In short
Cybersecurity management is the ongoing programme of governing, identifying, protecting, detecting, responding to and recovering from cyber threats across an organisation's systems and data. It is not a single product: it combines asset knowledge, vulnerability management, access control, monitoring, incident response and staff awareness, directed by policy and measured against a framework such as the NIST Cybersecurity Framework 2.0.
A programme, not a product
Security tools are necessary, but no tool on its own manages cybersecurity. Management means deciding what to protect and to what level, assigning responsibility, running controls consistently, checking that they work and improving them after incidents. The same tool can be highly effective in one organisation and useless in another, depending on how it is operated.
The six functions of NIST CSF 2.0
The NIST Cybersecurity Framework 2.0 is a widely used way to structure a security programme. It groups outcomes into six functions:
- Govern — set strategy, roles, policy and oversight for cybersecurity risk.
- Identify — understand assets, suppliers and risks.
- Protect — apply safeguards such as access control, secure configuration, training and data security.
- Detect — find attacks and anomalies through monitoring.
- Respond — contain, analyse and communicate about incidents.
- Recover — restore services and learn from incidents.
Vulnerability management
Vulnerability management is a cycle: discover weaknesses through scanning and testing, prioritise them, fix them within agreed timeframes, and verify the fix. Severity scores help, but the most useful prioritisation signal is whether a vulnerability is known to be exploited in real attacks — the purpose of the US CISA Known Exploited Vulnerabilities catalog — combined with how exposed and how important the affected system is.
Detection and monitoring
Attacks that are not detected cannot be stopped. Detection draws on several sources: logs from servers, directories and applications; network flow records that show who is talking to whom; and alerts from security devices. Rules should be tuned to the environment so that genuine warnings — repeated failed logins, port scans, unusual data transfers — stand out from the noise.
Incident response
An incident response process sets out how the organisation prepares, detects and analyses incidents, contains them, eradicates the cause, recovers and learns lessons. Record a timeline from the first alert: it supports decisions during the incident, any regulatory notification, and the review afterwards.
Access and identity
Many breaches start with a compromised account. Core practices are least privilege, multi-factor authentication, prompt removal of access when people leave, regular review of dormant and orphaned accounts, and granting administrator rights only when needed and for a limited time.
Cybersecurity obligations in Zambia
The Cyber Security Act No. 3 of 2025 repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73) and established the Zambia Cyber Security Agency in the Office of the President (s.3). The Act lists critical sectors including the public sector, banking and finance, health, transport, pensions and insurance, information and communications technology, energy, education and mining (s.8), and the Agency designates critical information and critical information infrastructure by notice in the Gazette (s.9).
For critical information infrastructure, a controller must immediately notify the Agency of a cyber security incident and submit a preliminary incident report within twelve hours of that notification, followed by a detailed report once the incident is resolved (s.17). Controllers must also appoint an information technology auditor each year to perform a cyber audit (s.14). Separately, a person may not provide a cyber security service without a licence, and a controller — in this Act, a person responsible for registered critical information or critical information infrastructure (s.2) — may not engage an unlicensed provider (s.42).
Where an incident involves personal data, Zambia's Data Protection Act No. 3 of 2021 also requires the data controller to notify the Data Protection Commissioner within 24 hours of the breach (s.49). This page is general information, not legal advice.
How Ontech ICTM supports this
Ontech ICTM's cybersecurity capabilities include:
- Vulnerability scanning using nmap service detection matched against known CVEs, plus web application and authenticated role-by-role testing.
- Live CVE lookups from the NVD, the CISA KEV catalog with scheduled matching against your vulnerabilities, and mapping of findings to MITRE ATT&CK.
- Network detection and response from NetFlow, IPFIX and sFlow records, detecting port scans, beaconing, lateral movement, DNS tunnelling and exfiltration.
- Collection of syslog, Windows event logs and Linux authentication logs, with configurable threshold rules that raise security events.
- Identity controls: dormant and orphaned account scans, time-limited privilege elevation with approval, and authenticator-app multi-factor authentication.
- Incident records and security awareness training with quizzes and certificates.
Key takeaways
- Cybersecurity management is a continuous programme, not a product.
- NIST CSF 2.0 organises the work into Govern, Identify, Protect, Detect, Respond and Recover.
- Prioritise vulnerabilities that are known to be exploited and affect important, exposed systems.
- Detection depends on collecting and tuning logs and network flow data.
- Zambia's Cyber Security Act 2025 sets incident-reporting and audit duties for critical information infrastructure.
Frequently asked questions
What is cybersecurity management?
Cybersecurity management is the continuous programme of governing and operating an organisation's security: knowing its assets and risks, protecting systems and data, detecting attacks, responding to incidents and recovering from them. It combines people, processes and technology, and is usually measured against a framework such as NIST CSF 2.0 or ISO/IEC 27001.
What is the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework, published by the US National Institute of Standards and Technology, is a voluntary framework for managing cybersecurity risk. Version 2.0 organises security outcomes into six functions — Govern, Identify, Protect, Detect, Respond and Recover — and is used by organisations of all sizes and countries.
How should vulnerabilities be prioritised?
Combine severity with real-world context: whether the vulnerability is known to be exploited (for example, listed in the CISA KEV catalog), whether the affected system is exposed to the internet, and how important the system is. Fix exploited vulnerabilities on exposed, critical systems first.
What must be reported under Zambia's Cyber Security Act 2025?
Controllers of critical information infrastructure must immediately notify the Zambia Cyber Security Agency of cyber security incidents affecting that infrastructure, submit a preliminary incident report within twelve hours of notifying, and file a detailed report once the incident is resolved (s.17). Check whether your systems have been designated and seek legal advice for specific cases.
Do cybersecurity providers in Zambia need a licence?
Yes. Under s.42 of the Cyber Security Act No. 3 of 2025, a person may not provide a cyber security service without a licence issued under the Act, and a controller of registered critical information infrastructure (as defined in s.2) may not engage a provider that is not licensed. Check whether a particular service falls within the Act's definition before engaging a provider.