MCJ Ventures Cyber Security Maturity Assessment
Your answers, evidence notes and attachments stay in your browser. Nothing is uploaded to our servers — closing this tab or using Clear removes them.
Professional Assessment · £295 + VAT
Includes the full assessment, domain-level scoring, maturity analysis, identified risks and gaps, prioritised recommendations, improvement roadmap and downloadable professional report.
Add MCJ practitioner review, findings validation, prioritisation and a 60-minute results session.
Understand your cyber maturity across 12 domains
Approximately 130 questions scored on a 0–5 maturity scale (Not Implemented → Optimised), with evidence notes and optional attachments per question. Delivers a weighted overall score, radar chart, domain heat map, prioritised risk view and phased 0–24 month improvement roadmap.
This assessment is an independent cyber security benchmarking tool developed by MCJ Ventures. It aligns with recognised cyber security good practice, including principles found within NCSC guidance, Cyber Essentials, ISO/IEC 27001, CIS Controls and the NIST Cybersecurity Framework. It does not constitute certification, accreditation or an official assessment by the UK National Cyber Security Centre or any other standards body.
What you'll receive
- Weighted overall maturity score (0–100%) and level (Initial → Optimised)
- Radar chart, domain heat map and per-domain scores
- Executive dashboard with risk register and top exposures
- AI-assisted per-domain recommendations, effort, priority and benefit
- Phased 0–24 month improvement roadmap (Quick Wins → Strategic)
- Board-ready PDF report including full response appendix
The 12 domains
- 1. Governance & Leadership
- 2. Risk Management
- 3. Asset Management
- 4. Identity & Access Management
- 5. Secure Configuration
- 6. Vulnerability & Patch Management
- 7. Network Security
- 8. Endpoint Protection
- 9. Data Security
- 10. Monitoring & Detection
- 11. Incident Response & Recovery
- 12. Security Culture & Supply Chain
Higher weighting applied to Governance, Identity, Vulnerability Management, Monitoring and Incident Response.
Used only in your on-screen dashboard and PDF. Not sent anywhere.
