Service
Cybersecurity Maturity Assessment
The maturity assessment answers the question of how mature and effective your organisation's cybersecurity really is, regardless of whether you are subject to specific requirements. Instead of only checking compliance with a regulation, we measure the actual level of sophistication of your safeguards, across three dimensions: people, processes and technology. We show you where you really stand and set out a realistic development path. This is a tool for organisations that want to consciously raise their security, not just tick off requirements.
Maturity assessment versus audit: what is the difference
These are two different things worth distinguishing. In short: an audit checks compliance with an external requirement, while a maturity assessment shows how mature your security is and how to develop it.
Audit
- Question
- Do you meet the requirements?
- Result
- Binary: compliant or not
- Reference point
- External requirement (KSC, NIS2, ISO)
- Purpose
- Because you have to
Maturity assessment
- Question
- How good is your security?
- Result
- A level on a development scale
- Reference point
- Internal condition and development
- Purpose
- Because you want to know and develop
Audit
Maturity assessment
What we assess: three dimensions of the organisation
Security is not only about technology, so we assess your organisation across three dimensions, examining each with specific methods.
People
The awareness and attitudes of staff, the most important link in security. Among other things, we check how the team responds to real threats, using controlled tests such as simulated phishing, to assess actual vigilance rather than declarations alone.
Processes
The way the organisation manages security day to day: policies, procedures, incident response and business continuity. We assess whether processes exist, whether they are applied in practice and whether they cover what matters.
Technology
The technical state of safeguards and systems. In this dimension we use tools such as vulnerability scanning to assess actual technical condition. These are one-off assessment tools for maturity assessment purposes, not a continuous monitoring or vulnerability management service.
How we measure maturity
In the assessment we use ShieldNet, a framework we created, as a reference point for good practice. A maturity assessment is not an assessment of compliance with ShieldNet, and it is not a certification. Our process-based approach and emphasis on continual improvement draw on good service management practices in the spirit of ITIL, while the maturity scale itself is based on the widely recognised CMMI model, in which the level of advancement is defined in five stages:
- Level 1
Initial
ad hoc, unformalised activities.
- Level 2
Repeatable
basic processes exist, but are not always applied consistently.
- Level 3
Defined
processes are documented and applied across the organisation.
- Level 4
Managed
processes are measured and controlled on the basis of data.
- Level 5
Optimising
processes are continually improved.
This scale lets us not only tell you where you are, but also clearly show what distinguishes your current level from the next one and how to reach it.
The model is not a universal template for everyone. For regulated sectors, including healthcare, we use the ShieldNet sector add-ons, so a hospital's maturity assessment looks different from that of an organisation in another industry. We assess you in the reality of your sector, not against a detached, one-size-fits-all measure.
What you receive
The outcome of the assessment is a clear picture of your situation and a concrete development plan. You receive a determination of your maturity level across three dimensions, that is, where you really stand. You receive a development map showing how to reach a higher level, together with priorities, that is, what to do first for the greatest effect. You also receive a reference point you can return to after some time to measure progress. We do not leave you with just an assessment, we show you the way forward.
- Maturity level across three dimensions
- Development map with priorities
- Reference point for measuring progress
Why you need a maturity assessment
The maturity assessment is a management tool, not only a technical one. It helps you find out where you really stand before you invest in security, so that you spend resources where they will have the greatest effect. It helps set priorities instead of scattering effort. It provides a reference point that lets you see progress over time. And it gives the board a clear picture that supports decisions and justifies the necessary spending. This is the basis for building security consciously rather than by chance.
Related services
The maturity assessment combines well with a formal compliance verification and with ongoing oversight of security development.
