Sample report

Free Maturity Report

This is the free report as it appears on screen after the assessment, generated for Harborlight Health Technologies, a fictional 45-person healthcare technology company that runs a telehealth and remote patient monitoring platform on Azure. Scores, tier, gap analysis, and findings are unedited output from that company's answers. The paid package adds the written assessment report, ten policies, and nine working documents.

NIST CSF 2.0 · Cybersecurity Readiness

Your Cybersecurity Maturity Report

Personalized assessment of your organization's NIST CSF 2.0 implementation posture.

September 5, 2026
Harborlight Health Technologies Healthcare · 45 employees

Harborlight Health Technologies has developing cybersecurity capabilities with meaningful gaps to close.

56% Overall Maturity
Strongest: Govern · Lowest: Respond
Current Tier T2 Risk-Informed
Lowest-Scoring Function Respond 38% · incident response and mitigation procedures

Executive Summary

Harborlight Health Technologies has a risk-informed cybersecurity posture with an overall NIST CSF 2.0 maturity score of 56% and an Implementation Tier of 2, Risk-Informed. The organization shows stronger governance and protective foundations, including documented risk themes, a conservative risk appetite, a risk register, and identified mission-critical processes supporting patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync services. The most consequential gaps are in Detect, Respond, and Recover, where monitoring practices, incident response execution, tabletop validation, and disaster recovery planning are not yet sufficiently repeatable for a healthcare SaaS platform handling PHI. These gaps are material given Harborlight's documented risks of ransomware, PHI exposure through third-party integrations, insider misuse, and dependency on a single cloud region. Priority actions should focus on formalizing incident response, defining monitoring for Azure-hosted applications and integrations, strengthening recovery planning, and implementing the generated policies in a sequenced roadmap tied to HIPAA and business associate agreement obligations.

Govern
82%
Identify
55%
Protect
75%
Detect
43%
Respond
38%
Recover
45%

CSF 2.0 Function Coverage

GOVERN · 82% 55% IDENTIFY 75% PROTECT 43% DETECT 38% RESPOND 45% RECOVER CSF 2.0 MATURITY

Govern wraps the five operational functions in NIST CSF 2.0. Filled wedges show your current maturity across each function.

Implementation Tier Ladder

↑ MORE MATURE TIER 4 Adaptive TIER 3 Repeatable TIER 2 Risk-Informed ● YOU ARE HERE TIER 1 Partial ↓ LESS MATURE

Your assessment places your organization within one of NIST CSF 2.0’s four implementation tiers.

Function Performance & Gap Analysis

Govern
82%

Govern is Harborlight's strongest function, supported by documented risk themes, conservative risk appetite, a risk register, and identified mission-critical processes. The score is limited by the absence of described governance structure, audit activity, compliance monitoring, and security metrics needed for repeatable oversight.

Identify
55%

Harborlight has identified key business processes and risks, including ransomware, PHI exposure through third-party integrations, insider misuse, and single-cloud-region dependency. The moderate score indicates that risk identification exists but needs stronger asset, vendor, data, and dependency management tied to the patient portal, APIs, telemetry ingestion, and EHR sync.

Protect
75%

Protective capabilities are relatively mature compared with other functions and are supported by generated policies for access control, data handling, acceptable use, vulnerability management, and secure development. The score indicates established protective direction, but implementation must be made consistent across PHI, PII, proprietary data, cloud workloads, endpoints, and third-party integrations.

Detect
43%

Detection is a significant gap because monitoring practices for Azure-hosted web applications, APIs, data pipelines, mobile workloads, and clinical data integrations are not yet defined. This limits Harborlight's ability to identify ransomware activity, data exfiltration, insider misuse, and supply chain events affecting patient-facing services.

Respond
38%

Respond is the lowest-scoring function because the incident response plan is draft or informal and has not been tested through tabletop exercises or incident response validation. This creates execution risk for breach notification, containment, evidence preservation, and communications under HIPAA and clinic business associate agreements.

