Skip to content
Calcrivo

Blue Team Readiness Calculator

Score defensive readiness from telemetry coverage, detection tuning, response times, staffing cover and exercise cadence.

Inputs

%
%
minutes
minutes
hours/week
%
exercises/year
%

Blue Team Readiness

64.9/ 100

Readiness Rating

C — Fair

Detection and Response Speed

43.7/ 100

Analyst Cover

76.2%

Total Dwell Before Containment

4.75hours

Priority Improvement

Extend analyst cover — an intrusion at 02:00 on Sunday currently waits for Monday

Step by step

  1. Values used

    Estate covered by security telemetry = 85 %; Detections tuned in the last quarter = 60 %; Mean time to detect = 45 minutes; Mean time to contain = 240 minutes; Hours of the week with analyst cover = 128 hours/week; Incident types with a tested playbook = 70 %; Tabletop or live exercises per year = 3 exercises/year; Alerts triaged by automation = 35 %

  2. Blue Team Readiness

    readiness = 0.25×speed + 0.20×telemetry + 0.15×analystCover + 0.13×playbooks + 0.12×tuning + 0.10×exercises + 0.05×automation.

  3. Blue Team Readiness

    = 64.9 / 100

  4. Readiness Rating

    = C — Fair

  5. Detection and Response Speed

    = 43.7 / 100

  6. Analyst Cover

    = 76.2

  7. Total Dwell Before Containment

    = 4.75 hours

  8. Priority Improvement

    = Extend analyst cover — an intrusion at 02:00 on Sunday currently waits for Monday

How it works

Detection and response speed carry the most weight and are scored logarithmically, because the difference between five minutes and ten matters far more than between five hours and ten. Analyst cover is scored against the full 168-hour week, since adversaries deliberately operate outside business hours. Exercises count because untested playbooks fail on first use. The score is a prioritisation estimate of readiness, not a guarantee of outcome in a real incident. Total dwell before containment is the number that maps to loss — every hour an adversary keeps privileged access is more data staged and more hosts encrypted.

Formula

Blue Team Readiness

readiness = 0.25×speed + 0.20×telemetry + 0.15×analystCover + 0.13×playbooks + 0.12×tuning + 0.10×exercises + 0.05×automation.

speed
Logarithmic score from MTTD and MTTC — each doubling of time costs a fixed number of points
telemetry
Share of the estate sending security-relevant logs
analystCover
Staffed hours out of the 168 in a week
playbooks
Incident types with a playbook that has actually been run

Frequently Asked Questions

How is Blue Team Readiness calculated?

readiness = 0.25×speed + 0.20×telemetry + 0.15×analystCover + 0.13×playbooks + 0.12×tuning + 0.10×exercises + 0.05×automation. Detection and response speed carry the most weight and are scored logarithmically, because the difference between five minutes and ten matters far more than between five hours and ten. Analyst cover is scored against the full 168-hour week, since adversaries deliberately operate outside business hours. Exercises count because untested playbooks fail on first use. The score is a prioritisation estimate of readiness, not a guarantee of outcome in a real incident.

Why does Blue Team Readiness matter?

Total dwell before containment is the number that maps to loss — every hour an adversary keeps privileged access is more data staged and more hosts encrypted.

What values do I need to enter?

This calculator takes 8 inputs: Estate covered by security telemetry, Detections tuned in the last quarter, Mean time to detect, Mean time to contain, Hours of the week with analyst cover, Incident types with a tested playbook, Tabletop or live exercises per year, Alerts triaged by automation. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is 24/7 staffing always required?

Not always in-house, but the coverage gap has to be closed somehow — a managed provider for out-of-hours triage, or automated isolation with an on-call escalation. What does not work is a 40-hour SOC guarding a 168-hour attack surface.

Why is automation weighted so low?

Because it multiplies existing capability rather than creating it. Automating triage on top of poor telemetry just reaches wrong conclusions faster, so it earns few points until the coverage and tuning underneath are sound.

You might also need