You measure cyber resilience by finding out how mature your capability is across detection, response and recovery, not by counting the controls you have switched on. A control either exists or it does not. Maturity is different: it describes how consistently that control is applied, whether it depends on one person’s memory, and whether it improves after every incident or stays exactly as it was installed. The most widely used scale for this is NIST’s four Implementation Tiers, and this page sets out what each tier looks like in practice, what to check to place yourself on it, and how to move up one.
- A maturity tier, not a percentage, because resilience improves in stages rather than by hitting a score.
- Detection and recovery are the functions a maturity assessment most often exposes as weaker than assumed.
- The tiers apply to the whole cyber resilience framework, not to any single control in isolation.
- Assessing honestly matters more than assessing often: a tier you cannot defend to an auditor is not a real result.
- The result is one input into the broader Resilience Score, not a replacement for it.
Why measure cyber resilience separately from business resilience?
Because they answer different questions. The Resilience Score measures your whole organisation across the three domains of the Resilience Loop: information security, data privacy and AI governance. It is a portfolio view. This page measures one slice of that portfolio in depth: how mature your capability is specifically against cyber attack, across the functions set out in the cyber resilience framework.
The distinction matters because averaging hides the answer you need. An organisation can carry a respectable overall resilience position while its detection and recovery functions sit years behind its prevention. A portfolio score will not surface that. A maturity assessment scoped to cyber specifically will, because it looks at each function on its own rather than blending them into one number.
Treat this page as the detailed instrument and the Resilience Score as the dashboard. Run this assessment first if cyber is where your risk concentrates, then feed the result upward once you have it.
What are the maturity tiers, and how do you know where you sit?
NIST’s Cybersecurity Framework defines four Implementation Tiers to describe how an organisation manages cyber risk, running from ad hoc practice through to a programme that adapts on its own. They are a maturity scale layered on top of the functions, not a fifth function or a replacement for them.

- Partial: practices exist but are applied ad hoc, usually reactively, and are not managed as an organisation wide programme. Risk is handled case by case rather than against a stated risk appetite.
- Risk-Informed: management has approved risk management practices, but they are not established as organisation wide policy and application is inconsistent across teams.
- Repeatable: practices are formally approved, expressed as policy, and applied consistently across the organisation. Staff have the knowledge and skills to carry them out, and the policy is reviewed on a regular cycle.
- Adaptive: the organisation adapts its practices based on lessons learned and on threat intelligence, and improves continuously through active risk management rather than a fixed annual cycle.
Most organisations that have never run a formal assessment sit at Partial or Risk-Informed without realising it, because prevention controls create a feeling of maturity that detection and recovery do not support. A tier only counts if you can point to evidence for it, which is the subject of the next section.
| Tier | What you can point to as evidence | Where most SMEs actually sit |
|---|---|---|
| Partial | Nothing written down. Whoever handled the last incident did it their own way. | Common before any formal cyber resilience work has started. |
| Risk-Informed | A policy exists and management has signed it off, but two teams could describe it differently. | The most common position for organisations mid way through a security programme. |
| Repeatable | The same policy, applied the same way, by whoever is on shift, with a review date in the diary. | Typical of an organisation certified to ISO 27001 and keeping the system live rather than shelved. |
| Adaptive | A change log showing the policy was updated after a real incident or a specific piece of threat intelligence. | Rare, and usually reached function by function rather than across the whole framework at once. |
Read the middle column literally. A tier is not a self assessment against a description. It is a claim that has to survive someone asking to see the proof.
There's a bigger picture behind this.
This page covers one part of business resilience. Real Resilience — IO’s framework for connecting security, privacy and AI governance — is where the full picture comes together.
What should you actually assess?
Assessing cyber resilience as one single thing produces a vague answer. Assessing it by function, against the six set out in the cyber resilience framework, produces a tier per function and shows you exactly where the gap sits rather than an average that hides it.
| Area | Signal you are still at Partial | Signal you have reached Repeatable or above |
|---|---|---|
| Visibility and detection | Logging exists but nobody reviews it unless something has already gone wrong. | Alerts are triaged on a defined schedule by a named person, whether or not anything has happened. |
| Incident response | The plan is a document nobody has read since it was written. | The plan has been exercised in the last year and the exercise changed something in it. |
| Recovery | Backups exist. Nobody has timed a restore. | A restore has been timed against a stated recovery objective and met it. |
| Third party and supply chain | Suppliers are onboarded once and never reassessed. | Critical suppliers are reassessed on a cycle and their access is reviewed against it. |
| Governance and reporting | The board hears about cyber risk only after an incident. | The board receives a standing report on coverage and open gaps, tested against the plan. |
Five areas, and a pattern worth naming: every Partial signal in the middle column describes something that exists on paper. Every Repeatable signal describes something that has actually been exercised or checked. That is the whole difference between the two ends of the scale.
