Cyber Maturity Assessment (CMA)
You have security tools in place. But would they stop a real attack?
The Cyber Maturity Assessment provides a clear, evidence-based view of how effectively your organisation manages cyber risk today and what needs to change next.
Cyber Maturity Assessment (CMA)
You have security tools in place. But would they stop a real attack?
The Cyber Maturity Assessment provides a clear, evidence-based view of how effectively your organisation manages cyber risk today and what needs to change next.
It is designed for organisations that:
-
Have invested in Microsoft 365, EDR and backups but have not validated configuration
-
Rely on internal IT or MSPs focused on uptime rather than security outcomes
-
Have partial controls in place but lack cohesion and visibility
-
Need defensible insight for executive or board discussions
-
Want direction, not another audit report
What makes the CMA different
This is not a policy review or checklist exercise. The CMA evaluates how security actually operates across technology, people and process. Controls are validated through evidence, interviews and technical review where appropriate.
You gain clarity on what is working, what is not, and what to improve first.
What we assess
Cyber maturity is evaluated across core operational domains, with each domain scored against defined maturity levels to establish a defensible baseline.
Assessment Domains
- Leadership and Governance
- Identity and Access
- Protection and Resilience
- Detection and Response
- People and Culture
- Operational Security Practices
CMA Service Levels
CMA — Small
For smaller organisations or those early in their security journey. Focuses on essential controls, critical risks and practical improvements that deliver immediate uplift without unnecessary complexity.
CMA — Medium
For mid-market organisations with existing tools and partial controls in place. Provides structured validation, maturity scoring and a prioritised improvement roadmap that replaces assumption with direction.
CMA — Large
For complex, multi-entity or regulated environments. Establishes a consistent maturity baseline across the organisation and aligns security strategy with executive oversight and growth objectives.
CMA — Custom Scope
For organisations with specific regulatory, operational or transformation requirements. Scope, depth and focus areas are tailored to business risk, compliance obligations and strategic initiatives.
How the CMA works
01
Discovery and context
We establish business drivers, risk appetite and your operating environment.
02
Evidence-based validation
Controls and practices are validated through interviews, artefact review and technical evidence.
03
Maturity scoring
Each domain is assessed against a consistent maturity model to establish a defensible baseline.
04
Reporting and roadmap
You receive executive-ready reporting, including a maturity heatmap, key risks and improvement priorities, and a practical prioritised roadmap.
Where you stand
What matters most
How to improve, step by step
Start with clarity
Cyber maturity is not about perfection. It is about understanding your position and improving deliberately.