🔒 This is a sample report for a fictional company. Section headings, the structure, and scores are shown so you can see the depth and format of the full 20-page report — the findings, risks, recommendations, and roadmap detail are blurred. Your purchased report shows everything in full, written specifically for your answers.
CRJ Security — Security Maturity Assessment Report SAMPLE · CONFIDENTIAL
SAMPLE

Overall Security Maturity

1 5
2.6
/ 5 · Level 2 — Developing
Executive Summary PAGE 3
SAMPLE
2.6 / 5
Overall maturity
Level 2
Maturity level
61
Areas to strengthen
Govern
Weakest area

This assessment evaluated the organisation across 13 security domains and 65 questions, aligned to NIST CSF 2.0 and CIS Controls v8.1. The organisation achieved an overall maturity that places it at an early, developing stage. The results below set out where the organisation stands today and which improvements will move the needle first — for day-to-day risk, for the controls cyber-insurers scrutinise, and for the security questions enterprise customers increasingly ask.

Key findings

The lowest-scoring areas are concentrated in governance and foundational technical controls, representing the best place to focus first. A significant number of individual controls scored below the optimised level — concrete, fixable areas to strengthen, several of them below the target level and warranting priority. Relative strengths provide a foundation to build on, while the weakest function indicates where capability is currently thinnest.

Immediate actions

Formally designate a named owner accountable for cybersecurity. Integrate cybersecurity objectives into business planning. Enforce multi-factor authentication across all accounts. Put the security program on the leadership agenda on a fixed schedule. Define and track a dedicated cybersecurity budget aligned to the security plan.

Methodology & Scope PAGE 4
SAMPLE

This assessment is based on a 65-question self-assessment — 5 scored questions in each of 13 domains — mapped to the six functions of NIST CSF 2.0 and to CIS Controls v8.1. Each answer maps to a 1–5 maturity score; a domain's score is the average of its 5 questions, and the overall score is the average of the 13 domain scores.

ScoreLevelMeaning
5OptimisedFully implemented, consistent, monitored and improved
4ManagedLargely implemented and reliable
3DefinedPartially in place, inconsistent, or in progress
2DevelopingMinimal or early-stage
1Ad-hoc / NoneNot in place, or only ad-hoc and undocumented
Maturity Results Dashboard PAGE 5
SAMPLE

Maturity by domain, ranked against a Level 3 target (green line).

Domain Target 3.0 → Score
Governance & Leadership
1.8
Access Control
2.0
Asset & Risk Management
2.2
Device & Endpoint Security
2.2
Policies & Documentation
2.4
Cloud Security
2.6
Vendor & Third-Party Risk
2.6
Physical & Operational Security
2.6
Email & Security Awareness
2.8
Incident Response
2.8
Continuity & Backup
3.0
Detection & Monitoring
3.2
Data Protection
3.6

Full domain table

DomainScoreLevelPriorityNIST
Governance & Leadership 1.8 Developing High Govern
Policies & Documentation 2.4 Developing Medium Govern
Asset & Risk Management 2.2 Developing Medium Identify
Access Control 2.0 Developing Medium Protect
Cloud Security 2.6 Defined Low Protect
Device & Endpoint Security 2.2 Developing Medium Protect
Data Protection 3.6 Managed Low Protect
Email & Security Awareness 2.8 Defined Low Protect
Vendor & Third-Party Risk 2.6 Defined Low Govern
Detection & Monitoring 3.2 Defined Low Detect
Incident Response 2.8 Defined Low Respond
Continuity & Backup 3.0 Defined Low Recover
Physical & Operational Security 2.6 Defined Low Protect
OVERALL2.6Developing
Maturity by NIST Function PAGE 6
SAMPLE

Your posture across the six NIST CSF 2.0 functions (gold) against a Level 3 target (dashed).