Recover
45%

Recover is limited by the documented dependency on a single cloud region and the need for disaster recovery planning aligned to mission-critical services. Recovery procedures should be defined for patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync processes to reduce downtime risk.

Strongest: Govern (82%). Lowest: Respond (38%).

Implementation Tier Analysis

OverallT2Risk-Informed GovernanceT2 Risk ManagementT2

Based on your responses, Harborlight Health Technologies is operating at Implementation Tier 2 (Risk-Informed) overall. Within that, your responses indicate governance at Tier 2 and risk management at Tier 2. The evidence below explains what is driving this placement.

What this assessment is based on

  • Govern: Govern is Harborlight's strongest function, supported by documented risk themes, conservative risk appetite, a risk register, and identified mission-critical processes. The score is limited by the absence of described governance structure, audit activity, compliance monitoring, and security metrics needed for repeatable oversight.
  • Identify: Harborlight has identified key business processes and risks, including ransomware, PHI exposure through third-party integrations, insider misuse, and single-cloud-region dependency. The moderate score indicates that risk identification exists but needs stronger asset, vendor, data, and dependency management tied to the patient portal, APIs, telemetry ingestion, and EHR sync.
  • Protect: Protective capabilities are relatively mature compared with other functions and are supported by generated policies for access control, data handling, acceptable use, vulnerability management, and secure development. The score indicates established protective direction, but implementation must be made consistent across PHI, PII, proprietary data, cloud workloads, endpoints, and third-party integrations.
  • Detect: Detection is a significant gap because monitoring practices for Azure-hosted web applications, APIs, data pipelines, mobile workloads, and clinical data integrations are not yet defined. This limits Harborlight's ability to identify ransomware activity, data exfiltration, insider misuse, and supply chain events affecting patient-facing services.
  • Respond: Respond is the lowest-scoring function because the incident response plan is draft or informal and has not been tested through tabletop exercises or incident response validation. This creates execution risk for breach notification, containment, evidence preservation, and communications under HIPAA and clinic business associate agreements.
  • Recover: Recover is limited by the documented dependency on a single cloud region and the need for disaster recovery planning aligned to mission-critical services. Recovery procedures should be defined for patient portal, scheduling, clinical API, telemetry ingestion, and EHR sync processes to reduce downtime risk.
Learn about NIST CSF Tiers →

What We Found

The gaps your responses surfaced, ordered by severity. Each maps to a NIST CSF 2.0 subcategory.

3 gaps surfaced from your responses (1 high, 2 medium), spanning 3 CSF functions.

  1. 1
    Incident response is not tested RS.MA-02High

    Plans that aren't rehearsed fail in real incidents. Tabletop and full-scale exercises surface gaps before adversaries do.

    Your full report covers how to close this and includes the Incident Response Policy that puts it in force.

  2. 2
    No documented top cybersecurity risks GV.RM-01Medium

    Leadership has not formally identified, ranked, or owned the organization's top cybersecurity risks.

    Your full report covers how to close this and includes the Information Security Policy that puts it in force.

  3. 3
    No disaster recovery plan RC.RP-01Medium

    Technology DR is undocumented. RTOs and RPOs for critical systems are not declared or measured.

    Your full report covers how to close this and includes the Backup & Recovery Policy that puts it in force.

Explore the paid deliverables

Security Assessment Report Information Security Policy Acceptable Use Policy Access Control & Identity Management Policy Data Classification & Handling Policy Logging, Monitoring, and Alerting Policy Vendor & Third-Party Risk Management Policy Backup & Recovery Policy Incident Response Policy Vulnerability & Patch Management Policy Secure Development (SDLC) Policy Cyber Insurance Application Worksheet Vendor Security Questionnaire Response Pack Executive and Board Memorandum Findings Register and CSF 2.0 Coverage Matrix Remediation Tracker Roles and Responsibilities Matrix Evidence Request Checklist Incident Response Quick Card