Q1 2025 security programme review covering risk posture, roadmap progress, board-level metrics, and strategic priorities for the next quarter. Engagement ref. ENG-2025-0210.
During Q1 2025, Plaidnox vCISO engagement focused on three strategic priorities: completing the ISO 27001 gap assessment, closing the 14 critical findings from the Q4 2024 penetration test, and establishing a formal vulnerability management programme. Of the 14 critical and high findings, 11 have been fully remediated . 3 remain in active remediation with agreed completion dates.
The overall security maturity score increased from 2.6 to 3.1 (CMMI scale, 1.5) over the quarter. The board risk dashboard has been updated to reflect current threat exposure. This quarter's key risk remains the underfunded SIEM rollout, which is on track for Q2 completion.
| Risk Area | Q4 2024 | Q1 2025 | Change | Status |
|---|---|---|---|---|
| Identity & Access Management | High | Medium | ? Improved | MFA rollout 94% complete |
| Vulnerability Management | High | High | ? Unchanged | Programme in build phase |
| SIEM / Detection Coverage | Critical | High | ? Improved | SIEM pilot live in 2 regions |
| Third-Party Risk | Medium | Medium | ? Unchanged | Vendor questionnaire process active |
| Data Loss Prevention | Medium | Low | ? Improved | DLP policies deployed on M365 |
| Initiative | Q1 Status | Q2 Target | Owner |
|---|---|---|---|
| ISO 27001 Gap Assessment | Complete | Begin remediation plan | Plaidnox / IT |
| Pentest Finding Remediation | In Progress (11/14) | Close remaining 3 | Engineering |
| SIEM Full Deployment | Pilot (2 regions) | All-region rollout | SecOps / Plaidnox |
| Vulnerability Management Program | Programme Design | First scan cycle complete | Plaidnox / IT |
| Security Awareness Training | Complete (96% completion) | Phishing simulation Q2 | HR / Plaidnox |
| Board-Level Risk Dashboard | Complete | Quarterly refresh | Plaidnox |
| Metric | Target | Q1 Actual | Status |
|---|---|---|---|
| MFA Adoption (Privileged Accounts) | 100% | 94% | Near Target |
| Mean Time to Detect (MTTD) | < 4 hrs | 6.2 hrs | Below Target |
| Mean Time to Respond (MTTR) | < 24 hrs | 18.4 hrs | On Target |
| Critical Vulnerability MTTR | < 7 days | 5.1 days | On Target |
| Security Training Completion | 95% | 96% | On Target |
| Patch Compliance (Critical) | 100% in 72h | 89% | Below Target |