Enterprises today are very dependent on their information systems and data. The IT environment has also become more complex, increasing the risk of information compromise. Cyber security risks are a fundamental type of risk for all organisations to manage. Potential impacts include higher costs, lower revenue, reputational damage, and the impairment of innovation. Protecting a company and its information assets requires a holistic approach: various security controls and compliance aspects need to be understood and addressed to get comprehensive protection.