A First Look at Governments' Enterprise Security Guidance
Kimberly Ruth (PhD student · Stanford)
34th USENIX Security Symposium (USENIX Security '25) · Day 1 · Social Issues and Usable Security and Privacy
Overview
In an increasingly complex and interconnected digital landscape, organizations of all sizes frequently seek authoritative guidance on best practices for cybersecurity. Governments, often perceived as impartial and reliable sources, have stepped into this critical role, with agencies like the US's Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) publishing extensive resources. This talk, presented by Kimberly Ruth, a PhD student at Stanford, delves into a comprehensive analysis of this governmental enterprise security guidance, examining its scope, content, and consistency across nations.

Key moments
- 0:00 Introduction and key research questions
- 2:00 Governments publish massive volumes of security guidance
- 3:20 Surprising diversity in targeted security guidance scopes
- 4:50 Methodology for selecting documents for deep analysis
- 6:00 Introducing the hierarchical content analysis framework
A First Look at Governments' Enterprise Security Guidance
Speakers: Kimberly Ruth, PhD student at Stanford
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=iiCqlHQeBeg
Overview
In an increasingly complex and interconnected digital landscape, organizations of all sizes frequently seek authoritative guidance on best practices for cybersecurity. Governments, often perceived as impartial and reliable sources, have stepped into this critical role, with agencies like the US's Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) publishing extensive resources. This talk, presented by Kimberly Ruth, a PhD student at Stanford, delves into a comprehensive analysis of this governmental enterprise security guidance, examining its scope, content, and consistency across nations.
The research, a collaborative effort with colleagues from Stanford, Chicago, and FSAC, addresses fundamental questions about the nature of this advice: Which governments provide it, how is it structured, what specific content do they cover, and crucially, do they agree? The study reveals a vast, heterogeneous, and often contradictory ecosystem of recommendations. Understanding these disparities is vital because this guidance is uniquely positioned to influence the security posture of countless organizations worldwide, yet its effectiveness and coherence have largely remained unexamined.
The findings challenge the assumption of a unified, evidence-based approach to government security recommendations. Instead, the research highlights a significant lack of consensus on what constitutes "essential" security controls, even among close allies. This inconsistency poses substantial challenges for practitioners attempting to navigate the overwhelming volume of advice, raising critical questions about the efficacy of current guidance formulation strategies and underscoring the urgent need for a more scientific, evidence-driven foundation for improving organizational security.
Background
▶ Watch: Introduction and key research questions (0:00)
The premise for this research lies in the critical need for companies to establish robust cybersecurity defenses in the face of persistent and evolving threats. In their quest for guidance, businesses often look to governmental bodies, which are generally regarded as trustworthy, impartial, and well-informed entities capable of distilling complex security principles into actionable advice. Agencies like CISA in the United States, known for initiatives such as the Cybersecurity Performance Goals (CPGs), and the NCSC in the United Kingdom, are prominent examples of national entities dedicated to this mission. These organizations invest significant resources into publishing a wide array of documents, frameworks, and advisories aimed at helping enterprises enhance their security posture.
Historically, the development of cybersecurity standards and best practices has often involved a degree of international collaboration and the adoption of common frameworks, such as NIST Special Publication 800-53 or ISO 27001. These frameworks provide a structured approach to managing information security risks and are widely used by organizations globally. However, the specific, actionable guidance issued by individual national governments to their domestic industries, particularly what they deem "essential" for all companies, has not been systematically analyzed on a global scale. This gap in understanding is significant because, while general frameworks exist, the granular recommendations from governments often translate directly into policy, compliance requirements, and operational priorities for businesses.
The problem arises from the sheer volume and potential for fragmentation within this guidance ecosystem. Companies are faced with a "buffet" of information, often from multiple agencies within a single country, let alone across international borders. Without a clear understanding of what these diverse sources are actually recommending, and whether those recommendations align or conflict, organizations risk misallocating resources, overlooking critical vulnerabilities, or even implementing contradictory security measures. The research thus aimed to fill this void by providing a systematic, data-driven analysis of this crucial but underexplored aspect of global cybersecurity.
Key Findings
▶ Watch: Governments publish massive volumes of security guidance (2:00)
The research uncovered a series of compelling findings that shed light on the state of government-issued enterprise security guidance. The initial phase of the study involved a comprehensive search across 41 high-profile countries, focusing on nations prominent in security, technological development, and population. The team systematically traversed government agency websites, specifically looking for documents advising companies on security improvements.
