Framework provenance

Research behind RACF-CC

From postgraduate research to a practical, resource-aware cybersecurity framework.

RACF-CC grew from applied postgraduate cybersecurity research into how organisations with limited security resources can use established enterprise principles without assuming enterprise budgets, staffing or operational capacity.

Research at a glance

A framework designed around operational reality

Research problem

Enterprise guidance is valuable, but implementation can assume specialist teams, mature monitoring, extensive documentation and budgets that smaller organisations do not have.

Research design

An applied single-case study informed by design science, focused on developing and evaluating a usable cybersecurity artefact in a real environment.

Evidence base

Configuration evidence, security telemetry, vulnerability scanning, Active Directory and firewall assessment, organisational records and operational observations.

Research contribution

A structured method for translating recognised cybersecurity principles into prioritised, feasible, staged and measurable controls.

Why the research was needed

The security requirement does not disappear when resources are limited

Care charities can hold sensitive personal information, operate distributed services, support vulnerable people and depend heavily on technology for continuity of care. At the same time, they may have small generalist IT teams, constrained budgets, legacy infrastructure, specialist operational systems and no dedicated Security Operations Centre.

Frameworks and standards such as NIST, Zero Trust Architecture, ISO/IEC 27001 and CIS Controls provide strong foundations. Comprehensive implementation, however, can assume staffing, automation, monitoring, documentation and specialist capability that are difficult for smaller organisations to sustain.

The objective was not to create a lower standard of security for charities. It was to develop a defensible way to decide what to do first, what could realistically be implemented, where compensating controls were needed and how improvement could be evidenced.

The issue is not whether strong cybersecurity principles apply to resource-constrained organisations. It is how those principles can be implemented proportionately without weakening their security intent.

The original problem

Turning enterprise expectations into achievable action

The study examined a hybrid care environment combining cloud services with on-premises infrastructure, legacy systems, network equipment and embedded or specialist devices. The environment already contained useful security capabilities; the problem was not simply an absence of tools.

The research focused on the gap between having security technology and operating it as a coherent, evidence-led security system.

  • Controls could be available but not fully enforced.
  • Implementation could vary across users or devices.
  • Legacy dependencies could make deployment difficult.
  • Management-platform visibility could be incomplete.
  • Enforcement could create operational risk without testing.
  • Many legitimate improvements competed for limited staff time.

Research approach

Designed and evaluated in a real operating environment

The dissertation used an applied design-science approach supported by a single organisational case study. The objective was not only to observe a problem, but to create an artefact intended to help solve it, apply that artefact and evaluate whether it produced useful results.

01

Assess

Establish the existing security posture, operational constraints, credible risks and control gaps.

02

Design

Adapt recognised security principles into a resource-aware framework suitable for the organisation's technical and operational environment.

03

Evaluate

Use technical evidence and before-and-after measurements to determine whether selected controls produced measurable improvement and remained operationally feasible.

Research boundary. The objective was analytical transferability rather than statistical generalisation. One care charity cannot represent every charity, but a repeatable method can provide learning that other organisations adapt using their own evidence, risks and constraints.

Formal research questions

Three questions guided the dissertation

RQ1

Framework adaptation

How can established cybersecurity frameworks, including Zero Trust, NIST SP 800-series controls, ISO/IEC 27001 and CIS Critical Security Controls, be adapted for low-resource care charities?

RQ2

High-impact controls

What cost-effective and high-impact security controls can reduce cyber risk in a hybrid care charity infrastructure?

RQ3

Evidence-led prioritisation

How can existing Microsoft 365, Entra ID, Intune, Defender, vulnerability and network telemetry be used to prioritise and justify security improvements in resource-constrained settings?

Evidence rather than assumption

Security posture was examined from several directions

No individual dashboard or assessment score was treated as definitive. Direct configuration evidence and platform telemetry were generally treated as stronger evidence than aggregate maturity scores. Operational observation provided context rather than replacing technical evidence.

