Skip to main content
Founding AssemblySeptember 18, 2026 — Establishing the Institute, the Profession and the Future of Enterprise Digital WellnessDiscover →
Clinical Cybersecurity Framework

A foundational clinical methodology

The Clinical Cybersecurity Framework (CCF) is a foundational methodology within Enterprise Intelligence. It reframes the security and technology of the enterprise as a clinical practice — observing, measuring, understanding and improving digital health. CCF is a living operating model, not a static checklist.

CCF Philosophy

From checklist to clinical practice

Traditional security asks: "Are we compliant?" CCF asks a more useful question: "How healthy is the digital enterprise?" Health is observed, measured, understood and improved — clinically, continuously, and in service of the mission.

Most organizations have security tools, compliance requirements, and incident response plans — but many still lack a clear understanding of their enterprise cyber wellness. CCF introduces a clinical model: establish a baseline, identify symptoms, diagnose risk, prescribe a resilience plan, monitor vital signs, and continuously improve.

"How healthy is the digital enterprise?"

The executive question at the heart of the framework.

The clinical model

Establish a baseline. Identify symptoms. Diagnose risk. Prescribe a resilience plan. Monitor vital signs. Continuously improve.

Enterprise Digital Anatomy

The structure of the digital body

A structured model of the enterprise's digital anatomy — the systems, connections and structures that compose the organization. CCF maps the enterprise as a living digital organism, where each component plays a clinical role in the health of the whole.

Critical business services
The organs
Data flows
The circulatory system
Identity & access
The immune system
Security operations
The diagnostic center
Incident response
Treatment
Recovery
Rehabilitation
Artificial intelligence
An accelerant that must be governed
Enterprise Digital Physiology

How the digital body functions

Physiology describes how the anatomy works in motion — the flows, dependencies and behaviors that determine whether the enterprise is well or unwell. Where anatomy maps the organs, physiology reveals whether they are functioning together: whether data flows freely, whether the immune system detects and responds, whether the diagnostic center observes and interprets correctly.

Flows & dependencies

How data, decisions, and authority move through the enterprise — and where they stall or break.

Behaviors & patterns

The recurring rhythms of the digital body — update cycles, access patterns, and operational cadence.

Function & dysfunction

The difference between a system that operates as intended and one that appears alive but is quietly degrading.

Clinical Delivery System

A repeatable practice methodology

The Clinical Delivery System is the repeatable method by which practitioners observe, measure, diagnose and improve the enterprise — turning the philosophy into daily practice. It follows a six-step clinical cycle that mirrors the practice of medicine.

01Assess

Establish the digital baseline and observe vital signs.

02Diagnose

Identify risks and interpret findings clinically.

03Prioritize

Rank treatments by mission impact and urgency.

04Treat

Implement the resilience plan — prescribe and act.

05Recover

Restore function and rehabilitate the enterprise.

06Improve

Adapt, strengthen, and continuously improve.

Digital Biomarkers

Measurable signals of digital health

Digital Biomarkers are the measurable indicators that reveal the state of the enterprise — developed through WG-400: Digital Biomarkers and Measurement. Like medical biomarkers, they are objective, repeatable, and clinically interpretable. They allow practitioners to detect change early, track progress, and compare health across organizations and over time.

What biomarkers measure

Patch velocity, detection time, recovery time, control coverage, configuration drift, access hygiene, and other quantifiable signals of posture.

How biomarkers are used

Biomarkers feed the Cyber Wellness Score, the Wellness Performance Indicators, and the maturity assessment — translating raw observation into executive insight.

Digital Vital Signs

Eight dimensions of organizational wellness

The CCF Cyber Wellness Index provides a multi-dimensional view of enterprise security health — moving beyond binary pass/fail compliance to holistic maturity measurement. These eight vital signs are the focused set that any practitioner can observe to form a clinical impression of enterprise health.

Preventive Strength

Controls that prevent compromise before it occurs.

Detection Accuracy

The precision and speed of threat detection.

Response Efficiency

How quickly and effectively the organization responds.

