Security Maturity Assessment: CIS Controls UK Guide

security maturity assessment

Table of Contents

Every UK business wants to be secure — but few can say with confidence how secure they truly are. Firms often spend thousands on antivirus software or firewalls, yet struggle to measure progress. Without a structured security maturity assessment, improvement is guesswork.

The CIS Controls, developed by the Center for Internet Security, provide a recognised framework for identifying, prioritising, and implementing the most effective defences. Combined with a cyber security maturity model, they allow organisations to benchmark their current state and plan measurable, cost-effective improvements.

For professional services firms — where client confidentiality, GDPR compliance, and uptime directly affect revenue — these models aren’t theoretical. They’re the foundation of risk management.

This guide explains how to use CIS Controls within a structured framework to measure and improve security maturity — assessing your current level and planning continuous improvement that aligns with UK compliance standards such as Cyber Essentials, GDPR Article 32, and NCSC guidance.

Understanding Security Maturity Assessment

A security maturity assessment measures an organisation’s ability to identify, protect, detect, respond to, and recover from threats. It’s not a one-time audit — it’s an ongoing process of self-improvement.

The key benefit is visibility. Firms can see where their security posture stands today and what’s required to reach a desired target state. In practice, this allows partners or directors to answer questions like:

  • “Are we spending the right amount on cyber security?”
  • “Where are our biggest gaps?”
  • “How do we prove compliance to clients or regulators?”

The Role of Maturity Levels

Most models divide maturity into five stages:

  1. Initial – Ad hoc, reactive processes; no defined ownership.
  2. Developing – Some policies and controls exist, but inconsistently applied.
  3. Defined – Documented, repeatable security processes.
  4. Managed – Metrics, monitoring, and accountability in place.
  5. Optimised – Continuous improvement culture supported by automation and governance.

Each stage represents a measurable increase in capability and consistency.

Why SMEs Need Formal Measurement

For smaller UK firms, especially in legal or financial sectors, the risk is often not lack of technology — but lack of measurement. Without a security maturity assessment, management assumes tools equal protection. In reality, maturity is about how effectively people, processes, and technology interact.

Applying the CIS Controls Framework

The CIS Controls are a practical, globally recognised baseline. They consist of 18 priority controls covering hardware, software, data protection, identity management, and incident response.

For SMEs, they provide structure: a roadmap for building resilience step by step.

CIS Controls Implementation Tiers

CIS defines three Implementation Groups (IGs):

  • IG1: Basic cyber hygiene for small, low-complexity organisations.
  • IG2: Intermediate maturity — multiple systems, moderate risk exposure.
  • IG3: Advanced — complex environments with high-value data.

Most UK SMEs fall between IG1 and IG2.

Implementing CIS Controls within a cyber security maturity model gives context. Each control can be measured against maturity criteria — from “not implemented” to “optimised.” This turns a static checklist into a measurable improvement programme.

Practical Examples for Professional Services

  • IG1 Controls: Use MFA on all accounts, enable automatic updates, restrict admin privileges.
  • IG2 Controls: Implement centralised logging and regular vulnerability scans.
  • IG3 Controls: Integrate threat hunting and automated response using Microsoft Sentinel.

This structured approach allows firms to benchmark progress annually and demonstrate compliance to clients, insurers, and regulators.

Mapping CIS Controls to a Cyber Security Maturity Model

A cyber security maturity model provides the measurement lens for CIS Controls. The model translates control adoption into maturity levels — making improvement visible.

Step 1: Define Assessment Criteria

Start by setting consistent evaluation criteria:

LevelDefinitionExample Metric
1InitialNo documented policy or ownership
2RepeatablePolicy drafted; inconsistent execution
3DefinedControl implemented; evidence available
4ManagedRegular review, monitoring, metrics gathered
5OptimisedContinuous improvement cycle in place

Each CIS Control can be scored against these levels.

Step 2: Conduct a Baseline Assessment

A security maturity assessment uses interviews, technical scans, and policy reviews to score each control. The output is a heatmap showing current versus target maturity.

For example, a law firm may score “2” (repeatable) on access control but “4” (managed) on patch management. That difference highlights where to prioritise investment.

Step 3: Plan and Track Improvement

The goal isn’t perfection; it’s progress. Set achievable targets — e.g., move all IG1 controls to Level 4 within six months.

How to Perform a Security Maturity Assessment

While external audits can help, SMEs can begin their security maturity assessment internally using structured templates and CIS Controls as benchmarks.

Step 1: Gather Documentation

Collect policies, procedures, and evidence of controls. Examples include password policies, backup schedules, and endpoint management logs.

Step 2: Interview Key Stakeholders

Speak with management, IT support, and users to understand day-to-day security practices. Many gaps appear not in technology but in behaviour.

