What a Cyber Maturity Score of 2.17 Tells You About Risk

A maturity score is more than a number — it’s a risk indicator. A score of 2.17, like the one shown in the Curtis Company example, tells a clear story:

The organization has defined some cybersecurity practices, but many are still reactive, inconsistent, or incomplete. This creates elevated exposure to cyber risk.

What 2.17 Really Means

A score in the low‑to‑mid 2 range typically indicates:

  • Policies exist, but enforcement is inconsistent
  • Some processes are documented, but not standardized
  • Technical controls are partially implemented
  • Leadership involvement is limited
  • Supply chain risk is underdeveloped
  • Incident response and recovery are not fully mature
  • Identity and access management has gaps
  • Monitoring is incomplete or informal

These aren’t failures — they’re opportunities.

Why 3.00 Is the Target

A maturity level of 3.00 represents:

  • Defined processes
  • Proactive behavior
  • Consistent implementation
  • Repeatable outcomes
  • Reduced risk exposure
  • Stronger resilience

It’s the point where cybersecurity becomes stable and predictable.

Where Organizations Typically Score Low

In the Curtis Company example, the lowest‑scoring areas included:

  • Organizational context
  • Roles and responsibilities
  • Supply chain risk
  • Identity and access management
  • Continuous monitoring
  • Incident mitigation
  • Recovery execution

These categories represent high‑risk gaps that can significantly impact operations.

How CyberDynamX Helps Improve Maturity

The CyberDynamX Assessment Program provides:

  • Evidence‑based scoring
  • Clear recommendations
  • Risk‑based prioritization
  • Leadership engagement
  • Strategic roadmaps
  • Governance alignment
  • Quarterly check‑ins (Tier 3)

This helps organizations move from reactive to proactive — and from uncertainty to confidence.