Recovery Speed

The time to restore function after disruption.

Adaptability Score

The capacity to learn and evolve from experience.

AI Governance Readiness

Maturity of AI oversight, policy, and risk management.

Executive Visibility

Board and leadership insight into cyber posture.

Workforce Readiness

The preparedness and capability of the people.

Cyber Wellness Plan

The organizational treatment plan

A Cyber Wellness Plan translates diagnosis into a prioritized, mission-aligned program of improvement — the enterprise's path to sustained digital health. Like a medical treatment plan, it is specific, time-bound, and reviewed regularly. It identifies what to treat, in what order, with what resources, and how to know it is working.

Prescribed

Each treatment is specific, prioritized, and tied to a diagnosed weakness — not a generic checklist.

Mission-aligned

Treatments are ordered by their effect on the mission, not by convenience or compliance.

Tracked

Progress is measured against Wellness Performance Indicators and reviewed at a defined cadence.

Wellness Performance Indicators

Measuring progress toward wellness

Wellness Performance Indicators (WPIs) measure whether the enterprise is moving toward — or away from — Enterprise Digital Wellness and Mission Readiness. They are the clinical outcome measures of the framework: not whether controls exist, but whether the enterprise is getting healthier.

Direction over position

WPIs track trend — improving, stable, or declining — not just a point-in-time score.

Outcome over activity

WPIs measure whether the enterprise is more resilient, not whether it completed more tasks.

10 Clinical Domains

A living operating model

CCF is organized around ten clinical domains — from initial intake through continuous improvement at scale. Each domain maps cybersecurity practice to a clinical discipline, with defined activities, deliverables, and metrics. Together, they form a complete operating model for enterprise cyber wellness.

01

Establish the Digital Baseline

Clinical analogy: Initial patient intake & vital signs

Map all critical business services, data flows, assets, and current security posture across the enterprise. Establish the foundation from which all future measurement occurs.

  • Critical business service inventory
  • Data flow & dependency mapping
  • Asset classification & tagging
  • Current control inventory
  • Digital anatomy documentation
02

Define the Cyber Wellness Profile

Clinical analogy: Diagnosis

Identify and score risks across the enterprise. Develop a quantified maturity index that translates findings into an executive-level cyber wellness score.

  • Risk identification & scoring
  • Maturity assessment
  • Gap analysis
  • Executive scoring
  • Wellness profile generation
03

Design the Cyber Resilience Plan

Clinical analogy: Treatment plan

Translate diagnosis into a prioritized, mission-aligned program of improvement — the enterprise's prescriptive treatment roadmap.

  • Treatment prioritization
  • Resilience roadmap
  • Resource allocation
  • Timeline development
  • Board-ready reporting
04

Operationalize the Framework

Clinical analogy: Clinical practice

Implement the resilience plan across the enterprise — operationalizing controls, processes, and behaviors that move the organization toward managed cyber wellness.

  • Control implementation
  • Process integration
  • Role assignment
  • Playbook activation
  • Operational handoff
05

Implement Continuous Monitoring

Clinical analogy: Vital signs monitoring

Establish ongoing measurement of biomarkers and vital signs — continuous, structured observation that detects change before it becomes failure.

  • Biomarker instrumentation
  • Vital signs dashboards
  • Alert thresholds
  • Trend tracking
  • Real-time visibility
06

Conduct Cyber Health Assessments

Clinical analogy: Periodic check-ups

Perform regular, structured assessments of cyber health — validating that the enterprise is improving, identifying regressions, and recalibrating the wellness profile.

  • Scheduled assessments
  • Independent review
  • Regression detection
  • Benchmark comparison
  • Recalibration
07

Drive Adaptive Improvement

Clinical analogy: Treatment adjustment

Continuously improve based on findings — adjusting treatments, strengthening weak areas, and ensuring the enterprise adapts faster than the threat landscape evolves.

