Cyber Maturity Assessment and Improvement Service
The Cyber Maturity Service provides an independent, consultancy-led assessment of an organisation’s cyber security posture. It helps organisations understand their current level of cyber maturity, identify risks and gaps, and develop a prioritised, proportionate improvement roadmap.
The service is advisory and does not include managed security services or system monitoring.
Features
- Independent cyber maturity assessment aligned to recognised public sector standards
- Alignment to NCSC Cyber Assessment Framework and NHS DSPT requirements
- Governance, risk management, and assurance capability review
- Policy, process, and control effectiveness assessment
- Third-party and supplier cyber risk evaluation
- Incident response and cyber resilience readiness assessment
- Identity, access management, and user security practices review
- Prioritised cyber improvement roadmap and recommendations
- Executive-level reporting for technical and non-technical stakeholders
- Consultancy-led, vendor-neutral, and non-managed cyber advisory service
Benefits
- Reduces cyber risk through structured, prioritised security improvement planning
- Improves governance clarity and decision-making around cyber security investment
- Strengthens operational resilience and incident response readiness
- Simplifies compliance with DSPT, CAF, and audit requirements
- Improves consistency of security processes across teams and suppliers
- Identifies control gaps before incidents disrupt services
- Reduces inefficiencies caused by unclear security ownership and processes
- Enables proportionate, risk-based cyber investment decisions
- Improves stakeholder confidence in organisational cyber capability
- Supports sustainable cyber maturity without introducing unnecessary operational burden
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 6 4 0 0 3 8 9 2 1 7 7 4 0
Contact
BY E.G. LTD
Emma Kirkbride
Telephone: 07703341500
Email: emma.kirkbride@byexampleltd.co.uk
About your service
- Service categories
-
Cloud Support Services
Security Services
- Security strategy
- Security risk management
- Security design
- Security incident management
- Security audit services
- Security quality assurance (QA) and testing
Service scope
- Service constraints
- This service provides consultancy-led, advisory cyber maturity assessment and improvement support. Scope includes review of governance, policies, risk management, and assurance arrangements; stakeholder interviews and workshops; gap analysis against recognised frameworks including CAF and DSPT and Cyber Essentials; identification of cyber risks and improvement opportunities; and development of a prioritised, proportionate improvement roadmap. The service provides executive-level reporting and recommendations only. It does not include system configuration, technical remediation, managed security services, monitoring, testing, or operational responsibility for cyber controls or live systems.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are logged via an email or ticketed service and triaged based on impact and urgency. All tickets are acknowledged within one business day. Service-impacting or high-priority issues are prioritised for same-day response during core business hours. Response times relate to initial assessment and advisory support rather than issue resolution. Where appropriate, issues are escalated or coordinated with the customer or relevant third-party suppliers. Support is delivered in line with agreed service scope and working arrangements.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
-
We provide a range of support levels designed to flex to the needs and scale of each organisation. Support can include standard business-hours assistance as well as enhanced or out-of-hours cover where required. Response times and availability are agreed in advance and aligned to the criticality of the service being supported.
Support costs vary depending on the level of cover, response expectations, and any out-of-hours or enhanced support requirements. Pricing is agreed on a case-by-case basis and set out clearly within the relevant contract or statement of work.
Depending on the service arrangement, clients may be supported by a named point of contact who provides continuity and oversight, alongside access to technical specialists as required. The exact model is tailored to the engagement and agreed at the outset.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Pricing
- Discount for educational organisations
- No
Architecture roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Trainee business architect | £550.00 | £750.00 |
| Associate business architect | £650.00 | £850.00 |
| Business architect | £1,000.00 | £1,200.00 |
| Lead business architect | £1,100.00 | £1,300.00 |
Chief digital and data roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Chief information security officer | £1,100.00 | £1,300.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Chief technology officer | £1,100.00 | £1,300.00 |
Cyber security roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Lead cyber security audit and assurance | £850.00 | £1,050.00 |
| Principal cyber security audit and assurance | £1,000.00 | £1,200.00 |
Product and delivery roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Trainee business analyst | £450.00 | £650.00 |
| Junior business analyst | £550.00 | £750.00 |
| Business analyst | £850.00 | £1,050.00 |
| Senior business analyst | £950.00 | £1,150.00 |
| Lead business analyst | £1,000.00 | £1,200.00 |
| Head of business analysis | £1,100.00 | £1,300.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate delivery manager | £650.00 | £850.00 |
| Delivery manager | £850.00 | £1,050.00 |
| Senior delivery manager | £900.00 | £1,100.00 |
| Head of (Agile) delivery management | £1,100.00 | £1,300.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Digital portfolio analyst | £550.00 | £750.00 |
| Digital portfolio manager | £800.00 | £1,000.00 |
| Senior digital portfolio manager | £900.00 | £1,100.00 |
| Head of portfolio | £1,100.00 | £1,300.00 |
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- Certified Data Protection Officer
- CISMP
- ISO/IEC 27001:2022 Requirements
- Certified Cyber Security Practitioner
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-