Step 3: Score Each Control

Use the 1–5 scale to rate every CIS Control. If your MFA policy covers 90% of users, score 3. If 100% coverage and quarterly testing are in place, score 4–5.

Step 4: Visualise the Results

Present findings as a radar or heatmap. This transforms complex data into an executive-level summary, ideal for board reporting or Cyber Essentials readiness.

Step 5: Benchmark Annually

A maturity assessment should recur annually — like financial audits. The difference between years becomes your measure of improvement.

Benchmarking and Measuring Progress

The main value of a cyber security maturity model lies in tracking progress over time. One-off projects fade; measurement sustains momentum.

Setting Measurable Objectives

Each control should have a measurable target:

  • 100% MFA adoption across all staff.
  • Patch deployment within seven days of release.
  • Incident response exercise every quarter.

Link these metrics to maturity levels. For instance, “Managed” means metrics are tracked; “Optimised” means metrics drive decisions.

Reporting to Stakeholders

Partners and directors want clarity, not technical detail. Dashboards showing year-on-year improvement in control maturity make security visible to non-technical leaders.

For example, an accounting firm could report:

“Security maturity improved from 2.3 to 3.8 over 12 months, reducing phishing incidents by 46% and improving Cyber Essentials audit readiness.”

Aligning with UK Compliance Standards

CIS Controls map naturally to GDPR Article 32 and the NCSC’s Cyber Assessment Framework. Achieving Level 4 maturity across IG1 controls typically ensures Cyber Essentials compliance and lowers insurance premiums.

Continuous Improvement and Long-Term ROI

Security maturity isn’t a destination — it’s a process. Every quarter brings new threats, technologies, and regulations. Firms that embed continuous measurement spend less reacting to crises and more improving strategically.

From Reactive to Proactive

Moving from Level 2 to Level 4 on the maturity scale can reduce security incidents by 40–60%. More importantly, it shifts culture: IT becomes a business enabler, not a cost centre.

Leveraging Microsoft 365 Security Tools

Microsoft 365 provides native tools that map directly to CIS Controls — Defender for Endpoint, Intune, Conditional Access, and Sentinel. Integrating these into your security maturity assessment reduces cost and simplifies reporting.

ROI Example

A 40-person law firm investing £3,000 in structured maturity improvement (training, MFA rollout, logging) prevented two major phishing incidents within a year, saving approximately £12,000 in downtime and lost billable hours.

The following sections expand on practical examples and controls.

Conducting a Security Maturity Assessment in Practice

Many UK firms start their security maturity assessment with enthusiasm but lose momentum because they lack a clear process. Below is a practical walkthrough tailored to small and mid-sized professional-services organisations — those without dedicated CISOs but with regulatory pressure to demonstrate compliance.

Step 1: Define Scope and Objectives

The biggest mistake is trying to assess everything at once. Begin with core business assets — client data, Microsoft 365 accounts, and critical financial systems. Define why you’re assessing maturity:

  • To meet Cyber Essentials or ISO 27001 requirements?
  • To satisfy a client or insurer audit?
  • To plan your 12-month security roadmap?

Once objectives are clear, align them with the CIS Controls Implementation Group most relevant to your size. Most small firms fit within IG1 or IG2.

Step 2: Build an Assessment Team

Even small organisations need multiple perspectives. A typical team might include:

  • Managing Partner or Director – ensures business alignment.
  • IT Manager or external MSP – provides technical insight.
  • Compliance or Finance Lead – ensures GDPR and regulatory coverage.

This cross-functional approach ensures the cyber security maturity model reflects operational reality, not just IT opinion.

Step 3: Use the CIS Controls Self-Assessment Tool

The Center for Internet Security offers a free assessment spreadsheet that maps each control to maturity levels. Adapt it with UK context — for example, referencing Cyber Essentials requirements for MFA and patch management.

Each control can be scored “0–5,” with short comments describing evidence. Use screenshots, policy documents, or service reports to justify scores.

Step 4: Review Gaps and Prioritise Actions

Not all gaps are equal. Use a risk matrix combining likelihood and impact. For instance:

  • High likelihood + high impact: MFA not enforced for remote users.
  • Medium likelihood + high impact: Backups untested for 12 months.
  • Low likelihood + medium impact: Outdated print drivers on isolated devices.

This pragmatic method avoids perfectionism and focuses resources where they prevent real loss.

Step 5: Communicate Findings in Plain English

Senior partners and directors often glaze over when presented with technical dashboards. Translate results into business outcomes:

  • “We reduced phishing risk by 40% through MFA.”
  • “Our backup recovery time decreased from 24 hours to 4 hours.”
  • “Client data is now encrypted at rest and in transit.”

