Free tool

Cyber Security Maturity Model

Five levels. Ten minutes. No form.

A cyber security maturity model describes how developed an organization's security practice is, using named levels. happier IT's has five: ad hoc, foundation, managed, secured and optimized. You find your level by answering six questions honestly and stopping at the first no.

All five levels are set out in full below, along with what each one looks like from the inside and the single most useful next move. Nothing here is gated, scored or emailed to you.

At a glance

The five levels, in one table.

Read down the middle column until you recognise your own organization. That is roughly your level: the questions further down will confirm it.

The five cyber security maturity levels, what is typically in place at each, and the most useful next step
Level What it sounds like from the inside The next move
1. Ad hoc “I think the antivirus is on everything?” Write down what you have. Accounts, devices, and who holds administrator rights. Then turn MFA on for email. Those two moves are free or close to it, and they take you most of the way to level two.
2. Foundation “We have a proper firewall and everyone has the two-factor app.” Stop assuming coverage and go and check it. Pull the list of accounts without MFA. Restore one real file from backup and time it. Both are afternoons, and both routinely change the picture.
3. Managed “We scan once a year and the training goes out every quarter.” Decide what happens overnight. That is either an internal rota or an outside team, see managed security services, and then write the incident runbook and read it aloud once with your leadership team.
4. Secured “Finance is on its own segment and we review risk every quarter.” Rehearse. Walk your leadership team through a realistic scenario and see where the plan stops matching reality. Then go through the exceptions list and close the ones that no longer have a reason.
5. Optimized “It is on the board agenda monthly, and most of the checks run themselves.” Keep it honest. Re-test the assumptions rather than re-reading the register, and treat every significant business change as a reason to look again.

Level three is the sensible target for most Canadian organizations of 15 to 200 people, and level four where a regulator, an insurer or a large client requires it. Level five costs real money and real management attention. It is not the right goal for everyone, and we will say so rather than sell you one.

The five levels

What each level actually looks like.

Written from the inside, in the words people use on a first call, not as a list of controls to be graded against.

Level 1

Ad hoc

Security is whatever the last person to touch it set up.

What is usually already in place
Whatever came with the laptops and the internet connection. Built-in antivirus, the router the provider supplied, passwords chosen by whoever opened each account. It is not that nothing is protecting you, it is that nobody chose it.
What is usually missing
A list of who has an account, a list of what devices exist, MFA (multi-factor authentication: a second check, usually on a phone, before a login is accepted) anywhere, a backup anyone has restored from, and a person whose job this is.
The one move that matters most
Write down what you have. Accounts, devices, and who holds administrator rights. Then turn MFA on for email. Those two moves are free or close to it, and they take you most of the way to level two.

Level 2

Foundation

The basics are there, and somebody chose them on purpose.

What is usually already in place
A business-grade firewall rather than a consumer router. The same antivirus on every machine instead of four different ones. A written password standard. MFA switched on for at least email. Somebody, usually one person, keeps an eye on it.
What is usually missing
Proof of coverage. Almost every organization at this level believes MFA is universal and finds two exceptions, the administrator account and a shared mailbox. Also missing: a restore anyone has actually tested, an offboarding record, and any involvement from leadership beyond signing the invoice.
The one move that matters most
Stop assuming coverage and go and check it. Pull the list of accounts without MFA. Restore one real file from backup and time it. Both are afternoons, and both routinely change the picture.

Level 3

Managed

There is a cycle, and it happens whether or not anyone remembers.

What is usually already in place
Annual vulnerability scanning and a gap analysis against a known list of controls. Protections chosen against common attack methods rather than bought ad hoc. An ongoing staff awareness programme. Patching on a schedule. Usually a client contract, an insurer or a regulator prompted all of it.
What is usually missing
Anything outside office hours. At this level an alert at 2am on a Saturday is discovered on Monday. There is often no written answer to who declares an incident, who they call, and what gets recorded.
The one move that matters most
Decide what happens overnight. That is either an internal rota or an outside team, see managed security services, and then write the incident runbook and read it aloud once with your leadership team.

Level 4

Secured

The design assumes something will eventually get in.

What is usually already in place
Network segmentation, so a problem on one machine does not reach everything. Zero trust in practice, meaning nothing is assumed safe just because it is inside your network; every request gets checked. Data classification, so people know which information is sensitive. A formal IT risk process with named owners, quarterly review and documented governance.
What is usually missing
Usually not a control. The gap at this level is between the documents and the daily habit: a policy nobody has read, a plan nobody has rehearsed, an exception granted two years ago that was never revisited.
The one move that matters most
Rehearse. Walk your leadership team through a realistic scenario and see where the plan stops matching reality. Then go through the exceptions list and close the ones that no longer have a reason.

Level 5

Optimized

Security is part of how the organization runs, not a project it does.

What is usually already in place
Executive ownership rather than IT ownership. Controls that enforce and report themselves rather than needing someone to check. Continuous improvement with a monthly risk review and reporting to the board. Security considered when the business changes, not after.
What is usually missing
By definition, nothing structural. The work here is staying here, organizations drift back down a level after an acquisition, a system replacement or the departure of the person who held it all together.
The one move that matters most
Keep it honest. Re-test the assumptions rather than re-reading the register, and treat every significant business change as a reason to look again.

