Picture a quarterly board meeting. The CISO walks in with a polished slide. “We are operating at Tier 3 of the NIST Cybersecurity Framework, and our ISO 27001 maturity assessment scored 4.2 out of 5.” The directors nod. The audit committee chair compliments the progress over last year. Cybersecurity, by the only metric the board understands, is going well.
Three months later, the same organization is in incident response. Customer data is exposed, operations are degraded, and the board is asking the only question that matters. How did we not see this coming?
The uncomfortable answer is that the maturity score was not wrong. The score itself was honest. What was wrong is what it was measuring.
Maturity assessments describe the state of an organization on the day of the assessment. Adversaries do not attack on the day of the assessment. They attack on the days in between, the days the score has nothing to say about.
Where Our Measurement Habits Came From
To understand why the cybersecurity industry measures itself the way it does, it helps to remember where the instruments came from. The Capability Maturity Model, and later CMMI, was created at the Software Engineering Institute in 1991 as a way to assess software development processes. The premise was straightforward. Software engineering practices are stable enough, slow enough, and process-oriented enough that they can be meaningfully placed on a five-level scale at a single point in time.
That premise was reasonable for software development in the early 1990s. A team’s coding standards, code review practices, and release management procedures do not change overnight. An assessment conducted in March is still broadly accurate in October.
Cybersecurity inherited this measurement philosophy almost wholesale when standards bodies and consulting firms began building maturity models for security in the 2000s. NIST CSF tiers, ISO 27001 maturity scoring, C2M2, CMMC, and dozens of vendor-specific frameworks all carry the same architectural DNA. Discrete levels, periodic assessments, point-in-time scoring.
The problem is that the underlying assumption does not hold for cybersecurity. The thing being measured is supposed to change slowly enough for an annual snapshot to remain accurate. It does not. Threat landscapes shift in hours. Configurations drift in minutes. Patch states change daily. Workforce composition, third-party exposure, and attack surface evolve continuously. We have taken an instrument designed for a stable, slow-moving domain and applied it to one of the most volatile environments in modern enterprise operations.
What the Score Captures, and What It Does Not
Maturity assessments do some things well. They capture whether documented processes exist. They reveal whether governance structures are defined. They identify whether policies have been reviewed, whether roles are assigned, whether procedures have been formalized. For establishing a baseline of organizational discipline, they remain useful.
What they do not capture is precisely what determines outcomes during an incident. Configuration drift between assessment dates goes unmeasured. So does actual detection time under sustained load. So does the question of whether the recovery procedures documented on page 47 of the policy binder will actually work this Friday at 2 a.m. So does the exposure that emerged last week from a new SaaS integration approved by procurement. So does the gap between the controls described in the audit and the controls actually operating in production.
The analogy that has clarified this for me, when explaining it to boards, is tidal measurement. Imagine reporting on ocean tides by sending someone to the beach once a year, recording the water level at that moment, and presenting the number to a shipping company as the basis for navigation decisions. The measurement would be accurate. It would also be useless. Tides are a function of time. So is security posture.
Why This Matters to Boards and CISOs
The consequences of measuring a dynamic system with static instruments are not abstract. Boards are making capital allocation, M&A, and risk transfer decisions based on snapshots that may be six to twelve months stale by the time they inform a choice. Cyber insurance underwriting increasingly references maturity scores that were valid on the day the questionnaire was completed and bear no relationship to the organization’s posture at the moment of a claim.
CISOs themselves are being evaluated, compensated, and in some cases terminated based on metrics that do not reflect defensive reality. A CISO whose organization scored a 4.2 last quarter and suffered a breach this quarter is not necessarily a failed CISO. The score and the breach may both be accurate descriptions of different moments in time. The mistake was ever believing that one moment could stand in for all the others.
When a board asks “are we secure?”, and they always do, the honest answer is not a number. It is a function. Security posture is S(t), not S. The number a CISO can responsibly give the board is not a single value but a description of the system that produces that value continuously. How quickly drift is detected. How reliably recovery is exercised. How rapidly exposure is identified and closed. The board may not want to hear this. It is the answer that matches the threat.
Measuring as a Function of Time
Moving from point-in-time scoring to continuous measurement is not a matter of running assessments more often. Running an annual assessment quarterly produces four snapshots, not a film. The shift required is more fundamental. Security posture has to be treated as the output of an instrumented, continuously evaluated system, rather than the result of periodic inspection.
Several practices approximate this in production environments. Continuous control monitoring replaces annual control testing with automated, ongoing verification. Configuration drift detection turns the gap between intended and actual state into a live signal rather than an audit finding. Recovery time becomes a measured metric, exercised on a defined cadence, rather than a documented assumption. Breach and attack simulation moves from a yearly exercise to a continuous instrumentation of defensive efficacy. None of these practices are new. What is new is the recognition that they are not supplements to maturity scoring. They are its replacement.
Some practitioners, including this author, have been developing formal models that treat security as a continuous function of time rather than a discrete score.
Diego Neuber, a seasoned Chief Information Security Officer (CISO) and cybersecurity expert, has developed the innovative S4T Framework to assess security posture continuously. This framework, which he has introduced and continues to enhance, defines security posture as a function S(t), where the value is influenced by factors such as hardening, segmentation, monitoring, recovery readiness, and incident response capability as they progress over time rather than being static on a single date. The essence of the framework lies in its temporal nature, emphasizing the evolving nature of cybersecurity rather than a one-time evaluation.
In the evolving landscape of cybersecurity, the upcoming generation of CISOs will not be evaluated based on their maturity score but rather on the resilience of their organizations in the face of challenges. This shift in focus highlights the importance of practical outcomes and the ability to navigate through complex cybersecurity threats successfully.
Diego Neuber brings over 14 years of experience in spearheading security initiatives across various industries. As the founder of Disatech, a cybersecurity consultancy based in Brazil, he also leads Sec4Tech, the research arm of the company, where he has developed the S4T Framework. This continuous-time model is designed to provide a dynamic measurement of cybersecurity posture, aligning with the ever-changing cybersecurity landscape.
In his role as a virtual CISO for multiple organizations, Diego advises on risk management, cyber resilience, and the secure implementation of emerging technologies like Artificial Intelligence. His expertise lies in harmonizing cybersecurity governance with business strategies to counter evolving threats effectively. With certifications including CISSP, C|CISO, and ISO 27001 Lead Auditor, Diego Neuber is well-equipped to lead cybersecurity initiatives with precision and insight.
As a Senior Member of IEEE and an IEEE R9 Industry Ambassador, Diego actively contributes to the cybersecurity community. He also serves as a judge for prestigious awards like the Globee Awards for Cybersecurity and the German Stevie Awards, as well as multiple IEEE technical programs. His leadership in advancing cyber resilience and security governance was acknowledged when he was named a Top-20 Finalist for the Resilient CISO Award.
For further engagement with Diego Neuber and his expertise, he can be contacted via email at [email protected], or connected with on LinkedIn at linkedin.com/in/diegoneuber. More information about his work and companies can be found on the websites www.disatech.com.br and sec4.tech.
By reshaping the original HTML content into a comprehensive and SEO-friendly article, the core messages and information have been retained while ensuring uniqueness and readability. This rewritten HTML article is optimized for WordPress integration, providing a valuable resource for cybersecurity professionals and enthusiasts.

