The whitepaper, in three sections
Six functions, one maturity rubric.
The paper walks each of the six functions in the canonical CSF 2.0 order — with the rubric categories the practice uses in briefings, the level each maps to, and the note that prompts the questions in the first conversation.
Govern
The organizational context for cybersecurity risk. Policies, roles, supply-chain obligations, and the cadence that makes all of the above survive staff turnover.
Sample rubric categories
- L2
Governance policy
Documented and reviewed annually.
- L1
Risk register
Maintained in a single system of record.
- L2
Supplier obligations
Contractual controls tracked.
3 rubric categories · 3-point scale
Identify
Asset inventories, data classification, and the dependency map that lets a defender answer "what runs on what" without opening five dashboards.
Sample rubric categories
- L2
Asset inventory
All accounts enumerated and tagged.
- L1
Data classification
Boundaries recorded at the workload level.
- L3
Business environment
Mapped to lines of business.
3 rubric categories · 3-point scale
Protect
Identity, access, secure configuration, and the data-protection primitives a regulated mid-market firm should be running on day one of the engagement.
Sample rubric categories
- L3
Identity & access
SSO + least privilege enforced.
- L2
Secure configuration
Baselines tracked per workload.
- L2
Data protection
Encryption at rest + in transit.
3 rubric categories · 3-point scale
Detect
Logging, monitoring, and anomaly detection that produces a defensible timeline during the 72 hours after an incident, not the 72 hours before the auditor asks.
Sample rubric categories
- L2
Continuous monitoring
Centralised log aggregation.
- L1
Detection coverage
Critical workloads instrumented.
- L2
Alert routing
Ownership assigned at queue level.
3 rubric categories · 3-point scale
Respond
The runbook, the communication plan, and the people who own the response — including who signs the regulatory disclosure when one is owed.
Sample rubric categories
- L1
Response plan
Documented and tabletop-tested.
- L2
Communications
Internal + external templates filed.
- L0
Disclosure readiness
Roles not yet assigned.
3 rubric categories · 3-point scale
Recover
Restoration playbooks, lessons-learned rituals, and the post-incident reporting that makes the next response cheaper than the last.
Sample rubric categories
- L2
Recovery plan
RTO/RPO documented per workload.
- L1
Improvements
Findings flow to backlog.
- L1
Validation
Restored environments re-tested.
3 rubric categories · 3-point scale
Sample rubric · 0–4 scale
L0
Absent
No documented control.
L1
Initial
Ad-hoc, owner unclear.
L2
Repeatable
Documented, owner assigned.
L3
Defined
Reviewed on a cadence.
L4
Adaptive
Measured and improved.
The paper shows how a regulated mid-market firm self-scores each function in ~30 minutes with the rubric above, then maps the lowest-ranked categories to the next engagement — a governance remediation, a FinOps programme, or the fractional advisor retainer.