How maturity, plans and risk fit together

Two ways in. One set of work — a maturity assessment and a risk analysis start from different questions and end up pointing at the same control.

Path 1 · Maturity assessment

Are we mature enough?

We measure ourselves against a framework and see where we fall short. It starts from the requirements.

Framework questions Our answers Gap

Path 2 · Risk analysis

What can go wrong here?

We start from our own assets and processes and think through what threatens them.

A threat exploits a weakness Risk

Where they meet

Controls

A control is a protective measure — multi-factor authentication, for example. The assessment judges whether we have it. The risk argues that we need it. It is the same control either way, and it should only be done once.

Tasks

The control broken into concrete steps. This is where the work is actually done.

Owner and date

Every control has someone accountable and a point in time. Without them, nothing happens.

Status

Not started, in progress, done. What makes the work followable.

Evidence

Documentation showing the control exists and is used in practice.

The same control, two reasons

One concrete example: multi-factor authentication.

From the maturity side

The question in the assessment: “Do you have multi-factor authentication on all administrative accounts?”

Our answer: No

Result: a gap against NIS2 — the control lands in our action plan.

From the risk side

The risk: “Stolen credentials give unauthorised access to customer data.”

Decision: reduce

Controls that lower it: MFA, access management, access reviews, monitoring.

and

Control: MFA One piece of work, one owner, one date, one piece of evidence

Two reasons to do it. Not two jobs.

A gap is not a risk

“We have no MFA” is not a risk — it is an absence of protection. The risk is what can happen because of it. Push gaps straight into the register and it fills with to-do items and stops answering the question it exists to answer.

And a risk is rarely closed by one control

Unauthorised access needs several controls from different directions. So the register cannot be a list of gaps — one risk draws on several controls, and one control lowers several risks.

Two different questions

A maturity assessment asks are we mature enough? It starts from a framework’s requirements, walks through them, and what it finds is a gap — something the framework expects that you do not have.

A risk analysis asks what can go wrong here? It starts from your own assets and processes, and what it finds is a risk — a threat exploiting a weakness, and what that would cost you.

Neither replaces the other. The framework carries other organisations’ experience, so it raises things you would never have thought to worry about. Your own risk analysis raises what no framework asked about, because it is specific to you.

Where they meet

Both paths end up pointing at the same thing: a control. Multi-factor authentication. Backups you have actually restored from. A routine for removing access when someone leaves.

The assessment judges whether you have the control. The risk argues that you need it. It is the same control either way, and it should only be done once.

That is why a control, and not a finding or a risk, is what the platform asks you to own. Each one carries the four things that turn intent into work:

  • Tasks — the control broken into concrete steps. This is where the work is done.
  • An owner and a date — without them, nothing happens.
  • A status — not started, in progress, done. What makes it followable.
  • Evidence — documentation that the control exists and is used in practice.

The same control, two reasons

Take multi-factor authentication.

From the maturity side. The assessment asks whether you have MFA on all administrative accounts. You answer no. That is a gap against the framework, and the control lands in your action plan.

From the risk side. You describe the risk stolen credentials give unauthorised access to customer data, and decide to reduce it. The controls that lower it are MFA, access management, access reviews, monitoring.

One control. One owner, one deadline, one piece of evidence. Two reasons to do it — not two jobs.

A gap is not a risk

“We have no MFA” is not a risk. It is an absence of protection. The risk is what can happen because of it, and what that would cost.

The distinction is practical, not academic. Push gaps straight into the risk register and it fills up with to-do items, and stops answering the question it exists to answer: what could happen to us, how bad would it be, and have we decided what to do about it?

And a risk is rarely closed by one control

Unauthorised access is not solved by MFA alone. It needs several controls, from different directions, before the exposure is genuinely lower.

So the register cannot be a list of gaps. One risk draws on several controls, and one control lowers several risks. That relationship is the reason the two live in different places and are connected rather than merged.

Why the platform has the steps it has

Each step exists because something happens there that cannot happen anywhere else.

1 · The assessment measures you against a framework. It produces findings — facts about where you stand, not decisions.

2 · The report turns those findings into a score per domain, your position against every framework the questions touch, and a prioritised set of recommendations.

3 · The action plan is where a recommendation becomes work. You choose what to take on, and it gains an owner, a date and tasks. Nothing moves here on its own; committing is a human act, and this is where it happens.

4 · The risk register is where exposure is described in plain language, weighed by likelihood and consequence, and given a treatment decision — avoid, transfer, reduce or accept — recorded with a name and a date. Where the decision is reduce, controls attach underneath. The same controls.

The register also has a second door: Create Risk, for an exposure no assessment asked about — after an incident, out of a supplier review, or because someone in the room simply knows about it. Those risks are not lesser. The path above is the one most risks take, not a rule that all of them must.

Where to start

Run an assessment first. It gives you the fastest honest picture, and it fills the action plan for you.

Work the plan — take controls on, give them owners and dates, close the tasks.

Add risk analysis when a finding is not really about missing work but about exposure you need to weigh, and whenever something arrives from outside the framework entirely.