Practice · Cybersecurity
Turn security posture into a board-ready plan.
Score a client's security posture against the standard they're held to, whether that's SOC 2, ISO 27001, NIST CSF or PCI DSS. Every score is evidenced from their own policies and controls, not opinion, and handed back as a board-ready report.
UK regulatory coverage: 3 of these 13 frameworks are UK-specific, built for firms advising regulated UK clients.
13 frameworks
Cybersecurity frameworks you can run
Each runs an evidence-based maturity or readiness assessment, scored on the standard's own scale.
SOC 2 (Trust Services Criteria)
Run a SOC 2 gap assessment across the five Trust Services Criteria before the audit.
ISO/IEC 27001 ISMS Readiness
Gauge ISMS readiness against the Annex A controls before committing to certification.
NIST CSF 2.0
Score maturity across all six CSF 2.0 functions, evidenced from the client's own controls.
PCI DSS v4.0
Assess cardholder-data security against the PCI DSS v4.0 requirements and SAQ scope.
CIS Controls v8
Benchmark the 18 CIS Controls and implementation groups against real evidence.
Zero Trust (CISA ZTMM)
Rate zero-trust maturity across the five CISA pillars and the gaps to close first.
Cyber Essentials (NCSC)
Check readiness against the five NCSC Cyber Essentials control themes before assessment.
NCSC Cyber Assessment Framework (CAF)
Assess against the 14 CAF principles for NIS-regulated and critical services.
NHS Data Security & Protection Toolkit (DSPT)
Evidence the NHS DSPT standards for health and care organizations.
ISO/IEC 27701 Privacy Information Management
Extend an ISMS to privacy and assess PIMS readiness against ISO 27701.
ISO 22301 Business Continuity
Gauge business-continuity management-system readiness against ISO 22301.
OWASP SAMM
Benchmark software-assurance maturity across the OWASP SAMM business functions.
Third-Party & Supply-Chain Risk
Assess vendor and supply-chain cyber risk and due-diligence maturity.
How it works
From the client's documents to a board-ready deck.
1 · Evidence in
Upload the client's documents: policies, reports, data. An AI interviewer asks targeted follow-ups to fill anything missing.
2 · Scored on the standard
Every dimension is scored on the framework's own scale, with each score traceable to the evidence behind it, and gaps ranked by severity.
3 · Board-ready out
A board-ready slide deck and HTML report are generated automatically: executive summary, maturity landscape and a sequenced plan.
Evidence-grounded, not opinion
Defensible Cybersecurity scores.
Every score links back to the evidence it rests on, so the diagnosis holds up in the steering committee. See how evidence is collected and assessments are scored.
- Scored against the standard's own bands, not a generic rubric
- Gaps ranked by severity, ready to become the plan
- Auto-generated slide deck and HTML report for the board

More practices
Explore other assessment practices
Data & AI · Technology · Finance & Risk · Operations · Growth · Strategy & Transformation · Sustainability · Human Capital
Run an assessment on real data.
We'll set up a framework live and score it from your client's own documents.