Overall Security Maturity
This assessment evaluated the organisation across 13 security domains and 65 questions, aligned to NIST CSF 2.0 and CIS Controls v8.1. The organisation achieved an overall maturity that places it at an early, developing stage. The results below set out where the organisation stands today and which improvements will move the needle first — for day-to-day risk, for the controls cyber-insurers scrutinise, and for the security questions enterprise customers increasingly ask.
Key findings
The lowest-scoring areas are concentrated in governance and foundational technical controls, representing the best place to focus first. A significant number of individual controls scored below the optimised level — concrete, fixable areas to strengthen, several of them below the target level and warranting priority. Relative strengths provide a foundation to build on, while the weakest function indicates where capability is currently thinnest.
Immediate actions
Formally designate a named owner accountable for cybersecurity. Integrate cybersecurity objectives into business planning. Enforce multi-factor authentication across all accounts. Put the security program on the leadership agenda on a fixed schedule. Define and track a dedicated cybersecurity budget aligned to the security plan.
This assessment is based on a 65-question self-assessment — 5 scored questions in each of 13 domains — mapped to the six functions of NIST CSF 2.0 and to CIS Controls v8.1. Each answer maps to a 1–5 maturity score; a domain's score is the average of its 5 questions, and the overall score is the average of the 13 domain scores.
| Score | Level | Meaning |
|---|---|---|
| 5 | Optimised | Fully implemented, consistent, monitored and improved |
| 4 | Managed | Largely implemented and reliable |
| 3 | Defined | Partially in place, inconsistent, or in progress |
| 2 | Developing | Minimal or early-stage |
| 1 | Ad-hoc / None | Not in place, or only ad-hoc and undocumented |
Maturity by domain, ranked against a Level 3 target (green line).
Full domain table
| Domain | Score | Level | Priority | NIST |
|---|---|---|---|---|
| Governance & Leadership | 1.8 | Developing | High | Govern |
| Policies & Documentation | 2.4 | Developing | Medium | Govern |
| Asset & Risk Management | 2.2 | Developing | Medium | Identify |
| Access Control | 2.0 | Developing | Medium | Protect |
| Cloud Security | 2.6 | Defined | Low | Protect |
| Device & Endpoint Security | 2.2 | Developing | Medium | Protect |
| Data Protection | 3.6 | Managed | Low | Protect |
| Email & Security Awareness | 2.8 | Defined | Low | Protect |
| Vendor & Third-Party Risk | 2.6 | Defined | Low | Govern |
| Detection & Monitoring | 3.2 | Defined | Low | Detect |
| Incident Response | 2.8 | Defined | Low | Respond |
| Continuity & Backup | 3.0 | Defined | Low | Recover |
| Physical & Operational Security | 2.6 | Defined | Low | Protect |
| OVERALL | 2.6 | Developing | ||
Your posture across the six NIST CSF 2.0 functions (gold) against a Level 3 target (dashed).
01 · Governance & Leadership
1.8 / 5 — Developing NIST: GovernFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
02 · Policies & Documentation
2.4 / 5 — Developing NIST: GovernFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
03 · Asset & Risk Management
2.2 / 5 — Developing NIST: IdentifyFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
04 · Access Control
2.0 / 5 — Developing NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
05 · Cloud Security
2.6 / 5 — Defined NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
06 · Device & Endpoint Security
2.2 / 5 — Developing NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
07 · Data Protection
3.6 / 5 — Managed NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
08 · Email & Security Awareness
2.8 / 5 — Defined NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
09 · Vendor & Third-Party Risk
2.6 / 5 — Defined NIST: GovernFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
10 · Detection & Monitoring
3.2 / 5 — Defined NIST: DetectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
11 · Incident Response
2.8 / 5 — Defined NIST: RespondFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
12 · Continuity & Backup
3.0 / 5 — Defined NIST: RecoverFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
13 · Physical & Operational Security
2.6 / 5 — Defined NIST: ProtectFindings
This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.
Risk
The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.
Recommendations
Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.
Your results mapped to the controls underwriters most commonly require — so you can see exactly where coverage or a deal could stall.
| Control | Status | Related domain |
|---|---|---|
| Multi-factor authentication (MFA) | Not in place | Access control |
| Endpoint detection & response (EDR) | Not in place | Device & endpoint |
| Tested, isolated backups | Partial | Continuity |
| Written & tested incident response plan | Partial | Incident response |
| Email security & anti-spoofing | In place | Email & awareness |
| Privileged & least-privilege access | Partial | Access control |
| Centralized logging & monitoring | In place | Detection |
| Patch & vulnerability management | Partial | Device & endpoint |
| Security awareness training | In place | Email & awareness |
| Vendor / third-party risk | Partial | Vendor risk |
Priority action 1: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.
Priority action 2: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.
Priority action 3: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.
Structured improvement 1: build out process, ownership, and documentation to reach a reliably managed standard.
Structured improvement 2: build out process, ownership, and documentation to reach a reliably managed standard.
Structured improvement 3: build out process, ownership, and documentation to reach a reliably managed standard.
Structured improvement 4: build out process, ownership, and documentation to reach a reliably managed standard.
Maturity initiative 1: formalise policy, accountability, and measurement to move toward an optimised program.
Maturity initiative 2: formalise policy, accountability, and measurement to move toward an optimised program.
Maturity initiative 3: formalise policy, accountability, and measurement to move toward an optimised program.
Maturity initiative 4: formalise policy, accountability, and measurement to move toward an optimised program.
A sequencing guide — the upper-left quadrant holds the quick wins (high impact, low effort) that come first.
Metrics to track between assessments
The full report includes a defined set of metrics to track progress between assessments — covering MFA coverage, EDR deployment, backup testing, access revocation time, patch SLAs, phishing results, and gaps closed.
This is what your report looks like.
Every section above — fully written, specific to your answers, with real findings, an insurance readiness breakdown, and a prioritised roadmap — delivered in less than 24 hours. See your score free first. Buy only if it's what you need.
Get my free security score →Free score · Full report $750 · 30-day money-back guarantee