Skip to content
← All posts

Maturity grows through execution

4 min read
A rising staircase of maturity levels — Before (ad hoc or reactive), Level 2 Managed (basic ownership and repeatable work), Level 3 Defined (clear process and roadmap), Level 4 Measured (track progress and improve), and After (optimizing or continuous improvement) — under the headline Maturity grows through execution

No security program has ever matured because someone scored it.

Assessments are useful. They establish a baseline, surface gaps, and give leadership a common vocabulary for what needs to improve. But a maturity level is a description of what the organization can reliably do, not a target to be argued into. The score does not move because the finding was written down. It moves because the work behind the finding got done, and because the program can show it.

That is the whole idea behind the model: maturity grows through execution.

What each level actually describes

Read the levels as statements about execution and they stop being abstract.

Ad hoc or reactive is the starting point for most programs. Work happens, often competently, but it happens in response to events. Nothing is repeatable because nothing was designed to be repeated.

Managed means basic ownership and repeatable work. Someone is accountable for a control, and the same task done twice looks broadly the same. This is a lower bar than most organizations expect, and a surprising number of programs never clear it — not for lack of skill, but because ownership was never assigned.

Defined means a clear process and a roadmap. The organization knows the sequence of work ahead and why it is in that order. Findings have somewhere to go. Priorities survive contact with a busy quarter.

Measured means the program tracks progress and improves on the evidence. Completed work updates the program’s view of itself, so the current state is a live picture rather than a recollection of the last assessment.

Optimizing is what becomes possible after that: continuous improvement, driven by data the program generates in the normal course of doing its job.

Each of those is a claim about executed work. None of them can be granted by a report.

Why programs stall between levels

The common failure is not a lack of recommendations. Most organizations have more recommendations than they can act on. The failure is the gap between the assessment and the work.

An assessment produces findings. The findings become a slide deck. The deck is presented, broadly agreed with, and then competes for attention against everything else on the team’s plate. Some items get done. A few get done well. Almost none of it flows back into an updated view of maturity or coverage, so the next assessment starts close to where the last one finished — and the improvement that did happen goes unrecorded.

This is what makes maturity feel stubborn. The program is not standing still. It just has no mechanism for turning motion into recorded progress, which is the difference between a busy team and a maturing one.

Closing the loop

Programs that climb reliably tend to have the same loop in place, whatever they call it. Findings become tracked work with a named owner and a due date. Completed work carries evidence with it. That evidence updates the program’s current state, which reprioritizes what comes next. And the cycle repeats — each pass starting from a real picture of where the program stands rather than from memory.

The loop is unglamorous, and it is the entire mechanism. Once it exists, the maturity score stops being something the program argues about at assessment time and starts being a byproduct of work that was already being done.

What this changes for leadership

For a security leader, this reframes the conversation with the board. The question is no longer “what is our maturity score?” but “what work moved us, and what work will move us next?” That is a discussion about priorities and investment rather than grading, and it is one where the program’s record of executed work is the evidence.

It also sets a realistic expectation about pace. Levels are earned at the speed the organization can absorb and sustain change — not the speed at which recommendations can be issued. Programs that accept that tend to move faster than those that don’t, because they stop spending effort on findings they were never going to execute.

Start where the loop is broken. In most organizations, that is the handoff between assessment and tracked work. Fix that one seam and maturity starts to compound, because for the first time the work and the score are describing the same thing.

Ready to see ProSentra in action?

See how threat-informed analysis turns your security budget into measurable risk reduction.