Engagements  /  PSY-AUD-0388

A maturity baseline the board could actually read

A credit union’s board asked a simple question — how secure are we? — and received three vendor reports that answered it three different ways.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
Financial services and fintech
Engagement
NIST CSF 2.0 audit
Frameworks
NIST CSF 2.0, CIS Controls v8.1
Duration
5 weeks

A regional credit union.

Over two years the credit union had collected a managed-services report, an insurer’s questionnaire and an internal IT review. Each used its own scoring, and none of them agreed on what to fix first.

The new CEO wanted one picture, in one framework, that could be repeated each year and compared.

What we did

One framework, one page, one roadmap.

Assess against NIST CSF 2.0

We built a current profile across all six functions, starting with Govern — new in version 2.0 — which surfaced that nobody at leadership level formally owned cyber risk.

Spot-check the technical claims

Interviews were verified against evidence: MFA coverage, backup restore tests and patch timelines were checked rather than taken on trust, using the CIS Controls v8.1 safeguards as the yardstick.

Turn gaps into a funded roadmap

Twenty-two gaps were grouped into four quarters of work, each with an owner, a rough cost and the CSF outcome it moves.

What we found

Where the three reports disagreed.

SeverityFindingMaps toStatus at retest
HighBackups were taken nightly, but no restore had been tested in 19 months.CSF RC.RP · CIS 11.5Closed
HighMFA was enforced for staff email but not for the core banking administrator console.CSF PR.AA · CIS 6.5Closed
HighNo named executive owner for cyber risk; not on the board agenda.CSF GV.RRClosed
HighTwo vendors held standing domain administrator access with no review.CSF GV.SC · CIS 5.4In progress
MediumIncident response plan last updated before the move to cloud email.CSF RS.MA · CIS 17.4Closed

What changed.

The board received a one-page CSF 2.0 profile showing current and target tiers per function, and a quarterly roadmap. The CEO now presents progress against the same profile at each board meeting.

Six months later the follow-up review showed three functions moved up a tier, and the insurer’s renewal questionnaire was answered from the same evidence.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.