ZENTARA
A Zentara architect briefing the board on a deployment architecture
Cybersecurity Roadmap · Maturity Advisory

Know where you stand. Fund what's next.

A scored security posture and a costed, sequenced roadmap — in 4–6 weeks.

Scored in the language your board and your regulator both speak — NIST CSF 2.0, ISO 27001, CIS v8.1, BSSN Indeks KAMI, OJK — from one evidence-backed assessment.

4–6 wks

From kickoff to a board-ready roadmap

5

Frameworks scored in one pass — CSF · ISO · CIS · KAMI · OJK

1.5 → 4.0

Indeks KAMI delta on a governed Zentara program

Certified & audited operations

BSSN — Badan Siber dan Sandi NegaraISO/IEC 27001 CertifiedISO/IEC 42001:2023 CertifiedAICPA SOC 2 Type 2
Verify at our trust centre

The gap

Boards fund evidence, not anxiety.

Boards approve security budgets against evidence, not anxiety. Most programs can't show where they are, where they're going, or why the sequence is right.

The FUD budget

Threat statistics and fear get a polite nod and a deferred line item. Boards fund evidence about their own estate, not headlines about someone else's.

The framework mush

A self-scored spreadsheet — generous threes down the column — that no one can defend when a director, an auditor, or OJK asks how the number was reached.

The roadmap without prices

Twenty initiatives, no costs, no sequence, no owners. That's not a plan the board can approve; it's a wishlist they can only admire.

The three questions every board asks

Where are we today?

A score with evidence behind it

Where do we need to be?

A target tied to your regulator and risk

What will it cost to get there?

A sequence with numbers attached

If the answer isn't a number, the answer is no.

What you get

What lands on the table

Four artifacts, built to be used — in the boardroom, with the regulator, and by the engineers who deliver the plan.

Zentara_Maturity_Scorecard_[CLIENT]_2026.pdf — sampleConfidential

Maturity scorecard · NIST CSF 2.0

Prepared for: · Assessed 12–23 May 2026 · Baseline #1

GVGovern

1.83.5

IDIdentify

2.13.5

PRProtect

2.43.5

DEDetect

1.64.0

RSRespond

1.94.0

RCRecover

2.23.0

Today, evidenced 24-month targetScale 0–5 · method ZTR-MM v3.1
Prepared by Zentara GRC Practice · QA: Lead AssessorPage 6 of 48
Zentara_Security_Roadmap_[CLIENT]_FY26-28.pdf — sampleConfidential

Now

0–90 days

Close MFA coverage gaps

$IT OPS

EDR to unmanaged endpoints

$$SEC ENG

IR runbook + escalation tree

$CISO

Next

6–12 months

Consolidate logging into one SIEM

$$SEC ENGEDR rollout

Vendor-risk program stand-up

$GRC

UU PDP gap closure — priority clauses

$$GRC · LEGAL

Later

12–36 months

Zero-trust segmentation, phased

$$$SEC ENGSIEM consolidation

ISO 27001 certification

$$GRC

Maturity re-score & target reset

$ZENTARA
Every initiative — owner · cost band · dependencyPage 12 of 48
01

Scored maturity assessment

Function-by-function scores with the evidence trail behind every number — defensible in front of a director, an auditor, or a regulator.

02

Regulatory gap register

Clause-level gaps against the frameworks that bind you — OJK, BSSN, UU PDP — each with severity and a closure owner.

03

Costed, sequenced roadmap

Every initiative with an owner, a cost band, and a dependency line — sequenced into horizons your team can actually deliver.

04

Board pack & briefing

The story in board language: posture, target, investment, and the risk of the do-nothing path. We present it in the room with you.

Frameworks

Assessed once. Scored on every scale.

Your board, your auditor, and your regulator each speak a different framework. One evidence base answers all of them — so you stop re-assessing for every stakeholder.

NIST CSF 2.0

The common language

Six functions your board, insurers, and international partners all recognize. The spine of the scorecard.

ISO 27001:2022

The certification path

Annex A control mapping — so the same assessment becomes your certification gap analysis when you're ready.

CIS Controls v8.1

The engineering cut

Control-level prioritization by implementation group — what your engineers fix first, in what order.

BSSN Indeks KAMI

The government scale

The maturity index Indonesian government and SOE entities are measured on. We score it formally, not by feel.

OJK / Bank Indonesia

The supervisory lens

IT risk maturity the way bank supervisors frame it — mapped to POJK obligations and inspection expectations.

How it runs

Six weeks. Four moves.

Audit-grade evidence discipline with a board-grade output — and your team's time protected throughout.

01Week 1

Frame

Scope, stakeholders, and regulatory applicability. We agree the target scale — CSF, KAMI, or both — and what the board needs to decide at the end.

02Weeks 2–3

Evidence

Interviews plus instruments — an AVAS technical baseline, configuration and log review, and control testing. Scores get evidence, not opinions.

03Week 4

Score

Function-by-function scoring with the evidence trail attached, calibrated against sector peers so the number means something in context.

04Weeks 5–6

Sequence & price

Initiatives costed in bands, sequenced by dependency and risk burn-down, packaged for the board — and briefed in the room, by us.

The measurement rule —Re-scored every six months against the same baseline · the delta is the deliverable

Start free

Not ready for the full assessment? Score yourself in five minutes.

The free self-check gives you a directional maturity read across the same functions — a first signal you can bring to the conversation. When you want a number that survives a board's follow-up question, we take it from there.

When it fits

Five moments this engagement is built for

01

A new CISO's first 100 days

Walk into your first board meeting with a scored baseline and a plan — not a request for more time.

02

After an incident

Rebuild credibility with a measured posture and a sequence that shows the lesson landed.

03

Before certification

ISO 27001 or SOC 2 on the horizon — know the gap and the cost before the auditor's clock starts.

04

A regulator deadline

OJK inspection, BSSN Indeks KAMI submission, or UU PDP enforcement — with a formal score to answer with.

05

Outgrowing ad-hoc security

The scale-up moment when enterprise clients start sending questionnaires you can't yet pass.

Track record

Roadmaps delivered for Islamic banking spin-offs, cross-border payment fintechs, and national banks.

And where Zentara stays to run the roadmap, the score moves: BSSN Indeks KAMI maturity taken from 1.5 toward ≥4.0 on a governed program, verified by formal re-scores.

FAQ

Common questions

Straight answers. If yours isn't here, ask us directly.

The self-check is directional: self-reported answers, indicative scoring, five minutes — a useful first signal. This engagement is defensible: four to six weeks of interviews and instruments, an AVAS technical baseline, evidence attached to every score, and a costed roadmap at the end. One tells you roughly where you are; the other survives a director's or a regulator's follow-up question.

Walk into the next board meeting with a number.

A scored posture, a costed roadmap, and a briefing delivered in the room — four to six weeks from kickoff. Start with the free self-check, or scope the full assessment.