That clarity builds executive support and justifies continued investment.

Case Study: How a UK Accounting Firm Used CIS Controls to Improve Maturity

To illustrate what measurable improvement looks like, consider a 35-person accounting practice based in Belfast — a typical INNOSEC client.

The Starting Point

The firm had basic antivirus and firewall protection but no structured security maturity assessment. Its systems were stable, yet incidents were rising — two phishing attempts per month and a failed ransomware attack in early 2024. The partners wanted to strengthen defences before renewing cyber insurance.

Step 1: Baseline Review

Using CIS Controls IG1 as the benchmark, INNOSEC conducted an initial maturity review. Average scores were 2.1 out of 5, meaning processes were defined but inconsistently applied. MFA covered only senior staff, and patching was manual.

Step 2: Prioritised Roadmap

Within six weeks, INNOSEC delivered a plan focusing on high-impact, low-cost improvements:

  • Enable MFA across all Microsoft 365 accounts.
  • Implement centralised endpoint management with Intune.
  • Configure automatic patching and monthly vulnerability scans.
  • Conduct a user awareness campaign (30-minute training).

These mapped directly to CIS Controls 4, 5, 7, and 14.

Step 3: Implementation and Tracking

Progress was tracked through quarterly cyber security maturity model reviews. Within three months, average maturity rose to 3.6, classified as “Defined.” Incidents dropped by 55%, and the firm achieved Cyber Essentials Plus certification.

Step 4: Measurable Outcomes

By the end of the year, the firm’s insurance renewal quote decreased by 22% (£1,100 annual saving). Partners reported fewer client interruptions and smoother audits. The maturity journey became part of quarterly management reporting.

This example demonstrates that maturity isn’t abstract theory — it’s measurable risk reduction tied to financial outcomes.

Integrating Maturity Models into Business Strategy

A security maturity assessment shouldn’t live in an IT silo. When integrated into wider business strategy, it becomes a management tool for resilience and governance.

Linking Security Maturity to Business KPIs

Firms already track utilisation, billable hours, or client satisfaction. Adding security KPIs strengthens that dashboard. Typical examples include:

  • Percentage of systems within patch compliance.
  • Number of phishing reports vs. successful clicks.
  • Average time to revoke access for leavers.

These metrics correlate directly with CIS Controls and can be plotted against maturity stages for board review.

The Board’s Role in Oversight

Under GDPR and the UK Companies Act, directors are personally responsible for ensuring “appropriate technical and organisational measures.” A cyber security maturity model provides defensible evidence that they are fulfilling that duty.

Boards can ask three questions each quarter:

  1. What is our current maturity score?
  2. What improvements have we made since last quarter?
  3. What evidence demonstrates control effectiveness?

This governance structure reduces exposure during regulatory or client audits.

Embedding Continuous Improvement

Once maturity tracking becomes routine, it supports other business initiatives such as ISO 27001, SOC 2 readiness, or Cyber Essentials renewal. Each quarter’s improvement cycle feeds the next, turning compliance into habit.

Cultural Impact

Perhaps the biggest benefit is behavioural. When employees see progress visualised — a dashboard moving from “Amber” to “Green” — engagement rises. Staff feel part of the security story, not just subject to IT rules.

One London-based legal firm reported a 70% reduction in phishing clicks after adding a “Maturity Tracker” board in its Teams channel, showing live progress across CIS Controls.

Expanding on Benchmarking: Building a Security Scorecard

Benchmarking doesn’t stop with internal comparisons. Many professional-services firms now share anonymised metrics through industry groups or insurance brokers to understand how they perform relative to peers.

Internal Benchmarks

Internal benchmarks use last year’s data as the baseline. For example, a 20% rise in CIS Control implementation or a two-level improvement on the cyber security maturity model indicates progress.

External Benchmarks

External benchmarks allow firms to compare against industry averages. For example, an FCA-regulated firm may target maturity Level 4 on access control and patch management — matching sector norms identified in government Cyber Breaches Surveys.

Building a Scorecard

A balanced scorecard might include:

  • Technical: Patch compliance rate, MFA coverage.
  • Process: Number of security policies reviewed.
  • Cultural: Phishing simulation success rate.
  • Compliance: Cyber Essentials or ISO status.

Each metric links to one or more CIS Controls, allowing directors to see at a glance where maturity is improving and where risk remains.

Insurance, Clients, and Audit Readiness

Many UK firms now face mandatory cyber-risk questionnaires from insurers or major clients. The answers often determine renewal rates or contract eligibility.

