A foundational clinical methodology
The Clinical Cybersecurity Framework (CCF) is a foundational methodology within Enterprise Intelligence. It reframes the security and technology of the enterprise as a clinical practice — observing, measuring, understanding and improving digital health. CCF is a living operating model, not a static checklist.
From checklist to clinical practice
Traditional security asks: "Are we compliant?" CCF asks a more useful question: "How healthy is the digital enterprise?" Health is observed, measured, understood and improved — clinically, continuously, and in service of the mission.
Most organizations have security tools, compliance requirements, and incident response plans — but many still lack a clear understanding of their enterprise cyber wellness. CCF introduces a clinical model: establish a baseline, identify symptoms, diagnose risk, prescribe a resilience plan, monitor vital signs, and continuously improve.
"How healthy is the digital enterprise?"
The executive question at the heart of the framework.
The clinical model
Establish a baseline. Identify symptoms. Diagnose risk. Prescribe a resilience plan. Monitor vital signs. Continuously improve.
The structure of the digital body
A structured model of the enterprise's digital anatomy — the systems, connections and structures that compose the organization. CCF maps the enterprise as a living digital organism, where each component plays a clinical role in the health of the whole.
How the digital body functions
Physiology describes how the anatomy works in motion — the flows, dependencies and behaviors that determine whether the enterprise is well or unwell. Where anatomy maps the organs, physiology reveals whether they are functioning together: whether data flows freely, whether the immune system detects and responds, whether the diagnostic center observes and interprets correctly.
Flows & dependencies
How data, decisions, and authority move through the enterprise — and where they stall or break.
Behaviors & patterns
The recurring rhythms of the digital body — update cycles, access patterns, and operational cadence.
Function & dysfunction
The difference between a system that operates as intended and one that appears alive but is quietly degrading.
A repeatable practice methodology
The Clinical Delivery System is the repeatable method by which practitioners observe, measure, diagnose and improve the enterprise — turning the philosophy into daily practice. It follows a six-step clinical cycle that mirrors the practice of medicine.
Establish the digital baseline and observe vital signs.
Identify risks and interpret findings clinically.
Rank treatments by mission impact and urgency.
Implement the resilience plan — prescribe and act.
Restore function and rehabilitate the enterprise.
Adapt, strengthen, and continuously improve.
Measurable signals of digital health
Digital Biomarkers are the measurable indicators that reveal the state of the enterprise — developed through WG-400: Digital Biomarkers and Measurement. Like medical biomarkers, they are objective, repeatable, and clinically interpretable. They allow practitioners to detect change early, track progress, and compare health across organizations and over time.
What biomarkers measure
Patch velocity, detection time, recovery time, control coverage, configuration drift, access hygiene, and other quantifiable signals of posture.
How biomarkers are used
Biomarkers feed the Cyber Wellness Score, the Wellness Performance Indicators, and the maturity assessment — translating raw observation into executive insight.
Eight dimensions of organizational wellness
The CCF Cyber Wellness Index provides a multi-dimensional view of enterprise security health — moving beyond binary pass/fail compliance to holistic maturity measurement. These eight vital signs are the focused set that any practitioner can observe to form a clinical impression of enterprise health.
Preventive Strength
Controls that prevent compromise before it occurs.
Detection Accuracy
The precision and speed of threat detection.
Response Efficiency
How quickly and effectively the organization responds.
Recovery Speed
The time to restore function after disruption.
Adaptability Score
The capacity to learn and evolve from experience.
AI Governance Readiness
Maturity of AI oversight, policy, and risk management.
Executive Visibility
Board and leadership insight into cyber posture.
Workforce Readiness
The preparedness and capability of the people.
The organizational treatment plan
A Cyber Wellness Plan translates diagnosis into a prioritized, mission-aligned program of improvement — the enterprise's path to sustained digital health. Like a medical treatment plan, it is specific, time-bound, and reviewed regularly. It identifies what to treat, in what order, with what resources, and how to know it is working.
Prescribed
Each treatment is specific, prioritized, and tied to a diagnosed weakness — not a generic checklist.
Mission-aligned
Treatments are ordered by their effect on the mission, not by convenience or compliance.
Tracked
Progress is measured against Wellness Performance Indicators and reviewed at a defined cadence.
Measuring progress toward wellness
Wellness Performance Indicators (WPIs) measure whether the enterprise is moving toward — or away from — Enterprise Digital Wellness and Mission Readiness. They are the clinical outcome measures of the framework: not whether controls exist, but whether the enterprise is getting healthier.
Direction over position
WPIs track trend — improving, stable, or declining — not just a point-in-time score.
Outcome over activity
WPIs measure whether the enterprise is more resilient, not whether it completed more tasks.
A living operating model
CCF is organized around ten clinical domains — from initial intake through continuous improvement at scale. Each domain maps cybersecurity practice to a clinical discipline, with defined activities, deliverables, and metrics. Together, they form a complete operating model for enterprise cyber wellness.
Establish the Digital Baseline
Clinical analogy: Initial patient intake & vital signs
Map all critical business services, data flows, assets, and current security posture across the enterprise. Establish the foundation from which all future measurement occurs.
