glacierr
get in touch
typical engagement
4–6 weeks · fixed fee

service · 01nist csf 2.0

cyber maturity assessment

know where you really stand.

We assess your security programme against all 106 outcomes of NIST CSF 2.0 and leave you with a scored baseline, a clear risk picture and a roadmap the board can act on.

nist csf 2.0 govern function risk register board read-out fixed fee
▼
4–6

weeks, start to board read-out

106

CSF 2.0 outcomes scored against evidence

1

fixed fee, agreed up front

01what changes for you

what changes for you.

Every outcome scored against evidence, not questionnaire answers — and every roadmap item tied to a gap and a risk, or accepted on the record.

01

a baseline you can defend

Every outcome scored 0–5 against evidence, not questionnaire answers.

02

governance the board can own

The Govern function in full — appetite, roles, oversight, supply chain.

03

a risk picture, not a gap list

Threats mapped to MITRE ATT&CK and a heat map of what you carry.

04

spend tied to risk

Every roadmap item linked to a gap and a risk — or accepted on the record.

05

audit & insurer ready

An evidenced position for the questionnaire, the renewal or the auditor.

06

small, focused delivery

Senior consultants only. No day-rate creep, no transformation programme.

02what we typically find

most can list their tools. few can score the programme.

Most organisations can list their security tools. Far fewer can tell the board how mature the programme actually is, where the gaps are and what closing them is worth. Budgets get argued on opinion, risk is accepted informally, and governance gaps sit quietly until an incident, an auditor or an insurer finds them.

43%
of UK businesses reported a breach or attack in the last 12 months
31%
have a board member responsible for cybersecurity
govern
the sixth CSF function, added in 2024 — and the one boards now own

03our approach

mobilise · discover · assess · report.

Four stages, each with a gate you sign. Senior consultants only — the people who scope are the people who deliver.

01 · mobilise

agree what "good" looks like

02 · discover

look hard

03 · assess

score against evidence

04 · report

a roadmap the board can act on

04what you get

what you get.

05who it's for

who it's for.

board & ceo

A plain answer to "how secure are we?"

cfo

A defensible basis for security spend.

cio

A roadmap that fits the technology plan.

ciso & team

An independent baseline to argue from.

Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026); NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (26 February 2024); DSIT, Cyber Governance Code of Practice (April 2025).

shall we get on with it?

Fixed scope, fixed fee — typically four to six weeks. Tell us the framework, the window and the scope on the first call; we come back inside a week with a proposal.

also from glacierr.