Security Posture and Maturity Review
Scans and tests tell you what is wrong today. A maturity review tells you whether the organisation is capable of staying secure, which is a different question and the one a board actually needs answered. We assess control by control against a recognised framework and produce a score you can track year on year rather than a snapshot that ages immediately.
1
Select
The right framework
2
Interview
How controls really run
3
Evidence
Verify the claims
4
Score
Maturity per domain
5
Roadmap
Sequenced improvement
How We Assess
01
Framework Selection
We choose the framework that fits your regulatory position rather than defaulting to the same one for everybody. An organisation pursuing certification has different needs from one demonstrating due care to a board.
- Framework selected against regulatory and client requirements
- Scope agreed by domain and business unit
- Maturity scale defined and agreed up front
- Comparison basis established for future reviews
02
Control Interviews
We interview the people who operate the controls rather than only those who own the policy. The gap between the two perspectives is consistently the most informative part of the review.
- Interviews across IT, security, HR and operations
- Control ownership and performance frequency established
- Distinction between documented and actual practice
- Resourcing and capacity constraints identified
03
Evidence Verification
Claimed maturity is verified against artefacts. A control described as operating monthly but evidenced twice in a year is scored on the evidence, not the description.
- Sampling of evidence per control claimed
- Policy currency and approval verification
- System configuration checks where relevant
- Scoring adjusted to evidenced reality
04
Maturity Scoring
Each domain is scored on a defined scale, producing a picture that shows where you are strong and where a single domain drags the overall position down. Scores are repeatable, so next year is a genuine comparison.
- Score per control domain against the scale
- Overall maturity position with domain breakdown
- Benchmarking against comparable organisations
- Repeatable method for year on year tracking
05
Roadmap and Board Reporting
A ranked improvement roadmap sequenced by risk reduction per unit of effort, with the quick wins separated from the multi year items, plus reporting written for a governing body rather than for engineers.
- Improvement actions ranked by risk reduction
- Quick wins separated from structural change
- Indicative effort and cost per action
- Board and audit committee reporting pack
What You Receive
- Maturity score per control domain with an overall position
- Evidence based assessment rather than self reported scoring
- Gap analysis against the selected framework
- Improvement roadmap ranked by risk reduction
- Indicative effort and cost per recommended action
- Board and audit committee reporting pack
Indicative Timeline
A maturity review normally runs three to five weeks depending on the number of domains and how dispersed control ownership is. Evidence gathering is the usual constraint rather than the interviews.
- Framework selection and scoping: three to five days
- Interviews across functions: one to two weeks
- Evidence verification and scoring: one week
- Roadmap and reporting: one week
Frameworks We Assess Against
The framework is chosen to fit your obligations rather than our convenience.
ISO/IEC 27001
The certifiable information security management standard, appropriate where clients or tenders require certification.
NIST CSF
Identify, protect, detect, respond and recover, a practical structure that boards find readable.
CIS Controls
A prioritised set of safeguards, useful where the objective is practical improvement rather than certification.
King IV
Principle 12, which puts technology and information governance with the governing body.
POPIA
The security safeguards condition, which imposes a legal floor regardless of framework choice.
Sector Requirements
Client, tender and regulator specific security requirements you are already contractually held to.
Frequently Asked Questions
Which framework should we choose?
If clients or tenders demand certification, ISO 27001. If the objective is a structure a board can follow, NIST CSF. If you want the fastest practical risk reduction, CIS Controls. We recommend one at scoping rather than assuming.
Is this the same as ISO 27001 certification?
No. A maturity review tells you where you stand and what closing the gap requires. Certification is a formal audit by an accredited body. Many organisations use a review first to decide whether certification is worth pursuing at all.
How is maturity actually scored?
Against a defined scale, from ad hoc through to managed and optimised, applied per control domain and supported by evidence. The scale is agreed up front so the score is repeatable rather than a matter of opinion.
Will this duplicate our ICT audit?
There is overlap on access and change controls, but the questions differ. An ICT audit tests whether specific controls operated during a period. A maturity review assesses organisational capability across a broader set. Where both are needed we scope them together.
Can we use the score in tenders?
Many organisations do, and an evidence based maturity assessment from an independent firm carries more weight than a self assessment questionnaire. It is not a certificate, and we are careful not to present it as one.
How often should we repeat it?
Annually. The method is deliberately repeatable so the second review measures movement rather than restating the position, which is what makes the trend meaningful to a board.
Related Services
This sits inside our Cyber Security Assessments practice. Related work: IT Governance Assessment for the King IV governance layer, and POPIA Readiness for the statutory security safeguards.
