TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessmentResults

Step 8 — results

The adjusted score, which constraints bound it, and which adversaries would walk through the gaps.

What this step shows

The results page reports the self-assessed score, the adjusted score, every constraint that bound it, and — the part most people have not seen before — which adversaries would walk through the gaps.

Detection exposure

For each threat group, the share of their in-scope playbook you would not reliably see: “you would not see 82 of 217 techniques they use”. Your prioritised groups first, then a second list of groups you did not prioritise and would not see either — which is usually the point of the exercise.

The exposure index

Probability × impact × visibility gap, aggregated and banded. A technique you can already see contributes nothing regardless of how dangerous it is, because this measures undetected risk rather than risk.

There is no currency figure, deliberately. A monetary number produced by a free tool from a guessed input is the number that gets challenged in the meeting where it matters. Crown jewels carry qualitative impact bands instead, and the CSV export carries every input out so real financial values can be applied in a register that owns them.

Declared versus claimed

Where what you declared in step 1 disagrees with what you scored in step 7, the model reports it rather than averaging it away — intelligence scored highly with no source declared, deception maturity claimed with nothing deployed, and so on.

Start the assessment