Research problem
Enterprise guidance is valuable, but implementation can assume specialist teams, mature monitoring, extensive documentation and budgets that smaller organisations do not have.
Framework provenance
From postgraduate research to a practical, resource-aware cybersecurity framework.
RACF-CC grew from applied postgraduate cybersecurity research into how organisations with limited security resources can use established enterprise principles without assuming enterprise budgets, staffing or operational capacity.
Research at a glance
Enterprise guidance is valuable, but implementation can assume specialist teams, mature monitoring, extensive documentation and budgets that smaller organisations do not have.
An applied single-case study informed by design science, focused on developing and evaluating a usable cybersecurity artefact in a real environment.
Configuration evidence, security telemetry, vulnerability scanning, Active Directory and firewall assessment, organisational records and operational observations.
A structured method for translating recognised cybersecurity principles into prioritised, feasible, staged and measurable controls.
Why the research was needed
Care charities can hold sensitive personal information, operate distributed services, support vulnerable people and depend heavily on technology for continuity of care. At the same time, they may have small generalist IT teams, constrained budgets, legacy infrastructure, specialist operational systems and no dedicated Security Operations Centre.
Frameworks and standards such as NIST, Zero Trust Architecture, ISO/IEC 27001 and CIS Controls provide strong foundations. Comprehensive implementation, however, can assume staffing, automation, monitoring, documentation and specialist capability that are difficult for smaller organisations to sustain.
The objective was not to create a lower standard of security for charities. It was to develop a defensible way to decide what to do first, what could realistically be implemented, where compensating controls were needed and how improvement could be evidenced.
The issue is not whether strong cybersecurity principles apply to resource-constrained organisations. It is how those principles can be implemented proportionately without weakening their security intent.
The original problem
The study examined a hybrid care environment combining cloud services with on-premises infrastructure, legacy systems, network equipment and embedded or specialist devices. The environment already contained useful security capabilities; the problem was not simply an absence of tools.
The research focused on the gap between having security technology and operating it as a coherent, evidence-led security system.
Research approach
The dissertation used an applied design-science approach supported by a single organisational case study. The objective was not only to observe a problem, but to create an artefact intended to help solve it, apply that artefact and evaluate whether it produced useful results.
Establish the existing security posture, operational constraints, credible risks and control gaps.
Adapt recognised security principles into a resource-aware framework suitable for the organisation's technical and operational environment.
Use technical evidence and before-and-after measurements to determine whether selected controls produced measurable improvement and remained operationally feasible.
Formal research questions
How can established cybersecurity frameworks, including Zero Trust, NIST SP 800-series controls, ISO/IEC 27001 and CIS Critical Security Controls, be adapted for low-resource care charities?
What cost-effective and high-impact security controls can reduce cyber risk in a hybrid care charity infrastructure?
How can existing Microsoft 365, Entra ID, Intune, Defender, vulnerability and network telemetry be used to prioritise and justify security improvements in resource-constrained settings?
Evidence rather than assumption
No individual dashboard or assessment score was treated as definitive. Direct configuration evidence and platform telemetry were generally treated as stronger evidence than aggregate maturity scores. Operational observation provided context rather than replacing technical evidence.
Microsoft Entra ID, Conditional Access, authentication reporting, Secure Score and Zero Trust Assessment outputs.
Microsoft Intune, Defender, device compliance, encryption and endpoint-hardening evidence.
Active Directory configuration, PowerShell review and PingCastle assessment.
Nessus scanning, platform configuration and remediation evidence.
Firewall policy, VLAN configuration, network reachability and WatchGuard logging.
Backup configuration, recovery evidence, Microsoft 365 protection and OneDrive health telemetry.
Policies, risk records, change-management evidence, incident processes and lightweight automation.
Security evidence is strongest when several independent signals support the same conclusion.
From gaps to prioritised controls
Compare existing controls with relevant recognised principles and classify them as implemented, partial or missing.
Consider how weaknesses could contribute to realistic compromise, persistence, lateral movement, data loss or disruption.
Assess technical compatibility, administrative effort and possible disruption. Where the preferred control is unrealistic, consider isolation, monitoring or formal residual-risk treatment.
Compare likely risk reduction with implementation effort, operational impact and cost to decide which useful work should happen first.
Original design principles
The analytical method was supported by four principles developed for the original research artefact. They explain how enterprise security expectations were adapted without abandoning their underlying security intent.
Prioritise controls that disrupt credible attack paths and reduce meaningful organisational risk rather than implementing controls simply to satisfy a checklist.
