Security Maturity Assessment
A scored, evidence-based picture of how capable your security program really is — measured against a recognized model, benchmarked against organizations your size, and turned into a roadmap that says which level to reach next and what it will cost.
Where does your program actually sit?
We score each capability area from 1 to 5. Most mid-sized organizations land between 2 and 3 — and the honest news is that level 5 everywhere is rarely the right target.
- 01 Initial Security happens when someone notices. Outcomes depend on individuals, not process.
- 02 Repeatable Practices exist and are broadly followed, but they're undocumented and vary between teams.
- 03 Defined Documented, approved and consistently applied across the organization, with clear ownership.
- 04 Managed Measured with metrics, tested regularly, and reported to leadership on a fixed cadence.
Level 5 — Optimizing — adds continuous improvement driven by those metrics, with the program adapting to threat and business change without prompting. We'll tell you plainly which of your capability areas justify the climb and which are fine where they are.
Measured against a model, not against opinion
We pick the model that matches your obligations and sector, then score consistently against it so results are defensible and repeatable year over year:
- NIST Cybersecurity Framework — the common language for boards and US partners
- ISO/IEC 27001 Annex A — where certification is the destination
- CIS Critical Security Controls — implementation-group scoring for lean IT teams
- C2M2 — for utilities, energy and critical infrastructure operators
Every assessment scores the same capability areas, so a low score in one place can be weighed honestly against strength in another:
- Governance & risk management — ownership, policy, risk decisions
- Asset & identity management — what you have and who can reach it
- Protective controls — network, endpoint, cloud, data
- Detection & monitoring — logging, alerting, coverage
- Response & recovery — incident handling, continuity, tested restores
- Third-party & supply chain — vendor risk and contractual controls
- People & awareness — training, phishing resilience, security culture
The report is built to be used by two different audiences without either needing a translation:
- Executive summary — current score, target score, and the three things that matter most
- Scored capability matrix — every area rated with the evidence behind the rating
- Peer benchmark — how comparable organizations in your sector and size band score
- Prioritized roadmap — sequenced initiatives with effort, owner and expected score movement
- Leadership walkthrough — a live session so the findings land, rather than sitting in an inbox
"A maturity score is only useful if it survives contact with an auditor. We score against evidence, not intentions." — A & T Global assessment team
-
Evidence-based scoringRatings backed by documents, configurations and interviews — not a self-assessment survey
-
Repeatable baselineRe-run it in twelve months and the movement is real, because the method didn't change
-
A budget you can defendEach roadmap item carries effort and expected score movement, so spend has a stated return
-
Right-sized targetsWe recommend the level each area should reach — not a blanket push to five
Three to five weeks, start to walkthrough
- 01 Scope & model selection We agree the boundary, choose the maturity model, and schedule interviews with the people who actually run each area.
- 02 Evidence gathering Document review, control walkthroughs and technical verification across every capability area — with scores justified as we go.
- 03 Report & roadmap Scored matrix, peer benchmark and sequenced roadmap, delivered in a working session with your team and leadership.
Maturity assessment FAQ
A maturity assessment measures capability — how well you do security as a discipline. A threat and risk assessment measures exposure — what could go wrong, how likely, and how bad. They answer different questions and pair well: maturity tells you what to build, risk tells you what to build first.
Almost never. Level 5 costs real money to reach and more to sustain, and for many capability areas the marginal risk reduction doesn't justify it. A well-run mid-sized program often targets 3 broadly, with 4 in the two or three areas where a failure would genuinely hurt the business. We'll tell you which those are.
Typically five to ten people for 45–60 minutes each: whoever owns IT operations, identity, networking, HR onboarding, vendor contracts, and a member of leadership. If you use an MSP, we'll want one of their engineers too. We schedule around your calendar and keep the load light.
Yes, and many clients do. We produce the executive summary as a standalone document specifically so it can be shared without exposing the detailed findings — which name specific weaknesses and shouldn't circulate outside your organization.
Get a number you can defend
Whether it's a board question, an insurer's request, or your own suspicion that spend isn't landing where it should — start with an honest baseline. We respond within one business day.