The model

Aegis is a fusion model. It doesn't replace established frameworks — it integrates them and adds the human layer most miss.

NIST CSF 2.0

Govern, Identify, Protect, Detect, Respond, Recover. The wheel on your dashboard. Govern is the new sixth function — board accountability at the centre.

ACSC Essential Eight

Maturity Level 0–3 across eight mitigation strategies. The ANZ hygiene spine. Drives the Maturity score.

CIS Controls v8.1

Implementation Groups 1–3. Used for control depth and benchmarking across mid-market.

ISO/IEC 27001:2022

Information security management baseline — drives governance maturity and audit-readiness.

MITRE ATT&CK

Every risk and every Maverick forecast maps to a real-world technique. Coverage map on the Risk register.

FAIR

Annualised Loss Exposure (likelihood × impact). Drives the dollar value behind every recommendation.

Zero Trust (NIST 800-207)

Architectural posture: never trust, always verify. Surfaces as a Pathway branch.

SANS Security Awareness Maturity Model

Five-stage human-risk maturity. Drives the Awareness score and Academy prescriptions.

Composite Cyber Resilience Score
CRS = 0.22·Govern + 0.20·Awareness + 0.20·Protect
    + 0.18·(Detect+Respond)/2 + 0.12·Identify + 0.08·Recover
    – risk drag (15 if risk>70, 8 if 50–70, else 0)

Weights are configurable in Settings — Aegis live-previews the CRS as you tune them.