Prefer controls that can be implemented and sustained safely. Where a preferred control is not currently achievable, use appropriate compensating controls rather than leaving the risk untreated.
Assume prevention will not always succeed. Limit the impact of compromise through segmentation, restricted trust, resilient backups and recoverable services.
Demonstrate security through configuration, telemetry, testing and operational evidence rather than assuming a policy, product or dashboard score proves a control is effective.
Eight connected security domains
Strong authentication is less effective if a compromised endpoint can steal credentials. Endpoint protection is less effective if compromise can move across flat networks. Segmentation provides limited assurance if enforcement is never tested. Backups provide limited resilience if recovery cannot be demonstrated.
What the evaluation found
The evaluation identified measurable improvements across several security areas, achieved largely through existing infrastructure, licensing and lightweight processes. These are findings from one environment, not a promise of equivalent outcomes elsewhere.
Better configuration, stronger enforcement, removal of unnecessary access, segmentation, improved telemetry and clearer governance could improve control effectiveness without always requiring a new platform.
Report-only, audit and pilot modes helped manage the risk of disrupting frontline work, legacy applications or distributed services. A control also had to be introduced in a way the organisation could sustain.
Use the Safe Enforcement Pattern →Where replacement was not immediately realistic, the approach favoured documented ownership, isolation, monitoring, compensating controls and explicit residual-risk decisions.
Use the legacy-risk treatment guide →Headline scores could conceal meaningful control-level change. Telemetry was treated as decision-support evidence rather than a final measure of security maturity.
From NIST Lite to RACF-CC
The dissertation called its research artefact NIST Lite. The name described a resource-aware adaptation for the case-study environment; it did not mean a reduced official NIST framework or an alternative standard.
The public framework evolved into the Resource-Aware Cybersecurity Framework for Care Charities—RACF-CC. The research provides its foundation and design rationale rather than freezing it at the state evaluated in the dissertation.
Establish the current state using configuration, telemetry, policy and operational evidence.
Compare improvements by security benefit and the resources and disruption needed to deliver them.
Introduce controls through manageable, governed change rather than assuming immediate full enforcement.
Demonstrate implementation, evaluate effectiveness, record exceptions and residual risk, then repeat the cycle.
The research contribution
RACF-CC addresses the implementation space between knowing what good security looks like and deciding how to move towards it when resources are constrained.
Eight connected domains reflecting the realities of hybrid environments.
Move from observed gaps to credible attack paths, feasibility assessment and prioritised treatment.
Evaluate likely risk reduction alongside implementation effort, operational impact and cost.
Use available management, infrastructure and operational evidence to determine whether exposure has changed.
What the research does not claim
The findings support analytical transferability, not a claim that every charity has the same risks, technology or security maturity.
The method can be adapted elsewhere, but different identity, endpoint, network and backup platforms require different evidence and controls.
Some measures remained in report-only, audit or pilot states. These provided implementation evidence but not the same protection as full enforcement.
Legacy replacement, recovery testing, incident-response maturity and governance require longer observation than some technical changes.
Asset visibility, scan coverage and assessment methodology affected some measurements. A better score was not automatically treated as proof of better security.
These boundaries shape the framework's philosophy: evidence should be interpreted honestly, residual risk should remain visible and claims should stay proportionate to what can be demonstrated.
Continuing the research in practice
The original dissertation identified continued work including stronger policy enforcement, safer progression of endpoint controls, treatment of legacy risk, continued Active Directory governance, more repeatable incident response and repeated technical reassessment.
The framework should be treated as a living implementation method, not a finished compliance checklist.
The principle that remains
Resource-constrained organisations face many of the same threats as larger enterprises while having less capacity to prevent, detect and recover from them. Strong cybersecurity therefore remains necessary; what changes is the route to achieving it.
Staged implementation, evidence-led prioritisation, compensating controls and lightweight governance can help organisations make meaningful improvements without assuming enterprise-scale technology or staffing.
Use recognised security principles, adapt delivery to operational reality, prioritise credible risk reduction and demonstrate progress with evidence.
Explore RACF-CC
See how the framework is structured, review the anonymised applied case study or use the prioritisation tool to begin comparing controls.
Research context statement. RACF-CC developed from independent postgraduate research into adapting enterprise cybersecurity frameworks for resource-constrained care environments. The original research artefact was named NIST Lite. RACF-CC is the subsequent independent evolution of that work and is not affiliated with or endorsed by NIST, CIS, ISO or the organisations responsible for the standards and guidance that informed the research.