NIST IR 8374 Rev. 1: The Ransomware Community Profile, Explained
NIST's ransomware guidance is not a new framework. It is a prioritised slice of the Cybersecurity Framework 2.0, and that is exactly what makes it usable by a leadership team.
What the document is
NIST Internal Report 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile, was finalised in June 2026. It replaces the 2022 edition that was written against CSF 1.1. NIST describes it as a guide for managing the risk of ransomware events, including gauging an organization's readiness to counter ransomware threats and to address the potential consequences of events. It was developed with industry, and NIST is explicit that it describes best practice rather than legal or regulatory requirements.
The key word is Profile. CSF 2.0 lists 106 security outcomes covering all of cybersecurity. A Community Profile takes a shared concern, in this case ransomware, and selects the outcomes that concern depends on, with a note on how each one applies. Revision 1 cites 43 of the 106 CSF 2.0 subcategories, spread across all six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Why ransomware gets its own Profile
NIST draws a distinction that boards should hear. Most cyber incidents are quiet: data is taken and monetised later. Ransomware is loud. It threatens an immediate, known impact on business operations, and it gives management a dilemma with a clock running: pay and hope the attackers keep their word, or refuse and restore operations yourself. There is little time to contain the damage, restore systems, or communicate with customers, partners and the public. So preparation, not reaction, is what the Profile is built around, and it insists that ransomware risk sit inside enterprise risk management rather than in the IT department.
“The Profile does not ask whether you have a backup product. It asks whether backups of critical data are isolated, tested and restorable within the time the business can tolerate. Those are different questions, and only the second one survives a real event.”
The six basic tips it starts with
Before the full Profile, the document offers a short list of essential practices for organizations that cannot do everything at once. Each tip is mapped to CSF 2.0 outcomes. In plain terms:
- Plan for ransomware events. Set priorities and risk appetite, know who decides what, and understand the legal, regulatory and contractual obligations a response will trigger.
- Educate employees. Run regular phishing simulations, cover the risk of personal devices on work networks, and build a reporting culture that does not blame the person who clicked.
- Remove the vulnerabilities ransomware exploits. Keep systems patched, apply zero-trust principles and segment networks, allow only authorised applications to run, and set expectations with technology vendors.
- Detect and stop attacks quickly. Run endpoint detection at all times, monitor directory services for signs of compromise, and block access to known-malicious web resources.
- Make it harder to spread. Use standard accounts with multi-factor authentication rather than administrative ones, lock out password guessing, enforce least privilege, store data immutably, and allow external access only through a secure VPN.
- Make recovery easier. Maintain and exercise an incident response and recovery plan with out-of-band communications, back up and isolate critical data and test restoration, keep an up-to-date contact list including law enforcement and counsel, and consider cyber insurance.
How the Profile is meant to be used
The Profile is a baseline, not a scorecard. NIST's intended workflow is the CSF one: use the Profile to describe your Current Organizational Profile, honestly, outcome by outcome; set a Target Profile based on your actual risk and tolerance; and treat the gap between them as the prioritised roadmap. The Profile's table gives, for each selected outcome, a short explanation of its ransomware application, which is what makes the gap conversation concrete instead of abstract.
Want to see where you stand against it in about ten minutes?
Start the Ransomware Readiness AssessmentWhat it does not do
It does not certify anything, and it does not predict whether you will be attacked. It does not replace operational playbooks: for step-by-step response guidance NIST points to its incident response publication, SP 800-61 Rev. 3, and the operational detail most organizations use day to day comes from the CISA #StopRansomware Guide. Read the Profile as the "what and why", and those documents as the "how".
My CISO Partner's perspective
We adopted IR 8374 Rev. 1 as the primary methodology for our free Ransomware Readiness Assessment for one reason: it is the only ransomware guidance that starts with governance and ends with recovery, using identifiers a board can trace into a full security program later. The assessment's 20 questions map only to CSF 2.0 outcomes the Profile itself cites, weighted across the six functions, with CISA's operational categories attached to each question. Seven questions cover the controls that decide whether an event is an incident or a catastrophe, and a gap in any of them is called out on its own, whatever the overall score says.
Read the source yourself: NIST IR 8374 Rev. 1 at NIST CSRC (doi:10.6028/NIST.IR.8374r1). It is 23 pages and free.
Where to go from here
If your organization has never described its ransomware posture in these terms, the assessment is the fastest honest first step. If it has, and the gaps are known but unfunded, that is a leadership conversation we are happy to have.
Questions, answered directly.
NIST Internal Report 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile (final, June 2026). It selects the CSF 2.0 outcomes most relevant to ransomware and explains how each applies to preventing, detecting, responding to and recovering from a ransomware event.
No. NIST states the guidelines address best practices rather than legal or regulatory requirements. It is a voluntary baseline organizations use to build their own Current and Target Profiles.
The CSF 2.0 lists 106 outcomes for all of cybersecurity. A Community Profile narrows that to the outcomes a shared concern depends on, here ransomware, and adds guidance on how each outcome applies. Organizations then use it as the starting point for their own Organizational Profile.
It is the primary methodology behind our free Ransomware Readiness Assessment. The assessment's 20 questions map only to CSF 2.0 outcomes the Profile itself cites, weighted across the six CSF functions, with CISA #StopRansomware guidance for the operational detail.
Talk to a CISO about your ransomware readiness.
30 minutes. No obligation. No sales pitch.