DIGITAL MATURITY: EVIDENCE FROM A 24-COMPANY ASSESSMENT WITH THE RR-FRAMEWORK. The RR-framework is the structured assessment method used here. Роман Резніков published the article in Економіка та суспільство in 2026. The practical problem is how to connect organizational maturity gaps with crisis exposure and prioritized action. That connection could make resilience investment more comparable and targeted. By the end, you will understand what the method assessed, what its modeled relationships mean and where the evidence stops. Maturity scores and resilience assessments often answer different questions. Резніков examines the gap between them: maturity scores are rarely tied to quantified crisis exposure, and resilience reviews do not always lead to prioritized action. The method brings capability scoring and severe-loss estimation into one diagnostic process. Резніков’s question is deliberately practical. Can an open, uniform assessment distinguish weaker organizations from stronger ones, connect maturity gaps to quantified crisis exposure, and support prioritized action? The cross-industry application also tests whether the results can provide useful comparison points. For cybersecurity teams, the scope matters: cyber is assessed alongside governance, IT continuity and workforce capabilities. The listener should therefore understand this as an enterprise-resilience assessment with a cybersecurity component, rather than a stand-alone measure of security effectiveness. The assessment covered 24 organizations from different industries. It used 424 questions across numerous business domains. Answers were adjusted according to confidence in the supporting evidence. They were then tested against crisis scenarios. The resulting scores were combined into a resilience profile. Severe losses were estimated through analytical calculations and Monte Carlo simulation. Finally, Резніков summarized the portfolio. Correlation analysis then checked how maturity moved alongside control breaches, gaps and modeled losses. Average maturity across the portfolio was 2.59 out of 5, with substantial variation among organizations. Higher maturity was associated with fewer cases where controls crossed critical limits. It was also associated with smaller shortfalls from target and lower modeled losses in severe outcomes. Organizations in the lowest-maturity group carried substantially more modeled loss than those in the highest-maturity group. These findings indicate that the assessment differentiated organizations and produced consistent relationships between its maturity and risk measures. Cyber and privacy crossed a critical threshold in more than 20 of the 24 assessed organizations. Governance, cybersecurity, IT continuity and workforce capabilities also appeared as recurring weak areas across the portfolio. The measurements linked rising maturity with falling modeled tail loss. Among cases with similar maturity, higher-severity crisis scenarios corresponded to higher modeled loss. Together, those patterns suggest the method captured both capability differences and the severity assumptions used in its loss calculations. The evaluated portfolio contains 24 organizations. The loss values came from crisis stress tests and analytical and Monte Carlo estimates. They do not demonstrate matching reductions in observed incident losses. Correlation shows that measures move together. By itself, it cannot prove that raising maturity caused losses to fall. Adjusting for confidence in supporting evidence does not remove those modeling constraints. For security architects, governance leads and continuity teams, a sensible operational use is triage. Identify capabilities that cross critical thresholds, compare those gaps with modeled crisis exposure, and prioritize areas where the two align. Because weaknesses recurred across governance, cyber, IT continuity and workforce domains, security planning may benefit from a shared resilience review rather than isolated cyber investment. Treat the modeled loss relationship as a hypothesis for prioritization, then validate it against local control testing, incident experience and loss evidence before using it to justify financial returns. Here is the practical recap: Резніков applied a reproducible structure for assessing maturity and resilience across industries. Within the evaluated portfolio, it distinguished weaker from stronger organizations. Maturity was associated with modeled loss. The resulting evidence can support targeted resilience investment. But these associations do not establish a universal causal effect. They also do not guarantee lower losses.