Experiencing a security incident? Emergency Response

Resources

Measuring security maturity: the method behind our Maturity Check

2026-07-20 · 6 min read

When we published our Security Maturity Check, we made a decision: publish the method too. The value of an assessment starts with knowing how it is calculated.

Why 6 domains?

The assessment looks at the same six domains as our service catalog: offensive testing, application security, vulnerability management, monitoring and response, threat intelligence, governance and compliance. That is not a marketing trick but a deliberate alignment. We translated the NIST CSF functions of Identify, Protect, Detect, Respond and Recover into domains that have a counterpart in enterprise purchasing language. The domain where you score lowest is also the address of the kind of work you need.

Why 4 levels?

Each question takes four answers: no, partially, yes but ad hoc, yes with a defined process. The scale is a simplified form of CMMI-style maturity models. The critical distinction is between the last two: a control existing and that control being a defined, repeatable, measured process are different maturity levels. A vulnerability scan that happens once a year because someone remembered is a "yes", but it is not a process.

How is the score calculated?

Each domain has 4 questions, each answer scores 0 to 3 points. Domain scores are out of 12, the total is out of 72, converted to a percentage. We use four maturity bands: Initial (0-25%), Developing (26-50%), Defined (51-75%), Managed (76-100%). The band names are deliberately modest; no self-assessment tool can credibly measure a fifth "optimizing" level.

The limits of this tool

Let's be honest: a 24-question self-assessment does not replace an audit or a penetration test. Answers are declarations, not verified facts. The tool's purpose is not a definitive diagnosis but a prioritized starting point: where you are weakest and where the first investment should go. The precise picture only comes from evidence-based work, which is why the results screen offers you a report with expert commentary.

Where is your data processed?

Nowhere. Scoring runs entirely in your browser with JavaScript; your answers reach us only if you request the detailed report, with your consent. If you don't, everything is gone when you close the page. A security company's assessment tool should not be an excuse to harvest data.

Let's build your defense together.

Whether a single penetration test or an end-to-end security program, let's clarify your needs in a 30-minute introductory call.