A security posture score of 41.7 out of 100 is the kind of number that ends careers in board meetings. One quarter later it was 75.9: 34 points, an 82% relative improvement, at a high-growth UK home-services marketplace. It came from automation and better detection, not a hiring spree or a bigger tooling budget. Here is how the quarter actually went.

The score is measured against the NIST Cybersecurity Framework, the control set most boards and insurers now recognise. It is worth saying up front what the number is and is not: it rates whether your controls actually run, not how well your policies read.

The result
One quarter, one team, no headcount added
41.775.9
NIST CSF posture score
+82%
Quarter startQuarter end
0100
Scored against the NIST Cybersecurity Framework on a 0-100 scale. The grey marker is where the quarter started; the purple marker is where it ended. No control was counted until it executed continuously.

First: what a posture score actually measures

NIST CSF scoring across Identify, Protect, Detect, Respond and Recover sounds abstract until you map it to what it really asks: can you see your estate, can you control it, and when something happens, how fast do you know and act? A 41.7 means the honest answer is "partially, slowly, and only for the parts we remember exist."

The five functions
What each function is really asking
Identify
Do we know what we have?
Every internet-facing service, every identity, every privileged account - named and owned.
Protect
Can we control it?
Access, hardening and exposure reduction that hold without someone remembering to apply them.
Detect
Would we know?
Signal quality good enough that an alert means something and gets acted on.
Respond
How fast do we act?
Containment measured in minutes, with the action logged rather than described.
Recover
Can we get back?
Restoration proven by test, not assumed from a runbook.
Read the framework as five questions rather than five categories, and the remediation order tends to write itself: you cannot protect an estate you cannot see, or respond to something you never detected.

The reframe that matters: the score reports on how you already operate. It is a result, not a target. You do not move it by writing better policy documents, because auditors and attackers both see through that. You move it by making controls actually run, on their own, all the time.

The sequence that worked

The quarter
Three overlapping phases across twelve weeks
Instrument before actingWeeks 1-3
Map the true attack surface and baseline control coverage. Unglamorous and non-negotiable. Locking every internet-facing system to UK-only access and switching off old services nobody needed alone moved the Protect score materially.
Identity is the dominoWeeks 3-8
Identity rebuilt end to end: one place where every account lives, single sign-on and mandatory MFA on every business-critical application, accounts created and removed automatically when people join, move or leave, and access decisions that take account of who the person is, what device they are on and where they are. Then admin rights removed and replaced with elevation granted for the task and expiring after it.
Automate detection and containmentWeeks 6-12
Continuous checking for company passwords appearing in breach dumps, with the password reset and every active session killed automatically, taking exposure to containment from days to minutes. Automated blocking now handles 5,000+ threats a day with no human in the path, and detection tuning killed the noise that had made alerts ignorable.
W1
W6
W12
The overlap is deliberate. Identity work started before instrumentation finished, and automation started before identity was fully done - because each phase produced the evidence the next one needed to be prioritised correctly.

Throughout: evidence as a by-product, not a project. Because controls executed automatically, the audit trail generated itself. That is the quiet superpower of automation - compliance stops being a documentation scramble.

What we deliberately did not do

Trade-offs
Where the movement came from, and what we refused
What moved the score
Instrumentation first, so every later decision was prioritised on real exposure
Identity consolidated into one place, with MFA everywhere and admin rights granted only for the task
Automated containment: forced reset, session revocation, 5,000+ threats blocked daily
Detection tuning, so alerts became worth reading again
What we refused
Hire first. The plan was leverage, not headcount - one senior security engineer joined after the architecture was proven
Buy our way out. Consolidation and renegotiation saved close to £300K a year while coverage grew
Chase the score. Every initiative was justified by risk reduction; the number followed
Note the direction of the budget. Tool consolidation saved close to £300K a year while the score went up - which is the opposite of how posture programmes are usually funded.

The uncomfortable truths about fast posture movement

  1. Detection tuning is the highest-ROI work in security. Most teams drown in alerts they have trained themselves to ignore. Fixing signal quality fixes everything downstream - response speed, analyst trust, board confidence.
  2. Zero friction is a design constraint. Controls that annoy users get routed around. MFA everywhere only works when the experience is seamless; temporary admin access only works when requesting it is faster than working around it.
  3. Same-day incident closure is possible. During this quarter we detected, contained and closed a live attack on a finance system the same day, with zero business impact. That sentence changes how a board listens to you.
  4. The last 20 points are the hard ones. Everything up to about 75 comes from fixing things that are plainly broken. Above that, the remaining gaps are the ones that need a management system behind them rather than another control, which is why the ISO 27001 and ISO 42001 work started at that point.
Do this next
The first three weeks, if you are starting at 40-something
1Inventory what is actually internet-facing today, from the outside in, and compare it with what your team believes is exposed. The gap is your first quick win.
2Switch off, or lock to your own country, any old internet-facing service nobody needs. Reducing what is reachable is the cheapest score movement available.
3Pick one identity plane and get mandatory MFA onto every business-critical application. Nothing else moves as many controls at once.
4Remove permanent admin rights. Replace them with access that is requested, approved, time-limited and recorded - and make it faster than the workaround people would otherwise use.
5Automate one containment path end to end (breached credential to forced reset and session revocation) and measure the time from exposure to containment before and after.
6Tune your three noisiest detections until an alert means something. Do this before adding any new detection source.
7Make each control emit its own evidence, so your next audit reads the system rather than interviewing your team.
Ask these
Questions to put to your team on Monday
What is our current score, when was it last measured, and by whom - us, or someone independent?
Which of our controls execute continuously, and which depend on a person remembering?
How long is it, in practice, between a credential appearing in a breach dump and that session being revoked?
How many people hold standing administrative rights in production right now, and could we name every one?
Which detections have we tuned in the last quarter - and which do we quietly ignore?
If an auditor asked for evidence that a control ran last Tuesday, would we query a system or write an email?
Are we buying tools to close gaps that consolidation would close for less?

The playbook generalises

We have now run versions of this sequence at a fintech unicorn, a £3bn listed manufacturer, and a high-growth marketplace. The constants: instrument first, identity as the domino, automate containment, and make compliance evidence fall out of the architecture.

If your posture score (or your board's patience) needs a quarter like this, that is a working session we run.