Guides/Resilience roadmap
Step-by-step guide

How to build a cyber resilience roadmap

A cyber resilience roadmap turns a gap assessment into a structured, accountable plan. This guide explains how to baseline your current posture, prioritise your gaps, build a 30/60/90 day action plan, and keep it live with quarterly reviews.

01

Establish your baseline

A roadmap without a baseline is a list of things you think you should do. A baseline gives you scored evidence of where you are now — so progress is measurable and prioritisation is defensible.

What to assess

Network and endpoint security, access control, data protection (GDPR), supply chain risk, incident response capability, and staff security awareness.

How to score it

Each domain should produce a score or a red/amber/green rating. The score is less important than the consistency — it needs to be reproducible so you can measure improvement next quarter.

Who should be involved

The person responsible for IT or operations, plus the business owner or a senior leader. Security is not just an IT problem — the roadmap needs executive visibility to get resourced.

What they look for

If you need to justify your roadmap to a board, a client, or an insurer, you need a scored baseline assessment — not a list of things you think need improving. The baseline is what makes the roadmap defensible: it shows a score, a methodology, and a date, so progress can be measured next quarter.

02

Identify and categorise your gaps

Your baseline assessment will produce a list of findings — things that are missing, inadequate, or not evidenced. Before building the roadmap, categorise each gap by two dimensions: severity and effort.

Severity

What is the realistic risk if this gap is exploited or triggers a regulatory finding? Critical (immediate material harm), High (significant exposure), Medium (meaningful gap, manageable risk), Low (good practice, low immediate risk).

Effort

How much time, money, or expertise does it take to fix? Quick win (a day or less), Medium (days to weeks), Large (weeks to months), Strategic (months, requires external support).

The priority matrix

Critical/quick-win gaps go first. Critical/large gaps need a plan and a timeline. Medium/quick-win gaps are scheduled. Low/large gaps are documented for future review.

What they look for

When reporting to senior leadership or to clients, your gap analysis should show not just what is missing but why it is prioritised in that order. A severity/effort matrix — even a simple one — demonstrates that you are working on the highest-risk items first, not just the easiest ones.

03

Build your 30/60/90 day plan

A 30/60/90 day structure gives the roadmap urgency and accountability without trying to fix everything at once. It also creates natural review points.

0–30 days: quick wins and critical gaps

MFA on all internet-facing accounts, patch outstanding updates, remove stale admin accounts, enable automatic backups. These are often low effort and high impact.

30–60 days: medium-effort gaps

Formalise your GDPR data register, send vendor security questionnaires, draft an incident response plan, deploy staff awareness training for the highest-risk behaviours.

60–90 days: structural improvements

Implement a business continuity plan, complete a full policy review, submit your Cyber Essentials application, or scope an ISO 27001 programme.

What they look for

A 30/60/90 plan with named owners and specific due dates is the document your board will review and your insurer may ask for. Vague milestones ('improve access control by Q3') are not useful. Each item needs: what will be done, by whom, by when, and what evidence will exist when it is complete.

04

Assign owners and due dates

A gap with no owner is a gap that will still be open in six months. Every item on the roadmap needs a named owner, a due date, and a clear definition of done.

Owner

The person accountable for completing the action — not just being informed. For small businesses, this is often the MD or operations lead for non-technical tasks.

Due date

Specific dates, not "Q3" or "soon". A deadline creates accountability. If the date slips, document why and set a new one — do not just leave it open.

Definition of done

What evidence will exist when this is complete? A policy document, a configuration screenshot, a training completion record. Without a definition of done, items never formally close.

What they look for

Roadmap items with no named owner and no due date effectively do not exist — they will be open in six months regardless of their severity. Auditors and insurers look for assigned accountability, not just a list of intentions. The owner must be a real person with capacity to act, not 'IT' generically.

05

Review quarterly and re-assess

A roadmap is a living document, not a one-time plan. At the end of each 90-day cycle, close completed actions, re-assess any that slipped, run a fresh assessment across the domains that changed, and set the next 30/60/90 day plan.

What to review

Actions completed, actions overdue (and why), new risks that emerged in the quarter (vendor incidents, new tools, staff changes), and posture change versus the prior assessment score.

Board or management reporting

Quarterly is the right cadence for reporting to senior leadership. A one-page summary: posture score, actions completed, open high/critical items, and next quarter plan.

Re-assess the baseline

Every 6–12 months, re-run the full baseline assessment. A higher score means the roadmap is working. A lower score means something changed and needs investigation.

What they look for

A quarterly review record — even a brief summary document — shows that your programme is active, not a one-time exercise. Insurers, ISO 27001 auditors, and clients doing due diligence all look for evidence that the security programme is ongoing. A completed roadmap with no subsequent reviews suggests the programme stopped.

Where people go wrong

Common roadmap mistakes

✕

Building a roadmap from memory rather than from an assessment

A roadmap built from instinct reflects what you think the problems are. A roadmap built from a scored assessment reflects what the evidence shows. The second is defensible; the first is not.

✕

No owners or due dates on roadmap items

An unowned action is a statement of intent, not a commitment. Every item needs a named person and a specific date. Without these, the roadmap becomes aspirational rather than operational.

✕

Trying to fix everything at once

Attempting a broad compliance programme without prioritisation leads to partial fixes across many areas rather than complete fixes in the highest-risk ones. A six-item list that gets done is more valuable than a 30-item list that does not.

✕

Not re-assessing after significant change

A staff restructure, a new cloud platform, a data breach, a new customer contract — all of these can change your risk profile materially. A roadmap built on a 12-month-old baseline is built on outdated information.

Common questions about resilience roadmaps

How long should a cyber resilience roadmap cover?

Three months as a working plan, twelve months as a strategic horizon. The 30/60/90 day structure is the actionable layer — things you commit to and track. The 12-month view captures strategic initiatives that require budget approval or external support.

What if we cannot resource everything on the roadmap?

Prioritise by risk. Critical/quick-win items should be non-negotiable — they are high impact at low cost. For resource-constrained businesses, a six-item roadmap that gets done is more valuable than a 30-item roadmap that doesn't.

How do we get board buy-in for the roadmap?

Frame it in business terms. The board cares about contract requirements (CE+ for government contracts), insurance premiums, and reputational risk — not CVEs and control frameworks. Present the roadmap as a business risk management plan, not a technical to-do list.

Should we run the assessment ourselves or use a consultant?

For most SMEs, self-assessment using a guided tool is the right starting point — it is faster, cheaper, and more honest, since you are describing your own environment without a consultant translating for you. Bring in external help for validation before a formal certification or audit.

Get your baseline — and your roadmap — in 10 minutes

The free Digital Resilience Assessment scores your posture across 8 domains and generates a prioritised action plan. Import your findings into the portal to track progress with owners and due dates.