7 min read

Cyber Resilience Index: How successful SMEs really measure their security posture

Cyber Resilience Index: How successful SMEs really measure their security posture

“We know we have gaps, but we don’t know where to start to close them.” We hear this sentence regularly. Not from companies that neglect their cybersecurity, but from IT managers, CISOs, and managing directors who have already invested in their IT security — for example in a SOC, an XDR solution, firewalls, or employee training. The technology is in place, but the overall strategy is missing.

It is precisely for situations like these that we at dacoso developed the Cyber Resilience Index (CRI). This metric provides a measurable, transparent, and dialogue‑based method to assess a company’s actual security maturity and translate it into concrete actions. In this article, you will learn what lies behind it, how the CRI differs from traditional audits, and who can benefit from it the most.

Cybersecurity for small to medium sized enterprises: Much investment, little visibility

Once a company reaches a certain size, it finds itself fighting on several fronts at the same time. These include rapidly growing threat landscapes, increasingly complex regulations such as NIS2, DORA, and ISO requirements, a shortage of skilled professionals, and the constant pressure of day‑to‑day business.

The result is paradoxical: companies invest in tools, licenses, and external service providers, yet it remains unclear whether these investments are sufficient overall, whether they target the right areas, and whether the company is truly resilient in an emergency.

There is also a structural problem: many service providers support their customers well on an operational level but fail to offer strategic guidance. Applications are monitored, tickets processed, meetings held. What’s missing is the answer to the crucial question: Where do you currently stand, and what is your next step?

Today, customers ask us this question explicitly. And the Cyber Resilience Index is our answer.

What companies truly need — and rarely receive

The expectation is clear: companies don’t just want a service provider who detects and handles incidents. They want an experienced partner who understands their situation, can put it into context, and says: Here are your strengths. Here are your critical gaps. This is the meaningful order of your next steps.

It sounds like a given. In the reality of IT security consulting for midmarket companies, however, it is not.

Traditional audits deliver reports. Long, detailed, technically accurate reports that end up in a drawer because no one has the resources to turn them into an actionable plan. Pure SOC providers detect and fight incidents. They are the operational firefighters — indispensable, but not a steering instrument.

What’s missing is the layer in between: strategic guidance embedded in ongoing operations, with a view of the bigger picture rather than just the next incident.

Advisory instead of audit: A fundamentally different approach

The term advisory may sound similar to audit, but it is not. The crucial difference is not the format — it is the underlying mindset. A traditional audit determines what is. An advisory answers the question of what that means and what needs to happen next. 

The dacoso advisory approach differs from a traditional audit in three essential ways:

  1. Dialogue instead of checklists: We don’t work with standardized questionnaires that customers fill out themselves. We conduct an open, structured consulting conversation, ask deeper questions when answers are inconsistent, and derive a realistic assessment from it. This prevents the risk of quick checkbox responses leading only to superficial results.

  2. Context instead of a snapshot: Because we, as a Managed Service Provider, know our customers, operational SOC data, observed incidents, and the specific IT landscape flow directly into the evaluation. This is fundamentally different from an external consultant who visits the company once a year and barely knows it.

  3. Actionable measures instead of a report: The outcome is not a static document but a prioritized roadmap that we regularly review, adjust, and further develop together with the customer. This ensures that the companies we support are always equipped with the right measures.

What is the Cyber Resilience Index?

The Cyber Resilience Index is a metric ranging from 0 to 100 that describes how well an organization can detect, withstand, respond to, and recover from cyberattacks.

It consolidates numerous individual indicators from different security domains into a single, comprehensible score — comparable to a stock market index. At a glance, you can see the overall development of cybersecurity maturity, and you can zoom into specific sub‑areas at any time to understand what is driving or slowing down the score.

Its methodological foundation is built on established international frameworks: the CIS Controls, the NIST Cybersecurity Framework, and the BSI IT‑Grundschutz compendium — supplemented by the requirements of NIS2 and the practical experience gained from dacoso’s SOC operations.

The five domains of the Cyber Resilience Index

The index evaluates five core areas — so‑called domains — that together provide a complete picture of an organization’s security maturity:

Number

Domain

What is being assessed?

1

Strategic Foundation

IT security strategy, staffing, support and substitution rules, awareness, service‑provider management 

2

Identity & Asset Management

Centralized inventory, Hardening-Baselines, Accounts, JML-Processes & Access Management

3

Vulnerability & Data Security

Remediation topics, data classifications, DLP, software inventory, endpoint and network defense, penetration tests

4

Resilience & Continuity

Questions on the topics of Business Impact Analysis, risk assessment, BCM and incident response, disaster recovery, and tabletop exercises  

5

SOC Coverage Score

Assessment of the SOC’s visibility and ability to act from the service provider’s perspective across various domains

Each domain is derived transparently: You can see exactly which assumptions and evaluations led to a partial score and which specific measures would improve it. No black‑box model, no opaque algorithmic magic but a basis for strategic decisions that is open to discussion and revision. 

