Your Cybersecurity Maturity Report
Personalized assessment of your organization's NIST CSF 2.0 implementation posture.
Harborlight Health Technologies has developing cybersecurity capabilities with meaningful gaps to close.
Executive Summary
Harborlight Health Technologies has a risk-informed cybersecurity posture with an overall NIST CSF 2.0 maturity score of 56% and an Implementation Tier of 2, Risk-Informed. The organization shows stronger governance and protective foundations, including documented risk themes, a conservative risk appetite, a risk register, and identified mission-critical processes supporting patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync services. The most consequential gaps are in Detect, Respond, and Recover, where monitoring practices, incident response execution, tabletop validation, and disaster recovery planning are not yet sufficiently repeatable for a healthcare SaaS platform handling PHI. These gaps are material given Harborlight's documented risks of ransomware, PHI exposure through third-party integrations, insider misuse, and dependency on a single cloud region. Priority actions should focus on formalizing incident response, defining monitoring for Azure-hosted applications and integrations, strengthening recovery planning, and implementing the generated policies in a sequenced roadmap tied to HIPAA and business associate agreement obligations.
CSF 2.0 Function Coverage
Govern wraps the five operational functions in NIST CSF 2.0. Filled wedges show your current maturity across each function.
Implementation Tier Ladder
Your assessment places your organization within one of NIST CSF 2.0’s four implementation tiers.
Function Performance & Gap Analysis
Govern is Harborlight's strongest function, supported by documented risk themes, conservative risk appetite, a risk register, and identified mission-critical processes. The score is limited by the absence of described governance structure, audit activity, compliance monitoring, and security metrics needed for repeatable oversight.
Harborlight has identified key business processes and risks, including ransomware, PHI exposure through third-party integrations, insider misuse, and single-cloud-region dependency. The moderate score indicates that risk identification exists but needs stronger asset, vendor, data, and dependency management tied to the patient portal, APIs, telemetry ingestion, and EHR sync.
Protective capabilities are relatively mature compared with other functions and are supported by generated policies for access control, data handling, acceptable use, vulnerability management, and secure development. The score indicates established protective direction, but implementation must be made consistent across PHI, PII, proprietary data, cloud workloads, endpoints, and third-party integrations.
Detection is a significant gap because monitoring practices for Azure-hosted web applications, APIs, data pipelines, mobile workloads, and clinical data integrations are not yet defined. This limits Harborlight's ability to identify ransomware activity, data exfiltration, insider misuse, and supply chain events affecting patient-facing services.
Respond is the lowest-scoring function because the incident response plan is draft or informal and has not been tested through tabletop exercises or incident response validation. This creates execution risk for breach notification, containment, evidence preservation, and communications under HIPAA and clinic business associate agreements.
Recover is limited by the documented dependency on a single cloud region and the need for disaster recovery planning aligned to mission-critical services. Recovery procedures should be defined for patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync processes to reduce downtime risk.
Strongest: Govern (82%). Lowest: Respond (38%).
Implementation Tier Analysis
Based on your responses, Harborlight Health Technologies is operating at Implementation Tier 2 (Risk-Informed) overall. Within that, your responses indicate governance at Tier 2 and risk management at Tier 2. The evidence below explains what is driving this placement.
What this assessment is based on
- Govern: Govern is Harborlight's strongest function, supported by documented risk themes, conservative risk appetite, a risk register, and identified mission-critical processes. The score is limited by the absence of described governance structure, audit activity, compliance monitoring, and security metrics needed for repeatable oversight.
- Identify: Harborlight has identified key business processes and risks, including ransomware, PHI exposure through third-party integrations, insider misuse, and single-cloud-region dependency. The moderate score indicates that risk identification exists but needs stronger asset, vendor, data, and dependency management tied to the patient portal, APIs, telemetry ingestion, and EHR sync.
- Protect: Protective capabilities are relatively mature compared with other functions and are supported by generated policies for access control, data handling, acceptable use, vulnerability management, and secure development. The score indicates established protective direction, but implementation must be made consistent across PHI, PII, proprietary data, cloud workloads, endpoints, and third-party integrations.
- Detect: Detection is a significant gap because monitoring practices for Azure-hosted web applications, APIs, data pipelines, mobile workloads, and clinical data integrations are not yet defined. This limits Harborlight's ability to identify ransomware activity, data exfiltration, insider misuse, and supply chain events affecting patient-facing services.
- Respond: Respond is the lowest-scoring function because the incident response plan is draft or informal and has not been tested through tabletop exercises or incident response validation. This creates execution risk for breach notification, containment, evidence preservation, and communications under HIPAA and clinic business associate agreements.
- Recover: Recover is limited by the documented dependency on a single cloud region and the need for disaster recovery planning aligned to mission-critical services. Recovery procedures should be defined for patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync processes to reduce downtime risk.
What We Found
The gaps your responses surfaced, ordered by severity. Each maps to a NIST CSF 2.0 subcategory.
3 gaps surfaced from your responses (1 high, 2 medium), spanning 3 CSF functions.
-
1
Incident response is not tested
Plans that aren't rehearsed fail in real incidents. Tabletop and full-scale exercises surface gaps before adversaries do.
Your full report covers how to close this and includes the Incident Response Policy that puts it in force.
-
2
No documented top cybersecurity risks
Leadership has not formally identified, ranked, or owned the organization's top cybersecurity risks.
Your full report covers how to close this and includes the Information Security Policy that puts it in force.
-
3
No disaster recovery plan
Technology DR is undocumented. RTOs and RPOs for critical systems are not declared or measured.
Your full report covers how to close this and includes the Backup & Recovery Policy that puts it in force.