One of the most striking findings was the sheer volume and heterogeneity of the guidance ecosystem. Every country examined, with the sole exception of Russia (which was noted for geoblocking western search efforts), had publicly posted security guidance. Many countries published dozens of resources, typically from two to five different agencies or ministries. The United States notably outflanked all other nations, offering 18 general-purpose resources from four agencies (CISA, NSA, FBI, NIST), with the total tally rising to 36 separate US agencies releasing security guidance when targeted documents were included. This volume underscores the significant investment governments make in this area.
The guidance was classified into two main categories: audience-focused and threat-focused. Audience-focused documents targeted specific sectors (e.g., telecoms, critical infrastructure, legal firms, esports, and even "computer-controlled chicken coops" from Israel) or technologies (e.g., cloud, network systems, dash cams from Malaysia, hearing aids from Norway). Threat-focused documents, by contrast, addressed specific attack types (e.g., Distributed Denial of Service (DOS), ransomware, "malicious ebooks" from Lithuania) or defense mechanisms (e.g., incident response plans, Identity and Access Management (IAM)). Nearly all countries also released timely advisories for new malware strains or CVEs (Common Vulnerabilities and Exposures). This vast and diverse landscape presents a significant challenge for companies trying to discern genuinely "essential" advice.
To conduct an in-depth, "apples-to-apples" comparison, the researchers narrowed their focus to a subset of 33 "general purpose" documents from 28 countries that specifically presented themselves as covering "essential" or "basic" security principles for all companies. From this, a sample of 10 documents was selected to ensure maximal geographic distribution and representation of varying document lengths.
The core analysis revealed a profound lack of consensus on what constitutes essential security content. Using a five-layer hierarchical content analysis framework (Theme, Sub-theme, Control, Implementation Detail Category, Specific Detail), the researchers mapped the content of these documents. At the highest level, only three themes appeared in every single document: Business Continuity and Disaster Recovery, Vulnerability and Patch Management, and Identity and Access Management. Other seemingly crucial themes, such as cloud security, security training, web and browser security, and third-party management, appeared in only about half of the documents.
Drilling down to individual controls, the disagreement became even more stark. Only two controls achieved unanimous recommendation across all 10 countries: creating backups and patching systems. Multifactor Authentication (MFA) was nearly unanimous, recommended by all countries except India and Ukraine. Beyond these few, the vast majority of controls formed a "long tail" of recommendations. Only 3% of controls were recommended by at least three-quarters of the countries, with over a third of all controls falling into a middle ground where countries showed neither strong consensus for nor against their inclusion. This long tail included highly specific or unique recommendations, ranging from Israel's advice not to disclose organizational details externally unless needed, to Australia's guidance to annually validate Microsoft Office's list of trusted publishers, and even the US's recommendation to sponsor "at least one pizza party per year" to strengthen IT and OT security team relationships.
Perhaps the most critical finding was the presence of inconsistent and directly contradictory advice. Beyond simply differing on whether to include a control, countries often varied dramatically in the level of detail provided. For instance, Egypt advised updating periodically without specifying an interval, while Australia set concrete targets like patching browsers and email clients within two weeks. More alarmingly, direct contradictions emerged: Norway, Australia, and India offered differing advice on acceptable software versions (latest, latest or previous, latest stable, respectively). Most notably, Ukraine specified traditional password complexity requirements, while the UK explicitly rejected this, advocating for a three random words strategy. These two approaches are fundamentally incompatible.
Even among close allies, such as the Five Eyes Alliance (US, UK, Australia), the agreement was surprisingly low, with only 13% of their deemed "essential" controls being common to all three. For example, the UK alone addressed network segmentation, Australia alone mentioned asset discovery, and the US alone discussed DNS-based email protocols like SPF, DKIM, and DMARC. This pervasive disagreement suggests that the current consensus-driven approach to formulating guidance is not effectively harmonizing recommendations, leaving practitioners in a difficult position.
Technical Deep Dive
▶ Watch: Surprising diversity in targeted security guidance scopes (3:20)
The methodology employed in this research was rigorous and systematic, aiming to provide a principled analysis of a vast and unstructured data landscape. The first step involved identifying relevant documents. The researchers focused on 41 countries globally, chosen for their prominence in security, technological development, and/or population size. For each country, data from the United Nations was used to identify government agencies involved in cybersecurity strategy or policy. This was supplemented with extensive web searches to ensure comprehensive coverage. Each identified agency's website was then manually traversed to locate any published guidance resources intended for companies to improve their security. This meticulous manual process was crucial given the varied presentation of such information across different national government portals.
Once the corpus of documents was collected, a classification system was developed to categorize the scope of the guidance. This system divided documents into audience-focused and threat-focused categories. Audience-focused documents were further broken down by specific sectors (e.g., critical infrastructure, telecoms, legal firms, small and medium-sized businesses (SMBs)) or technologies (e.g., cloud computing, network systems, mobile devices, specific Internet of Things (IoT) devices like dash cams or hearing aids). Threat-focused documents, conversely, concentrated on particular attack vectors (e.g., Distributed Denial of Service (DDoS), ransomware, phishing) or specific defensive measures (e.g., incident response planning, Identity and Access Management (IAM)). Additionally, a category for timely advisories (e.g., alerts on new malware strains, CVEs) was included, recognizing their prevalence.
