A baseline, not a benchmark deck.
Most assessments end in a heat map nobody acts on. This one ends with a maturity position per domain, a queue gated on what you can actually execute, and the measures that will judge the next ninety days.
Eight IO domains, assessed against your evidence.
Cohort click rate on unseen lures
Share of detections that were tool-led rather than person-led
Share of AI usage running through sanctioned paths
Policies past review date
Time to restore the named process in exercise
Controls with current, dated evidence
Rating coverage and freshness across the supplier base
Stale physical access revoked, and whether it stayed revoked
What you get, and what you do with it.
Where you sit per domain, evidenced against what your systems actually show rather than what the policy says.
The prioritised work, with prerequisites named, so nothing on the list is blocked on something absent.
The measures, their sources and their baseline values, captured before any intervention runs.
Tell us where you think you are.
See it before you talk to anyone.
Two quarters of recorded activity across sixteen seats. One click, no install.