A well-maintained security maturity assessment simplifies this process:

  • Insurers view maturity data as quantifiable evidence of reduced risk.
  • Clients gain confidence that data-handling meets industry standards.
  • Auditors receive clear documentation for GDPR Article 32 compliance.

In 2025, several insurers, including Hiscox and Aviva, introduced premium incentives for firms demonstrating maturity improvements over 12 months. Reporting CIS Control adoption alongside score progression has become the new standard for risk disclosure.

Common Pitfalls and How to Avoid Them

Treating Assessment as a One-Off Project

Security maturity is not a pass/fail test. Without continuous review, progress stalls, and initial enthusiasm fades.

Ignoring People and Process

Technology gaps are easy to fix; behaviour is harder. Regular staff training, phishing simulations, and clear policies ensure CIS Controls translate into everyday habits.

Overcomplicating Metrics

Start small. Track no more than 10 key metrics in your first year. Expanding too quickly overwhelms non-technical managers.

Failing to Align with Compliance

Tie every improvement to a UK regulation or client requirement. For example, linking access control to SRA confidentiality principles or GDPR Article 32 makes improvements tangible.

Lack of Executive Sponsorship

Without board-level champions, assessments become IT paperwork. Show ROI — reduced downtime, lower insurance, stronger client trust — to secure lasting support.

Extended FAQ

How does a security maturity assessment reduce cyber insurance costs?

Insurers price risk based on control effectiveness. By documenting maturity improvements through CIS Controls, you demonstrate lower exposure. Firms with verified MFA, endpoint protection, and tested backups often qualify for 15–25% premium reductions.

How can we present results to the board?

Use a visual dashboard with five columns for each maturity level and 18 rows for CIS Controls. Highlight each control’s current score and target. Include trend arrows and short business impacts (“Improved patching reduced downtime by 8 hours per month”). Boards respond to visuals, not jargon.

Is it worth using an external provider?

Yes — particularly for small firms lacking internal IT capacity. External assessors bring objectivity, validated scoring, and industry benchmarks. INNOSEC typically delivers a baseline security maturity assessment within two weeks, including a 12-month improvement roadmap.

Can a maturity model integrate with ISO 27001?

Absolutely. CIS Controls map closely to ISO 27001 Annex A controls. Many firms use CIS as the “how” to ISO’s “what,” aligning technical implementation with compliance objectives.

What’s the difference between a cyber security maturity model and a risk assessment?

A risk assessment identifies threats and vulnerabilities; a cyber security maturity model measures how well you manage them. The two work together — risk defines what to protect, maturity defines how effectively you protect it.

Conclusion

A structured security maturity assessment allows UK SMEs to move from reactive to proactive security management.

Key takeaways:

  • CIS Controls offer a step-by-step roadmap for cyber defence.
  • Maturity models turn controls into measurable improvement.
  • Annual reassessment quantifies progress and ROI.
  • UK frameworks like Cyber Essentials align naturally with CIS Controls.
  • Continuous improvement delivers compliance confidence and resilience.

Improve Your Firm’s Security Maturity

Most professional-services firms can reach Level 4 maturity within 12 months with focused effort and CIS-aligned planning.

Contact INNOSEC to book your free Microsoft 365 Security Assessment. We’ll benchmark your current security maturity, identify improvement opportunities, and deliver a practical roadmap aligned to CIS Controls and UK compliance standards.

Frequently Asked Questions

What is a security maturity assessment?

It’s a structured review that measures how effectively your organisation manages cyber risk. Unlike a simple audit, it benchmarks people, process, and technology performance against recognised frameworks like the CIS Controls.

How often should SMEs conduct a security maturity assessment?

At least annually. Quarterly reviews are ideal for high-risk sectors such as finance or law, ensuring that improvements are tracked and reported to stakeholders.

How do CIS Controls help small firms?

CIS Controls break down cyber security into manageable actions. By following Implementation Groups 1–3, even small firms can prioritise what matters most and reduce risk efficiently.

What is a cyber security maturity model?

It’s a scale (typically Levels 1–5) that measures how consistently and effectively security controls are applied. It helps track progress and prove compliance.

Can a security maturity assessment help with Cyber Essentials certification?

Yes. CIS Controls and maturity assessments map closely to Cyber Essentials and NCSC guidance, simplifying certification and demonstrating continuous compliance.

02890 025 435

hello@innosec.co.uk

Unlock the Future of Work with Microsoft Copilot!

microsoft ebook cover ebook cover

50 Reasons Why Your Business Should Be Using Microsoft Copilot

💼 Supercharge Productivity
🛡️ Boost Security
📊 Empower Data-Driven Decisions

This website uses cookies

We use cookies to personalise content, provide social media features, and analyse our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy and Cookie Policy.

02890 025 435

hello@innosec.co.uk