Skip to content

Security baseline assessment

The Custos Secure Baseline

Your customers depend on you, and the buyers reviewing you want proof. The Custos Secure Baseline scores your security against the level enterprise reviews expect, and lays out the ranked plan to reach it.

Book a discovery call

The foundation your business runs on

To keep serving your customers without interruption, and protect the revenue and reputation tied to it, your security needs a foundation that holds as you grow.

Most growing companies have stronger security instincts than they get credit for. Multi-factor authentication is on, the engineers care. What is usually missing is the programme around it. That absence stays out of sight until a customer's security review or an incident forces your hand.

A small team does not need a full security programme on day one. The baseline is the right starting point, a solid minimum that lets you operate with confidence now. From there you build the security culture and grow into a certifiable ISMS when you are ready.

What the baseline is

We assess your security across the six functions of the NIST Cybersecurity Framework, and the ten dimensions grouped under them, scored on a five-level maturity scale. Where the score points to a deeper review of a specific platform, that becomes a focused next step rather than part of this engagement.

LEVEL 01

Initial

Reactive, ad hoc

Ad hoc. The area may exist, but no one owns it and nothing is written down.

LEVEL 02

Managed

Foundations laid

Owned and documented. A basic, repeatable process is in place, with someone accountable for it.

Baseline target

LEVEL 03

Defined

Consistently applied

Part of a formal information security programme, with written policy, a defined way to assess and treat risk, and a regular review.

LEVEL 04

Quantitatively Managed

Measured and controlled

Measured. It is monitored, reviewed on a schedule and tracked with metrics that show whether it works.

LEVEL 05

Optimising

Continuous improvement

Continuously improved. The area adapts and is benchmarked against the outside world.

The scale is adapted from CMMI. We place each of the ten dimensions on it, based on what we find. The baseline is reaching Level 2 across all ten, so every area has an owner, is written down, and operates day to day. Level 3 is ISO 27001 readiness, reached by turning what already works into written policy, a defined way to assess and treat risk, and a regular review cycle. Certification itself is a separate step, awarded by an independent accredited body after its own audit.

Ten scored dimensions

Those six functions break into ten dimensions we score, from who owns the risk to how you recover.

Govern

Who owns security, the risks that matter most, and the third parties and AI you depend on.

  • Security ownership and risk management
  • Third-party and subprocessor risk
  • AI governance and responsible AI (where relevant)

Identify

Knowing the accounts, services, devices and data you depend on, and where the sensitive data lives.

  • Asset and data inventory

Protect

The controls that keep identities, devices, data and people safe.

  • Identity and access lifecycle
  • Endpoint and device security
  • Security culture and awareness

Detect

Seeing what happens across your environment, and catching what matters.

  • Logging, monitoring and detection

Respond

A plan to act under pressure when an incident occurs.

  • Incident response

Recover

Getting the business running again after disruption.

  • Business continuity and recovery

Scored to act on and measure again

A baseline is a measure you come back to as you grow, so you can see what improved and set the next target.

A point-in-time audit

  • A thorough snapshot of where things stood that day.
  • A clear list of the gaps it found.

The Custos baseline

  • A maturity score across the ten dimensions.
  • A ranked path, the heaviest risks first.
  • Proof a customer or an investor can check.

What you walk away with

Where you stand today, and a ranked plan to reach the baseline. A report your board and your engineers can act on together, with a line of sight to ISO 27001 readiness for when you choose to pursue it. When a term sheet or an acquisition gets serious, the same scored report goes straight into the technical due diligence.

And if you would like our help working through the roadmap, that is work we are happy to take on.

What the report shows

Govern Dimension 01 / 10

Security ownership is informal

What we found
No single owner for security decisions, and no documented process behind them.
Why it matters
When no one owns it, security falls to whoever is free, and a customer cannot see who is accountable.
To reach the target
Name a security owner and document the key governance artefacts.
Priority rank
Start here

Where this dimension stands

Level 1 (Initial), target Level 2

An illustration of how we structure a scored finding. The data is generic.

Custos was founded by Liran Aknin, who has run security operations and hardened cloud environments in production. The work is delivered to that standard.

Who you work with

Find out where your baseline stands

A 30-minute discovery call to see whether the Custos Secure Baseline is the right starting point for you.

Book a discovery call