Maturity Scorecard (Template)
Scale: 1 = ad hoc, 2 = basic, 3 = managed, 4 = measured, 5 = optimized
| Domain | Score (1–5) | What we observed | What “3” looks like |
|---|---|---|---|
| Identity & Access | MFA enforced, minimal admins, least privilege | ||
| Email & Collaboration | Baseline phishing protections, forwarding controlled | ||
| Endpoints | Inventory + patch cadence + encryption visibility | ||
| Backups & Restore | Coverage known, restore tested, alerts in place | ||
| Ops readiness | Incident roles, vendor escalation, runbooks |