- Critical business service inventory
- Data flow & dependency mapping
- Asset classification & tagging
- Current control inventory
- Digital anatomy documentation
Define the Cyber Wellness Profile
Clinical analogy: Diagnosis
Identify and score risks across the enterprise. Develop a quantified maturity index that translates findings into an executive-level cyber wellness score.
- Risk identification & scoring
- Maturity assessment
- Gap analysis
- Executive scoring
- Wellness profile generation
Design the Cyber Resilience Plan
Clinical analogy: Treatment plan
Translate diagnosis into a prioritized, mission-aligned program of improvement — the enterprise's prescriptive treatment roadmap.
- Treatment prioritization
- Resilience roadmap
- Resource allocation
- Timeline development
- Board-ready reporting
Operationalize the Framework
Clinical analogy: Clinical practice
Implement the resilience plan across the enterprise — operationalizing controls, processes, and behaviors that move the organization toward managed cyber wellness.
- Control implementation
- Process integration
- Role assignment
- Playbook activation
- Operational handoff
Implement Continuous Monitoring
Clinical analogy: Vital signs monitoring
Establish ongoing measurement of biomarkers and vital signs — continuous, structured observation that detects change before it becomes failure.
- Biomarker instrumentation
- Vital signs dashboards
- Alert thresholds
- Trend tracking
- Real-time visibility
Conduct Cyber Health Assessments
Clinical analogy: Periodic check-ups
Perform regular, structured assessments of cyber health — validating that the enterprise is improving, identifying regressions, and recalibrating the wellness profile.
- Scheduled assessments
- Independent review
- Regression detection
- Benchmark comparison
- Recalibration
Drive Adaptive Improvement
Clinical analogy: Treatment adjustment
Continuously improve based on findings — adjusting treatments, strengthening weak areas, and ensuring the enterprise adapts faster than the threat landscape evolves.
- Treatment adjustment
- Weakness remediation
- Adaptive response
- Lessons learned
- Continuous improvement
Scale with Intelligence
Clinical analogy: Population health
Scale the clinical practice across the enterprise using intelligence — extending the model to new business units, acquisitions, and partner ecosystems.
- Enterprise-wide rollout
- Cross-domain intelligence
- Ecosystem extension
- Partner integration
- Scalable governance
Establish Governance & Executive Oversight
Clinical analogy: Clinical governance
Establish board-level oversight and governance structures that ensure cyber wellness is reviewed with the same rigor as financial health.
- Board reporting
- Governance committees
- Executive accountability
- Policy frameworks
- Oversight cadence
Measure Maturity & Wellness at Scale
Clinical analogy: Population metrics
Measure maturity and wellness across the enterprise at scale — producing the executive view that enables confident, evidence-based decisions.
- Maturity indexing
- Wellness scoring
- Trend analysis
- Executive dashboards
- Benchmark reporting
Five stages of cyber wellness
The CCF Maturity Model provides a clear progression from reactive security to autonomous, AI-driven cyber resilience. Each stage is defined by a Cyber Wellness Score range and a description of the organization's clinical posture at that level.
Reactive
Cyber Wellness Score: 0–25Incident-driven response. The organization reacts to events after they occur, with minimal proactive visibility or structured process.
Aware
Cyber Wellness Score: 26–50Basic controls and visibility. The organization has begun to instrument and document, but practice is inconsistent and siloed.
Managed
Cyber Wellness Score: 51–70Defined processes in place. The clinical practice is operational — observation, measurement, and diagnosis occur regularly.
Resilient
Cyber Wellness Score: 71–88Adaptive response capability. The organization sustains operation under stress and improves from each incident.
Autonomous
Cyber Wellness Score: 89–100Predictive, AI-driven defense. The enterprise anticipates risk and adapts continuously with minimal manual intervention.
Compatible with the frameworks you already use
CCF is designed to complement — not replace — existing security and governance frameworks. It provides the clinical overlay that turns compliance artifacts into wellness intelligence.
The foundational knowledge base
The CCF Body of Knowledge is the curated, governed knowledge base of the framework — developed and maintained through EII working groups and research. It encompasses the terminology, models, methods, biomarkers, and measures that constitute the discipline, and is continuously refined through practice, evidence, and peer review.
Terminology & models
The governed vocabulary and structural models — digital anatomy, physiology, biomarkers — that define the framework.
Explore standardsMethods & practice
The Clinical Delivery System, assessment methods, and wellness planning procedures that operationalize the framework.
Working groupsMeasures & indicators
The biomarker catalog, vital signs, Wellness Performance Indicators, and maturity model that make health measurable.
Explore researchFramework documentation
The following publications are in development through EII working groups and will be published as exposure drafts for member and public review.
CCF Overview & Philosophy
To be published — WG-100
Enterprise Digital Anatomy Model
In development — WG-200
Enterprise Digital Physiology Guide
In development — WG-200
Digital Biomarkers Catalog
In development — WG-400
Digital Vital Signs Reference
In development — WG-400
Clinical Delivery System Guide
To be published — WG-300
Cyber Wellness Plan Template
In development — WG-300
Wellness Performance Indicators
In development — WG-400
CCF Maturity Model
In development — WG-500
Frequently Asked Questions
Common questions about the Clinical Cybersecurity Framework — its clinical analogy, how it differs from traditional security frameworks, and how to participate in its development.
