Cybersecurity Capabilities Model

A three-level decomposition of roughly 230 cybersecurity and information security capabilities, with Level 3 definitions and Level 2 KPIs, delivered as core and bonus archives.

Cybersecurity Capabilities Model — ~230 capabilities, 3 levels deep, 2 archives

About This Capability Model

Why this exists

A Security Function Described by What It Does, Not What It Bought

The Cybersecurity Capabilities Model is a three-level decomposition of roughly 230 security capabilities — with definitions at Level 3 and KPIs at Level 2 — delivered as a core archive of editable PowerPoint, Excel, and Word files plus a bonus archive of eight business architecture deliverables.

Ask a security team what it does and the answer usually arrives as a tool inventory. Identity runs on this, detection on that, vulnerability management on the other. It is an accurate description of spend and a poor description of the function.

The gap shows up in the conversations that matter most. A board question about coverage, a due diligence questionnaire, a budget review, an incident post-mortem asking why nobody owned a particular control — none of those can be answered from a tool list, because the unit of the question is a capability and the unit of the answer is a product license.

A capability model closes that gap. It states what the function does — identity governance, threat detection, vulnerability management, incident response, third-party risk, the rest — decomposed far enough to be assigned and scored, and independent of which vendor currently provides it.

This model is that description, decomposed and defined, ready to customize.

What a Capability Model Is Actually For

A capability model earns its keep in specific, recurring situations. These are the ones security functions hit most often.

Answering coverage questions honestly. "Are we covered for X?" is answerable against a capability model and guesswork against a tool inventory. The uncomfortable cases — where a capability is technically owned by a team that has no time for it — become visible rather than assumed.

Rationalizing overlapping tooling. Security estates accumulate tools that overlap in ways nobody planned. Mapping products to capabilities is what turns a renewal conversation from a price negotiation into a coverage decision.

Separating what you do from what you outsource. Managed detection, outsourced SOC arrangements, and vendor-provided controls all move execution without moving accountability. A capability-level split is what makes that boundary explicit before an incident tests it.

Why a Stable Model Matters More Right Now

Security functions are absorbing AI in two directions at once — as a tool inside their own operations, and as a new attack surface everyone else in the business is deploying.

AI Is a Capability Question Twice Over

Applying models to triage and detection changes how existing capabilities are performed. Securing the organization's own AI deployments is closer to a new set of capabilities. Conflating the two produces roadmaps that address neither, and a granular model keeps them apart.

Operational Resilience Expectations Keep Rising

Financial services supervisors increasingly ask firms to demonstrate — not assert — that critical services can withstand disruption. That demonstration is far easier from a capability model with owners and measures attached than from an architecture diagram.

Third-Party Risk Is Where Most Estates Are Thinnest

Supplier and fourth-party exposure tends to be modeled least and asked about most. Decomposing it into distinct capabilities is what stops it being a single box everyone assumes someone else is holding.

KPIs Make Maturity Assessable

Indicators at Level 2 — time to detect, time to remediate, control coverage — turn a current-state assessment into a baseline with numbers attached.

The core deliverables

What Is Included

Two archives — the core model files and a bonus set of business architecture deliverables. Everything is editable and populated with real content:

Capabilities Map (PowerPoint)A nested visualization of the model, built for the slide that has to carry a coverage discussion into a risk committee or a board session.
Capabilities Matrix (Excel)All roughly 230 capabilities in a structured grouping — the working format for scoring maturity, assigning owners, and mapping capabilities to tools or providers.
Capabilities List (Word)The same content as a multilevel list, the easiest format in which to edit, extend, and redline with reviewers.
Capability DefinitionsWritten at Level 3, precise enough that security, technology, risk, and audit reach the same reading of the same capability name.
Capability KPIsPerformance indicators attached at Level 2, so an assessment opens with candidate measures already on the page.
Bonus Archive (8 deliverables)Business Capability Modeling Overview, Capability Summary Profile Template, Capabilities to Microservices Mapping Example, Business Architecture — Framework to Enablement, Business Architecture Deliverables List, Capabilities Relationship Mapping Templates, Business Architecture Leader Expectations and Role, and A Practical Guide to Business Architecture.

