The challenge

What the organization was facing.

Security investment decisions were being made without an objective baseline. Different stakeholders held genuinely different views of how mature the program was, and spending was skewing toward areas with the loudest internal advocates rather than the highest measured risk. Leadership wanted an independent read before approving the next budget cycle.

What ISC did

The approach.

  1. 01

    Interviewed stakeholders across security, IT, operations and executive leadership to capture both stated and actual practice.

  2. 02

    Benchmarked the program against NIST CSF, assessing each function on evidence rather than self-reported maturity.

  3. 03

    Validated key claims technically, confirming whether controls described in policy were actually operating in the environment.

  4. 04

    Built a risk register connecting technical findings to business impact, so each gap carried a consequence leadership recognized.

  5. 05

    Delivered a prioritized roadmap and an executive summary framing the findings in investment terms rather than control language.

Outcomes

What changed.

  1. 01

    An evidence-based maturity baseline replacing conflicting internal assessments.

  2. 02

    A risk register linking each finding to business consequence and an accountable owner.

  3. 03

    A reprioritized investment roadmap directing spend toward the highest-measured risks.

Services used

Capabilities behind this engagement.