Unless you are looking to “sell” cybersecurity internally to leadership, the process of maturing cybersecurity within an organization is not about “good-better-best” or “silver-gold-platinum.” Rather, the organization must understand its current level of maturity, assess the risks to the business objectives and decide how to reach the state of maturity necessary to achieve and exceed the business objectives. The last part requires using some framework around cybersecurity maturity, preferably.
There are several maturity-based frameworks available for businesses to use, like the NIST Cybersecurity Framework, ISO 27001/2, COBIT 5.0, etc. None use an approach like “good-better-best” or “medallion” reference to achieve maturity. Why? It doesn’t make sense. Who says, “My cybersecurity is just good,” or “Wow, we achieved silver status with our cyber maturity”? Of course, everyone wants to be the “best” or have “platinum” maturity for cybersecurity.
Here is the reality, though: Every business is different. Every business has different objectives, different risks and different viewpoints on maturity. So, why have legacy, outdated sales labels identify the maturity of your organization? A better approach may be using foundational, enhanced and optimal instead. Still, these labels should only be used internally and not externally since they may give the wrong impression of an organization’s current level of maturity.
Learning How to Better Understand Business Risk
Cyber maturity requires a firm understanding of the risks that may prevent a business from achieving its objectives. That starts by knowing your business objectives. Believe it or not, many small and medium-sized businesses do not have a business plan. This is like knowing a destination and not having a map of how to get there. You see, there could be obstacles on the path you want to take, like accidents, construction, etc. Your journey may require a deviation. Having a map can help you navigate around obstacles much faster. A business plan is no different. Business plans are there to guide, run and grow the organization.
While the U.S. Small Business Administration (SBA) doesn’t have specific statistics on success rates for businesses with a business plan, they stress the importance of having one. One very important 2024 statistic shared by the Commerce Institute is that over 49% of small businesses fail within the first five years. As a good starting point, the SBA does have resources available to help organizations develop a business plan.
Once you have a business plan outlining your objectives, you must now identify risks that will or may prevent you from achieving them. While this may sound complicated, the process itself is fairly straightforward. Let’s say this right up front: Identification is not the process of mitigation; that is the next step in the process. Uncovering your obstacles and then planning to mitigate them is how an organization successfully tackles the challenge of cybersecurity.
Establishing, managing and improving cybersecurity maturity within an organization takes planning. That planning involves the entire organization, top-down, bottom-up and left-right—the whole nine yards, not just one department or team. An organization is not going to find improvement or achieve its objectives without everyone focused on success.
Maturity cannot be solved using technology alone, either. Either the entire organization is working on maturity, or it is not. Yes, it’s very black and white, with no gray involved. Once the organization better understands the risks, it can begin mitigation activities, which often results in increasing its maturity level and enhancing a security-first culture.
This Is a Process. Sometimes a Very Long Process
Is it easy to give up on maturing the organization? Yes. I suggest you stick it out. Ashton Kutcher said it best, “Sometimes opportunity looks a lot like hard work.” He is not wrong. I always hear, “This is really hard,” and it can be if you do not know where to get the appropriate training and education to help you solve the gaps within the organization. But it doesn’t have to be hard.
As an industry, solution providers are a very resilient bunch. Look around at the various communities that exist; everyone helps each other. That is remarkable when you think about it. This industry circles the wagons when threatened or attacked. Most of the community members help freely since it benefits the industry as a whole. Help is truly just an ask away.
Cybersecurity Is the Cost of Doing Business Today
Back to cybersecurity not being categorized as a sales process. Cybersecurity is classified as the cost of doing business, or at least it should be. If your organization is not looking at cybersecurity through this lens, it might be time to re-align your perspective. Looking back, the introduction of technology and the subsequent advances without the forethought of securing the technology really put everyone at a disadvantage.
Attempting to sell cybersecurity without understanding what it truly is, is a huge mistake. Organizations that go down that path are setting themselves and their customers up to fail. Aligning your risk to your objectives is the method to understand why cybersecurity is important for the organization. Cybersecurity is a business decision, not a sales process.
Learn more about GTIA Cybersecurity Programs.
Wayne R. Selk is vice president of cybersecurity programs and executive director of the GTIA Information Sharing and Analysis Organization (ISAO).