  • Treatment adjustment
  • Weakness remediation
  • Adaptive response
  • Lessons learned
  • Continuous improvement
08

Scale with Intelligence

Clinical analogy: Population health

Scale the clinical practice across the enterprise using intelligence — extending the model to new business units, acquisitions, and partner ecosystems.

  • Enterprise-wide rollout
  • Cross-domain intelligence
  • Ecosystem extension
  • Partner integration
  • Scalable governance
09

Establish Governance & Executive Oversight

Clinical analogy: Clinical governance

Establish board-level oversight and governance structures that ensure cyber wellness is reviewed with the same rigor as financial health.

  • Board reporting
  • Governance committees
  • Executive accountability
  • Policy frameworks
  • Oversight cadence
10

Measure Maturity & Wellness at Scale

Clinical analogy: Population metrics

Measure maturity and wellness across the enterprise at scale — producing the executive view that enables confident, evidence-based decisions.

  • Maturity indexing
  • Wellness scoring
  • Trend analysis
  • Executive dashboards
  • Benchmark reporting
CCF Maturity Model

Five stages of cyber wellness

The CCF Maturity Model provides a clear progression from reactive security to autonomous, AI-driven cyber resilience. Each stage is defined by a Cyber Wellness Score range and a description of the organization's clinical posture at that level.

1

Reactive

Cyber Wellness Score: 0–25

Incident-driven response. The organization reacts to events after they occur, with minimal proactive visibility or structured process.

2

Aware

Cyber Wellness Score: 26–50

Basic controls and visibility. The organization has begun to instrument and document, but practice is inconsistent and siloed.

3

Managed

Cyber Wellness Score: 51–70

Defined processes in place. The clinical practice is operational — observation, measurement, and diagnosis occur regularly.

4

Resilient

Cyber Wellness Score: 71–88

Adaptive response capability. The organization sustains operation under stress and improves from each incident.

5

Autonomous

Cyber Wellness Score: 89–100

Predictive, AI-driven defense. The enterprise anticipates risk and adapts continuously with minimal manual intervention.

Standards Alignment

Compatible with the frameworks you already use

CCF is designed to complement — not replace — existing security and governance frameworks. It provides the clinical overlay that turns compliance artifacts into wellness intelligence.

NIST Aligned ISO 27001 Compatible CMMC Ready SOC 2 Informed FAIR Methodology Zero Trust Architecture
CCF Body of Knowledge

The foundational knowledge base

The CCF Body of Knowledge is the curated, governed knowledge base of the framework — developed and maintained through EII working groups and research. It encompasses the terminology, models, methods, biomarkers, and measures that constitute the discipline, and is continuously refined through practice, evidence, and peer review.

Terminology & models

The governed vocabulary and structural models — digital anatomy, physiology, biomarkers — that define the framework.

Explore standards

Methods & practice

The Clinical Delivery System, assessment methods, and wellness planning procedures that operationalize the framework.

Working groups

Measures & indicators

The biomarker catalog, vital signs, Wellness Performance Indicators, and maturity model that make health measurable.

Explore research
CCF Publications

Framework documentation

The following publications are in development through EII working groups and will be published as exposure drafts for member and public review.

TBA

CCF Overview & Philosophy

To be published — WG-100

TBA

Enterprise Digital Anatomy Model

In development — WG-200

TBA

Enterprise Digital Physiology Guide

In development — WG-200

TBA

Digital Biomarkers Catalog

In development — WG-400

TBA

Digital Vital Signs Reference

In development — WG-400

TBA

Clinical Delivery System Guide

To be published — WG-300

TBA

Cyber Wellness Plan Template

In development — WG-300

TBA

Wellness Performance Indicators

In development — WG-400

TBA

CCF Maturity Model

In development — WG-500

Frequently Asked Questions

Common questions about the Clinical Cybersecurity Framework — its clinical analogy, how it differs from traditional security frameworks, and how to participate in its development.

Join the Profession

Participate in the framework's development

Cookie & Privacy Notice

EII uses cookies to operate the site, enhance functionality, and analyze traffic. By clicking "Accept all", you consent to our use of cookies as described in our Privacy Policy and Cookie Policy.