
| Characteristic | No plan | Initial | Managed | Defined | Quantitatively managed | Optimising |
|---|---|---|---|---|---|---|
| - | - | - | - | - | - | - |
| - | - | - | - | - | - | - |
| - | - | - | - | - | - | - |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Download
Source
Release date
March 2022
Region
Asia, APAC
Survey time period
2019 to 2022
Number of respondents
900 respondents
Special properties
among cyber security decision makers; 100 respondents each from Malaysia, Philippines, and Singapore; 200 respondents each from Australia, India, and Japan
Supplementary notes
The source defines maturity levels as follows:
No plan: there is no cybersecurity capability in place.
Managed: Basic level strategy in place that ensures projects and activities are undertaken in a planned manner with basic performance, measurement and controls in place to track progress.
Defined: Capability is proactive rather than reactive and organisation-wide with
appropriate guidance for projects and activities in a co-ordinated program.
Quantitative: Capabilities, performance and assessment are metrics-based with
quantified objectives that are aligned to company cybersecurity strategy and goals.
Optimised: Focus on continuous improvement cycles with a proven ability to adapt to change.
Citation formats









