Scoring cyber maturity from the work actually underway
Instead of a hand-assembled annual snapshot, the Cyber Maturity Index scores MillerKnoll’s cybersecurity posture against NIST CSF 2.0 from the live project portfolio — and projects where the score is heading.
The opportunity
Cybersecurity maturity is usually reported as a point-in-time, hand-assembled snapshot — expensive to produce and stale the moment it’s done. The Information Security team wanted a live, defensible read that reflected the work actually underway, and a view of where the posture was heading.
What AISE built
The Cyber Maturity Index reads the InfoSec project portfolio from Smartsheets and scores all five NIST CSF 2.0 categories — Identify, Protect, Detect, Respond, and Recover — from that real work rather than a subjective survey. It then projects how the scores move as active projects complete, recommends what to accelerate for the most improvement, and drafts the leadership report, with distribution via Outlook.
The benefit to the business
A spreadsheet of security projects becomes a leadership-ready maturity score with a defensible trajectory — decision support the InfoSec leadership can act on, while still owning the call on priorities and posture. CMI is in UAT, owned by Duncan Bocks.
