Skip to content

Audit & Assurance

Cybersecurity Maturity Assessment

An evidenced view of where your security programme actually stands, scored against NIST CSF 2.0 — including Govern, the function most organisations in this region score lowest on.

What gets assessed

NIST CSF 2.0 organises cyber security into six functions. Govern was added in the 2.0 revision and is the one that most changes the conversation, because it moves cyber security from a technical topic to an accountability topic — and it cannot be solved by buying anything.

  • Govern — strategy, roles and responsibilities, policy, risk management strategy, supply chain, and oversight.
  • Identify — asset management, risk assessment, and improvement.
  • Protect — identity and access, awareness and training, data security, platform security, and resilience of technology infrastructure.
  • Detect — continuous monitoring and adverse event analysis.
  • Respond — incident management, analysis, mitigation, and reporting.
  • Recover — recovery plan execution and communication.

Why we assess rather than survey

The common approach in this market is a questionnaire completed by the security team, scored by the same team, and presented to the board as a maturity rating. It reliably over-scores, and not through dishonesty — control owners assess against what they know to be true, rather than against what an assessor could evidence.

We score against evidence. Where we revise a self-assessed score downward, we show precisely which maturity criterion is unmet and what artefact would satisfy it. That is more useful than the score itself.

NIST CSF 2.0 — SIX FUNCTIONS Govern was added in 2.0. It is where most assessments in this region score lowest,because it is the one function that cannot be bought. GV Govern Strategy, roles,policy, oversight ID Identify Assets, risk, supplychain PR Protect Access, awareness,data, platform DE Detect Monitoring, adverseevent analysis RS Respond Management, analysis,mitigation RC Recover Plan execution,communication
Govern was added in CSF 2.0 and is where most assessments in this region score lowest.

Target profile, not maximum maturity

The goal is not level five everywhere. That would be an irrational use of budget for most organisations. The output is a target profile — the maturity level each function needs to reach given your threat exposure, regulatory obligations and risk appetite — and a costed path to it.

Where the current profile already exceeds what your risk warrants, we say so. Over-investment in one function while another sits exposed is a common and expensive pattern.

Where this fits with regulatory frameworks

NIST CSF is voluntary and structural. If you are also subject to a supervisory framework — SAMA CSF in the Kingdom, the SBP technology framework in Pakistan, or NCA controls — we map the assessment across both so a single evidence exercise serves each, and report separately in each framework's own structure.

How the engagement runs

  1. 1

    Scope and profile

    Agree the organisational scope and the target profile appropriate to your risk and obligations.

  2. 2

    Evidence collection

    Documentation, configuration, records and metrics — gathered before the interviews, not during.

  3. 3

    Interviews and walkthroughs

    Test whether the documented programme is the one people actually operate.

  4. 4

    Scoring

    Score each category against evidence, with the specific criterion cited for every score.

  5. 5

    Gap and roadmap

    Current versus target profile, with remediation sequenced by risk reduction per unit of effort.

  6. 6

    Board reporting

    Present in language a board can act on, with a metric set they can track quarterly.

Why self-assessed scores get revised down

1. Defined A document exists and is approved 2. Implemented Operates across the full scope 3. Measured A metric exists and is acted on 4. Reviewed Assessed, and something changed THE COMMONOVER-SCORE Levels 3 and 4claimed on theevidence of levels1 and 2.
The upper levels require measurement and review — not a policy and a deployed tool.

What you receive

Maturity score per NIST CSF 2.0 function and category, with evidence for each
Current profile against agreed target profile, visualised
Specific unmet criterion stated for every score below target
Prioritised roadmap sequenced by risk reduction, with indicative effort
Cross-mapping to SAMA CSF, NCA ECC or ISO 27001 where those also apply
Board and audit committee presentation

Frequently asked questions

A penetration test asks whether a specific system can be broken into today. A maturity assessment asks whether the organisation is capable of keeping systems secure over time. They answer different questions and most organisations need both — we often run a targeted test as a technical work stream inside the assessment to validate what the programme claims.

Different tools. NIST CSF is a maturity model that describes a security programme and scores capability — good for a board conversation about where you stand. ISO 27001 is a certifiable management system standard — good when a customer or regulator wants a certificate. Many organisations use CSF internally and certify to ISO externally.

Not at all — it accelerates the work considerably and it is a useful artefact in itself. We use it as the starting hypothesis and test it against evidence. Expect some scores to come down; that is the point of the exercise, and where scores hold up you have independent confirmation.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top