Scope and critical service selection
An assessment does not survey the whole organization at equal depth; it starts from critical services. Which service stopping stops the business is answered by the business, and technical scope is derived from that answer.
- Criticality is the business's call, technical scope is ours
- Whatever is excluded is recorded with its reason
- Third-party dependencies belong inside the scope
- Depth is proportional to the criticality of the service
Measuring capability
Measurement covers four areas: detect, respond, recover and learn. For each, what the organization can do today is established from evidence — observed behavior rather than written procedure.
- Evidence comes from records, not from procedure documents
- Detection time is calculated from past incidents
- Recovery capability is confirmed by rehearsal records
- Learning is measured by the rate of findings closed
Scenario work
Concrete scenarios replace abstract maturity: what happens if ransomware spreads, if a privileged account is taken, if a supplier reports a breach. A scenario makes visible who actually holds each decision.
- Scenarios run against your real architecture
- Decision points and decision owners are marked
- The communication chain is exercised inside the scenario
- Output feeds directly into a plan update
Roadmap and ownership
A findings list produces no work by itself. Each finding is ranked by impact and cost to close, then tied to an owner and a date. A finding without an owner disappears when the report closes.
- Ranking weighs impact and cost together
- Every finding has exactly one owner
- Quick wins are collected on a separate list
- Progress is remeasured on the same scale