Place yourself

Six questions. Stop at the first honest no.

Answer in order. The first question you cannot answer yes to sets your level, because each level depends on the one below it holding up.

  1. 1Can you produce a current list of everyone with an account, and everyone with administrator rights?

    If no, you are at level one, whatever else is in place. Everything above this depends on knowing what exists.

  2. 2Is MFA enforced on every account, including administrator accounts and shared mailboxes, and can you show the report that proves it?

    If it is on but unproven, you are at level two. If you can produce the coverage report, you have cleared level two.

  3. 3Has someone restored a real file from your backup in the last three months, and do you know how long it took?

    If backups run but nobody has restored from one, you are at level two regardless of how good the rest looks.

  4. 4Does something happen on a schedule, scanning, patching, awareness training, a gap review, without a person having to remember?

    If yes, you are at level three. If it only happens when someone chases it, you are at level two.

  5. 5If an alert fires at 2am on a Saturday, does a named person or team see it and act?

    If no, you are at level three. Overnight response is the wall between level three and level four.

  6. 6Is your network segmented, is access checked rather than assumed, and does a risk register with named owners get reviewed at least quarterly?

    If yes, you are at level four. If leadership owns it and reviews it monthly with automated enforcement, you are at level five.

If you are unsure, answer no

The most common mistake here is answering yes to a question about something that is switched on but has never been checked. Switched on and verified are different answers, and the difference is usually a whole level.

Want a second opinion?

happier IT's free IT assessment covers this same ground in about 45 minutes and produces a written plan you keep, whether or not you ever hire us.

What to do with it

A level is a direction, not a grade.

Nobody starts at five, and a good number of well-run organizations stop deliberately at three.

The reason to name your level is that it makes the next decision small. At level one the next thing to do is write down what you have, not buy a security platform. At level three it is deciding who answers an alert overnight, not adding another tool to the ones already unread.

Maturity also moves backwards, and usually not because anything was attacked. It slips after an acquisition, after a system is replaced, and after the person who quietly held it together leaves. That is why the levels above are described by habits rather than by purchases, a habit survives a departure, and a licence does not.

If you want the outside frameworks, they are free to read: the NIST Cybersecurity Framework, the CIS Critical Security Controls, and the Canadian Centre for Cyber Security's baseline controls for small and medium organizations. If a client contract or an insurer names one of those, work to that one rather than to this page, and compliance and risk management is where that gets turned into evidence you can show.

Where each level leads

Questions

What people ask about this model.

What is a cyber security maturity model?

A cyber security maturity model is a set of named levels that describe how developed an organization's security practice is, from nothing formal at all to security built into how the business runs. happier IT's model has five: ad hoc, foundation, managed, secured and optimized. Its purpose is to make the next step obvious, not to produce a grade.

What are the five levels of the happier IT cyber maturity model?

Level one is ad hoc: no formal programme, and security is whatever was set up by default. Level two is foundation: business-grade firewall, standardised antivirus, a password standard and MFA (multi-factor authentication) chosen deliberately. Level three is managed: scanning, patching and awareness training happen on a schedule. Level four is secured: segmentation, access checked rather than assumed, and a formal quarterly risk process. Level five is optimized: executive ownership, automated controls, monthly review and board reporting.

What level should a 50-person company be at?

Level three is the sensible target for most Canadian organizations of 15 to 200 people, and level four if a regulator, an insurer or a large client requires it. Level five costs real money and real management attention, and it is not a sensible goal for every organization. Aiming for a level you do not need is a way to spend a budget without reducing much risk.

How do I find out what level we are at?

Work through the six placement questions on this page in order and stop at the first honest no, that is your level. It takes about ten minutes and needs no tools. If you would rather have someone else look, happier IT's free IT assessment covers the same ground in about 45 minutes and produces a written plan you keep.

Is level one bad?

No, it is common, and it is where nearly every organization starts. Most of the distance between level one and level two is made up of things that are free or nearly free: writing down what you have, turning on MFA, and checking that a backup restores. It is a starting point, not a verdict.

Can we skip a level?

Not usefully. Each level depends on the one below it, segmentation does not help much if nobody can list the accounts, and a monthly board report on a risk register nobody maintains is theatre. What you can do is move through the early levels quickly, because most of level one and level two is configuration rather than spend.

Which public frameworks does this relate to?

This is happier IT's own five-level model, written to be readable by a business owner rather than an auditor. The public frameworks doing a similar job are free to read and worth knowing: the NIST Cybersecurity Framework and its implementation tiers, the CIS Critical Security Controls and their implementation groups, and the Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations. If a client or insurer names one of those, work to that one.

Does going up a level mean buying more software?

Usually less than expected. The move from level one to level two is mostly configuration of things you already pay for. Level two to level three is mostly cadence, deciding that something happens on a schedule and then making it happen. Spending tends to start at level three to four, where overnight monitoring and segmentation genuinely need people or products behind them.

Landed on a level and not sure what to do about it?

Tell us the number and the question you stopped at. Twenty minutes is usually enough to turn that into a short list of next steps.