Reading progress
0 of 17 sections read
9 / 17

SECTION 06

06The five maturity levels

1 min read9 of 17

An organisation is at the level it can prove, not the one it describes. From improvised security to adaptive cognitive security: no level is skipped and no rank is bought with a tool. Nor is a level permanent: stop measuring and level four falls back to three — maturity is a capability maintained, not a certificate.

FIGURE 4 — THE MATURITY STAIRCASE
FIGURE 4 — THE MATURITY STAIRCASE
Text in this figure

1 · 2 · 3 · 4 · 5 · Initial · Managed · Defined · Quantitatively managed · Cognitive-optimised · Initial → cognitive-optimised · no level is skipped

Initial

Fragmented, reactive practices, manual controls and inconsistent policy enforcement. AI systems, where they exist, run without dedicated security oversight — exposed to adversarial manipulation and data poisoning.

Evidence required: None. The default level for every organisation not yet assessed.

Managed

Structured security policies, formally assigned responsibilities and basic monitoring. AI risk is recognised as a category in its own right, with early processes to manage it.

Evidence required: an approved policy · a named owner for AI risk · an initial model inventory.

Defined

Systematic integration of AI governance and security: policies protecting data and model pipelines, a unified security architecture, and AI risk assessment inside the development and deployment lifecycle.

Evidence required: a mandatory security review gate before any model deployment · a complete model register · training-data controls.

Quantitatively managed

Security has become measurable: advanced analytics, behavioural monitoring, machine-learning-based detection, and performance indicators under continuous evaluation that anticipate weakness before it is exploited.

Evidence required: time-based indicators (detect, contain, recover) · model drift monitoring · periodic board reporting.

Cognitive-optimised

A fully AI-augmented security function: autonomous learning algorithms, real-time threat intelligence and predictive analytics that detect and respond dynamically. The human analyst collaborates with the intelligent platform in an adaptive defence able to face AI-driven attacks.

Evidence required: documented automated response · proactive attack-scenario simulation · a learning cycle that changes controls without waiting for an incident.

FIGURE 5 — THREE RULES FOR CROSSING LEVELS
FIGURE 5 — THREE RULES FOR CROSSING LEVELS
Text in this figure

01 · No skipping · Tools can produce an apparent level four on top of level-two governance — more fragile than nothing, because it creates the illusion of safety. · 02 · Balance before height · Raise the weakest dimension before improving the strongest; resilience is set by the weakest dimension, not the average. · ✓ · 03 · Evidence before declaration · No level is claimed without an auditable output: a document, a record, or a measured indicator.

Tip: use ← → to move between sections.