7 min read
Cyber Resilience Index: How successful SMEs really measure their security posture
Sascha Scholz : Updated on July 22, 2026
Table of content
“We know we have gaps, but we don’t know where to start to close them.” We hear this sentence regularly. Not from companies that neglect their cybersecurity, but from IT managers, CISOs, and managing directors who have already invested in their IT security — for example in a SOC, an XDR solution, firewalls, or employee training. The technology is in place, but the overall strategy is missing.
It is precisely for situations like these that we at dacoso developed the Cyber Resilience Index (CRI). This metric provides a measurable, transparent, and dialogue‑based method to assess a company’s actual security maturity and translate it into concrete actions. In this article, you will learn what lies behind it, how the CRI differs from traditional audits, and who can benefit from it the most.
Cybersecurity for small to medium sized enterprises: Much investment, little visibility
Once a company reaches a certain size, it finds itself fighting on several fronts at the same time. These include rapidly growing threat landscapes, increasingly complex regulations such as NIS2, DORA, and ISO requirements, a shortage of skilled professionals, and the constant pressure of day‑to‑day business.
The result is paradoxical: companies invest in tools, licenses, and external service providers, yet it remains unclear whether these investments are sufficient overall, whether they target the right areas, and whether the company is truly resilient in an emergency.
There is also a structural problem: many service providers support their customers well on an operational level but fail to offer strategic guidance. Applications are monitored, tickets processed, meetings held. What’s missing is the answer to the crucial question: Where do you currently stand, and what is your next step?
Today, customers ask us this question explicitly. And the Cyber Resilience Index is our answer.
What companies truly need — and rarely receive
The expectation is clear: companies don’t just want a service provider who detects and handles incidents. They want an experienced partner who understands their situation, can put it into context, and says: Here are your strengths. Here are your critical gaps. This is the meaningful order of your next steps.
It sounds like a given. In the reality of IT security consulting for midmarket companies, however, it is not.
Traditional audits deliver reports. Long, detailed, technically accurate reports that end up in a drawer because no one has the resources to turn them into an actionable plan. Pure SOC providers detect and fight incidents. They are the operational firefighters — indispensable, but not a steering instrument.
What’s missing is the layer in between: strategic guidance embedded in ongoing operations, with a view of the bigger picture rather than just the next incident.
Advisory instead of audit: A fundamentally different approach
The term advisory may sound similar to audit, but it is not. The crucial difference is not the format — it is the underlying mindset. A traditional audit determines what is. An advisory answers the question of what that means and what needs to happen next.
The dacoso advisory approach differs from a traditional audit in three essential ways:
-
Dialogue instead of checklists: We don’t work with standardized questionnaires that customers fill out themselves. We conduct an open, structured consulting conversation, ask deeper questions when answers are inconsistent, and derive a realistic assessment from it. This prevents the risk of quick checkbox responses leading only to superficial results.
-
Context instead of a snapshot: Because we, as a Managed Service Provider, know our customers, operational SOC data, observed incidents, and the specific IT landscape flow directly into the evaluation. This is fundamentally different from an external consultant who visits the company once a year and barely knows it.
-
Actionable measures instead of a report: The outcome is not a static document but a prioritized roadmap that we regularly review, adjust, and further develop together with the customer. This ensures that the companies we support are always equipped with the right measures.
What is the Cyber Resilience Index?
The Cyber Resilience Index is a metric ranging from 0 to 100 that describes how well an organization can detect, withstand, respond to, and recover from cyberattacks.
It consolidates numerous individual indicators from different security domains into a single, comprehensible score — comparable to a stock market index. At a glance, you can see the overall development of cybersecurity maturity, and you can zoom into specific sub‑areas at any time to understand what is driving or slowing down the score.
Its methodological foundation is built on established international frameworks: the CIS Controls, the NIST Cybersecurity Framework, and the BSI IT‑Grundschutz compendium — supplemented by the requirements of NIS2 and the practical experience gained from dacoso’s SOC operations.
