Skip to content

Home Expertise / Audits & assessments

AUD / AUD-01

Cybersecurity maturity assessment

A review of practices, tools and responsibilities to decide what to secure first, rather than starting with a product purchase.

WHEN IT HELPS

A focused response
to a defined need.

Executives or IT leaders without a roadmap, fragmented spending, or questions from a customer or insurer.

AT A GLANCE

Family
Audits & assessments

Engagement
Assessment

Reference
AUD-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Business and IT interviews
  • review of sampled evidence
  • assessment of gaps and prioritisation by business impact

Deliverables

  • Executive summary
  • gap map
  • roadmap with owners and dependencies

Acceptance evidence

Each priority links to a risk, evidence and an owner; unexamined areas are identified.

DELIVERY

How the work is structured.

Approach

Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.

Prerequisites & responsibilities

Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.

Scope factors

Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.

Questions to clarify

Which activity cannot stop? What evidence already exists? Who approves investment priorities?

IMPORTANT BOUNDARIES

A maturity assessment is not a penetration test, proof of no compromise, or certification.

Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A 120-person SME has accumulated tools after incidents. Project: review accounts, backups and governance. Target outcome: three justified workstreams, a budget proposal and an executive decision instead of another shopping list.

Scenario 02

A group has five subsidiaries with unknown security levels. Project: apply a shared assessment grid with sampled evidence. Target outcome: a group baseline and local exceptions; a subsidiary lacking evidence is marked “not assessed”, not given a reassuring score.

Technology and reference context

ANSSI guidance and NIST CSF; evidence-gathering tools selected during scoping.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.