CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 5

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 5

CCI Series | Preparing your organization for NIS2 with SG2CI – STEP 5 6912 3456 Centro de Ciberseguridad Industrial

Step 5. If you cannot measure your capabilities, you cannot improve them

During the previous steps, we built governance, understood industrial operations, developed protection, detection, and response capabilities, and learned to manage the risk introduced by the supply chain. Now a new question arises:

How do we know if we are truly prepared? Many organizations respond by showing the number of patched vulnerabilities, inventoried devices, hours of training delivered, or recorded incidents. All of that information can be useful, but none of it answers the question Management really cares about: Is our capability to maintain operational continuity against a cyberattack actually increasing? Because measuring activity is not the same as measuring capability.

Maturity is not about getting a score

One of the most common mistakes is turning maturity models into a competition to reach the highest possible level. Maturity is not an award; it is a tool for making better decisions.

Two organizations can achieve the same score and present completely different risk levels. One may have invested in capabilities critical to its operations, while the other may have developed capabilities that are barely relevant to the risks it actually faces.

That is why maturity only makes sense when interpreted alongside the industrial context, the criticality of essential processes, and the strategic objectives of the organization. Not all capabilities need to evolve at the same pace.

SG2CI turns maturity into a decision-making tool

In SG2CI, this fifth step is developed through Axis 5 “Resilience and Improvement”, especially through the following domains:

D11. Operational resilience and continuity, whose goal is to verify that the organization can maintain or recover operations when preventive capabilities are no longer sufficient.

D12. Assessment, maturity, and continuous improvement, where an objective model is established to measure capability evolution, identify priorities, and guide decision-making.

These domains make it possible to answer questions such as:

    • Which capabilities currently represent our greatest risk?

    • Which improvements will produce the greatest increase in resilience?

    • Where are we investing more than necessary?

    • How do we justify investments to Management?

    • How do we demonstrate the continuous improvement required by NIS2?

In this way, assessment stops being a document-based exercise and becomes a permanent governance tool.

MACIN to measure what truly matters

To facilitate this work, SG2CI incorporates MACIN, the CCI platform for assessing the maturity of industrial cybersecurity capabilities.

MACIN allows organizations to consistently evaluate the level of development across each SG2CI domain, identify strengths, detect areas for improvement, and build a prioritized evolution roadmap.

It helps answer an essential question: What should be the next step to increase organizational resilience with the highest possible impact? Because not all improvements provide the same value, nor should they all be executed at the same time.

How to know if this fifth step has been achieved?

By the end of this phase, the organization should objectively know the development level of its capabilities, understand which areas require priority attention, and have a roadmap aligned with actual business risk.

It should also be able to explain to Management why certain investments must be made before others and how each contributes to increasing operational resilience.

It is not about getting a high score, but about having the necessary information to make better decisions.

A final reflection

In engineering, no one improves a process without measuring its performance first. In industrial cybersecurity, the exact same thing must happen. Intuition helps you get started, but measurement allows you to evolve.

Continuous improvement does not begin when we deploy new technologies, but when we are able to objectively measure our capabilities and decide, with clear criteria, what the next step should be.

In the next and final post, we will conclude the journey by building a multi-year transformation program that integrates governance, architecture, capabilities, supply chain, and maturity into a single strategy aligned with NIS2.

José Valiente
CCI Director