Governance and processes: The most frequently underestimated weakness

One observation we repeatedly make in our consulting work — and one that surprises many customers — is this: the biggest security gaps rarely lie in technology. Firewalls and XDR solutions are often at an acceptable level. But as soon as we dig deeper — Who is internally responsible when a critical system is compromised? Is there a documented incident‑response plan that has actually been practiced? How are new employees introduced to security processes? — things quickly become uneasy.

Missing governance and unclear processes are, in practice, more often the cause of security incidents than technical vulnerabilities. And they are often far more cost‑effective to fix — if you know where to look.

NIS2 and DORA: When compliance increases the pressure to act

For many companies, cyber resilience is no longer a voluntary investment. European regulation is significantly tightening requirements:

  • NIS2 obliges thousands of companies in Germany to implement risk management, incident reporting, and demonstrable security measures.
  • DORA sets binding standards for digital operational resilience in the financial sector.
  • ISO 27001 certifications are increasingly expected by customers and partners.

The challenge: meeting these requirements demands exactly what is most often missing internally — a structured methodology, specialist expertise, and time. Internal IT teams are tied up in daily operations, specialists are scarce, and the path from regulatory text to actionable measures is unclear for many organizations.

The dacoso Cyber Resilience Index makes compliance requirements tangible. It shows which required capabilities already exist, where gaps remain, and in which order measures should be addressed to achieve regulatory goals efficiently.

Who is the Cyber Resilience Index particularly relevant for? 

An ideal starting point — your organization should meet at least one of the following criteria:

  • Mid-sized companies with roughly 250 employees or more and a grown, heterogeneous IT infrastructure
  • Existing security investments (SOC, XDR, firewalls) — but no clear overall picture of maturity
  • Compliance requirements driven by NIS2, DORA, or ISO 27001
  • IT teams that repeatedly postpone strategic security topics due to lack of time
  • Executive leadership that wants to make security decisions based on reliable, quantifiable metrics

How to get started with the dacoso advisory model

The Cyber Resilience Index is an integral part of dacoso’s managed‑service model for the cybersecurity domain — an advisory approach with real operational context. We know our customers’ systems, we see the signals coming from the SOC, and we understand from day‑to‑day operations where the real pressure points are. This combination of operational depth and strategic perspective is the core of the model.

The onboarding process follows three phases:

  1. Phase 1 – Initial assessment: All dacoso managed‑service customers in the cybersecurity area receive a full CRI assessment once per year, included at no additional cost. In structured workshops, we jointly examine all five domains — dialog‑based and without any checkbox forms.

  2. Phase 2 – Roadmap: The initial assessment results in a prioritized action plan, tailored to the customer’s specific situation on a risk basis. Not according to a standard template, but according to what will make the biggest difference in the organization.

  3. Phase 3 – Continuous advisory: For organizations that want to go deeper, a dedicated advisory budget enables quarterly updates, extended analyses, and ongoing support for implementing measures. The index grows with the company and makes progress visible. 

Quick Wins in 3 months

  • Hardening of exposed systems

  • Closing critical vulnerabilities

  • Clear responsibilities 

     

Structural maturity within 12–24 months 

  • Identity Management

  • Zero Trust

  • Network Segmentation

  • Security-culture

Fazit: Measured cyber resilience is not a luxury — it’s a leadership responsibility

Cybersecurity investments without strategic guidance are shots in the dark. The dacoso Cyber Resilience Index provides exactly the foundation organizations need: a clear, measurable, and comprehensible assessment of their actual resilience — plus a concrete path for improvement.

It doesn’t produce a report that disappears into a drawer, nor a score that nobody can interpret. The result is a genuine management instrument for IT leaders, CISOs, and executives who want to steer cybersecurity strategically and successfully.

Want to learn more about our Cyber Resilience Index?

Discover how our Managed Security Services work with an integrated advisory approach — combining operational SOC insights with strategic guidance to strengthen your organization’s resilience.

 

 

Frequently asked questions about Cyber Resilience Index

saschascholz_neu
Sascha Scholz, Lead Cyber Security Advisor, dacoso

Sascha Scholz is Lead Cyber Security Advisor at dacoso within the Customer Success Management Protect division. He is responsible for advising on and advancing cybersecurity strategies, supporting customers in implementing sustainable and resilient security concepts.