What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
Assurance review AI estate inventory Model evaluation & red team Human risk & impersonation defense API discovery & governance Cloud security posture assessment Infrastructure design review Managed detection & response Cybersecurity maturity & risk assessment OT & industrial cybersecurity assessment
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team

Engagement  ·  Cybersecurity Maturity & Risk Assessment Measure the Program, Not the Policy.

Your security program measured against NIST CSF 2.0, C2M2 and the CIS Controls, mapped to the regional requirements that apply, and scored so progress can be shown rather than asserted. You leave with a baseline, a risk register and a roadmap.

Duration set at scopingAI CybersecurityNIST CSF 2.0 · C2M2 · CIS
Request a Maturity Assessment

What this is

Cybersecurity Maturity & Risk Assessment

A Cybersecurity Maturity & Risk Assessment is the broad entry point to your security program. It measures how each function actually operates (govern, identify, protect, detect, respond and recover) against NIST CSF 2.0, the Cybersecurity Capability Maturity Model (C2M2) and the CIS Controls, maps the result to the regional requirements you are held to, and scores it so the next review can show movement against the same baseline.

Where You Stand

Four statements · self-check

Answer honestly.

0 / 4 ANSWERED

You could show a board this year's security posture against last year's, on the same scale.

Each critical control has a named owner and evidence that it operated this quarter.

Your top ten cyber risks are written down, each with an owner and a decision against it.

You know which regional requirements apply to you, and where you stand against each.

Reading

Answer all four to see where you stand.

Nothing is sent anywhere. This runs entirely in your browser.

Deliverables

What You Get

01

Maturity Baseline

Every function scored against NIST CSF 2.0 and C2M2, with the evidence behind each score recorded.

02

Control Coverage

The CIS Controls that apply to you, each marked implemented, partial or absent.

03

Regulatory Mapping

The baseline mapped to the regional requirements you are held to, gap by gap.

04

Risk Register

Ranked by likelihood and impact, each risk with an owner and the decision it needs.

05

Prioritized Roadmap

Sequenced by risk reduction, with the effort each step takes and what it moves.

06

Board Summary

Where you stand, where you are going, and the scale both are measured on.

Questions We Are Asked

Which framework do you score against?
NIST CSF 2.0 for the program as a whole, C2M2 for maturity levels, and the CIS Controls for implementation detail. The result is mapped to the regional requirements that apply to you, such as those of your national cybersecurity authority or financial regulator, so one assessment answers all of them. Maturity is expressed on a five-level scale in the style of CMMI, but the method itself is the cybersecurity frameworks, not generic CMMI.
How is this different from an audit?
An audit checks compliance at a point in time and reports pass or fail. This assessment measures maturity on a scale, explains what each score rests on, and is designed to be repeated, so the second run shows how far the program has moved.
Is this the same as the Assurance Review?
No. The Assurance Review is specific to AI systems and the obligations around them. This assessment covers the whole security program. Organizations that run AI in production often do both, starting with whichever their regulator asks about first.
Do you need access to our systems?
Mostly to people and documents. The assessment works through interviews, review of policies and procedures, and evidence that controls operate. Where a score depends on a technical fact, we verify it with a targeted check agreed in advance.
What happens after the assessment?
You hold the roadmap and can execute it with anyone. If you want Orvix to deliver parts of it, that is agreed separately, and a re-assessment on the same baseline is the usual way to show the board what changed.

Where This Usually Leads

Related engagements

Start here

Start with a Baseline.

A fixed-scope assessment of your security program against NIST CSF 2.0, C2M2 and the CIS Controls, mapped to the regional requirements that apply, with a risk register and a prioritized roadmap. Fixed fee, scope agreed up front.

Request a Maturity Assessment

A score you can defend is worth more than a posture you can describe.