Oil and gas businesses rely heavily on information technology solutions to support the country’s economic sustainability. However, vulnerabilities in the organization's IT systems pose significant risks, as they may be exploited by hackers or cybercriminals, potentially disrupting operations and compromising sensitive data. To address this, a strategic plan is necessary to enhance cybersecurity and ensure the reliability of IT systems. This research adopts the NIST Cybersecurity Framework, a structured approach developed by the National Institute of Standards and Technology (NIST), to design a strategic cybersecurity plan. Data were collected through interviews, field observations, and exploring public web-based applications identified as IT assets. Based on these results, the research provides targeted control recommendations using the NIST Cybersecurity Framework to strengthen the protection of applications essential for customer interactions and overall business operations.