How do you turn an assessment into a target profile?
NIST’s own approach to using the tiers is to score a current profile, decide a target profile, and treat the distance between the two as the plan. The target should be set by risk, not by ambition. Aiming for Adaptive everywhere when your actual exposure does not justify it spends budget the cyber resilience strategy page argues should go elsewhere. A regulated organisation handling sensitive data has a different target profile to a small business with a simple estate, and both can be entirely correctly positioned at different tiers.
In practice this means scoring where you are, function by function, honestly and against evidence rather than intention; picking a target tier per function based on what that function actually protects; and treating the gap between the two as the backlog rather than the whole programme. For the full walkthrough of NIST’s own scoping and gap analysis steps, see our guide to NIST CSF 2.0.
Start your free trial
Want to explore?
Sign up for your free trial today and get hands on with all the compliance features that ISMS.online has to offer
How does cyber resilience maturity connect to the Resilience Loop?
Almost every piece of evidence a maturity tier asks for is also asked for by something else. A reviewed policy, a named owner, a tested restore: the same records that move you from Risk-Informed to Repeatable on the cyber scale are the records an information security audit wants to see.

The Resilience Loop runs information security under ISO 27001, data privacy under ISO 27701 and AI governance under ISO 42001 as one connected system. A maturity assessment scoped to cyber sits inside that shared system rather than beside it. The evidence a Repeatable tier requires is the same evidence an ISO 27001 auditor asks for, and the same evidence that feeds the security domain of your Resilience Score. Run the assessment once and it answers both questions.
Why choose ISMS.online for measuring cyber resilience?
A maturity claim is only as good as the evidence behind it, and evidence rots the moment it stops being maintained. ISMS.online keeps the assessment current rather than treating it as a one off exercise.
- Score by function, not by average: see the tier for detect, respond and recover separately, so a strong average cannot hide a weak function.
- Evidence attached to every claim: exercises, restore tests and reviews are recorded as they happen, not reconstructed for an audit.
- One control set, every standard: the same evidence supports NIST CSF, ISO 27001 and the wider Resilience Score without repeating the work.
- Target profiles with owners: every function gets a target tier and a named owner accountable for closing the gap.
- Supplier tiers assessed alongside your own: third party risk sits in the same system rather than a separate spreadsheet.
- Built for UK and regulated markets: designed for organisations that have to show their maturity claim to an auditor or a customer, not just assert it.
See how it fits together on the business resilience platform, or book a demo.
FAQs
What is the quickest way to move up a tier?
Fix the weakest function rather than polishing the strongest one. Most organisations are already close to Repeatable on prevention and years behind it on detection and recovery, so a written policy, a named owner and one exercised test of that weakest function moves the tier faster than any amount of extra work on controls that already work. The evidence in the tables above shows the pattern: it is always about what has been checked, not what has been bought.
What tier should a small business aim for?
Whichever one matches its actual exposure, not the highest one available. A small business with a simple estate and low regulatory exposure can be correctly positioned at Risk-Informed for some functions. Aiming for Adaptive everywhere regardless of risk spends effort that would do more good closing a genuine gap in detection or recovery.
Is a maturity assessment the same as a risk assessment?
No, and the two are commonly confused. A risk assessment identifies what could go wrong and how badly. A maturity assessment asks how well managed your response to that risk actually is, whether it is documented, applied consistently and evidenced. Most programmes need both: the risk assessment sets the target profile, and the maturity assessment shows the current one.
How often should you reassess your maturity tier?
At least annually, and immediately after any incident that tested response or recovery for real. A tier that has not been reassessed after a real event is not current, whatever the last formal review said. Some functions, particularly detection and recovery, are worth checking more often because they are the ones most likely to have quietly slipped.
Does ISO 27001 certification guarantee a high maturity tier?
No, though it makes a high tier much easier to reach and to prove. Certification confirms a management system exists and is independently audited, which supports Repeatable. Reaching Adaptive additionally needs evidence that practices change in response to lessons learned and threat intelligence, which is a matter of how the system is run rather than whether it is certified.