For the in-depth content analysis, the researchers selected a subset of documents to ensure an "apples-to-apples" comparison. This involved first identifying 33 general-purpose documents from 28 countries that explicitly positioned themselves as covering "security essentials" or "basics" for all companies, as opposed to comprehensive catalogs of all possible controls. From this set, 10 documents were chosen for the deep dive, ensuring a maximally broad geographic distribution and representation of the full spectrum of document lengths observed in the data. This sampling strategy minimized bias towards any particular region or document style.
The core of the technical analysis relied on a novel hierarchical content analysis framework. Recognizing that existing industry common controls frameworks (like NIST 800-53 or ISO 27001) provided a strong starting point but lacked the granular structure needed for this comparative study, the researchers adapted these using qualitative methods techniques. The resulting framework was a five-layer taxonomy designed to capture varying levels of abstraction in the guidance content:
- Theme: The highest level, grouping broad, related security concepts (e.g., Business Continuity, Vulnerability Management, Identity and Access Management).
- Sub-theme: More focused groups of controls within a theme, centered on a common goal (e.g., within Vulnerability Management, sub-themes included "Scanning for Vulnerabilities" and "Patching Vulnerabilities").
- Control: Distinct security countermeasures or practices within a given sub-theme (e.g., "Prioritizing vulnerabilities to patch" versus "Operationalizing the patch").
- Implementation Detail Category: This layer captured whether a control's description addressed specific categories of implementation guidance, essentially the "what, where, when, who, and how" of achieving the control objective.
- Specific Detail: The most granular layer, describing the concrete details themselves (e.g., "patching weekly" versus "patching within 24 hours").
To populate this framework, the content of each of the 10 selected guidance documents was analyzed using a combination of deductive and open coding techniques from qualitative analysis. Deductive coding applied pre-defined categories from the framework, while open coding allowed for the emergence of new themes, sub-themes, controls, and details not initially anticipated. This iterative process resulted in a "tree" representation for each document, visually demonstrating its scope, depth, and specificity. For instance, the talk highlighted examples of these trees, using color coding (blue for backups, green for authentication, orange for patching) to illustrate how countries like Ukraine and Israel offered concise guidance, while Singapore provided substantially more, and New Zealand covered a very broad range of content.
The analysis then moved to quantitative comparisons based on these structured trees. By counting the occurrences of themes, sub-themes, and controls across the documents, the researchers could identify areas of consensus and divergence. The "long tail" plot, which illustrated how many controls were included by how many countries, visually underscored the lack of widespread agreement beyond a handful of universal recommendations. The deep dive into specific control details allowed for the identification of not just differences in emphasis, but also direct contradictions, such as the differing advice on password complexity between Ukraine and the UK. This meticulous, multi-layered approach provided a robust foundation for the study's significant findings regarding the fragmented and often inconsistent nature of government security guidance.
Demo / Proof of Concept
▶ Watch: Methodology for selecting documents for deep analysis (4:50)
This particular talk, "A First Look at Governments' Enterprise Security Guidance," is a research presentation focused on an extensive qualitative and quantitative analysis of existing documents, rather than the demonstration of a novel tool, exploit, or a live system. Therefore, a traditional "Demo" or "Proof of Concept" section, in the sense of showcasing functional code, a working exploit, or a security product, does not apply.
Instead, the "demonstration" within the talk involved presenting the results of the research methodology. This included showing examples of the diverse types of government guidance documents found, illustrating the classification system (audience-focused vs. threat-focused documents, including humorous examples like "computer-controlled chicken coops" and "malicious ebooks"). Crucially, the speaker presented visual representations of the "trees" generated by the hierarchical content analysis framework for different countries, allowing the audience to immediately grasp the dramatic differences in scope and depth. The "long tail" plot, which graphically depicted the lack of consensus on specific controls, was also a key visual aid. These visual components served to concretely illustrate the findings and the analytical framework used to derive them, effectively acting as the "proof of concept" for the research itself.
Defensive Implications
▶ Watch: Introducing the hierarchical content analysis framework (6:00)
The findings of this comprehensive study carry significant implications for cybersecurity defenders and organizations striving to enhance their security posture. The pervasive lack of consensus and the presence of direct contradictions in government security guidance present a complex challenge, fundamentally questioning the efficacy of simply following all advice.
