Approach & Process

How we measure where you stand — and exactly how the work runs.

Two halves of the same promise: first the standard we measure you against, then the disciplined path every engagement follows. No proprietary checklist, no black box — and nothing reaches you until your advisor has reviewed it.

The approach · the standard

What we measure you against.

Securidigm scores your business on the NIST Cybersecurity Framework 2.0 — the U.S. government's cybersecurity standard, free of licensing strings and recognized everywhere. A clear, defensible picture of your posture and the gaps that matter most.

The six functions

Govern, Identify, Protect, Detect, Respond, and Recover — the full arc from setting direction to recovering after an incident. We read across all six, not just the technical bits.

A 0–4 maturity score

0 not done, 1 ad hoc, 2 partial, 3 consistent and documented, 4 measured and improved. You see exactly where you sit and where the targets are.

Sized to your business

Your profile sets a scoping tier, so targets reflect a company your size and risk — not a Fortune 500. Up to 106 control outcomes (Comprehensive covers all 106).

Threat-informed, not just framework-aligned. Our most thorough engagements connect your specific gaps to real attacker behavior using MITRE ATT&CK® — computed from your own scores through a published, version-pinned method, never AI's guess. "Exposure" always means a path is less obstructed, never a prediction.

How AI fits in. AI turns your answers into first drafts of the findings, roadmap, and policy language. Scoring and risk ratings are never AI's call — those are calculated the same way every time, and every draft is advisor-reviewed before it reaches you.

The process · step by step

What the engagement actually involves.

1
Engage

Discovery & scoping

A confidential conversation to understand your business — what you do, what you protect, the obligations you carry — and to set clear terms.

  • Engagement paperwork — services agreement, statement of work, mutual NDA — so terms are clear before we start
  • A scoping tier set with you, so you're measured against what fits a business your size
2
Understand

Business & environment profile

We map how your business actually runs, so every finding is grounded in your reality rather than a generic checklist.

  • Your IT model — in-house, a managed provider (MSP), or hybrid
  • Your systems and cloud tools, the data you hold, and how sensitive it is
  • The regulations and key vendors that shape your risk
3
Assess

Guided assessment

A guided, plain-language review against NIST CSF 2.0 — across all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

  • Up to 106 control outcomes, sized to your tier (Comprehensive covers all 106)
  • Questions in business language, not jargon — worked through together
  • Supporting evidence collected where it's available
4
Measure

Scoring & maturity scorecard

Every answer is scored 0–4 and rolled up by category and function against the target maturity that fits your size and risk tolerance.

  • Current vs. target for each outcome — the gap to close, not just a grade
  • A function-by-function breakdown and weakest-link analysis
  • Transparent and repeatable — the same inputs always produce the same score
5
Quantify

Risk analysis

We translate the gaps into business risk — a register of your top cyber risks, each rated by likelihood and impact, in terms leadership can weigh.

  • Your most significant risks, ranked by severity — so leadership can focus on what drives the most exposure
  • A recommended response for each: reduce, transfer, or formally accept
6
Prioritize

Prioritized remediation roadmap

The findings become a prioritized, sequenced plan — what to fix first, in order of risk, so the path is clear and achievable rather than an undifferentiated list.

  • A 30 / 60 / 90-day remediation roadmap
  • Owners and effort for every item
  • The specific risk each move removes
7
Pressure-test where scoped

Threat-informed analysis

Our most thorough engagements add the attacker's-eye view — your gaps mapped to the real techniques used against businesses like yours (MITRE ATT&CK®).

  • A prioritized technical action plan — the controls that break the attack chain
  • A breach pre-mortem — how an incident would most likely unfold, and where it stalls
  • A detection-gap analysis — would you even see it happen?
8
Equip

Policies, governance & deliverables

Everything a real program needs, produced as finished, firm-branded documents you can use the day you receive them.

  • A tailored policy set — information security, incident response, backup & recovery, vendor and data handling
  • An executive report for leadership and a technical task list routed to your IT team or MSP
  • Cyber-insurance readiness and a formal risk-acceptance record for your board or insurer
  • One navigable package — Word files plus a single web report
9
Assure & sustain

Review, release & ongoing improvement

Your advisor reviews every finding and document before anything is delivered — nothing goes out unchecked.

  • The complete, branded package, released when it's right — yours to act on
  • On a retained (vCISO) engagement: remediation project-managed to closure, policies kept current, and scheduled reassessment with a Posture Improvement Report
One framework · three tiers

Right-sized to your business.

The same NIST CSF 2.0 engine scales to your business. Your scoping tier sets which controls are in scope and what "good" looks like for a company your size — so you're measured against what's realistic, not a Fortune 500.

Smaller · lower-risk

Essential

The foundational controls every business needs — MFA, backups, patching, basic policies, and an incident plan. The right starting point for smaller teams or lower-sensitivity data.

Growing · sensitive data

Enhanced

A broader control set for businesses handling sensitive or regulated data, with dedicated IT or a managing MSP and more on the line if something goes wrong.

Larger · high-stakes

Comprehensive

The full program for larger or higher-risk organizations — formal governance, tested recovery, supply-chain and data-handling policy, and measured, continuous improvement.

Begin

See where you actually stand.

Start with a confidential, no-obligation conversation. We'll scope the right engagement for your business and walk you through what to expect.

Start the conversation →