Skip to main content
  • Enterprise IT & cloud
  • Payments & fintech

Security Maturity Review

Your security organisation and your controls: who decides, who owns what, and which controls are running.

Why we test it this way

The binding constraint is rarely a missing product. It is that nobody owns a decision, or the team that would fix something never hears about it, or a control was bought and never finished being deployed. Those are properties of an organisation, not of a control set, so the review covers both together and says where your next unit of effort goes furthest.

Each row is one dimension on a four-step scale. The filled block is where the organisation sits today and the dashed one is the target agreed with it, so the gap between them is the plan.

Assessed bottom-up, by testing

  • Systems hardened and patched
  • Vulnerabilities managed
  • Privileged access controlled
  • Systems monitored

Assessed top-down, by documentation and interview

  • Governance streamlined
  • Architecture secured
  • Users aware and accountable
  • Stakeholders crisis-ready

Illustrative positions. Filled is today, dashed is the agreed target.

Eight dimensions, four of them organisational and four technical. Four are assessed top-down, by reading the documentation and interviewing the people who own the work, and four bottom-up, by testing: internet and internal exposure scans, an IAM review, endpoint and server baseline checks. The comparison is against security practice in comparable organisations rather than against a checklist standard. The output is a rating on each of the eight, and a split between what can be fixed in weeks and what is a year of work. Those are different conversations with different budgets, so they are reported separately.

What we found

Our Hackability Score puts organisations on a single scale from an Internet survey alone, which makes comparison across industries and regions possible. It reads four things an outsider can see: identity and access management, security architecture, asset hardening and patch management. We built it by scanning more than 5,000 companies across geographies and verticals. In that data, from 2018, banks came out among the three best-protected industries. The score reads only what is visible from the Internet. It says nothing about endpoint security and nothing about whether anyone inside those banks would click a link, and we have not re-run it since.

How

Internet-wide scanning across four directly measurable areas, scored per organisation and aggregated by industry and region.

What it does not support

It reads only what is visible from the Internet. It says nothing about endpoint security and nothing about social-engineering resilience, and it has not been re-run since 2018.

The Hackability of organizations can be measured and compared

Banks scored above other industries, but not evenly across the sub-scores: the areas an auditor looks at were ahead, and the areas an auditor does not were behind. Regulation moved attention, not security.

How

Compared the shape of the Hackability sub-score distribution for banks against other industries, testing two competing explanations: security evolution under attack pressure, versus compliance-directed effort.

Banking regulation has an effect on Hackability

Where engagements usually start

Maturity review

We assess your technical controls and your security organisation against your actual threat profile.

  • Technical controls, including whether they are fully deployed
  • Ownership and decision rights: who can approve, who can block, who finds out
  • How findings travel from whoever discovers them to whoever fixes them
  • Assessed against the threats that apply to your business, not a generic model

Immediate improvements

The subset of findings that can be closed in weeks, separated out so they actually get done.

  • Fixes that need no new budget or headcount
  • Controls you already own but have not finished deploying
  • Ordered by risk removed per week of work
  • Owners named against each one

Longer-term programme

The structural changes, planned properly, with the sequencing that makes them survive.

  • Initiatives sized and sequenced against dependencies
  • What each one needs in budget and people, stated plainly
  • Designed around how your business actually operates
  • Checkpoints where we expect to be wrong and will re-plan

The eight dimensions

Four are assessed top-down, by documentation and interview. Four are assessed bottom-up, by testing.

How the organisation runs

  1. 1 Governance streamlined Who sets security policy, who audits it, and whether either has authority.
  2. 2 Architecture secured Whether security concepts reach your technical platforms, or stop at the document.
  3. 3 Users aware and accountable Whether the people with access to your data handle it safely, and know they are answerable for it.
  4. 4 Stakeholders crisis-ready Whether you could run a hacking crisis when every other control has already failed.

How the technology holds

  1. 5 Systems hardened and patched How much hacking your systems resist as configured and as patched today.
  2. 6 Vulnerabilities managed Whether flaws in your systems and applications get found, and then fixed.
  3. 7 Privileged identities and access controlled Who can reach your systems with elevated rights, and who decided that.
  4. 8 Systems monitored Whether you would see abuse of your own systems while it was happening.

How we work

We interview the people doing the work as well as the people accountable for it, and the gap between the two accounts is usually where the finding is. The technical half is measured, not asked about: internet and internal exposure scans, an IAM review, endpoint and server baseline checks, the same reading that produced the Hackability data across more than 5,000 companies. What is deployed matters more than what was purchased, so the technical checks read running configuration. A recommendation that needs a reorganisation before anyone can adopt it is worth little. We write the report so the person who has to act on each item can find their own part without reading all of it.

Send us the problem

Tell us what you are building and what you need looked at. You will get an answer from the people who would run the engagement, and if another firm is the better fit for what you are asking, we will name one.

Get in touch

Security Research Labs is a member of the Allurity family. Learn more(opens in a new tab)