Service

Cybersecurity Maturity Assessment

The maturity assessment answers the question of how mature and effective your organisation's cybersecurity really is, regardless of whether you are subject to specific requirements. Instead of only checking compliance with a regulation, we measure the actual level of sophistication of your safeguards, across three dimensions: people, processes and technology. We show you where you really stand and set out a realistic development path. This is a tool for organisations that want to consciously raise their security, not just tick off requirements.

Maturity assessment versus audit: what is the difference

These are two different things worth distinguishing. In short: an audit checks compliance with an external requirement, while a maturity assessment shows how mature your security is and how to develop it.

Audit

Question
Do you meet the requirements?
Result
Binary: compliant or not
Reference point
External requirement (KSC, NIS2, ISO)
Purpose
Because you have to

Maturity assessment

Question
How good is your security?
Result
A level on a development scale
Reference point
Internal condition and development
Purpose
Because you want to know and develop

What we assess: three dimensions of the organisation

Security is not only about technology, so we assess your organisation across three dimensions, examining each with specific methods.

People

The awareness and attitudes of staff, the most important link in security. Among other things, we check how the team responds to real threats, using controlled tests such as simulated phishing, to assess actual vigilance rather than declarations alone.

Processes

The way the organisation manages security day to day: policies, procedures, incident response and business continuity. We assess whether processes exist, whether they are applied in practice and whether they cover what matters.

Technology

The technical state of safeguards and systems. In this dimension we use tools such as vulnerability scanning to assess actual technical condition. These are one-off assessment tools for maturity assessment purposes, not a continuous monitoring or vulnerability management service.

How we measure maturity

In the assessment we use ShieldNet, a framework we created, as a reference point for good practice. A maturity assessment is not an assessment of compliance with ShieldNet, and it is not a certification. Our process-based approach and emphasis on continual improvement draw on good service management practices in the spirit of ITIL, while the maturity scale itself is based on the widely recognised CMMI model, in which the level of advancement is defined in five stages:

  1. Level 1

    Initial

    ad hoc, unformalised activities.

  2. Level 2

    Repeatable

    basic processes exist, but are not always applied consistently.

  3. Level 3

    Defined

    processes are documented and applied across the organisation.

  4. Level 4

    Managed

    processes are measured and controlled on the basis of data.

  5. Level 5

    Optimising

    processes are continually improved.

This scale lets us not only tell you where you are, but also clearly show what distinguishes your current level from the next one and how to reach it.

The model is not a universal template for everyone. For regulated sectors, including healthcare, we use the ShieldNet sector add-ons, so a hospital's maturity assessment looks different from that of an organisation in another industry. We assess you in the reality of your sector, not against a detached, one-size-fits-all measure.

What you receive

The outcome of the assessment is a clear picture of your situation and a concrete development plan. You receive a determination of your maturity level across three dimensions, that is, where you really stand. You receive a development map showing how to reach a higher level, together with priorities, that is, what to do first for the greatest effect. You also receive a reference point you can return to after some time to measure progress. We do not leave you with just an assessment, we show you the way forward.

  • Maturity level across three dimensions
  • Development map with priorities
  • Reference point for measuring progress

Why you need a maturity assessment

The maturity assessment is a management tool, not only a technical one. It helps you find out where you really stand before you invest in security, so that you spend resources where they will have the greatest effect. It helps set priorities instead of scattering effort. It provides a reference point that lets you see progress over time. And it gives the board a clear picture that supports decisions and justifies the necessary spending. This is the basis for building security consciously rather than by chance.

Related services

The maturity assessment combines well with a formal compliance verification and with ongoing oversight of security development.