By Biyu Wu | Senior Security Consultant, Mantel

Key takeaways for business leaders:

  • A strong CRA meets your organisation where it actually is. Not every business unit, region, or acquired entity is at the same stage of cyber maturity, and a well-designed assessment doesn’t expect them to be. In a recent engagement spanning a parent group, its Indian operations, and a newly acquired subsidiary, this meant three distinct assessments: each calibrated to where that part of the business stood, not where a checklist assumed it should be.
  • The security work your team does all year deserves to be seen. Progress in cyber security is often invisible: spread across dozens of process improvements, governance changes, and operational fixes that individually seem routine. A year-on-year delta assessment changes that, turning incremental gains into clear, boardroom-ready evidence of risk reduction that leadership can understand and act on.
  • An assessment only creates lasting value if the findings drive decisions. The most common failure in security assessments isn’t the quality of the findings; it’s that the report never reaches the people who need to act on it. By producing tiered outputs: a technical workbook, a strategic report, and executive dashboards, this engagement ensured every audience, from practitioners to the C-suite, had what they needed to move forward.

Annual security assessments are a familiar part of the cyber calendar. For many organisations, they’re a scheduled checkpoint: a way to test assumptions, review control maturity, and give leaders a clearer view of where the security programme stands.

But the most valuable assessments do more than produce a score or satisfy a reporting cycle. They create space for a security team to step back from the pace of delivery and look at the bigger picture. They help an organisation understand not only where gaps exist, but where progress has been made, where momentum is building, and where the next round of investment will have the greatest impact.

That was the focus of a recent Cyber Readiness Assessment (CRA) engagement we completed for a large, ASX-listed property technology group with operations spanning multiple geographies and a growing portfolio of acquisitions.

The engagement covered three related assessments: one for the parent group, one for its overseas operations, and one for a recently acquired technology subsidiary. Each part of the organisation came to the assessment from a different starting point, which made the work particularly meaningful. For the parent group and its overseas operations, the assessment provided an opportunity to understand how maturity had shifted over time. For the acquired subsidiary, where there was no prior assessment baseline, the focus was on establishing a clear, practical view of current cyber readiness.

This is where a well-designed assessment creates real value. It gives organisations a consistent way to measure maturity while respecting that different business units, regions, or acquired entities may be at different stages of their cyber journey. Rather than applying a single template and expecting every environment to look the same, the assessment meets each part of the business where it is.

Using the framework without losing the context

The CRA was aligned to the NIST Cybersecurity Framework (CSF), covering all five CSF functions – Identify, Protect, Detect, Respond, and Recover, to provide a maturity view across the full breadth of the security programme.

That structure was crucial. NIST CSF gives organisations a common language to understand security maturity across areas such as governance, risk management, protective controls, detection, response, and recovery. It also allows leaders to see how maturity differs across functions, which is often where the most useful conversations begin.

However, a framework is only valuable if it is used with judgement.

In this engagement, NIST CSF provided the structure, but the assessment was not treated as a mechanical control-mapping exercise. The aim supports an understanding of how security practices operated in the real environment: what was embedded, what was still developing, what had improved over time, and what needed to become more consistent.

Documentation and evidence reviews gave us the foundation, but the workshops brought the assessment to life. These conversations allowed us to hear directly from the teams responsible for delivering and operating security practices day-to-day. They provided context that a document alone rarely captures: the decisions behind a process, the constraints teams are working within, the improvements made, and the areas where further uplift would make the biggest difference.

That distinction matters. Maturity isn’t simply about whether a policy exists or whether a control can be evidenced once. It is about whether the practice is repeatable, understood, sustainable, and genuinely supporting the organisation’s risk posture.

For government, this is where it gets serious. If an agent is automating decisions that affect grants, benefits, or penalties, the accountability chain must be correct, explicit, and auditable. The last thing anyone needs is Robodebt proliferated across dozens of use cases.

Making year-on-year progress visible

For the group’s oversea operations, one of the most valuable aspects of the assessment was the ability to compare current maturity against the previous year’s results.

This kind of delta assessment is powerful because security progress is often easier to feel than to prove. Teams spend the year improving processes, responding to issues, strengthening governance, uplifting third-party assurance, and refining response practices – but the results of that effort are often spread across many small changes. Individually, each improvement may seem operational. Collectively, they represent a meaningful uplift in cyber readiness.

The assessment helped make that uplift visible.

The year-on-year view reflected maturity growth across several important areas, including improved incident response practices, stronger third-party risk management, and more consistent risk management processes. These are foundational improvements. They help security become more predictable, more accountable, and better integrated into the way the organisation manages risk.

Being able to show that progress clearly is valuable for both security teams and business leaders. It helps demonstrate that previous investment has translated into measurable uplift. It also gives teams recognition for work that may otherwise remain invisible – because when security improvement is done well, it becomes part of how the organisation simply operates.

