Most organizations now critically depend on IT services, making business operations vulnerable to cyber security incidents. As IT delivery shifts from purely on-premises to hybrid models that combine on-premises, hosting, and cloud services, organizations gain flexibility and potential cost reduction but face increased complexity in management, compliance, and security. Because business goals, best practices, and technologies constantly evolve—and because regulations such as the EU GDPR raise expectations for data protection—cyber security programs must be regularly reviewed and updated. Cloud adoption also changes accountability by splitting security responsibilities between the cloud service provider (CSP) and the cloud tenant, requiring clarity about who secures which parts of the service delivery stack.
The document frames hybrid IT security through five service delivery planes (from physical data centre through infrastructure to applications and data) and emphasizes that each plane must be managed and secured, with responsibility varying by cloud model (IaaS, PaaS, SaaS). To help organizations evaluate and improve, KuppingerCole provides Maturity Level Matrices aligned with CMM concepts and recommends a five-point maturity scale based on the Carnegie Mellon Maturity Index. Level 1 is ad hoc and reactive, with weak governance, unclear responsibilities, minimal risk management, manual identity processes, and inconsistent controls; it is hard to evidence compliance. Level 4 features integrated governance across cloud and on-premises, strong management support, standardized risk-based controls, automated assurance, and an architecture aligned to recognized standards. Level 5 builds on Level 4 with optimized, self-sustaining processes, automated governance, continuous benchmarking, continuous evidence from suppliers, and full integration across identity, access, and hybrid services.
Assessment is guided by twelve Key Support Attributes: six organizational (governance, standards, management organization, risk management, control processes, audit/assurance) and six technical (architecture, data/access, application security, network security, compute/storage, physical security). The matrices also support board-level communication, for example by visualizing maturity in a spider chart against industry norms to identify risks, savings opportunities, and high-return security investments.
See All Locations
See All Locations