The five domains of the Cyber Resilience Index
The index evaluates five core areas — so‑called domains — that together provide a complete picture of an organization’s security maturity:
|
Number |
Domain |
What is being assessed? |
|
1 |
Strategic Foundation |
IT security strategy, staffing, support and substitution rules, awareness, service‑provider management |
|
2 |
Identity & Asset Management |
Centralized inventory, Hardening-Baselines, Accounts, JML-Processes & Access Management |
|
3 |
Vulnerability & Data Security |
Remediation topics, data classifications, DLP, software inventory, endpoint and network defense, penetration tests |
|
4 |
Resilience & Continuity |
Questions on the topics of Business Impact Analysis, risk assessment, BCM and incident response, disaster recovery, and tabletop exercises |
|
5 |
SOC Coverage Score |
Assessment of the SOC’s visibility and ability to act from the service provider’s perspective across various domains |
Each domain is derived transparently: You can see exactly which assumptions and evaluations led to a partial score and which specific measures would improve it. No black‑box model, no opaque algorithmic magic — but a basis for strategic decisions that is open to discussion and revision.
Governance and processes: The most frequently underestimated weakness
One observation we repeatedly make in our consulting work — and one that surprises many customers — is this: the biggest security gaps rarely lie in technology. Firewalls and XDR solutions are often at an acceptable level. But as soon as we dig deeper — Who is internally responsible when a critical system is compromised? Is there a documented incident‑response plan that has actually been practiced? How are new employees introduced to security processes? — things quickly become uneasy.
Missing governance and unclear processes are, in practice, more often the cause of security incidents than technical vulnerabilities. And they are often far more cost‑effective to fix — if you know where to look.
NIS2 and DORA: When compliance increases the pressure to act
For many companies, cyber resilience is no longer a voluntary investment. European regulation is significantly tightening requirements:
- NIS2 obliges thousands of companies in Germany to implement risk management, incident reporting, and demonstrable security measures.
- DORA sets binding standards for digital operational resilience in the financial sector.
- ISO 27001 certifications are increasingly expected by customers and partners.
The challenge: meeting these requirements demands exactly what is most often missing internally — a structured methodology, specialist expertise, and time. Internal IT teams are tied up in daily operations, specialists are scarce, and the path from regulatory text to actionable measures is unclear for many organizations.
The dacoso Cyber Resilience Index makes compliance requirements tangible. It shows which required capabilities already exist, where gaps remain, and in which order measures should be addressed to achieve regulatory goals efficiently.
Who is the Cyber Resilience Index particularly relevant for?
An ideal starting point — your organization should meet at least one of the following criteria:
- Mid-sized companies with roughly 250 employees or more and a grown, heterogeneous IT infrastructure
- Existing security investments (SOC, XDR, firewalls) — but no clear overall picture of maturity
- Compliance requirements driven by NIS2, DORA, or ISO 27001
- IT teams that repeatedly postpone strategic security topics due to lack of time
- Executive leadership that wants to make security decisions based on reliable, quantifiable metrics
How to get started with the dacoso advisory model
The Cyber Resilience Index is an integral part of dacoso’s managed‑service model for the cybersecurity domain — an advisory approach with real operational context. We know our customers’ systems, we see the signals coming from the SOC, and we understand from day‑to‑day operations where the real pressure points are. This combination of operational depth and strategic perspective is the core of the model.
The onboarding process follows three phases:
-
Phase 1 – Initial assessment: All dacoso managed‑service customers in the cybersecurity area receive a full CRI assessment once per year, included at no additional cost. In structured workshops, we jointly examine all five domains — dialog‑based and without any checkbox forms.
-
Phase 2 – Roadmap: The initial assessment results in a prioritized action plan, tailored to the customer’s specific situation on a risk basis. Not according to a standard template, but according to what will make the biggest difference in the organization.