Identity and cloud security

Microsoft Entra ID, Conditional Access, authentication reporting, Secure Score and Zero Trust Assessment outputs.

Endpoint and device security

Microsoft Intune, Defender, device compliance, encryption and endpoint-hardening evidence.

Hybrid identity

Active Directory configuration, PowerShell review and PingCastle assessment.

Vulnerability and configuration

Nessus scanning, platform configuration and remediation evidence.

Networks and containment

Firewall policy, VLAN configuration, network reachability and WatchGuard logging.

Data protection and resilience

Backup configuration, recovery evidence, Microsoft 365 protection and OneDrive health telemetry.

Governance and operations

Policies, risk records, change-management evidence, incident processes and lightweight automation.

Triangulation

Security evidence is strongest when several independent signals support the same conclusion.

From gaps to prioritised controls

A repeatable analytical method

01

Gap analysis

Compare existing controls with relevant recognised principles and classify them as implemented, partial or missing.

02

Attack-path interpretation

Consider how weaknesses could contribute to realistic compromise, persistence, lateral movement, data loss or disruption.

03

Feasibility assessment

Assess technical compatibility, administrative effort and possible disruption. Where the preferred control is unrealistic, consider isolation, monitoring or formal residual-risk treatment.

04

Prioritisation

Compare likely risk reduction with implementation effort, operational impact and cost to decide which useful work should happen first.

What the method is for. It does not calculate financial loss expectancy or replace formal quantitative risk analysis. It helps a resource-constrained team compare useful security work consistently.

Original design principles

The design philosophy behind NIST Lite

The analytical method was supported by four principles developed for the original research artefact. They explain how enterprise security expectations were adapted without abandoning their underlying security intent.

Risk over compliance

Prioritise controls that disrupt credible attack paths and reduce meaningful organisational risk rather than implementing controls simply to satisfy a checklist.

Feasibility over completeness

Prefer controls that can be implemented and sustained safely. Where a preferred control is not currently achievable, use appropriate compensating controls rather than leaving the risk untreated.

Containment over perfect prevention

Assume prevention will not always succeed. Limit the impact of compromise through segmentation, restricted trust, resilient backups and recoverable services.

Measurement over assumption

Demonstrate security through configuration, telemetry, testing and operational evidence rather than assuming a policy, product or dashboard score proves a control is effective.

How the principles evolved. Their intent remains visible in RACF-CC through its Risk-led, Resource-aware, Care-conscious and Evidence-led philosophy. The newer wording is designed for practical public use; the original principles are retained here to show the research reasoning from which the framework developed.

Eight connected security domains

Security improvement was treated as a system

Strong authentication is less effective if a compromised endpoint can steal credentials. Endpoint protection is less effective if compromise can move across flat networks. Segmentation provides limited assurance if enforcement is never tested. Backups provide limited resilience if recovery cannot be demonstrated.

What the evaluation found

Practical improvement was possible in the evaluated environment

The evaluation identified measurable improvements across several security areas, achieved largely through existing infrastructure, licensing and lightweight processes. These are findings from one environment, not a promise of equivalent outcomes elsewhere.

Existing capability can deliver value

Better configuration, stronger enforcement, removal of unnecessary access, segmentation, improved telemetry and clearer governance could improve control effectiveness without always requiring a new platform.

Safe staging matters

Report-only, audit and pilot modes helped manage the risk of disrupting frontline work, legacy applications or distributed services. A control also had to be introduced in a way the organisation could sustain.

Use the Safe Enforcement Pattern →

Legacy risk needs explicit treatment

Where replacement was not immediately realistic, the approach favoured documented ownership, isolation, monitoring, compensating controls and explicit residual-risk decisions.

Use the legacy-risk treatment guide →

Measurement needs context

Headline scores could conceal meaningful control-level change. Telemetry was treated as decision-support evidence rather than a final measure of security maturity.

From NIST Lite to RACF-CC

The research artefact became a broader public framework

The dissertation called its research artefact NIST Lite. The name described a resource-aware adaptation for the case-study environment; it did not mean a reduced official NIST framework or an alternative standard.

