Matu­ri­ty assess­ment of cyber­se­cu­ri­ty resilience


The Cybersecurity Resilience Maturity Assessment provides a quick assessment of the extent to which your organization is protected against cyberattacks. The most common gateways of cyber attackers are discussed, these are prioritized, and then the probability of occurrence is determined. Weighing the company's established defenses, resilience against cyber threats is determined in a risk model.



The most com­mon cyber thre­ats include:

  • Infec­tion by mal­wa­re such as viru­s­es, back­doors, Trojans.
  • Ran­som­wa­re / encryp­ti­on Tro­jans — a spe­cial form of mal­wa­re aimed at extort­ing money from the company
  • Phis­hing and spear phis­hing attacks — the (tar­ge­ted) decep­ti­on of employees in order to spy out infor­ma­ti­on or access data
  • CEO Fraud or CFO Fraud — a fraud sche­me to trig­ger money trans­fers or redi­rect pay­ments using a fal­se identity
  • Deni­al of Ser­vice (DoS) or Dis­tri­bu­ted Deni­al of Ser­vice (DDoS) attacks — the blo­cking of their access and ser­vices by a varie­ty of auto­ma­ted systems
  • IT intru­si­on through mis­con­fi­gu­ra­ti­on or open vul­nerabi­li­ties
  • Misu­se of IT resour­ces for cryp­to-mining or cri­mi­nal attacks

The cyber­se­cu­ri­ty resi­li­ence matu­ri­ty assess­ment includes the fol­lo­wing audit are­as:

  • Matu­ri­ty level of employees’ infor­ma­ti­on secu­ri­ty understanding.
  • Ope­ra­tio­nal secu­ri­ty, virus pro­tec­tion, backup/restore and monitoring
  • Access pro­tec­tion and user management
  • Remo­te access and access to cloud services
  • Hand­ling of clas­si­fied documents
  • Use of cryp­to­gra­phic measures
  • Deal­ing with secu­ri­ty incidents
  • Secu­ri­ty aspects in busi­ness con­ti­nui­ty management

Pro­ce­du­re of the work­shop: The matu­ri­ty level is deter­mi­ned in the work­shop using a SEC4YOU ques­ti­on­n­aire. The work­shop par­ti­ci­pan­ts of the cus­to­mer must have know­ledge about the imple­men­ted infor­ma­ti­on secu­ri­ty mea­su­res of the com­pa­ny, the spe­ci­fic ques­ti­ons are explained.

A writ­ten assess­ment of rele­vant test are­as and an iden­ti­fi­ca­ti­on of devia­ti­ons from the sta­te of the art in cyber­se­cu­ri­ty defen­se is performed.

The Cyber­se­cu­ri­ty Resi­li­ence Matu­ri­ty Assess­ment pro­vi­des IT lea­der­ship and seni­or manage­ment with both a quick assess­ment of whe­ther the orga­niza­ti­on has deve­lo­ped resi­li­ence to the gro­wing thre­at of cyber­at­tacks, as well as a list of deviations/measures that can fur­ther streng­then that resilience.…

The matu­ri­ty assess­ment is con­duc­ted as an online work­shop and takes appro­xi­m­ate­ly 3 hours.

The result of the cyber­se­cu­ri­ty resi­li­ence matu­ri­ty assess­ment is a tabu­lar report as well as a meaningful visua­liza­ti­on of the matu­ri­ty level per audit field in the levels 0 to 5.


