Sample consultancy report
Hooli: Network & Infrastructure Security
Where AI has moved into this function, whether the controls kept up, and the one move that earns the next rung. Read in five minutes; decided in one meeting.
- Prepared on
- The aisecurityskills function diagnostic
- Basis
- Cloud Security Alliance (CSA) AI Controls Matrix (AICM) · AI Security Maturity Model (AISMM) × AI Cyber Maturity Model (AI-CMM)
- Evidence state
- Illustrative · fictional organisation
- Issued
- 18 Jul 2026
The verdict
Governed acceleration on the wire: segmentation, east-west inspection, and host hardening have earned the autonomy they run — with one deliberate review lag held back.
Hooli's network and infrastructure security function reads at L3.5 governance against L2.8 autonomy: the strongest read this instrument can evidence for the function, with the gate open and positive margin. Restrictive network controls, enforced AI-workload segmentation, host hardening with drift checks, and measured active defense are in place. The remaining distance is not a flat network: it is the autonomy Hooli has deliberately not yet claimed on segmentation review while access-point logging catches up to the standard the rest of the estate already meets.
Governance
L3.5
AI Security Maturity Model (AISMM) · how well it is secured
Autonomy
L2.8
AI Cyber Maturity Model (AI-CMM) · how far AI has gone
The gate
Open
margin +0.2 · autonomy inside what governance allows
Where this function stands
The whole method in one drawing. Governance runs across, autonomy runs up, and the staircase is the gate: each governance level earned is the autonomy an organisation may responsibly claim.
What was measured
Two ladders, one instrument. Each answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control; a category claims a level only when that tier is evidenced, and an absent control caps it. The same rule scores every live run.
How well it is secured
L3.5
The CSA AI Security Maturity Model (AISMM): every answer maps to an AI Controls Matrix (AICM) control, and a level is claimed only when the tier is evidenced.
How far AI has gone
L2.8
The AI Cyber Maturity Model (AI-CMM): where the human sits in each workflow — in, on, then over the loop. our model · calibrated to SAE J3016.
Findings
Three, ranked, classified by what leadership does with each: act on a priority, protect a strength, and hold a deliberate choice.
- 01Priority
Access-point controls trail an otherwise enforced estate
Physical and logical entry points to where AI infrastructure lives are controlled, but logging and regular review are only partial: the one incomplete posture in an otherwise implemented infrastructure category, and the natural next evidence item.
The exact control ids (for your security and governance, risk and compliance team)
DCS-08 · I&S-01 · DCS-06
- 02Strength
Segmentation, east-west, and host hardening carry Capable evidence
AI workloads sit in enforced segments with east-west traffic controlled; hosts run a defined hardening baseline with drift checks; and active network defense around the AI estate detects, responds, and tracks metrics. That is the tier-4 floor underneath the claimed read.
The exact control ids (for your security and governance, risk and compliance team)
I&S-06 · I&S-04 · I&S-09 · I&S-03
- 03By design
Segmentation review is the deliberate autonomy laggard
Four of five network workflows run assisted-to-augmented. Segmentation review is held a rung lower on purpose: the team keeps a human in that loop until access-point controls reach full coverage. That restraint is what keeps the gate margin positive.
The exact control ids (for your security and governance, risk and compliance team)
I&S-06 · DCS-08
The climb
Direction, not a how-to: the next rung, and the governance that must move before autonomy does.
- Next quarter
Close the access-point partial: controlled, logged entry points to AI infrastructure, reviewed on a cadence, so the lead category evidences Capable without a remaining gap.
- Two quarters
With access-point evidence complete, lift segmentation review one autonomy rung and re-assess: the gate stays open only if governance moved first.
- Continuous
Hold host-hardening drift checks and active-defense metrics through each segment and edge change; re-run the diagnostic after material network shifts.
About this instrument
What a reader should carry out of the room: how the diagnostic works, how progress is tracked, and what the practice is for.
One questionnaire, two reads
Every answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control. Read one way, the answers grade the function: governance versus autonomy, joined by the gate. Read the other way, the same answers name the skills each person in the function must acquire. Diagnosis and reskilling from one sitting.
Tracked, not judged
The first run is a baseline, never a verdict. Re-assess after the work and the radar overlays the previous run, so leadership sees movement, not a grade. The compatible-standard packs (ISO/IEC, the National Institute of Standards and Technology, and the CSA AI Consensus Assessments Initiative Questionnaire) are lenses on the same answers: assess once, report many ways.
Direction, not a solution
AI is a moving target, so the report names the next rung and the governance that must move first — never a vendor stack or a how-to. The gate keeps the climb honest: autonomy is claimed only after the controls that catch it are in place.