About CCF
About CCF

The Clinical Approach to Cybersecurity Maturity

The Clinical Cybersecurity Framework was created to solve a fundamental gap: most organizations know when something is broken, but few understand what healthy looks like.

Origin

Why CCF Was Created

Most security frameworks were built for auditors — designed to verify that specific controls exist at a point in time. They produce compliance scores, not wellness insights.

Organizations that pass audits still suffer breaches. Organizations with extensive tool sets still lack visibility into their actual resilience posture. The challenge isn't just technical — it's organizational.

CCF was created to bridge this gap. Drawing from clinical medicine — where health is measured, monitored, diagnosed, and treated continuously — CCF provides a structured operating model for building genuine cyber resilience, not just compliance.

PD
Patrick J. Doliny
Creator, Clinical Cybersecurity Framework
Award-Winning CISO · Global C-Level Executive
"Cybersecurity is not just technical. It is organizational wellness. The same way a clinician doesn't just treat symptoms but manages overall patient health — CISOs need a model that helps organizations understand, measure, and improve their entire cyber wellness posture."
Philomena J. Doliny, BSN — CCF Co-Author
CCF Co-Author

Philomena J. Doliny, BSN

Oncology Nursing Leader · Memorial Cancer Institute

A distinguished oncology nursing professional whose 33-year partnership with Patrick J. Doliny inspired the human-centered, clinical approach at the heart of CCF — a framework built not from code, but from covenant and compassion.

The Clinical Analogy

Cybersecurity as Organizational Medicine

Every concept in clinical medicine maps directly to cybersecurity practice — and CCF makes that connection explicit and operational.

Clinical
Patient Intake
Cybersecurity
Digital Baseline Assessment
Clinical
Vital Signs
Cybersecurity
Continuous Security Monitoring
Clinical
Medical History
Cybersecurity
Incident & Threat History
Clinical
Diagnosis
Cybersecurity
Risk Identification & Scoring
Clinical
Treatment Plan
Cybersecurity
Cyber Resilience Plan
Clinical
Medication
Cybersecurity
Security Controls & Technologies
Clinical
Physical Therapy
Cybersecurity
Workforce Readiness & Training
Clinical
Preventive Care
Cybersecurity
Proactive Threat Management
Clinical
Medical Team
Cybersecurity
Security Leadership & Governance
The CCF Difference

How CCF Differs from Traditional Frameworks

Clinical vs. Compliance

Traditional frameworks focus on what controls to implement. CCF focuses on how healthy your organization is — measuring wellness, not just compliance.

Living System vs. Static Checklist

CCF is an operating model that evolves with threats, technology, and the business — not a one-time assessment.

Organizational Wellness vs. Technical Security

CCF addresses the full enterprise — governance, culture, AI exposure, workforce readiness, and board accountability — not just technical controls.

Prescriptive Roadmap vs. Gap Analysis

CCF produces a Cyber Resilience Plan — a prescriptive treatment program — not just a list of gaps.

AI Governance Integrated

CCF treats AI as an enterprise system requiring governance, monitoring, and clinical oversight — not an afterthought.

Executive-Grade Reporting

CCF produces board-ready Cyber Wellness Indices and executive dashboards built for leadership decision-making.

Who CCF Is For

Built for Every Level of Leadership

CISOs & Security Leaders

Establish a clinical baseline, build a resilience plan, and present measurable progress to the board.

Board Members & Executives

Understand cyber risk in organizational wellness terms. Receive board-ready Cyber Wellness Indices.

Security Practitioners

Earn CCF certification, access implementation playbooks, and apply the clinical methodology to real engagements.

Consulting Partners

License the CCF methodology to deliver structured assessments and resilience plans to your clients.

Academic Institutions

Integrate CCF into cybersecurity curricula, support applied research, and earn academic endorsement.

AI Governance Leaders

Apply CCF's clinical AI governance model to manage AI risk across the enterprise digital anatomy.

The Digital Bloodstream

How CCF Moves Cyber Treatment Through the Enterprise

In CCF, every part of the digital body has a clinical function. Tap any highlighted system to see how CCF ensures its wellness and resilience.

The Digital Bloodstream

Tap any glowing point to explore its CCF clinical function

All Digital Body Systems
CCF Treatment Flow (ADME for Cyber)
1
Absorption
The treatment is introduced into the environment.
2
Distribution
The intervention propagates through the digital bloodstream.
3
Metabolism
The organization's systems operationalize and enforce the treatment.
4
Excretion
Residual risk, artifacts and unsafe states are removed or flushed out.

CCF is how we diagnose, treat, and heal the digital body — better visibility, smarter treatment, stronger resilience.

Future Vision

CCF Institute — The Roadmap

CCF is evolving from a framework into a full institution — with certification programs, applied research, academic partnerships, practitioner communities, and annual benchmark publications.

CCF Institute
Practitioner Certification
Academic Endorsements
Annual Benchmark Reports
Research Partnerships
Global Practitioner Network