls; there is no CIS certificate issued to a business. What an assessment produces is evidence of alignment — a pass or fail position against each benchmark, plus a remediation roadmap.

What is the difference between CIS Benchmarks and the CIS Controls?

Benchmarks are technology-specific configuration settings — set this value, on this platform. The Controls are 18 prioritised safeguards describing what an organisation should be doing. Benchmarks are how several of the Controls get implemented in practice.

Which platforms do CIS Benchmarks cover?

Microsoft 365 and Azure Active Directory, Windows Server and Windows 10/11, Active Directory Domain Services, SQL Server, FortiGate and Sophos firewalls, plus common Linux distributions and web servers.

See how your environment measures up

A CIS Assessment gives you an evidence-based picture of your security configuration — and something concrete to show your insurer, your board or your auditors.

Contact Us

More videos