Roll seven cloud security pillar scores into one weighted health score, penalise open critical findings and name the weakest pillar.
The pillar weights follow blast radius: identity is the cloud control plane so it carries 20%, while container and supply chain carry 10% each because their failures are usually contained to a workload. Open critical findings are subtracted rather than averaged in, capped at 15 points, so a good-looking set of pillar scores cannot hide a live backlog of urgent work. Executives need one number and engineers need to know where to spend the next sprint, and a weighted roll-up with an explicit weakest-pillar uplift answers both questions from the same inputs.
Cloud Security Health Score
Health score = identity × 0.20 + data × 0.15 + network × 0.15 + detection × 0.15 + compliance × 0.15 + container × 0.10 + supply chain × 0.10 − critical finding penalty.
Marginal investment
Uplift if the weakest pillar reached 85 = health score + (85 − weakest pillar score) × that pillar's weight — the best single investment available.
Health score = identity × 0.20 + data × 0.15 + network × 0.15 + detection × 0.15 + compliance × 0.15 + container × 0.10 + supply chain × 0.10 − critical finding penalty. The pillar weights follow blast radius: identity is the cloud control plane so it carries 20%, while container and supply chain carry 10% each because their failures are usually contained to a workload. Open critical findings are subtracted rather than averaged in, capped at 15 points, so a good-looking set of pillar scores cannot hide a live backlog of urgent work.
Executives need one number and engineers need to know where to spend the next sprint, and a weighted roll-up with an explicit weakest-pillar uplift answers both questions from the same inputs.
This calculator takes 9 inputs: Identity and access pillar score, Data protection pillar score, Network security pillar score, Detection and response pillar score, Compliance pillar score, Container and Kubernetes pillar score, Supply chain pillar score, Open critical findings across all pillars, Target health score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No. These are sensible defaults for a typical cloud estate; a company whose product is a Kubernetes platform should weight containers far higher, and a regulated data business should weight data protection and compliance up. Set the weights once, write down why, and keep them stable so the trend stays meaningful.
Because attackers do not average. A 78 built from seven pillars near 78 is a genuinely decent posture; the same 78 built from a 95 and a 45 means there is one route in that nobody has closed. That is why pillar spread and the weakest pillar are shown next to the headline number.