Almost 75% of the CISOs surveyed rated their organisation at only level 1 (Initial) or level 2 (Repeatable) on the Capability Maturity Model (CMM).