Domain 04 of six
Cybersecurity
This domain establishes what you are protecting, what is protecting it, and where the gap between those two sits. It is a governance assessment, not a product recommendation.
Why it matters
The problem this addresses
Security spending tends to follow whatever was most recently in the news, or whatever the last supplier presented. That produces strong controls in some places and nothing at all in others, with no way to tell which is which.
The question worth answering is not whether you have security tools. It is whether the controls you hold match the exposure you actually carry, and whether you could demonstrate that to somebody who asked.
Scope
What we examine
- What information you hold, where it sits, and who can reach it
- The security policy suite, and whether it reflects how people really work
- Control coverage against the exposure identified, not against a generic list
- Access, joiners and leavers, and privileged accounts
- Incident response: who is called, in what order, and whether that has been rehearsed
- Awareness, because most incidents begin with an ordinary person doing an ordinary thing
Assessment
Included in the Assessment
Fixed scope, agreed in writing before work begins. Findings your leadership can act on within ten working days of the final interview.
- Maturity rating for this domain on the five-level scale
- Security policy suite, written to be read by the people expected to follow it
- Controls gap assessment against your actual exposure
- Prioritised remediation plan, ranked by consequence
- A position you can present to an oversight committee or a regulator
What this does not include
We do not sell, resell or install security products, and we do not carry out penetration testing. This is deliberate. An assessment of your control coverage is worth more when the organisation carrying it out has nothing to sell you at the end of it. Where testing or a product is genuinely needed, we will say so and you can procure it independently.
Implementation
Available as an Implementation Engagement
An assessment that ends at a report has done half the job. Most organisations know roughly what is wrong. What they lack is the time and the specialist capacity to fix it while also running the organisation.
In this domain that means
- Write the policy suite and take it through approval
- Work the remediation plan with your team, in priority order
- Design and run the first incident rehearsal
Where does this sit for you today?
If you are not sure whether this domain is a priority, the Quick Diagnosis takes about two minutes and gives you a position on the page. Nothing is sent anywhere.