MillerKnoll AI
Executive Summary

Cyber Maturity Index

CMI gives the Information Security team a live, defensible read on cybersecurity maturity. Instead of a hand-assembled annual snapshot, it scores all five NIST CSF 2.0 categories from the active project portfolio, projects where the scores are heading, and produces the leadership report to match.

By the numbers

What it delivers

NIST CSF 2.0
The scoring framework
5 categories
Identify · Protect · Detect · Respond · Recover
Predictive
Trajectory modeled from the active portfolio
Leadership-ready
Reports + Outlook distribution
Why it works

The principles

01

Grounded in the real portfolio

Scores are derived from the live InfoSec project portfolio in Smartsheets — not a subjective survey — so the number reflects work actually underway.

02

Trajectory, not just a snapshot

CMI projects how maturity moves as active projects complete, turning a point-in-time score into a forward-looking plan leadership can act on.

03

Decision-support, human-owned

It recommends what to accelerate and drafts the report; the InfoSec leadership still owns the call on priorities and posture.

Where it stands

CMI is in Test in the Copilot Agents environment. It scores all five NIST CSF 2.0 categories from the Smartsheets portfolio, projects trajectory as projects complete, and generates leadership reports with Outlook distribution — a decision-support tool for the Information Security team, owned by Duncan Bocks.