
Know where you stand. Fund what's next.
A scored security posture and a costed, sequenced roadmap — in 4–6 weeks.
Scored in the language your board and your regulator both speak — NIST CSF 2.0, ISO 27001, CIS v8.1, BSSN Indeks KAMI, OJK — from one evidence-backed assessment.
4–6 wks
From kickoff to a board-ready roadmap
5
Frameworks scored in one pass — CSF · ISO · CIS · KAMI · OJK
1.5 → 4.0
Indeks KAMI delta on a governed Zentara program
The gap
Boards fund evidence, not anxiety.
Boards approve security budgets against evidence, not anxiety. Most programs can't show where they are, where they're going, or why the sequence is right.
The FUD budget
Threat statistics and fear get a polite nod and a deferred line item. Boards fund evidence about their own estate, not headlines about someone else's.
The framework mush
A self-scored spreadsheet — generous threes down the column — that no one can defend when a director, an auditor, or OJK asks how the number was reached.
The roadmap without prices
Twenty initiatives, no costs, no sequence, no owners. That's not a plan the board can approve; it's a wishlist they can only admire.
The three questions every board asks
“Where are we today?”
A score with evidence behind it
“Where do we need to be?”
A target tied to your regulator and risk
“What will it cost to get there?”
A sequence with numbers attached
If the answer isn't a number, the answer is no.
What you get
What lands on the table
Four artifacts, built to be used — in the boardroom, with the regulator, and by the engineers who deliver the plan.
Maturity scorecard · NIST CSF 2.0
Prepared for: · Assessed 12–23 May 2026 · Baseline #1
GVGovern
1.8 → 3.5
IDIdentify
2.1 → 3.5
PRProtect
2.4 → 3.5
DEDetect
1.6 → 4.0
RSRespond
1.9 → 4.0
RCRecover
2.2 → 3.0
Now
0–90 days
Close MFA coverage gaps
EDR to unmanaged endpoints
IR runbook + escalation tree
Next
6–12 months
Consolidate logging into one SIEM
Vendor-risk program stand-up
UU PDP gap closure — priority clauses
Later
12–36 months
Zero-trust segmentation, phased
ISO 27001 certification
Maturity re-score & target reset
Scored maturity assessment
Function-by-function scores with the evidence trail behind every number — defensible in front of a director, an auditor, or a regulator.
Regulatory gap register
Clause-level gaps against the frameworks that bind you — OJK, BSSN, UU PDP — each with severity and a closure owner.
Costed, sequenced roadmap
Every initiative with an owner, a cost band, and a dependency line — sequenced into horizons your team can actually deliver.
Board pack & briefing
The story in board language: posture, target, investment, and the risk of the do-nothing path. We present it in the room with you.
Frameworks
Assessed once. Scored on every scale.
Your board, your auditor, and your regulator each speak a different framework. One evidence base answers all of them — so you stop re-assessing for every stakeholder.
NIST CSF 2.0
The common language
Six functions your board, insurers, and international partners all recognize. The spine of the scorecard.
ISO 27001:2022
The certification path
Annex A control mapping — so the same assessment becomes your certification gap analysis when you're ready.
CIS Controls v8.1
The engineering cut
Control-level prioritization by implementation group — what your engineers fix first, in what order.
BSSN Indeks KAMI
The government scale
The maturity index Indonesian government and SOE entities are measured on. We score it formally, not by feel.
OJK / Bank Indonesia
The supervisory lens
IT risk maturity the way bank supervisors frame it — mapped to POJK obligations and inspection expectations.
How it runs
Six weeks. Four moves.
Audit-grade evidence discipline with a board-grade output — and your team's time protected throughout.
Frame
Scope, stakeholders, and regulatory applicability. We agree the target scale — CSF, KAMI, or both — and what the board needs to decide at the end.
Evidence
Interviews plus instruments — an AVAS technical baseline, configuration and log review, and control testing. Scores get evidence, not opinions.
Score
Function-by-function scoring with the evidence trail attached, calibrated against sector peers so the number means something in context.
Sequence & price
Initiatives costed in bands, sequenced by dependency and risk burn-down, packaged for the board — and briefed in the room, by us.
Start free
Not ready for the full assessment? Score yourself in five minutes.
The free self-check gives you a directional maturity read across the same functions — a first signal you can bring to the conversation. When you want a number that survives a board's follow-up question, we take it from there.
When it fits
Five moments this engagement is built for
A new CISO's first 100 days
Walk into your first board meeting with a scored baseline and a plan — not a request for more time.
After an incident
Rebuild credibility with a measured posture and a sequence that shows the lesson landed.
Before certification
ISO 27001 or SOC 2 on the horizon — know the gap and the cost before the auditor's clock starts.
A regulator deadline
OJK inspection, BSSN Indeks KAMI submission, or UU PDP enforcement — with a formal score to answer with.
Outgrowing ad-hoc security
The scale-up moment when enterprise clients start sending questionnaires you can't yet pass.
Track record
Roadmaps delivered for Islamic banking spin-offs, cross-border payment fintechs, and national banks.
And where Zentara stays to run the roadmap, the score moves: BSSN Indeks KAMI maturity taken from 1.5 toward ≥4.0 on a governed program, verified by formal re-scores.
Build the program
Pairs well with
vCISO — Virtual CISO
A roadmap needs an owner. A named vCISO runs it to completion — chaired governance, quarterly board reporting, and a re-score every six months.
Information Security Assessment (ISO 27001)
If the roadmap ends at certification, the ISMS assessment by certified Lead Auditors is the next formal step.
VAPT — Vulnerability Assessment & Penetration Testing
Scores say the controls exist. Certified offensive testing proves they hold — and feeds the next re-score with hard evidence.
FAQ
Common questions
Straight answers. If yours isn't here, ask us directly.
The self-check is directional: self-reported answers, indicative scoring, five minutes — a useful first signal. This engagement is defensible: four to six weeks of interviews and instruments, an AVAS technical baseline, evidence attached to every score, and a costed roadmap at the end. One tells you roughly where you are; the other survives a director's or a regulator's follow-up question.
Related
More in Advisory & Compliance
Walk into the next board meeting with a number.
A scored posture, a costed roadmap, and a briefing delivered in the room — four to six weeks from kickoff. Start with the free self-check, or scope the full assessment.