Offer · Assurance & Internal Audit

Security maturity assessment

An assessment of people, processes, governance and technology against established maturity models, with a maturity level per area and a roadmap showing what should be done first.

Current stateMaturity modelScorecardRoadmapA few weeks

Who it is for and when

Suits organisations that want to know how well security actually works, not just whether individual requirements are met, and that need a basis for prioritising and for tracking progress over time.

  • You have made security investments but do not know what effect they had.
  • Management asks how you are doing, and the answer differs depending on who answers.
  • You are about to prioritise next year’s security budget and need something to base it on.
  • You want to be able to show progress over time, not just a snapshot.

What we do

  1. Target state and framework. We agree which maturity model to use and what target level is reasonable for you, based on sector, size and the requirements that affect you.
  2. Interviews per area. We go through people, processes, governance and technology with those who own the questions: risk management, incident management, governance structure and technical controls.
  3. Maturity rating. Each area is given a level with rationale and evidence, so that the assessment can be followed afterwards and repeated next time.
  4. Gap against the target state. We set the current state against the target level and point out where the distance is greatest relative to the risk, not just where it is greatest in absolute terms.
  5. Roadmap and walkthrough. A prioritised roadmap with proposed sequence, ownership and measurable outcomes, presented to management.

What you get

  • A scorecard with a maturity level per area
  • Gaps against the target state, with rationale and evidence
  • A prioritised roadmap with proposed sequence and ownership
  • A summary for management without technical jargon
  • A basis that can be repeated and compared next time

Scope and price

A defined engagement that normally takes a few weeks, depending on how many areas and parts of the business are assessed.

The price varies from engagement to engagement and depends on the scope above. You get an estimated cost proposal and, where possible, a fixed price.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Which maturity model do you use?

We choose the model based on what you will use the result for and which requirements affect you. What matters is that the levels are defined and that the assessment can be repeated, so you can track progress over time.

Is this the same as a gap analysis?

No. A gap analysis measures you against a specific regulation or standard, requirement by requirement. A maturity assessment measures capability: how well the ways of working actually function. Many do both, because they answer different questions.

How often should a maturity assessment be done?

Usually every one to two years, or after a major change. The point is the comparison with the previous measurement, so the method needs to stay the same.

Reviewed by Kristensson i Skåne AB. .

Sources: NIST Cybersecurity Framework · ISO/IEC 27001, information security management systems · CIS Controls

Would you like to know where you stand and what should come first?

Contact us