Skip to Content

CYBERSECURITY SCORE

Discover your company's cyber maturity before an attacker tests it for you.

Fifteen questions across five security domains, based on the NIST and CIS Controls frameworks, reveal your maturity score and show, domain by domain, where your posture is solid and where it is still fragile. With no sensitive data required.

Calculate my scoreTalk to a specialist

SPEED CHANGED SIDES

Artificial intelligence made the attacker faster. The question is no longer whether you will be hit, but how long until you detect, contain and recover.

What changed for the attacker: automated campaigns scan the internet for the weakest defense, and artificial intelligence accelerated the attack to the point where the average time between break-in and spreading across the network has dropped to about eight minutes (Adlumin, N-able, 2025).

What that demands of you: maturity is not about having more tools, but about having governance, process, technology, people and response operating together, with evidence. 62% of mid-sized companies report a rise in AI-generated phishing and deepfake scams, and 46% suffered three or more incidents in twelve months (Futurum Research, Cybersecurity in the Age of AI, 551 mid-market leaders).

If your company were assessed today by the same criteria a security auditor would use, which of the five domains would make you proud, and which would you rather not be asked about?

Most companies only measure their own maturity after the first serious incident, when the bill and the exposure have already arrived. This Cybersecurity Score reverses that order: in three minutes, it applies the same reasoning as a professional maturity assessment, so you know exactly where you stand before an attack finds out for you. These attacks have known names and methods: the phishing that steals the password, the ransomware that holds the data hostage and the executive fraud that diverts a payment. Maturity is closing the door to each of them.

MATURITY SELF-ASSESSMENT

Measure your security posture across five domains

Answer honestly, one domain at a time. The calculation runs instantly, in your browser, and no data is sent at this stage. For each question, choose the option closest to your reality.

Before we start, tell us briefly about your company:

1
2
3
4
5

Domain 1 of 5

Governance and leadership

Policies and processes

Technology and controls

People and awareness

Response and recovery

WHAT CYBER MATURITY MEASURES

Five domains decide whether your company is protected or only thinks it is

Cyber maturity is the ability to protect, detect, respond to and recover from an attack, and it is measured across five domains that have to evolve together. A single fragile domain drags down the rest: the best technology does not protect a company with no policies, and the best backup does not save the one who never tested recovery. Your score measures each of them, based on the NIST and CIS Controls frameworks.

1

Governance and leadership

Leadership treats cyber risk as a business risk, with a defined owner, priority and budget, and not as a problem only for the technical team.

2

Policies and processes

Written, communicated and updated security rules, with confirmed routines and documentation ready for a compliance audit.

3

Technology and controls

A second check beyond the password, advanced defense that reacts in real time and filtering that blocks the scam before the click.

4

People and awareness

A trained team, tested against phishing on a recurring basis, with documented knowledge, because most attacks start with a person, not a machine.

5

Response and recovery

A rehearsed response plan, an isolated and tested backup and clear recovery-time targets, so an incident is a scare and not the end.

FROM SCORE TO PLAN

The Professional Cyber Maturity Assessment

The result for you is straightforward: instead of a loose number, you get a clear path of evolution, with the clarity of where to invest first and why, defensible before your board, a client or an insurer.

The self-assessment shows where you stand. The Professional Cyber Maturity Assessment, run by a specialist, shows how to evolve. In an in-depth analysis, you receive:

  • Your maturity score by domain, compared to references in your industry and to the NIST CSF and CIS Controls frameworks.
  • An executive report, for leadership, and a technical report, for those who implement, with the evidence behind each gap.
  • A prioritized investment roadmap: what to evolve first, with recovery targets and right-sized investment for your reality.
1

We map your posture

A specialist starts from your answers to understand how your company works, what it depends on and where a breach would hurt most. No jargon, in the language of your business.

2

We benchmark your industry

We position your maturity against references in your industry and the NIST and CIS Controls frameworks, separating perception from evidence.

3

We prescribe the evolution

We present a prioritized roadmap: what to protect first, with governance, advanced defense, tested recovery and the sequence that makes your investment go further.

You do not get a sales pitch. You get an honest reading of where your posture stands today and a clear path to enterprise-grade maturity, with priorities you can act on right away.

WHAT IF NOTHING CHANGES?

The attacker will not wait for you to mature

Low maturity is not a bad grade on a report: it is the door an automated attack finds open. Ransomware (data held hostage) appeared in the majority of breaches at mid-sized companies, and the average cost of a breach reached 4.44 million dollars in 2025 (IBM Cost of a Data Breach Report 2025). Companies of every size are targets, because the attacker's criterion is ease, not size.

The difference between a scare and a crisis is almost never the tool a company bought, but the maturity with which it governs, detects and recovers. When defense operates with method and intelligence, more than 70% of threats are contained automatically, before they become an incident (Adlumin, N-able, 2025). Climbing one maturity level today costs a fraction of the first day of stopped operations tomorrow.

Calculate my score

For 15 years Zamak Technologies has sustained the cyber maturity of companies that cannot afford to stop, from those structuring their first IT to those with their own team that need an enterprise backbone. We operate with tools certified to SOC 2 Type II, ISO 27001, HIPAA and PCI-DSS (SentinelOne for advanced defense, Cove Data Protection from N-able for backup), as a Microsoft Solutions Partner and a member of the Addee Elite Group, with Great Place to Work recognition.

FREQUENTLY ASKED QUESTIONS

What companies ask before measuring their own maturity

It is a measure of how prepared your company is to protect, detect, respond to and recover from an attack, spread across five domains (governance, policies, technology, people and incident response), based on the NIST and CIS Controls frameworks. Each answer adds points by domain, and the result is a score from 0 to 100: the higher it is, the more mature and resilient your posture.

It takes about three minutes, across fifteen multiple-choice questions, revealed one domain at a time. No sensitive technical data is requested, and the calculation happens in your browser. To get the full reading and the roadmap, we only ask for your name, work email and company.

It is the question that separates maturity from assumption. Having antivirus, backup and a strong password is not the same as having evidence that they hold up against a real attack. Part of what the score evaluates is exactly that: how much of your protection is proven, not just presumed.

It does, and it is often revealing. Zamak acts as the backbone behind your IT team, not as a replacement. The score shows where a lean team is naturally exposed (formal governance, recovery testing, after-hours coverage) and where Zamak adds advanced defense, monitoring and enterprise-grade response behind your team.

It is the in-depth step, run by a specialist, that goes beyond the self-assessment: it maps your maturity with evidence, benchmarks it against your industry and the NIST and CIS Controls frameworks, and delivers an executive and technical report with a prioritized investment roadmap. Unlike the free score, it is a professional service dedicated to your company.

NEXT STEP

Turn your score into an evolution plan

You already know where your maturity is solid and where it is fragile. Now choose how you want to advance your maturity.

Book a meeting

A specialist reviews your result with you, digs into the most fragile points and shows how to advance your maturity, with no commitment.

Book a meeting

Free General Assessment

Assess your operation's continuity too, beyond security, across six domains.

Open the assessment

Updated June 2026 · Free tool by Zamak Technologies