Govern 2.3 Identify 2.2 Protect 2.6 Detect 3.2 Respond 2.8 Recover 3.0
Domain-by-Domain Analysis 13 DOMAINS · PAGES 8–13
SAMPLE

01 · Governance & Leadership

1.8 / 5 — Developing NIST: Govern

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

02 · Policies & Documentation

2.4 / 5 — Developing NIST: Govern

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

03 · Asset & Risk Management

2.2 / 5 — Developing NIST: Identify

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

04 · Access Control

2.0 / 5 — Developing NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

05 · Cloud Security

2.6 / 5 — Defined NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

06 · Device & Endpoint Security

2.2 / 5 — Developing NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

07 · Data Protection

3.6 / 5 — Managed NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

08 · Email & Security Awareness

2.8 / 5 — Defined NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

09 · Vendor & Third-Party Risk

2.6 / 5 — Defined NIST: Govern

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

10 · Detection & Monitoring

3.2 / 5 — Defined NIST: Detect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

11 · Incident Response

2.8 / 5 — Defined NIST: Respond

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

12 · Continuity & Backup

3.0 / 5 — Defined NIST: Recover

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

13 · Physical & Operational Security

2.6 / 5 — Defined NIST: Protect

Findings

This domain reflects the organisation's current maturity in this area, with specific strengths identified alongside the controls most in need of attention. Core practices may be partially in place; the work now is to make them consistent, documented, and measurable against the framework.

Risk

The gaps identified in this domain create specific, named exposure — the kind of weakness that insurers probe at renewal, that enterprise customers ask about in due diligence, and that attackers most commonly exploit in organisations of this size.

Recommendations

Targeted, prioritised actions aligned to NIST CSF 2.0 and CIS Controls are provided here in the full report — typically four specific, sequenced steps per domain, ordered by impact.

Cyber-Insurance Readiness PAGE 14
SAMPLE

Your results mapped to the controls underwriters most commonly require — so you can see exactly where coverage or a deal could stall.

ControlStatusRelated domain
Multi-factor authentication (MFA)Not in placeAccess control
Endpoint detection & response (EDR)Not in placeDevice & endpoint
Tested, isolated backupsPartialContinuity
Written & tested incident response planPartialIncident response
Email security & anti-spoofingIn placeEmail & awareness
Privileged & least-privilege accessPartialAccess control
Centralized logging & monitoringIn placeDetection
Patch & vulnerability managementPartialDevice & endpoint
Security awareness trainingIn placeEmail & awareness
Vendor / third-party riskPartialVendor risk
3 of 10 insurer-expected controls are fully in place. The full report details exactly which controls to close before you apply or renew — and how the same evidence answers enterprise customer security questionnaires.
Prioritised Remediation Roadmap PAGE 15
SAMPLE
Phase 1 · 0–30 days — close priority gaps

Priority action 1: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.

Priority action 2: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.

Priority action 3: close a below-target gap that delivers the highest immediate risk reduction, achievable with minimal procurement.

Phase 2 · 30–90 days — strengthen to a managed standard

Structured improvement 1: build out process, ownership, and documentation to reach a reliably managed standard.

Structured improvement 2: build out process, ownership, and documentation to reach a reliably managed standard.

Structured improvement 3: build out process, ownership, and documentation to reach a reliably managed standard.

Structured improvement 4: build out process, ownership, and documentation to reach a reliably managed standard.

Phase 3 · 3–12 months — optimise & mature

Maturity initiative 1: formalise policy, accountability, and measurement to move toward an optimised program.

Maturity initiative 2: formalise policy, accountability, and measurement to move toward an optimised program.

Maturity initiative 3: formalise policy, accountability, and measurement to move toward an optimised program.

Maturity initiative 4: formalise policy, accountability, and measurement to move toward an optimised program.

Effort vs. Impact & Next Steps PAGES 16–17
SAMPLE

A sequencing guide — the upper-left quadrant holds the quick wins (high impact, low effort) that come first.

Quick wins Major projects Fill-ins Re-evaluate Effort →

Metrics to track between assessments

The full report includes a defined set of metrics to track progress between assessments — covering MFA coverage, EDR deployment, backup testing, access revocation time, patch SLAs, phishing results, and gaps closed.

This is what your report looks like.

Every section above — fully written, specific to your answers, with real findings, an insurance readiness breakdown, and a prioritised roadmap — delivered in less than 24 hours. See your score free first. Buy only if it's what you need.

Get my free security score →

Free score · Full report $750 · 30-day money-back guarantee