
Cyber Maturity & Resilience Exercises
Cyber Maturity Assessment & Tabletop
Measure Your Security Programme, Then Rehearse the Bad Day
- Maturity scoring against NIST CSF 2.0 and CIS Critical Security Controls v8
- Evidence-based: interviews, documentation review and control testing, not a self-assessment survey
- Prioritised roadmap sequenced by risk reduction and budget, with quick wins identified
Overview
CRS Cyber Maturity Assessment & Tabletop answers two questions every board eventually asks: how good is our security programme, and would we cope with a serious incident? The maturity assessment scores the organisation against NIST CSF 2.0 and the CIS Critical Security Controls v8 through interviews, evidence review and control testing, and turns the scores into a prioritised, budget-aware roadmap. The tabletop exercises then put the executive team and the technical responders through a realistic scenario, such as ransomware, a business email compromise or a supplier breach, facilitated by CRS. Every exercise ends with an after-action report that records what worked, what didn't and who owns each fix. Run together, the two give an organisation a baseline, a plan and evidence of preparedness for insurers, auditors and the board.
Who It's For
Key Differentiators
- Maturity scoring against NIST CSF 2.0 and CIS Critical Security Controls v8
- Evidence-based: interviews, documentation review and control testing, not a self-assessment survey
- Prioritised roadmap sequenced by risk reduction and budget, with quick wins identified
- A repeatable baseline, so progress can be measured year on year
- Executive tabletop exercises focused on decisions: communication, legal, regulatory notification and ransom policy
- Technical tabletop exercises for IT and security responders: detection, containment and recovery
- Scenarios tailored to the client's sector and threat profile: ransomware, business email compromise, insider or supplier breach
- After-action report with findings, owners and deadlines for every gap the exercise exposes
- Evidence of incident preparedness for cyber insurers, auditors and regulators
Competitive Positioning
vs. Big-4 and large consultancies
- ›CRS delivers the same frameworks without enterprise consulting rates
- ›Faster mobilisation and a roadmap sized to a mid-market budget
- ›Partners can resell under their own brand and keep the client relationship
vs. Self-assessment questionnaires
- ›Self-assessments score intentions. CRS tests the evidence behind each answer
- ›An independent assessor's findings carry more weight with the board and insurers
vs. An untested incident response plan
- ›The first time a team uses its response plan should not be during a real incident
- ›A tabletop surfaces missing contacts, unclear authority and slow decisions at no real cost
Full partner battle cards and objection-handling guides available in the partner portal.
Partner Use Cases
Leading With a Maturity Assessment Instead of a Product Pitch
A partner wants a consultative way into a mid-market account. It resells a CRS maturity assessment. The NIST CSF scores and roadmap give the client's IT manager a board-ready case for investment, and give the partner a prioritised list of the projects the client needs next.
Rehearsing a Ransomware Attack With the Executive Team
A partner's client has an incident response plan that has never been tested. CRS facilitates an executive tabletop built around a ransomware scenario. The after-action report shows missing contacts and unclear authority to pay or not pay, and assigns an owner to each fix.
Measuring Progress Year on Year
A partner repeats the CRS maturity assessment every year for a client on a managed security contract. The change in scores shows the value of the partner's work to the client's board and supports the contract renewal.
Want to walk through one of these scenarios against your own environment? Request a demo or speak to a CRS specialist.
Frequently Asked Questions
Which frameworks does the CRS maturity assessment use?
NIST Cybersecurity Framework 2.0 and the CIS Critical Security Controls v8. Scores are based on interviews, documentation review and control testing, not a self-assessment survey.
What is a tabletop exercise?
A facilitated, discussion-based rehearsal of a realistic incident, such as ransomware, business email compromise or a supplier breach. Executive exercises focus on decisions, communication and regulatory notification. Technical exercises focus on detection, containment and recovery.
What does the client receive?
A maturity scorecard and prioritised, budget-aware roadmap from the assessment, and an after-action report from each tabletop that records findings, owners and deadlines.
Can the assessment and tabletop be bought separately?
Yes. Each can be scoped on its own, though running them together gives the client a baseline, a plan and tested response capability in one engagement.
Partner Intelligence Available
Detailed battle cards, partner collateral, certification courses, and full sales enablement content for Cyber Maturity Assessment & Tabletop are available exclusively to authorized CRS partners.
Become a CRS Partner
Get exclusive sales tools, and enablement resources for Cyber Maturity Assessment & Tabletop.
Apply for Access Partner Sign InBuild the Skills
Equip your team to deploy and manage Cyber Maturity Assessment & Tabletopwith CRS authorized IBM, Red Hat, SUSE & CompTIA technical training.
Explore CRS technical trainingTalk to a Specialist
Scope Your Cyber Maturity Assessment & Tabletop Engagement
Tell us about the organisation and what it needs, and suggest a time for a scoping call. The CRS team will follow up with a tailored scope and quote.
More in CRS Services
Services CRS partners commonly position alongside Cyber Maturity Assessment & Tabletop.