The public framework evolved into the Resource-Aware Cybersecurity Framework for Care Charities—RACF-CC. The research provides its foundation and design rationale rather than freezing it at the state evaluated in the dissertation.

Understand

Establish the current state using configuration, telemetry, policy and operational evidence.

Prioritise

Compare improvements by security benefit and the resources and disruption needed to deliver them.

Implement

Introduce controls through manageable, governed change rather than assuming immediate full enforcement.

Evidence

Demonstrate implementation, evaluate effectiveness, record exceptions and residual risk, then repeat the cycle.

The research contribution

An adaptation method, not another security standard

RACF-CC addresses the implementation space between knowing what good security looks like and deciding how to move towards it when resources are constrained.

A practical domain structure

Eight connected domains reflecting the realities of hybrid environments.

A consistent process

Move from observed gaps to credible attack paths, feasibility assessment and prioritised treatment.

Resource-aware prioritisation

Evaluate likely risk reduction alongside implementation effort, operational impact and cost.

Evidence-led evaluation

Use available management, infrastructure and operational evidence to determine whether exposure has changed.

The intended middle path. Organisations should not have to choose between doing very little because enterprise frameworks appear overwhelming and attempting a programme they do not have the resources to sustain. See how RACF-CC complements NIST, ISO, CIS Controls and Zero Trust →

What the research does not claim

Scope and limitations matter

It was a single case study

The findings support analytical transferability, not a claim that every charity has the same risks, technology or security maturity.

The environment was strongly Microsoft-centric

The method can be adapted elsewhere, but different identity, endpoint, network and backup platforms require different evidence and controls.

Not every control reached full enforcement

Some measures remained in report-only, audit or pilot states. These provided implementation evidence but not the same protection as full enforcement.

The evaluation period was limited

Legacy replacement, recovery testing, incident-response maturity and governance require longer observation than some technical changes.

Metrics required interpretation

Asset visibility, scan coverage and assessment methodology affected some measurements. A better score was not automatically treated as proof of better security.

These boundaries shape the framework's philosophy: evidence should be interpreted honestly, residual risk should remain visible and claims should stay proportionate to what can be demonstrated.

Read the finding in practice. The article Why headline security scores can hide real progress examines how the dissertation's Active Directory, Zero Trust and vulnerability evidence changed beneath the aggregate numbers.

Continuing the research in practice

RACF-CC is intended to evolve

The original dissertation identified continued work including stronger policy enforcement, safer progression of endpoint controls, treatment of legacy risk, continued Active Directory governance, more repeatable incident response and repeated technical reassessment.

The framework should be treated as a living implementation method, not a finished compliance checklist.

  • Test the method across additional organisations and technology environments.
  • Refine prioritisation as more implementation evidence becomes available.
  • Strengthen repeatable assurance and residual-risk tracking.
  • Evaluate long-term control sustainability, not initial deployment alone.
  • Continue alignment with recognised standards, technologies and threat patterns.

The principle that remains

Low-resource should not mean low ambition

Resource-constrained organisations face many of the same threats as larger enterprises while having less capacity to prevent, detect and recover from them. Strong cybersecurity therefore remains necessary; what changes is the route to achieving it.

Staged implementation, evidence-led prioritisation, compensating controls and lightweight governance can help organisations make meaningful improvements without assuming enterprise-scale technology or staffing.

Use recognised security principles, adapt delivery to operational reality, prioritise credible risk reduction and demonstrate progress with evidence.

Explore RACF-CC

Move from the research foundation to practical action.

See how the framework is structured, review the anonymised applied case study or use the prioritisation tool to begin comparing controls.

Research context statement. RACF-CC developed from independent postgraduate research into adapting enterprise cybersecurity frameworks for resource-constrained care environments. The original research artefact was named NIST Lite. RACF-CC is the subsequent independent evolution of that work and is not affiliated with or endorsed by NIST, CIS, ISO or the organisations responsible for the standards and guidance that informed the research.