Information Security 3 min read

Embedding threat modeling and security architecture into business operations

An overview of the updated NIST CSF 2.0 framework, MITRE ATT&CK threat modeling, and Zero Trust implementation to protect corporate systems.

New cybersecurity standards: the role of the Govern function in NIST CSF 2.0

The updated NIST CSF 2.0 framework establishes the "Govern" function as the core of security, shifting information protection from a purely technical task to strategic management. This helps bridge the gap between technical specialists and executive leadership. According to ENISA, between July 2024 and June 2025, over 53.7% of successful attacks targeted critical organizations subject to the NIS2 directive, highlighting the urgent need to integrate cyber risks into overall business strategy.

Threat modeling and architectural controls

Threat modeling using the MITRE ATT&CK matrix helps structure adversary behavior. The ENISA Threat Landscape 2025 report indicates that phishing remains the leading initial access vector (27.7% of compromises). In the telecom sector, according to CFCA 2025, fraud losses reached $41.82 billion, necessitating the implementation of specific anti-fraud controls.

The foundation of modern defense is the Zero Trust concept. It requires authentication and authorization for every request, alongside network microsegmentation to prevent lateral movement by attackers within the infrastructure.

Practical implementation: the Security by Design approach

An effective method is designing systems with built-in security. Intecracy Group specialists implement this approach when building enterprise solutions on the UnityBase low-code platform. Commercial editions of the platform (Enterprise and Defence) provide architectural-level protection through the following tools:

  • Row-Level Security (RLS) and ACL: role-based access control for database records.
  • Attribute-level security: restricting access to specific document fields.
  • Audit log: immutable logging of operations for ISO/IEC 27001 and NIS2 compliance.
  • Digital signatures: ensuring data integrity.

An example of applying these technologies is the Megapolis.DocNet electronic document management system, which holds a G2-level security certificate.

Enterprise cybersecurity maturity levels

  1. Ad hoc: reactive defense without threat modeling.
  2. Defined: basic policies in place (MFA, segmentation) but disconnected from business risks.
  3. Managed: threat modeling via MITRE ATT&CK, compliance with NIS2 and ISO/IEC 27001.
  4. Integrated: implementation of Security by Design, utilizing platforms with built-in access control mechanisms.

How this affects the sector

The transition to strategic governance and frameworks like NIST CSF 2.0 and NIS2 means that cybersecurity is now a board-level responsibility. Organizations that fail to align technical defenses with business strategy face severe consequences, including high vulnerability to phishing and massive financial losses from fraud, particularly in critical sectors like telecommunications.

Where to start

  • Implement Zero Trust: Require authentication and authorization for every single request and deploy network microsegmentation.
  • Model Threats: Use the MITRE ATT&CK matrix to proactively counter leading threat vectors like phishing.
  • Adopt Security by Design: Build systems using secure-by-default platforms like UnityBase to leverage built-in tools like Row-Level Security, attribute-level security, and immutable audit logs.
  • Elevate Maturity: Move from reactive (Ad hoc) defense to an Integrated level where security architecture directly supports business operations and compliance standards.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. UnityBase — unitybase.info
  2. Nectain Platform — nectain.com
  3. Megapolis.DocNet — inbase.com.ua
  4. А5 Персонал — inbase.com.ua