Cloud Threat Detection Calculator
Score cloud threat detection from account coverage, detection latency and alert precision, and price GuardDuty-style flow, trail and data event analysis.
Inputs
Detection Capability Score
77.4/ 100
Grade
B — Good
Account Coverage
98.3%
Finding Precision
15.8%
False Positive Rate
84.2%
Total Dwell Time
37.0hours
Monthly Detection Cost
$4,616.00
Cost per Confirmed Finding
$121.47
Verdict
Enable detection in every account — an unmonitored account is where the activity will happen
Step by step
Values used
Accounts in scope = 120 accounts; Accounts with threat detection enabled = 118 accounts; VPC flow log volume analysed = 3,200 GB/month; Flow log analysis price per GB = 1 USD; CloudTrail management events analysed = 126 million/month; Management event analysis price per million = 4 USD; S3 data events analysed = 1,140 million/month; S3 data event analysis price per million = 0.8000 USD; Findings raised per month = 240 findings; Findings confirmed as real per month = 38 findings; Mean time to detect = 9 hours; Mean time to respond = 28 hours
Cloud Threat Detection
Detection score = account coverage × 0.5 + latency score × 0.3 + precision score × 0.2, where latency score = max(0, 100 − 3 × MTTD hours) and precision score = min(100, 2 × precision).
Detection cost
Monthly cost = flow log GB × $1.00 + management events in millions × $4.00 + S3 data events in millions × $0.80, the three GuardDuty analysis dimensions.
Detection Capability Score
= 77.4 / 100
Grade
= B — Good
Account Coverage
= 98.3
Finding Precision
= 15.8
False Positive Rate
= 84.2
Total Dwell Time
= 37.0 hours
How it works
Coverage carries half the score because a detection you have not enabled everywhere is not a detection, and latency carries 30% because dwell time is what turns an alert into a breach. Precision is deliberately capped at a doubling: 50% precision scores the full 100, since a cloud detection service that raises one real finding for every false one is performing very well by real-world standards. Cost per confirmed finding is the number that ends the argument about whether to keep S3 data event analysis on, and dwell time is the number that predicts whether you will be writing a breach notification.
Formulas
Cloud Threat Detection
Detection score = account coverage × 0.5 + latency score × 0.3 + precision score × 0.2, where latency score = max(0, 100 − 3 × MTTD hours) and precision score = min(100, 2 × precision).
- coverage
- Accounts with detection enabled ÷ accounts in scope × 100
- mttdHours
- Mean hours from activity to a finding being raised
- precision
- Confirmed findings ÷ all findings × 100
Detection cost
Monthly cost = flow log GB × $1.00 + management events in millions × $4.00 + S3 data events in millions × $0.80, the three GuardDuty analysis dimensions.
- flowLogGb
- VPC flow log volume analysed per month
- s3DataEventsMillions
- S3 data events analysed per month
- costPerTruePositive
- Monthly cost ÷ confirmed findings
Frequently Asked Questions
How is Cloud Threat Detection calculated?
Detection score = account coverage × 0.5 + latency score × 0.3 + precision score × 0.2, where latency score = max(0, 100 − 3 × MTTD hours) and precision score = min(100, 2 × precision). Coverage carries half the score because a detection you have not enabled everywhere is not a detection, and latency carries 30% because dwell time is what turns an alert into a breach. Precision is deliberately capped at a doubling: 50% precision scores the full 100, since a cloud detection service that raises one real finding for every false one is performing very well by real-world standards.
Why does Cloud Threat Detection matter?
Cost per confirmed finding is the number that ends the argument about whether to keep S3 data event analysis on, and dwell time is the number that predicts whether you will be writing a breach notification.
What values do I need to enter?
This calculator takes 12 inputs: Accounts in scope, Accounts with threat detection enabled, VPC flow log volume analysed, Flow log analysis price per GB, CloudTrail management events analysed, Management event analysis price per million, S3 data events analysed, S3 data event analysis price per million, Findings raised per month, Findings confirmed as real per month, Mean time to detect, Mean time to respond. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is low precision a reason to disable a detection?
Rarely — it is a reason to tune it. Suppress by resource and finding type rather than turning off the finding class, because the same rule that fires on your benign vulnerability scanner is the one that will fire on a real reconnaissance sweep. Disabling it wholesale removes both.
Which cost dimension usually dominates?
Flow log analysis in network-heavy estates, S3 data event analysis in data-heavy ones. Both scale with workload rather than with security value, so scope data event analysis to the buckets that matter and consider sampling flow logs on high-volume, low-risk VPCs.
You might also need
- Runtime Security CalculatorCommonly used together
- CloudTrail Coverage CalculatorCommonly used together
- Cloud Logging Coverage CalculatorCommonly used together
- Cloud WAF Capacity CalculatorCommonly used together
- Cloud Security Health Score CalculatorAlso in Cloud Security
- Cloud IAM Risk CalculatorAlso in Cloud Security