A good assessment gives that work a shape. It creates a milestone that allows leaders to say: this is where we were, this is where we are now, and this is where we should focus next.

Establishing a baseline where one did not exist

The assessment of the recently acquired subsidiary required a different lens entirely. Without a previous maturity baseline, the goal was to establish a clear view of current cyber readiness rather than measure year-on-year movement.

This is particularly important for organisations that have been acquired, invested in, or brought into a broader group environment. Before leaders can make informed decisions about alignment, uplift, or investment, they need a reliable understanding of the current state.

A baseline assessment helps answer practical questions:

  • Which areas are already operating well?
  • Where are practices less mature or less consistently applied?
  • What should be prioritised first?
  • Where would stronger alignment with group-level expectations create the most value?

For the acquired subsidiary, the assessment provided that starting point. It created a structured maturity view across the NIST CSF functions and identified targeted recommendations to support future uplift. Importantly, this was not about treating lower maturity as a failure. In many cases, lower maturity simply means the organisation is at a different stage of formalisation, scale, or integration.

The value is in making that starting point clear, so improvement can be planned with confidence.

One of the common weaknesses of maturity assessments is that the report becomes the final deliverable. A large document is produced, the findings are technically sound… and then, the people who most need to act on the information struggle to engage with it.

Biyu WuSenior Security Consultant, Mantel

We wanted the outputs from this engagement to work differently.

Different audiences need different levels of detail. Technical teams need evidence, observations, and implementation context. Security and risk leaders need themes, priorities, and a roadmap. Executives need a clear view of maturity, risk, and direction without having to interpret every underlying detail.

To support those different needs, the engagement produced several connected outputs:

  • A technical workbook capturing maturity ratings, detailed observations, and supporting evidence
  • A comprehensive report outlining key themes, strengths, gaps, and recommendations
  • A summary deck with visual dashboards to support executive reporting and leadership conversations

The visual layer was particularly important. By mapping maturity across the NIST CSF functions, the dashboards helped make relative strengths and less mature areas easier to see at a glance. This allowed the assessment to become more than a written record of findings – it became a communication tool.

That matters because cyber maturity isn’t only a technical issue. It is a leadership conversation, a prioritisation exercise, and, often, an investment decision. If the outputs can’t support those conversations, the assessment has only done part of its job.

Turning assessment findings into a practical roadmap

The most useful assessments do not stop at identifying gaps; they help the organisation decide what to do next.

In this engagement, recommendations were designed to be targeted and achievable. Because the assessment covered the full set of NIST CSF functions, we identified where maturity was stronger, where further consistency was needed, and where focused effort would have the greatest impact.

Recommendations were also tailored to the maturity context of each assessment. For areas that were already more mature, the focus shifted towards refinement, consistency, and embedding. For less mature areas, the priority was to strengthen foundations and create a clearer path for uplift. For the oversea operations, the delta assessment helped demonstrate progress while identifying the next stage of improvement. For the acquired subsidiary, the baseline assessment provided a practical starting point for future planning and alignment.

A useful roadmap should not feel like a generic catalogue of controls. It should reflect the organisation’s operating reality, maturity profile, and capacity to change – helping leaders prioritise rather than overwhelming them with a long list of disconnected recommendations.

Why cyber readiness matters

Cyber maturity can be difficult to communicate because much of the work is invisible when it’s going well. Better risk management, stronger third-party assurance, clearer incident response practices, and more consistent governance don’t always announce themselves. They show up in better decisions, faster coordination, clearer accountability, and greater confidence when the organisation needs to respond.

A CRA helps bring that work into view. It gives security teams a way to evidence progress, gives leaders a clearer understanding of maturity and risk, and gives the business a shared language for discussing priorities. Most importantly, it turns cyber improvement from a set of scattered activities into a structured, visible, and actionable programme of work.

Cyber readiness is not measured by a maturity score alone. It is measured by whether an organisation understands its risks, can see its progress, and knows where to focus next.

In this engagement, the CRA provided that clarity across three distinct parts of a complex, fast-growing business – showing year-on-year uplift where a baseline already existed, establishing a starting point where one did not, and translating findings into a practical roadmap for continued improvement.

That is where assessments create lasting value: not in the score itself, but in the decisions that score helps leaders make.

Ready to assess your cyber readiness?

At Mantel, we design and deliver Cyber Readiness Assessments that go well beyond compliance checklists. We tailor every engagement to the reality of your organisation – your size, your risk profile, your operating model – and we deliver outputs that leaders at every level can actually use.

Whether you are looking to understand your current security maturity, benchmark progress year on year, or establish a baseline for a newly acquired entity, we can help you turn assessment findings into strategic clarity and a practical plan for what comes next.

Our assessors bring deep, practitioner-level expertise across the NIST CSF and a proven track record of working with complex, multi-entity organisations across Australia and the Asia-Pacific region. We know how to run assessments that people trust, understand, and act on.

Talk to Mantel about what a CRA could look like for your organisation.

View our Cyber Security capabilities