HireACISO

Security maturity assessment, seven domains

Seven questions, one per domain, scored on the screen with a level for each and the single next thing worth doing. Written for someone who has to explain the result to a board rather than to an auditor.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

A maturity score is only useful if it points at what to do next. This scores seven domains, gives each one a level, names your weakest, and puts one concrete action against every domain. It takes about four minutes and the whole result is on the screen.

Answer as things actually are rather than as they are meant to be. A score that flatters the program is worth nothing to you and will not survive an auditor or an underwriter.

Governance: who owns security and how are decisions made?

Risk: do you know what you are exposed to?

Access: who can get to what, and how do you know?

Operations: patching, logging, endpoints and backups

Incident response: what happens at two in the morning?

Third parties: the suppliers holding your data

Compliance: frameworks and the law that already applies

How the scoring works

Each domain scores 0 to 3, so the total runs 0 to 21. The bands are Ad hoc at 0 to 5, Developing at 6 to 10, Defined at 11 to 15, Managed at 16 to 19, and Leading at 20 or 21. Those names are the common maturity vocabulary rather than a proprietary model, which is deliberate: a score from a model only that provider uses is a score you cannot compare to anything or take with you.

The overall number is the least interesting output. What matters is the spread. A program at Defined overall with access at 0 is in worse shape than one sitting at Developing evenly, because a single weak domain is where incidents and audit findings actually come from. The result names your weakest domain for exactly that reason.

Using the result with a board

Show the same seven domains every quarter with last quarter's number beside this quarter's. The movement is what a director can act on, and a single score without a trend invites the reasonable question of whether 2.8 is good. The board report template sets out where this sits in a full quarterly paper and what else belongs alongside it.

Do not let the score replace the risk section. A maturity model measures whether practices exist and are followed. It does not measure what would hurt your company most if it happened tomorrow, and those are different questions that boards conflate constantly.

Common questions

What is a good security maturity score for a company our size?

For a Canadian company between 50 and 500 people with no regulator, Defined is a reasonable target and Managed is more than most peers hold. Below Developing you will struggle with enterprise security reviews and with a cyber insurance application. Regulated companies and anyone holding health data should be aiming at Managed, because the obligations do not scale with headcount.

Is this the same as a SOC 2 or ISO 27001 readiness assessment?

No. This measures whether practices exist and are followed across seven domains. A readiness assessment maps your controls against the specific criteria of a named framework and produces an evidence gap list. This is the cheaper, faster view that tells you whether readiness work is worth commissioning yet, and the two are complementary rather than substitutes.

Our weakest domain is access. Where do we start?

With an inventory of who has access to what, including administrative and service accounts, followed by multi-factor authentication on everything that inventory turns up. That single artifact answers a disproportionate share of every security questionnaire you will receive, and it is the control most likely to be the one that saves you. Do it before buying anything.

Should we re-run this after hiring a vCISO?

Re-run it quarterly regardless, with the same person answering, because consistency of assessor matters more than precision. If you do bring in a vCISO, score the program the week before they start so the baseline is yours rather than theirs. Providers grade generously at the start and strictly at renewal, and having your own baseline removes the argument.