Maturity assessment
A current-state score against a chosen framework, documented gaps, and a prioritised remediation plan, typically in two to four weeks.
What we deliver
- Framework selection and tailoring
We pick CIS Controls v8, NIST CSF 2.0, ISO 27001:2022, or the Secured by FM CyberSecurity baseline with you, and scale the scope to your organisation.
- Current-state scoring
Every control in the chosen framework is rated against today's operation, with a maturity score per area and a trace back to interview, document, or observation.
- Gap analysis with owner and impact
Each finding gets a named customer-side owner, an impact rating, and a short rationale for why it matters to the business.
- Prioritised remediation roadmap
The actions sit in three horizons, ninety days, six months, and twelve months, so both operations and the board can see what moves when.
- Executive summary for the board
A single document written for leadership and the board, with the maturity picture, the largest risks, and the investment choices they have to make.
How we deliver this service
- In a project
A standalone engagement with a fixed scope, typically two to four weeks up to report and presentation.
- As part of a service
Included as the baseline assessment in the Secured by FM CyberSecurity bundle and used to scope the rest of the delivery.
Recent insights on Maturity assessment
- ISO 27001 work as part of a security subscription
Secured by FM CyberSecurity combines security operations, advice and ISO 27001 preparation. Here is what to clarify when buying that work as a subscription.
- What CISSP certification means when picking a cybersecurity consultant
CISSP is a broad security credential with experience requirements. Verify it, then assess the person's fit for your specific systems and assignment.
- Publishing a website without a public admin login
A static website can keep publishing separate from visitor traffic. Git, a build pipeline and a controlled publishing service each have a distinct role.