EDIH, EEN, Interreg: the platform for European programmes.Find out more

Cyber Risk Management Framework · Maturity

A cyber risk management framework measured by capability, translated into a prioritised roadmap.

10 themes, 159 questions, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Cyber Risk Management Framework · Maturity

Cyber risk governanceN1 → N5
Knowledge of assets and dependenciesN1 → N5
Risk assessment and prioritisationN1 → N5
Treatment and protective measuresN1 → N5

10 themes, 159 questions, 5-level scale.

Nordhavn Industries

53 / 100

Cyber risk governance6484
Knowledge of assets and dependencies5379
Risk assessment and prioritisation6182
Treatment and protective measures3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • Cetim
  • Aerospace Valley
  • Pôle SCS
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Cyber Risk Management Framework (capability-based approach, inspired by the NIST Cybersecurity Framework and ISO 31000) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, a level, the level above, and the action that links the two, that turns a finding into a trajectory.

Are cyber risks assessed using a stable method and linked to traceable decisions?

  1. N1

    No formalised assessment. Issues surface only after an incident or an external request.

  2. N2

    Some analyses exist for a few areas, carried out using different approaches, with no decision recorded afterwards.

  3. N3

    A common method is documented and applied to critical areas. Major risks are decided in committee and decisions are logged.

  4. N4

    Assessment covers the entire scope, including third parties. Residual risks are accepted at the appropriate management level and tracked over time.

  5. N5

    The method is revised in light of incidents, exercises and business change, with a revision history and comparison of levels across entities.

Action to move from L2 to L3

Adopt a single assessment method, apply it first to critical processes identified with the business, and add the review of major risks, with decisions logged, to the agenda of the quarterly security committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

A cyber risk management framework describes the capabilities an organisation needs to control its digital exposure: governing the subject, knowing its assets and dependencies, assessing risks using a stable method, choosing protective measures, detecting events, responding and then recovering. The most widely used frameworks, from the Cybersecurity Framework to the principles of ISO 31000, share this logic built around functions. They do not impose a binding list of requirements: they describe a set-up, and leave each organisation to adapt it to its own risk profile.

This is what makes the framework hard to steer. Everyone claims to use it, few can pinpoint their actual level. Does the asset inventory cover cloud, industrial environments and suppliers, or only the estate managed by IT? Does risk assessment lead to decisions that are actually made, or to a register nobody reopens between committee meetings? Does detection rely on written procedures, or on three people who know where to look? These questions are not yes or no, they sit on a scale.

A confusion often arises: the risk management framework is not a certifiable standard, and it does not replace an information security management system. It sits upstream. It structures capabilities, feeds the management system, and serves as a common baseline when several texts apply to the same scope, for example a sector directive and a client framework. Organisations that have adopted it as a shared language between security, risk and the business gain above all in comparability across entities.

The maturity assessment answers a different question than an audit. An audit concludes with a gap or a compliance finding. The assessment places each capability on a progressive scale, exposes the gap against the target you set, and names the action that moves it up a level. In Pilot, the gap between score and target generates the action plan, and the AI groups it into a prioritised roadmap. The benchmark compares business units against each other and each entity against its own past, which makes it possible to measure the trajectory of a transformation programme, not just its starting point.

The framework is ready to use and belongs to you. You adjust the themes, questions and levels: the AI refines the wording using the CMMI method, or builds a variant from your security policy and your own governance documents.

Reference standard: Cyber Risk Management Framework (capability-based approach, inspired by the NIST Cybersecurity Framework and ISO 31000)

The themes assessed

  • Cyber risk governance

    Formalised policy, roles and responsibilities, committee structure, alignment with corporate governance, resources allocated, risk appetite expressed by leadership.

  • Knowledge of assets and dependencies

    Inventory of systems, data and flows, mapping of internal and external dependencies, business criticality, coverage of cloud and industrial environments.

  • Risk assessment and prioritisation

    Method used, risk scenarios, likelihood and impact evaluation, distinction between inherent and residual risk, review frequency.

  • Treatment and protective measures

    Treatment options, selection and monitoring of measures, identity and access management, hardening, vulnerability and patch management.

  • Third-party and supply chain risk

    Supplier qualification, security clauses, periodic assessment, critical dependencies, reversibility and exit plans.

  • Detection and monitoring

    Logging sources, detection use cases, alert thresholds, hours of coverage, use of threat intelligence.

  • Incident response

    Qualification and escalation procedures, crisis unit, internal and external communication, notification to authorities and clients, exercises conducted.

  • Continuity and recovery

    Recovery objectives, tested backups and restores, business continuity plans, system rebuild scenarios.

  • Culture and skills

    Awareness by population, training for technical teams, security built into projects, reporting mechanisms.

  • Measurement and continuous improvement

    Indicators tracked, management review, lessons learned after incidents or exercises, comparison over time and across entities.

A short version of the framework, with 34 questions, is available for the online self-assessment. The full version covers 10 themes and 159 questions.

Frequently asked questions

Is this framework certifiable?

No. A cyber risk management framework describes capabilities, with no certification body behind it. Certification falls under ISO 27001 or SOC 2. The assessment measures your level of control and prepares for these processes, it does not issue any certificate.

What is the difference with a compliance audit?

An audit checks for the presence of requirements and concludes with a gap or a compliance finding. The assessment places each capability on a progressive scale and states the action that moves it up a level. The assessment prepares for the audit, the audit validates.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with several contributors, takes one to two weeks, most of the time spent gathering input from the relevant teams.

Can we adapt the framework to our organisation?

Yes. You can edit the questions, levels and themes, or start from your own documents: the AI then builds a variant and refines the levels using the CMMI method. The framework remains under your control.

How can we compare several business units?

Each entity runs its assessment on the same framework, making scores comparable by theme. The benchmark positions entities against each other and each one against its previous assessments. A cross-entity roadmap then consolidates the action plans.

Do respondents need technical expertise?

The questions cover management and governance practices, not configurations. A security or risk manager can answer most of them. Collaborative mode allows technical questions to be assigned to the right contact.

Can this assessment be reused for NIS 2 or DORA?

Yes, largely. These texts rely on the same capabilities: governance, risk assessment, third-party management, detection, notification, continuity. The baseline measured here can be reused, and the cross-entity roadmap avoids duplicating actions across frameworks.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurement