Skip to main content

Methodology

Every assessment in the portfolio runs through the same six phases, is scored on the same five-level maturity scale, and ends with the same board-ready deliverable set. The subject changes; the discipline does not.

The six phases

Phase 1 Scope and Planning

Activity

Confirm business units, systems, locations, vendors, assessment objectives, stakeholders, and success criteria.

Output

Approved scope, stakeholder list, assessment plan, and document request list.

Phase 2 Evidence Collection

Activity

Review policies, procedures, system configurations, audit logs, architecture diagrams, contracts, recovery plans, and prior audit findings.

Output

Evidence inventory and initial control observations.

Phase 3 Interviews and Workshops

Activity

Conduct interviews with IT, security, risk, compliance, business continuity, legal, procurement, and business process owners.

Output

Validated process understanding, control ownership, and dependency mapping.

Phase 4 Control and Maturity Testing

Activity

Evaluate design effectiveness, operating effectiveness, maturity level, risk exposure, and control gaps.

Output

Assessment results, maturity ratings, and risk-ranked findings.

Phase 5 Validation

Activity

Discuss findings with control owners to confirm accuracy, context, root cause, and remediation feasibility.

Output

Management-validated findings and agreed action owners.

Phase 6 Executive Reporting

Activity

Prepare a board-level summary, heatmap, roadmap, risk themes, and priority decisions.

Output

Final board report, action plan, and implementation roadmap.

Scoring

Findings are rated on a five-level maturity scale, applied per control domain, so results can be compared across assessments and tracked over time.

1 Initial / Ad Hoc
Controls are informal, inconsistent, undocumented, or dependent on individual effort.
2 Developing
Some controls exist, but coverage, ownership, testing, or evidence is incomplete.
3 Defined
Controls are documented, assigned, and implemented across most relevant areas.
4 Managed
Controls are monitored, tested, measured, and supported by regular reporting.
5 Optimized
Controls are continuously improved, automated where practical, and aligned with risk appetite and business resilience objectives.

Deliverables

Deliverables included with each assessment
Deliverable Purpose
Executive Summary Board-level view of current state, major risks, priority actions, and decisions required.
Assessment Report Detailed findings, evidence reviewed, control gaps, maturity scores, and observations.
Risk Heatmap Visual prioritization of high, medium, and low risks by likelihood and impact.
Maturity Scorecard Capability rating by domain, category, or control area.
Remediation Roadmap Prioritized action plan with owners, timelines, dependencies, and expected risk reduction.
Management Action Plan Agreed corrective actions, accountable owners, target dates, and a tracking mechanism.
Board Dashboard Concise metrics for ongoing oversight, trend monitoring, and investment decisions.
Risk heatmap (illustrative)

An illustrative five-by-five risk heatmap plotting likelihood against impact, with risk intensity increasing toward the top right.

Assessments align with NIST CSF 2.0, ISO 27001, CIS Controls, PCI DSS, GDPR, and Zero Trust architecture principles.

Start with a scoping conversation

Phase one begins with your objectives, stakeholders, and systems. The document request list follows from scope, so nothing is collected that is not needed.

Request a scoping call