The assessment organises cybersecurity resilience into six connected capability groups: Governance and Risk Management, Threat Intelligence and Situational Awareness, Preventative Security Controls, Detection and Response, Resilience and Recovery, and Culture and Capability Development. Together, these areas provide a broad operational and governance view of how the organisation anticipates threats, protects critical assets, detects incidents, responds effectively, recovers essential operations and develops sustained human capability.
Governance and Risk Management
Governance and Risk Management addresses the strategic and structural elements of cybersecurity within the organisation. It ensures cybersecurity policies align with business objectives, legal obligations, and regulatory requirements. It encompasses risk identification, assessment, and mitigation strategies, clearly defined roles and responsibilities, and the governance of third-party relationships. A strong governance framework provides oversight, accountability, and proactive risk management to maintain security resilience. This capability group is foundational for integrating cybersecurity into enterprise-wide decision-making and ensures that the organisation is positioned to respond effectively to both internal and external cybersecurity risks.
- Cybersecurity Strategy and Policy Alignment
- Risk Identification and Assessment
- Compliance and Regulatory Adherence
- Roles and Responsibilities Clarity
Threat Intelligence and Situational Awareness
Threat Intelligence and Situational Awareness focuses on understanding and anticipating cyber threats through intelligence gathering and analysis. It includes monitoring the evolving threat landscape, integrating threat intelligence into decision-making processes, and participating in intelligence-sharing networks. Situational awareness allows organisations to maintain visibility of potential risks, vulnerabilities, and adversary behaviours. By proactively analysing and responding to cyber threats, organisations enhance their ability to anticipate attacks, reduce exposure, and take informed, timely action. The capabilities within this group provide a dynamic understanding of the environment, enabling effective threat modelling and improving overall cybersecurity posture.
- Third-Party Risk Management
- Threat Landscape Monitoring
- Threat Intelligence Integration
- External Intelligence Sharing
- Attack Surface Analysis
Preventative Security Controls
Preventative Security Controls involve the implementation and management of technical and procedural controls to prevent unauthorised access, data breaches, and system compromise. It includes securing networks, endpoints, systems, and data through layered defences, proper configuration, and access controls. Identity and access management ensures only authorised individuals can access critical systems, while encryption and data protection techniques safeguard sensitive information. By establishing robust security baselines and proactively mitigating vulnerabilities, organisations strengthen their first line of defence against malicious activity. These preventative measures are critical for reducing the likelihood and impact of cyber incidents.
- Vulnerability Intelligence
- Network Segmentation and Perimeter Security
- Endpoint Protection and Control
- Secure Configuration Management
- Identity and Access Management
Detection and Response
Detection and Response addresses an organisation’s capability to detect, respond to, and investigate cybersecurity incidents. It includes continuous monitoring, event correlation through SIEM tools, and the establishment of alerting mechanisms for anomalous activity. Capabilities also include structured incident response procedures, forensic readiness, and evidence handling. Effective detection and response mechanisms enable organisations to rapidly identify threats, limit the spread of attacks, and recover from incidents. This capability group ensures that responses are timely, coordinated, and informed by data, supporting operational continuity and regulatory compliance during and after security events.
- Data Protection and Encryption
- Continuous Security Monitoring
- Security Information and Event Management (SIEM)
- Incident Detection and Alerting
- Incident Response and Investigation
Resilience and Recovery
Resilience and Recovery focuses on the organisation’s ability to maintain essential operations and recover from cyber incidents. It includes business continuity planning, disaster recovery processes, system backup protocols, and coordinated crisis communication. Post-incident reviews ensure lessons are learned and improvements are implemented. Resilience planning minimises downtime, protects critical assets, and ensures stakeholder confidence. This capability group supports long-term sustainability by enabling rapid restoration of services and reinforcing the organisation’s capacity to withstand and recover from disruptive cyber events without significant loss or reputational damage.
- Forensics and Evidence Handling
- Business Continuity Planning
- Disaster Recovery Capabilities
- System Backup and Restoration
- Crisis Communication and Coordination
Culture and Capability Development
Culture and Capability Development emphasises the importance of fostering a security-conscious culture and building human capability. It includes cybersecurity awareness programmes, leadership engagement, simulations and exercises, and continuous skills development. Maintaining an informed workforce and an actively engaged leadership is critical to embedding security into the organisational culture. Structured capability development ensures that staff possess the competencies needed to manage cybersecurity responsibilities effectively. This group promotes organisational resilience by encouraging proactive behaviours, shared accountability, and adaptability in the face of changing cyber threats and technologies.
- Post-Incident Review and Learning
- Cybersecurity Awareness and Training
- Executive Engagement and Support
- Simulation and Exercise Programmes
- Skills and Competency Management
- Knowledge Retention and Transfer
The playbook uses a structured capability framework that links strategic governance, operational controls, incident readiness, recovery planning and workforce capability into one consistent assessment view.