Who This Is Built For

Security and Enterprise ArchitectsThe primary audience — customize the model directly rather than facilitating it into existence from a blank page.
CISOs and Security LeadersLeaders who need coverage, ownership, and investment expressed in terms a risk committee can evaluate.
Consultants and AssessorsA structured basis for a security capability review. Multi-client use requires the Consultancy License.

This is a cross-sector functional model rather than a financial services one. The structure holds across industries; firms in regulated sectors should expect to extend it against their own supervisory expectations.

How to Put It to Work

  • Score current-state maturity and identify capability gaps.
  • Map tools and providers to capabilities to expose overlap and blind spots.
  • Assign an owner to every capability, and find the ones nobody owns.
  • Use capabilities as the shared language between security, technology, and risk.

Where Functions Typically Start

Answering a board coverage question. Produce a capability-level view rather than a tool list, and be able to point at the gaps deliberately.

Rationalizing overlapping tooling. Map products to capabilities before a renewal, so the decision is about coverage rather than price.

Reviewing a managed security arrangement. State precisely which capabilities are delegated and which are retained, before an incident tests the assumption.

Building a security roadmap. Sequence investment by capability gap rather than by whichever threat is currently in the news.

Framing AI security work. Separate applying AI to security operations from securing the organization's own AI deployments.

The economics

What You Are Actually Buying Is Time

Building a capability model from scratch is not intellectually hard. It is long — many hours of decomposition and definition, most of it spent rediscovering structure common to every security function.

  • You edit rather than originate. The generic structure is done; your effort goes to what is specific to your estate.
  • Reviewers get something to react to. Critiquing a draft model is a far faster conversation than facilitating one from an empty whiteboard.
  • It works as a cross-reference. If you already have a partial map, this is a gap-finder rather than a replacement.
Build it internally
Hundreds of hours

Decomposition and definition workshops across security domains, largely re-deriving what is common to the function.

Commission it externally
Five to six figures

A consulting engagement producing a comparable model, once elicitation and review are counted.

This model
$699 · today

Immediate download. Editable source files. Begin customizing the same day.

Those first two columns describe what comparable efforts tend to involve, not a quoted benchmark — your figures will depend on scope and who does the work.

Built From Real Engagements

We are software entrepreneurs and business consultants who have delivered business architecture and transformation work across financial services firms. This model is the distilled, reusable output of that work rather than a theoretical exercise — which is also why it carries the opinions and gaps described below.

Read before you buy

An Honest Note on Fit

This is a generic model designed as a starting point. Customization to your organization's context is expected, not a sign that something went wrong.

One thing to be clear about before buying: this is a business capability model of the security function. It is not a control framework, and the distinction matters more here than in any other product we publish.

Specifically:

Not a Control Framework — This does not map to NIST CSF, ISO 27001, CIS Controls, or any other standard, and it is not a substitute for one. It describes what the function does; a control framework describes what you must demonstrate. Most organizations need both, and they are different artifacts.
Not a Compliance Artifact — Nothing here satisfies an audit, a certification, or a supervisory requirement. Scoring well against this model is not evidence of anything to a regulator.
Coverage — Decomposed into roughly 230 granular capabilities rather than a one-page diagram. Some will not apply to your organization, and some of yours will be missing — operational technology and industrial control security in particular are represented lightly.
Definitions — Written at Level 3, at the granularity we judged useful — not exhaustively at every level. Extend and revise freely.
KPIs — A starting set at Level 2. Your function may already track a different and better-suited set, and should.
Vendor Neutrality — Deliberately assumes no product, which also means it will not tell you which tool covers which capability. That mapping is yours to do, and it is the step where most of the value appears.
Delivery Format — Supplied as two archives rather than individually listed files. The contents are the same editable PowerPoint, Excel, and Word documents described above.

Terms You Should Know Before Purchasing

Read the description above in full before you buy. Delivery is immediate and the files are yours to keep, which is also why we cannot take returns, issue refunds, or swap a purchase for a different product once it has been downloaded. What you receive is what is listed — no warranty beyond that, and no bundled customization, implementation help, or support. A Enterprise License covers everyone inside one organization; if you intend to reuse the material across several clients, the Consultancy License is the one you need. The full digital product terms govern the sale.

