Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 5 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.5

The cognitive security maturity model

After the voice-forgery incident, Fawzooz needed an instrument that would answer a single question: how ready is this organisation for an attack aimed at cognition rather than at infrastructure? UCSMM was born out of that question, and what follows is the model in full.

FIG. 29 — The four dimensions
Awareness
Do people know that cognition is an attack surface? And what an attack on them would look like?
Verification
Are there mandatory procedures for confirming identity and exceptional requests?
Monitoring
Are attempts at deception and impersonation detected, and reported without blame?
Response
Is there a tested procedure for a forgery incident, and who speaks in it?
fawzooz.ai
FIG. 30 — The five levels
1
1 Unaware
No perception of the danger; security is entirely technical.
2
2 Aware
The danger is talked about, with no written procedure.
3
3 Systematic
Procedures are written, published and trained on.
4
4 Measured
Procedures are tested by exercises, and their results measured.
5
5 Adaptive
Procedures change of themselves as attack methods change.
fawzooz.ai
The maturity matrix — where do you stand on each dimension?

Read each row and mark the last description that is true of your organisation today — not the one you intend to reach.

FIG. A8 — Four dimensions × five levels
1 Unaware2 Aware3 Systematic4 Measured5 Adaptive
AwarenessNobody sees perception as an attack surfaceScattered warnings with no planScheduled, regular trainingThe effect of training is measuredA settled culture, reviewed
VerificationWhat arrives is believed as it arrivesPrivate, unwritten doubtA documented verification procedureCompliance rates are trackedAutomated verification, audited
DetectionNo detection and no channelOccasional reportsA known reporting channelIndicators and a dashboardProactive watch for campaigns
ResponseImprovisation in the crisisOne person who gets calledA written, communicated planThe plan is rehearsed regularlyFast recovery, lessons folded back in

fawzooz.ai

Your weakest row is your real ceiling, not the arithmetic average. The practical rule: raise one level in one cycle, no more.

0 absent · 1 partial · 2 in place and documented. Total each dimension out of 10.

How to read the result

A score of 0 to 3 in a dimension puts you at level 1 or 2. From 4 to 6 puts you at level 3, from 7 to 8 at level 4, and from 9 to 10 at level 5. And do not add the four dimensions together into a single number: your maturity is your lowest dimension, exactly as the strength of a chain is the strength of its weakest link. An organisation with excellent awareness and no response at all will fall at the first incident.

And the plan for climbing has one rule to it: one level per cycle, in the weakest dimension only. Organisations that try to jump two levels across four dimensions at once finish nothing at all — I have watched it happen many times.

Do this

  1. 1 — In your field. Fill in the twenty items honestly. The items you hesitate over are usually a "zero".

  2. 2 — Verify. Ask a colleague in another department to fill it in independently. The gap between the two assessments is the truest thing you will read.

  3. 3 — In writing. Write a plan to climb one level in the weakest dimension: three actions, an owner for each, and a date.