How the score works

Fifteen questions across five domains. Every answer maps to a maturity level, domains are averaged, and the overall score is weighted toward the capabilities that decide the outcome of a real incident.

Maturity scale

0

Not implemented / Unknown

No established capability exists, or the answer is not known.

1

Ad hoc

Some capability exists but it is inconsistent or informal.

2

Partially implemented

Controls exist but are incomplete or inconsistently applied.

3

Operational and documented

Implemented, documented and routinely used.

4

Tested and continuously improved

Regularly tested, measured and improved.

Domain weighting

Identify

15%

Protect

15%

Detect

25%

Respond

25%

Recover

20%

Classification

0–39HIGH EXPOSURESignificant security and operational gaps exist.
40–59DEVELOPINGCore controls exist, but detection, response or recovery remain inconsistent.
60–74MANAGEDGood foundations exist, but operational resilience gaps remain.
75–89RESILIENTSecurity operations are mature and coordinated.
90–100ADVANCEDOperations are continuously measured, tested and improved.

Critical gaps

A good overall score must never hide a decisive weakness. A separate gap engine flags critical and high findings — such as missing 24×7 monitoring or untested recovery — independently of the overall score.

The DIAMATIX Cyber Resilience Score is an indicative maturity assessment based on information provided by the respondent. It does not constitute a security audit, certification, legal opinion or guarantee that a cybersecurity incident will not occur.

Start Assessment