-
Phase 3 – Continuous advisory: For organizations that want to go deeper, a dedicated advisory budget enables quarterly updates, extended analyses, and ongoing support for implementing measures. The index grows with the company and makes progress visible.
Quick Wins in 3 months
-
Hardening of exposed systems
-
Closing critical vulnerabilities
-
Clear responsibilities
Structural maturity within 12–24 months
-
Identity Management
-
Zero Trust
-
Network Segmentation
-
Security-culture
Fazit: Measured cyber resilience is not a luxury — it’s a leadership responsibility
Cybersecurity investments without strategic guidance are shots in the dark. The dacoso Cyber Resilience Index provides exactly the foundation organizations need: a clear, measurable, and comprehensible assessment of their actual resilience — plus a concrete path for improvement.
It doesn’t produce a report that disappears into a drawer, nor a score that nobody can interpret. The result is a genuine management instrument for IT leaders, CISOs, and executives who want to steer cybersecurity strategically and successfully.
Want to learn more about our Cyber Resilience Index?
Discover how our Managed Security Services work with an integrated advisory approach — combining operational SOC insights with strategic guidance to strengthen your organization’s resilience.
Frequently asked questions about Cyber Resilience Index
-
What is a Cyber Resilience Index?
A Cyber Resilience Index is a metric that describes how well an organization can detect, withstand, respond to, and recover from cyberattacks. It aggregates multiple security domains — from governance and technical controls to awareness — into a single score between 0 and 100. The dacoso Cyber Resilience Index does not rely on self‑assessment alone; instead, it is built through a structured advisory dialogue with experienced security experts, ensuring a realistic and evidence‑based evaluation.
-
What is the difference between a security audit and an advisory?A traditional security audit determines what is present or missing at the moment of assessment — the outcome is a report. An advisory approach goes much further: it not only evaluates the status quo but also translates findings into prioritized actions, supports implementation, and evolves alongside the organization. In the dacoso advisory model, the Cyber Resilience Index serves as the central steering instrument for this ongoing partnership.
-
How is the Cyber Resilience Index calculated?
The index is based on weighted sub‑areas (domains) that are assessed through structured advisory conversations. Its methodological foundation draws on elements of the CIS Controls, the NIST Cybersecurity Framework, and the BSI IT‑Grundschutz Compendium — supplemented by NIS2 requirements and operational SOC data. Every component is derived transparently, allowing customers to understand at any time how their score was calculated and which measures will improve each specific domain.
-
Who does NIS2 apply to — and what does it have to do with cyber resilience
NIS2 (Network and Information Security Directive 2) obliges thousands of companies in Germany to implement demonstrable cybersecurity measures — including risk management, incident reporting, and supply‑chain security. The dacoso Cyber Resilience Index helps organizations assess their maturity against these requirements, identify gaps, and implement improvements in the right order to achieve compliance efficiently.
-
Is the Cyber Resilience Index also useful for smaller companies
Yes, the approach is scalable. For smaller companies, we focus on a limited set of core indicators to keep effort and value in balance. Organizations benefit especially when they face compliance pressure (NIS2, DORA, ISO 27001) and lack the internal capacity to address these requirements in a structured way.
-
What does the dacoso Cyber Resilience Index cost
For all dacoso Protect‑area Managed Service customers, one full initial CRI assessment per year is included in the service at no additional cost. T
hose who want quarterly updates, extended analyses, and continuous support in implementing measures can use a dedicated advisory budget. Organizations that are not yet dacoso Managed Service customers are welcome to contact our security experts.
Sascha Scholz, Lead Cyber Security Advisor, dacoso
Sascha Scholz is Lead Cyber Security Advisor at dacoso within the Customer Success Management Protect division. He is responsible for advising on and advancing cybersecurity strategies, supporting customers in implementing sustainable and resilient security concepts.
Headline
Add content here.
Cyber Resilience Index: How successful SMEs really measure their security posture
“We know we have gaps, but we don’t know where to start to close them.” We hear this sentence regularly. Not from companies that neglect their...