The Cyber Defense Matrix, A Book Summary
Cyber Defense Matrix by Sounil Yu
Executive Summary (For General Audiences)
I read this book around 2022 so that I could really understand how the Cybersecurity Framework benefits the company I was working at. We were all about the NIST 800-53 and I personally felt going to the CSF was a step down. I should have been thinking, what if we still did the 800-53 but presented as the CSF.
Imagine trying to keep a large building secure. You have physical items to protect (doors, windows, keycards, sensitive documents, and the people inside). You also have different tasks to perform (putting locks on doors, installing security cameras, hiring security guards, and knowing what to do if an alarm goes off). If you do not organize these pieces, it is easy to spend money on extra cameras while forgetting to lock the back door.
In Cyber Defense Matrix: The Essential Guide to Navigating the Cybersecurity Landscape, author Sounil Yu provides a simple 5×5 grid (like a bingo card or a spreadsheet) to help business leaders organize their security efforts. The grid places the things you need to protect on one side, and the tasks you need to carry out across the top.
WHAT YOU DO (Functions)
Identify Protect Detect Respond Recover
+----------+---------+--------+---------+---------+
Devices | | | | | |
WHAT Applications | | | | | |
YOU Networks | | | | | |
HAVE Data | | | | | |
Users | | | | | |
+----------+---------+--------+---------+---------+
The Plain-English Takeaway
The key value of this book is not found in complex technical code or computer jargon, but in operational common sense:
- Left Side (Automation): Early tasks (like finding equipment or setting up passwords) rely heavily on software tools and automation.
- Right Side (Human Action): Later tasks (like responding to a break-in or restoring business operations after a crisis) rely heavily on trained people and clear decision-making.
- The Middle (Process): Step-by-step procedures bridge the gap between automated software and human action.
Even as computer technology changes, this basic balance between technology, people, and processes remains constant. The book gives non-technical leaders a straightforward visual chart to see where their organization is well-protected, where money is being wasted on duplicate software, and where human training has been neglected.
1. Formal Overview & Purpose
Sounil Yu’s Cyber Defense Matrix addresses a structural problem in modern information security: overwhelming complexity. Rather than introducing another complex technology or specialized terminology, Yu presents a lightweight visual framework designed to organize, measure, and communicate security capabilities. Intersecting fundamental asset types with core security functions provides security leaders and executive stakeholders with a unified visual tool for portfolio organization, gap analysis, and resource planning.
2. Core Framework & Structure
The Cyber Defense Matrix (CDM) plots five critical asset types along the vertical axis against the primary operational functions of security along the horizontal axis.
- Asset Classes (Y-Axis): Devices, Applications, Networks, Data, and Users.
- Core Functions (X-Axis): Identify, Protect, Detect, Respond, and Recover (derived from the original NIST Cybersecurity Framework version 1.1).
This intersection creates a 25-cell matrix where specific security controls, software products, and operational responsibilities reside.
| Asset Class | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Devices | |||||
| Applications | |||||
| Networks | |||||
| Data | |||||
| Users |
3. Practical Utility: The Left-to-Right Continuum
A common concern with books based on specific industry frameworks is that their guidance becomes outdated when standard frameworks are revised. The Cyber Defense Matrix relies on the five functions established in NIST CSF 1.1. However, the model retains its practical value because its main contribution is visual organization rather than strict compliance rules.
The matrix demonstrates an operational continuum moving from left to right across the core functions:
- Technology Heavy (Left Side – Identify & Protect): Tasks on the far left depend primarily on automated technology (e.g., automated equipment discovery, network firewalls, baseline system configurations).
- People Heavy (Right Side – Respond & Recover): Moving to the right, software automation reaches its limits. These functions depend on human expertise, critical thinking, crisis leadership, and business management.
- Process Throughout: Operational procedures run across the entire matrix, connecting software tools on the left to human actions on the right.
[ TECHNOLOGY ] ————————————> [ PEOPLE ]
<—————————— [ PROCESS ] ——————————>
Regardless of how compliance standards evolve, this left-to-right shift remains structurally sound. Organizations that invest exclusively in automated software on the left while failing to train personnel on the right struggle during real-world operational disruptions. The matrix makes this operational reality immediately visible to leadership and oversight boards without requiring technical expertise.
4. Analysis: Integrating “Govern” into the Matrix
When standard cybersecurity frameworks evolve, new categories are sometimes added. For instance, updated industry standards (such as NIST CSF 2.0) introduced Govern as an overarching function focused on strategy, policy, and oversight. Because Yu’s book relies on the 5-column model, fitting a governance function into the matrix requires logical positioning.
Three structural approaches exist for integrating governance into the CDM:
Option A: The Overlay / “Z-Axis” Approach (Most Logical Alignment)
- Structure: Rather than adding a 6th column, Govern functions as an overarching layer sitting above the 5×5 grid.
- Rationale: Governance (business policy, risk tolerance, executive oversight, regulatory compliance) does not belong to a single asset class or functional phase. It sets the direction for all 25 cells. Treating governance as a top-level overlay reflects its role as the administrative oversight plane across technology, people, and process.
Option B: Column 0 (Pre-Identify)
- Structure: Placing Govern to the left of Identify.
- Rationale: Policy creation precedes daily operations. An organization must define its risk acceptance and business goals before it can inventory assets or purchase technical controls.
Option C: The Foundation Frame
- Structure: Govern acts as the outer boundary supporting the entire grid.
- Rationale: Institutional policies and executive accountability create the operating environment within which software tools operate and personnel execute response plans.
5. Summary of Strategic Value
- Identifying Coverage Gaps: Helps leaders map software tools into specific grid cells to uncover redundant software spending and unaddressed vulnerabilities.
- Clear Operational Roles: Simplifies ownership responsibilities across external service providers and internal teams.
- Executive Communication: Provides a clear, non-technical visual summary to present security priorities, budget requests, and operational balance to senior leadership.
6. Conclusion
Sounil Yu’s Cyber Defense Matrix provides a durable conceptual framework for managing security operations. By organizing complex activities into an accessible grid and highlighting the transition from automated technology to human execution, the book offers a clear mental model that remains practical regardless of ongoing changes in underlying technical standards.
