Score defensive readiness from telemetry coverage, detection tuning, response times, staffing cover and exercise cadence.
Detection and response speed carry the most weight and are scored logarithmically, because the difference between five minutes and ten matters far more than between five hours and ten. Analyst cover is scored against the full 168-hour week, since adversaries deliberately operate outside business hours. Exercises count because untested playbooks fail on first use. The score is a prioritisation estimate of readiness, not a guarantee of outcome in a real incident. Total dwell before containment is the number that maps to loss — every hour an adversary keeps privileged access is more data staged and more hosts encrypted.
Blue Team Readiness
readiness = 0.25×speed + 0.20×telemetry + 0.15×analystCover + 0.13×playbooks + 0.12×tuning + 0.10×exercises + 0.05×automation.
readiness = 0.25×speed + 0.20×telemetry + 0.15×analystCover + 0.13×playbooks + 0.12×tuning + 0.10×exercises + 0.05×automation. Detection and response speed carry the most weight and are scored logarithmically, because the difference between five minutes and ten matters far more than between five hours and ten. Analyst cover is scored against the full 168-hour week, since adversaries deliberately operate outside business hours. Exercises count because untested playbooks fail on first use. The score is a prioritisation estimate of readiness, not a guarantee of outcome in a real incident.
Total dwell before containment is the number that maps to loss — every hour an adversary keeps privileged access is more data staged and more hosts encrypted.
This calculator takes 8 inputs: Estate covered by security telemetry, Detections tuned in the last quarter, Mean time to detect, Mean time to contain, Hours of the week with analyst cover, Incident types with a tested playbook, Tabletop or live exercises per year, Alerts triaged by automation. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Not always in-house, but the coverage gap has to be closed somehow — a managed provider for out-of-hours triage, or automated isolation with an on-call escalation. What does not work is a 40-hour SOC guarding a 168-hour attack surface.
Because it multiplies existing capability rather than creating it. Automating triage on top of poor telemetry just reaches wrong conclusions faster, so it earns few points until the coverage and tuning underneath are sound.