What's Included

Core Product FilesCORE PRODUCT FILES
Bonus FilesBONUS FILES

At a Glance

  • Capabilities map (PowerPoint) — nested view of the model
  • Capabilities matrix (Excel) — the working format for scoring and mapping
  • Capabilities list (Word) — multilevel list for editing
  • Capability definitions at Level 3
  • Capability KPIs at Level 2
  • Bonus archive — 8 business architecture deliverables
$699–$1,999depending on license
(optional)

Enterprise License

$699

Consultancy License

$1,999

All sales are final. No refunds. No returns.
Digital products are delivered instantly upon payment.

Instant digital download after payment
Secure checkout via Stripe
Vendor-neutral content
Editable PowerPoint/Excel files
5 downloads · 30-day access
Finantrix Insights

Sign up for Finantrix Insights for periodic updates of new and notable.

Protected by reCAPTCHA. No spam. Unsubscribe anytime.

About the Store

The Finantrix Store sells reusable business-architecture reference deliverables — capability models, data models, and value-stream maps — built for financial-services strategy and technology teams.

Browse the full Store →

Before You Buy

The questions worth settling first. Still unsure? Email us before purchasing — all sales are final.

What exactly do I receive?

The files listed under "What's Included" on the product page, and nothing beyond them. Most products are editable PowerPoint, Excel, and Word documents; some are supplied as archives containing those files. Delivery is immediate — a download link is issued as soon as payment completes.

Are the files editable, or locked?

Editable. They are working documents in their native formats, not locked PDFs or images, because the point of the product is that you customize it. A few reference guides are supplied as PDF where editing them would serve no purpose.

How long is my download link valid?

Links stay active for 7 days after purchase and allow up to 3 downloads. Save the files somewhere durable when you receive them. If a link expires or you run out of downloads, email support@finantrix.com and we will issue a new one — that is a support request, not a repurchase.

What is the difference between the Enterprise and Consultancy licenses?

An Enterprise License covers use anywhere within a single organization — your colleagues can all work from the material. A Consultancy License covers use across multiple client engagements, which the Enterprise License does not permit. If you advise more than one organization, the Consultancy License is the one you need. Full terms are at /legal/digital-products-terms.

Do I get a receipt and proof of license?

Yes, both, automatically. Your order confirmation email links to a purchase receipt and a license certificate, and normally carries them as PDF attachments as well. Unlike the download link, those documents do not expire and opening them does not use up one of your 3 downloads — they are there for expense claims, accounting, and procurement reviews that arrive long after the files do. Finantrix collects no sales tax or VAT, so the receipt shows the tax line as not applicable rather than as a computed amount.

Can I get a refund?

No. These are digital products delivered immediately and in full, so all sales are final — no returns, refunds, or exchanges once a purchase completes. That is why every product page carries a detailed manifest and an honest note on fit: we would rather you decide correctly before buying than be disappointed afterwards. If you are unsure whether a product suits your situation, email support@finantrix.com before purchasing and we will tell you.

How much customization should I expect to do?

A meaningful amount, and that is by design. These are generic, sector-level artifacts intended as a substantial head start rather than a finished deliverable for your organization. Each product page includes an honest note on fit setting out, deliverable by deliverable, what is complete and what you will need to supply.

Is implementation help or support included?

No. The purchase covers the files only — it does not include customization, implementation assistance, training, or consulting. Our consulting team is available separately on a paid basis if you want deeper help; contact us to discuss scope.

Do you offer a preview or sample before purchase?

Not as a downloadable sample. The product page is the preview: it lists every file, states the capability counts and levels of decomposition, and sets out where the artifact stops. If something specific would settle your decision, email support@finantrix.com and ask.

Can I share the files with colleagues or clients?

Colleagues within your organization, yes, under the Enterprise License. Clients, no — that requires a Consultancy License. Redistribution, resale, or publishing the material publicly is not permitted under either license.

How current is the content?

The artifacts describe business structure — capabilities, value streams, information entities — which changes far more slowly than technology or regulation. Where a product includes market-facing material such as vendor profiles, the product page says so and advises verifying currency before relying on it for a decision.