The Executive Diagnostic and Governance Toolkit
Proving Cyber Hygiene Maturity
Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing they already hold the cyber hygiene playbook: the implementation guide, the roadmap and the working files, so repeating any of that is worthless. What is missing is the layer after implementation. How to assess the function honestly, what evidence to retain, how to score maturity, and how to put the result in front of a manager, an auditor or a client who was not involved. The immediate question: for one month of cyber hygiene work, can you show what was measured, against what target, and what changed as a result.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
| 1 |
You stop guessing where you stand. You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis. |
| 2 |
You can defend the decision. You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language. |
| 3 |
The work actually moves. The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total. |
| 4 |
You use it the day it lands. No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over. |
The situation this is built for
You’ve executed the cyber hygiene playbook. Controls are configured, policies are signed, and training is complete. Yet when an auditor, client, or executive asks, 'Show me what improved,' you hesitate. The implementation assets exist—but the proof of impact does not. There’s no consistent way to score maturity, retain evidence, or link actions to outcomes. Without this, your work remains invisible or untrusted.
Who this is for
A security practitioner who owns cyber hygiene implementation and now must demonstrate its effectiveness to stakeholders who were not involved in the work.
Who this is not for
This is not for teams still building their first cyber hygiene controls or selecting tools. It is not for executives seeking high-level overviews or vendors selling automation platforms.
What you walk away with
- Score cyber hygiene maturity with objective criteria
- Retain defensible evidence of control effectiveness
- Map monthly activities to measurable outcomes
- Report confidently to auditors and leadership
- Build a living assessment cycle that survives staff changes
How this maps to your situation
- Implementer overwhelmed by auditor requests
- Owner unable to show progress to leadership
- Team maintaining controls but not measuring them
- Practitioner needing to prove program value
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed to be completed alongside ongoing work. Total time: 36 hours over 12 weeks with flexible pacing.
How this compares to the alternatives
Most training focuses on implementing controls or using specific tools. This course is different—it teaches the discipline of proving those controls work. Unlike generic audit prep or maturity frameworks, it delivers actionable methods for documenting, scoring, and reporting real outcomes from existing cyber hygiene efforts.
Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)
Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.
- Defining cyber hygiene beyond checklist completion
- Distinguishing assessment from implementation work
- Identifying stakeholders who demand proof
- Mapping evidence requirements to audience type
- Understanding the lifecycle of control validation
- Setting boundaries for what counts as proof
- Aligning with internal audit expectations
- Documenting control ownership clearly
- Using maturity models without overcomplicating
- Avoiding common assessment pitfalls
- Integrating feedback from past reviews
- Building a baseline for progress tracking
- Choosing evidence types for technical controls
- Capturing screenshots with context and date
- Logging command-line execution with timestamps
- Archiving policy acknowledgment records
- Preserving training completion reports
- Documenting exception approvals formally
- Standardizing file naming for audit trails
- Organizing evidence by control domain
- Assigning retention periods to artifacts
- Using version control for policy documents
- Linking evidence to control objectives
- Validating evidence completeness before review
- Setting measurable outcomes for patching cadence
- Tracking endpoint configuration compliance rates
- Measuring phishing test failure reduction
- Calculating mean time to detect anomalies
- Auditing privileged account review frequency
- Assessing backup restoration success rates
- Monitoring DNS change approval adherence
- Evaluating firewall rule change logging
- Scoring multi-factor authentication adoption
- Verifying asset inventory accuracy updates
- Quantifying vulnerability scan coverage
- Benchmarking control performance monthly
- Defining levels of maturity for access reviews
- Scoring consistency in log retention practices
- Rating incident response playbooks for readiness
- Assessing change management enforcement strength
- Grading user training effectiveness by role
- Evaluating encryption coverage across data tiers
- Measuring completeness of third-party assessments
- Scoring segmentation compliance in network zones
- Rating configuration drift detection capability
- Assessing automated alerting reliability
- Grading documentation update timeliness
- Using scoring to prioritize improvement areas
- Structuring the assessment playbook for reuse
- Including evidence collection instructions
- Adding control-specific measurement criteria
- Embedding retention policies for artifacts
- Linking to existing implementation guides
- Updating the playbook after audits
- Versioning assessment methodology changes
- Including stakeholder communication templates
- Defining roles in the assessment cycle
- Integrating feedback from control owners
- Aligning with regulatory mapping tables
- Maintaining the playbook across team changes
- Scheduling the monthly review meeting
- Preparing evidence packets in advance
- Inviting control owners to present
- Documenting unresolved findings formally
- Tracking action items with deadlines
- Verifying fix implementation promptly
- Updating scorecards after review
- Archiving meeting minutes securely
- Notifying stakeholders of results
- Integrating findings into risk register
- Adjusting review scope based on risk
- Measuring review efficiency over time
- Writing executive summaries from scorecards
- Highlighting improvement trends clearly
- Calling out persistent control gaps
- Using visuals without oversimplifying
- Linking findings to business impact
- Avoiding technical jargon in reports
- Including time-to-remediate metrics
- Reporting on evidence retention status
- Stating confidence in control coverage
- Balancing transparency with discretion
- Aligning report cadence to board meetings
- Archiving management reports systematically
- Mapping controls to common audit frameworks
- Pre-populating auditor request templates
- Organizing evidence by control ID
- Writing clear control descriptions
- Including testing methodology summaries
- Preparing control owners for interviews
- Validating evidence authenticity beforehand
- Flagging compensating controls clearly
- Documenting control exceptions formally
- Providing access logs for review systems
- Responding to auditor findings promptly
- Tracking auditor recommendations to closure
- Comparing maturity scores quarter over quarter
- Graphing reduction in control failures
- Showing increased compliance rates
- Presenting improved response times
- Highlighting staff awareness improvements
- Tracking audit finding closure rates
- Demonstrating fewer exceptions granted
- Showing stronger policy adherence
- Measuring reduced configuration drift
- Illustrating faster evidence retrieval
- Reporting fewer access control lapses
- Using timelines to show program growth
- Onboarding new staff to assessment routines
- Documenting tribal knowledge formally
- Scheduling knowledge transfer sessions
- Updating contact lists for control owners
- Conducting peer reviews of evidence
- Rotating review responsibilities fairly
- Archiving departed employee access
- Preserving institutional memory digitally
- Rehearsing audit responses annually
- Maintaining playbook accessibility
- Reviewing assessment roles annually
- Measuring team assessment proficiency
- Feeding findings into the risk register
- Linking control gaps to risk ratings
- Informing risk treatment decisions
- Updating risk heat maps quarterly
- Supporting internal audit planning
- Providing data for insurance renewals
- Contributing to third-party risk assessments
- Aligning with compliance obligations
- Informing cyber insurance questionnaires
- Supporting board-level risk reporting
- Connecting to incident response planning
- Updating risk scenarios based on findings
- Extending assessment to new business units
- Adapting evidence collection for cloud systems
- Integrating assessment into onboarding
- Scaling scoring for larger environments
- Automating evidence collection selectively
- Adjusting review frequency by risk tier
- Managing third-party assessment demands
- Standardizing assessment across regions
- Integrating with continuous monitoring tools
- Training partners on evidence standards
- Evaluating tooling needs objectively
- Planning capacity for audit season
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Thousands of organisations have bought from The Art of Service since 2000.