Firstly, practitioners cannot blindly adhere to all government guidance. The sheer volume, coupled with the heterogeneity and inconsistencies, makes it practically impossible and potentially counterproductive. Organizations must adopt a critical, analytical approach to evaluating recommendations, recognizing that a "one-size-fits-all" solution is not being offered, even by official sources.
Secondly, the identified lack of consensus on "essential" controls means that organizations bear a significant responsibility for developing their own robust prioritization strategies. Relying solely on a single government's list of "essentials" may lead to critical security gaps if that guidance overlooks controls deemed vital by others. For example, while backups and patching systems are universally recommended and thus non-negotiable foundational controls, organizations must look beyond these to address their unique threat landscape and risk profile, considering controls like network segmentation or asset discovery that may not be universally highlighted.
Thirdly, the existence of direct contradictions, such as those concerning password policies (Ukraine's complexity rules vs. UK's three random words strategy), forces defenders to make informed choices. Instead of assuming all government advice is harmonized, security teams must research current best practices, consult industry standards, and assess their organizational capabilities to select the most appropriate and effective strategy. Implementing conflicting advice could inadvertently weaken security or lead to operational friction.
Fourthly, the "long tail" of unique and sometimes unusual recommendations (e.g., the US's "pizza party" suggestion) highlights the need for resource allocation based on proven security benefits and organizational context. While some unique recommendations might offer niche value, defenders must prioritize controls that address known, high-impact risks and have a clear, measurable security return on investment. This means discerning between genuinely impactful security measures and less critical, or even anecdotal, advice.
Finally, the study underscores a broader need for greater collaboration and an evidence-based approach in developing government guidance. Defenders, through their engagement with industry groups, professional organizations, and direct feedback channels to government agencies, can advocate for more harmonized, scientifically vetted, and practical guidance. Sharing real-world experiences about what security interventions are truly effective in practice can help bridge the gap between academic research, governmental policy, and operational realities, ultimately leading to more actionable and impactful advice for the entire security community. Organizations should view government guidance as one input among many, integrating it with threat intelligence, risk assessments, and industry-specific best practices to forge a resilient and adaptive security posture.
Key Takeaways
- Massive and Heterogeneous Guidance Landscape: Governments worldwide publish an overwhelming volume of enterprise security guidance, which is highly diverse in its scope, target audience, and level of detail, making it challenging for companies to navigate.
- Striking Lack of Consensus on "Essentials": Despite being framed as essential, there is a profound disagreement among nations on fundamental security controls. Only two controls – creating backups and patching systems – are unanimously recommended across all countries analyzed, with Multifactor Authentication (MFA) being nearly universal.
- "Long Tail" of Unique and Varied Recommendations: Beyond the few universally agreed-upon controls, the vast majority of recommendations are part of a "long tail," indicating a significant number of unique, highly specific, or even idiosyncratic suggestions from individual governments.
- Direct Contradictions Impede Implementation: The research uncovered direct contradictions in advice regarding critical implementation details, such as acceptable software versions and password policies (e.g., Ukraine's complexity requirements vs. the UK's three random words strategy), which creates confusion and operational challenges for practitioners.
- Ineffectiveness of Current Guidance Formulation: The pervasive disagreements, even among close allies like the Five Eyes Alliance, suggest that the current consensus-driven approach to developing government security guidance is not producing a coherent or unified message for industry.
- Call for Evidence-Based and Contextual Security: The findings highlight an urgent need for the security community to build a better evidence base for effective interventions and for organizations to critically evaluate and prioritize security controls based on their specific context and risk profile, rather than relying on a universally agreed-upon set of "essentials."
About the Speaker(s)
Kimberly Ruth is a PhD student at Stanford University, specializing in cybersecurity research. Her work, as demonstrated in this talk, focuses on understanding and improving organizational security practices through the analysis of guidance provided by authoritative sources. This particular research was a collaborative effort, conducted jointly with colleagues from Stanford, the University of Chicago, and FSAC, highlighting a multidisciplinary approach to tackling complex problems in cybersecurity. Her academic pursuit emphasizes a scientific and analytical lens to evaluate the effectiveness and coherence of security interventions, aiming to bridge the gap between policy, research, and practical application in the field of enterprise security.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Rigorous empirical work that most practitioners have never thought to do: actually read what governments are telling companies to do, across 41 countries, and measure whether any of it agrees. The finding that Five Eyes allies share only 13% of their 'essential' controls is genuinely embarrassing to the agencies involved and useful to everyone downstream of their guidance.
Heather Calloway (CISO) — STRONG ACCEPT
Rigorous, uncomfortable research that exposes the incoherence of government security guidance at a structural level — not as a complaint, but as an empirical finding. The governance implications are real and underserved by the talk itself, but the underlying work earns its place in front of security leaders.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)