Security Posture and Maturity Review

Scans and tests tell you what is wrong today. A maturity review tells you whether the organisation is capable of staying secure, which is a different question and the one a board actually needs answered. We assess control by control against a recognised framework and produce a score you can track year on year rather than a snapshot that ages immediately.

1

Select

The right framework

2

Interview

How controls really run

3

Evidence

Verify the claims

4

Score

Maturity per domain

5

Roadmap

Sequenced improvement

How We Assess

01

Framework Selection

We choose the framework that fits your regulatory position rather than defaulting to the same one for everybody. An organisation pursuing certification has different needs from one demonstrating due care to a board.

02

Control Interviews

We interview the people who operate the controls rather than only those who own the policy. The gap between the two perspectives is consistently the most informative part of the review.

03

Evidence Verification

Claimed maturity is verified against artefacts. A control described as operating monthly but evidenced twice in a year is scored on the evidence, not the description.

04

Maturity Scoring

Each domain is scored on a defined scale, producing a picture that shows where you are strong and where a single domain drags the overall position down. Scores are repeatable, so next year is a genuine comparison.

05

Roadmap and Board Reporting

A ranked improvement roadmap sequenced by risk reduction per unit of effort, with the quick wins separated from the multi year items, plus reporting written for a governing body rather than for engineers.

What You Receive

Indicative Timeline

A maturity review normally runs three to five weeks depending on the number of domains and how dispersed control ownership is. Evidence gathering is the usual constraint rather than the interviews.

Frameworks We Assess Against

The framework is chosen to fit your obligations rather than our convenience.

ISO/IEC 27001

The certifiable information security management standard, appropriate where clients or tenders require certification.

NIST CSF

Identify, protect, detect, respond and recover, a practical structure that boards find readable.

CIS Controls

A prioritised set of safeguards, useful where the objective is practical improvement rather than certification.

King IV

Principle 12, which puts technology and information governance with the governing body.

POPIA

The security safeguards condition, which imposes a legal floor regardless of framework choice.

Sector Requirements

Client, tender and regulator specific security requirements you are already contractually held to.

Frequently Asked Questions

If clients or tenders demand certification, ISO 27001. If the objective is a structure a board can follow, NIST CSF. If you want the fastest practical risk reduction, CIS Controls. We recommend one at scoping rather than assuming.

No. A maturity review tells you where you stand and what closing the gap requires. Certification is a formal audit by an accredited body. Many organisations use a review first to decide whether certification is worth pursuing at all.

Against a defined scale, from ad hoc through to managed and optimised, applied per control domain and supported by evidence. The scale is agreed up front so the score is repeatable rather than a matter of opinion.

There is overlap on access and change controls, but the questions differ. An ICT audit tests whether specific controls operated during a period. A maturity review assesses organisational capability across a broader set. Where both are needed we scope them together.

Many organisations do, and an evidence based maturity assessment from an independent firm carries more weight than a self assessment questionnaire. It is not a certificate, and we are careful not to present it as one.

Annually. The method is deliberately repeatable so the second review measures movement rather than restating the position, which is what makes the trend meaningful to a board.

Related Services

This sits inside our Cyber Security Assessments practice. Related work: IT Governance Assessment for the King IV governance layer, and POPIA Readiness for the statutory security safeguards.

Discuss a maturity review