A cyber resilience roadmap turns a gap assessment into a structured, accountable plan. This guide explains how to baseline your current posture, prioritise your gaps, build a 30/60/90 day action plan, and keep it live with quarterly reviews.
A roadmap without a baseline is a list of things you think you should do. A baseline gives you scored evidence of where you are now — so progress is measurable and prioritisation is defensible.
Network and endpoint security, access control, data protection (GDPR), supply chain risk, incident response capability, and staff security awareness.
Each domain should produce a score or a red/amber/green rating. The score is less important than the consistency — it needs to be reproducible so you can measure improvement next quarter.
The person responsible for IT or operations, plus the business owner or a senior leader. Security is not just an IT problem — the roadmap needs executive visibility to get resourced.
What they look for
If you need to justify your roadmap to a board, a client, or an insurer, you need a scored baseline assessment — not a list of things you think need improving. The baseline is what makes the roadmap defensible: it shows a score, a methodology, and a date, so progress can be measured next quarter.
Your baseline assessment will produce a list of findings — things that are missing, inadequate, or not evidenced. Before building the roadmap, categorise each gap by two dimensions: severity and effort.
What is the realistic risk if this gap is exploited or triggers a regulatory finding? Critical (immediate material harm), High (significant exposure), Medium (meaningful gap, manageable risk), Low (good practice, low immediate risk).
How much time, money, or expertise does it take to fix? Quick win (a day or less), Medium (days to weeks), Large (weeks to months), Strategic (months, requires external support).
Critical/quick-win gaps go first. Critical/large gaps need a plan and a timeline. Medium/quick-win gaps are scheduled. Low/large gaps are documented for future review.
What they look for
When reporting to senior leadership or to clients, your gap analysis should show not just what is missing but why it is prioritised in that order. A severity/effort matrix — even a simple one — demonstrates that you are working on the highest-risk items first, not just the easiest ones.
A 30/60/90 day structure gives the roadmap urgency and accountability without trying to fix everything at once. It also creates natural review points.
MFA on all internet-facing accounts, patch outstanding updates, remove stale admin accounts, enable automatic backups. These are often low effort and high impact.
Formalise your GDPR data register, send vendor security questionnaires, draft an incident response plan, deploy staff awareness training for the highest-risk behaviours.
Implement a business continuity plan, complete a full policy review, submit your Cyber Essentials application, or scope an ISO 27001 programme.
What they look for
A 30/60/90 plan with named owners and specific due dates is the document your board will review and your insurer may ask for. Vague milestones ('improve access control by Q3') are not useful. Each item needs: what will be done, by whom, by when, and what evidence will exist when it is complete.
A gap with no owner is a gap that will still be open in six months. Every item on the roadmap needs a named owner, a due date, and a clear definition of done.
The person accountable for completing the action — not just being informed. For small businesses, this is often the MD or operations lead for non-technical tasks.
Specific dates, not "Q3" or "soon". A deadline creates accountability. If the date slips, document why and set a new one — do not just leave it open.
What evidence will exist when this is complete? A policy document, a configuration screenshot, a training completion record. Without a definition of done, items never formally close.
What they look for
Roadmap items with no named owner and no due date effectively do not exist — they will be open in six months regardless of their severity. Auditors and insurers look for assigned accountability, not just a list of intentions. The owner must be a real person with capacity to act, not 'IT' generically.
A roadmap is a living document, not a one-time plan. At the end of each 90-day cycle, close completed actions, re-assess any that slipped, run a fresh assessment across the domains that changed, and set the next 30/60/90 day plan.
Actions completed, actions overdue (and why), new risks that emerged in the quarter (vendor incidents, new tools, staff changes), and posture change versus the prior assessment score.
Quarterly is the right cadence for reporting to senior leadership. A one-page summary: posture score, actions completed, open high/critical items, and next quarter plan.
Every 6–12 months, re-run the full baseline assessment. A higher score means the roadmap is working. A lower score means something changed and needs investigation.
What they look for
A quarterly review record — even a brief summary document — shows that your programme is active, not a one-time exercise. Insurers, ISO 27001 auditors, and clients doing due diligence all look for evidence that the security programme is ongoing. A completed roadmap with no subsequent reviews suggests the programme stopped.
Where people go wrong
Building a roadmap from memory rather than from an assessment
A roadmap built from instinct reflects what you think the problems are. A roadmap built from a scored assessment reflects what the evidence shows. The second is defensible; the first is not.
No owners or due dates on roadmap items
An unowned action is a statement of intent, not a commitment. Every item needs a named person and a specific date. Without these, the roadmap becomes aspirational rather than operational.
Trying to fix everything at once
Attempting a broad compliance programme without prioritisation leads to partial fixes across many areas rather than complete fixes in the highest-risk ones. A six-item list that gets done is more valuable than a 30-item list that does not.
Not re-assessing after significant change
A staff restructure, a new cloud platform, a data breach, a new customer contract — all of these can change your risk profile materially. A roadmap built on a 12-month-old baseline is built on outdated information.
How long should a cyber resilience roadmap cover?
Three months as a working plan, twelve months as a strategic horizon. The 30/60/90 day structure is the actionable layer — things you commit to and track. The 12-month view captures strategic initiatives that require budget approval or external support.
What if we cannot resource everything on the roadmap?
Prioritise by risk. Critical/quick-win items should be non-negotiable — they are high impact at low cost. For resource-constrained businesses, a six-item roadmap that gets done is more valuable than a 30-item roadmap that doesn't.
How do we get board buy-in for the roadmap?
Frame it in business terms. The board cares about contract requirements (CE+ for government contracts), insurance premiums, and reputational risk — not CVEs and control frameworks. Present the roadmap as a business risk management plan, not a technical to-do list.
Should we run the assessment ourselves or use a consultant?
For most SMEs, self-assessment using a guided tool is the right starting point — it is faster, cheaper, and more honest, since you are describing your own environment without a consultant translating for you. Bring in external help for validation before a formal certification or audit.
The free Digital Resilience Assessment scores your posture across 8 domains and generates a prioritised action plan. Import your findings into the portal to track progress with owners and due dates.
Latest on this topic