Audit & Assurance
Cybersecurity Maturity Assessment
An evidenced view of where your security programme actually stands, scored against NIST CSF 2.0 — including Govern, the function most organisations in this region score lowest on.
What gets assessed
NIST CSF 2.0 organises cyber security into six functions. Govern was added in the 2.0 revision and is the one that most changes the conversation, because it moves cyber security from a technical topic to an accountability topic — and it cannot be solved by buying anything.
- Govern — strategy, roles and responsibilities, policy, risk management strategy, supply chain, and oversight.
- Identify — asset management, risk assessment, and improvement.
- Protect — identity and access, awareness and training, data security, platform security, and resilience of technology infrastructure.
- Detect — continuous monitoring and adverse event analysis.
- Respond — incident management, analysis, mitigation, and reporting.
- Recover — recovery plan execution and communication.
Why we assess rather than survey
The common approach in this market is a questionnaire completed by the security team, scored by the same team, and presented to the board as a maturity rating. It reliably over-scores, and not through dishonesty — control owners assess against what they know to be true, rather than against what an assessor could evidence.
We score against evidence. Where we revise a self-assessed score downward, we show precisely which maturity criterion is unmet and what artefact would satisfy it. That is more useful than the score itself.
Target profile, not maximum maturity
The goal is not level five everywhere. That would be an irrational use of budget for most organisations. The output is a target profile — the maturity level each function needs to reach given your threat exposure, regulatory obligations and risk appetite — and a costed path to it.
Where the current profile already exceeds what your risk warrants, we say so. Over-investment in one function while another sits exposed is a common and expensive pattern.
Where this fits with regulatory frameworks
NIST CSF is voluntary and structural. If you are also subject to a supervisory framework — SAMA CSF in the Kingdom, the SBP technology framework in Pakistan, or NCA controls — we map the assessment across both so a single evidence exercise serves each, and report separately in each framework's own structure.
How the engagement runs
-
1
Scope and profile
Agree the organisational scope and the target profile appropriate to your risk and obligations.
-
2
Evidence collection
Documentation, configuration, records and metrics — gathered before the interviews, not during.
-
3
Interviews and walkthroughs
Test whether the documented programme is the one people actually operate.
-
4
Scoring
Score each category against evidence, with the specific criterion cited for every score.
-
5
Gap and roadmap
Current versus target profile, with remediation sequenced by risk reduction per unit of effort.
-
6
Board reporting
Present in language a board can act on, with a metric set they can track quarterly.
Why self-assessed scores get revised down
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal