Evolving Cyber Defenses — CIS Community Defense Model v3


V3-Center for Internet Security-Summer Promo Ads

 

Previously presented on Tuesday, June 30, 2026 

 

 

The CIS Community Defense Model (CDM) is one of the most rigorous, data-driven models for understanding how the CIS Critical Security Controls® defend against real-world cyber threats. By mapping CIS Safeguards to the MITRE ATT&CK framework and grounding the analysis in authoritative industry threat data, the CIS CDM gives enterprises an evidence-based answer to the question every security leader asks: Are we investing in the right defenses?

The CIS CDM v3.0 will be released in 2026 and represents a significant evolution in how the CIS Controls are analyzed and applied. The headline addition is a fundamentally new way of thinking about defense and highlights the release of the CIS Controls Active Defense Lifecycle. 

Why This Matters for Your Organization

The shift from CIS CDM v2.0 to v3.0 reflects how the threat landscape has matured, and how defensive thinking must evolve with it. Knowing that a Safeguard mitigates a technique is valuable. Knowing when in an attack lifecycle that Safeguard stops an adversary in their tracks is a strategic advantage.

By attending this webinar, you’ll about:

  • The evolution from CDM v2.0 to v3.0 and its impact on security programs
  • The CIS Controls Active Defense Lifecycle to view and disrupt the attack lifecycle
  • Identifying key attack types, coverage improvements, and updated frameworks
  • Using Kill Chain–based decision making to strengthen your security strategy
  • Communicating the value of IG1 as a starting point for organizations of any size
  • Mapping controls to the attacker lifecycle, identify gaps, and prioritize improvements
  • Operationalizing insights using CIS tools, including Attack Cards, mappings, ATT&CK Navigator, and CIS WorkBench resources

About Our Presenters

Curt Dukes
Executive Vice President and General Manager, Security Best Practices

Curt Dukes

Curt Dukes joined CIS as the Executive Vice President and General Manager of the Best Practices and Automation Group in January 2017. The CIS Benchmarks® and CIS Controls® program provides vendor-agnostic, consensus-based best practices to help organizations assess and improve their security. Prior to CIS, he served as the Director, Information Assurance for the National Security Agency, Central Security Service. In that role Curt was responsible for securing systems that handle classified and critical information for military and intelligence activities. Dukes earned a Bachelor’s Degree in Computer Science from the University of Florida, and a Master’s Degree in Computer Science from Johns Hopkins University. He is a 2004 graduate of the Intelligence Community Officer Training Program.

 

Phyllis Lee
Vice President of Security Best Practices Content Development

Phyllis Lee headshot

Phyllis Lee has over 25 years of experience in information assurance and has performed vulnerability assessments, virtualization research, and worked in security automation. Prior to joining CIS, Lee worked at the National Security Agency (NSA) focusing on the intersection between malware and virtualization, which included collaboration with MIT Lincoln Labs. Lee also participated in a variety of security automation standardization efforts and led the security automation strategy for the NSA Information Assurance Directorate (IAD). She graduated from Johns Hopkins University with a Master of Science in computer science.

 

Phillipe Langlois
Data Breach Investigations Report (DBIR) Author, Verizon

Headshot of Philippe Langlois

Philippe Langlois is currently working as the lead engineer and author of the Verizon Data Breach Investigations Report (DBIR). Prior to joining Verizon, he worked at CIS leading various data driven projects, such as the CIS Controls and the MS-ISAC Nationwide Cybersecurity Review.