Score cyber resilience across anticipate, withstand, detect, respond and recover, using MTTD, MTTR, segmentation and proven immutable restores.
Withstand and recover carry the heaviest weights because resilience is about continuing to operate and getting back, not about preventing every intrusion — that is what the preventive controls elsewhere are for. Detection and response are banded rather than scaled linearly, since the difference between fifteen minutes and an hour matters enormously while the difference between three days and four does not. Resilience is the question regulators and boards now ask instead of are we secure, and it has a different answer: an organisation with modest prevention and excellent segmentation and restores survives events that flatten a well-defended flat network. These are management estimates from your own metrics, not a tested recovery capability.
Cyber Resilience
Resilience index = 0.25 × withstand + 0.25 × recover + 0.20 × detect + 0.15 × anticipate + 0.15 × respond, each pillar scored 0–100.
Recover and anticipate
Recover = 0.7 × restore success rate + 30 if an immutable or offline copy exists; anticipate = 0.6 × dependency mapping + 10 per exercise up to four.
Resilience index = 0.25 × withstand + 0.25 × recover + 0.20 × detect + 0.15 × anticipate + 0.15 × respond, each pillar scored 0–100. Withstand and recover carry the heaviest weights because resilience is about continuing to operate and getting back, not about preventing every intrusion — that is what the preventive controls elsewhere are for. Detection and response are banded rather than scaled linearly, since the difference between fifteen minutes and an hour matters enormously while the difference between three days and four does not.
Resilience is the question regulators and boards now ask instead of are we secure, and it has a different answer: an organisation with modest prevention and excellent segmentation and restores survives events that flatten a well-defended flat network. These are management estimates from your own metrics, not a tested recovery capability.
This calculator takes 9 inputs: Mean time to detect, Mean time to respond and contain, Immutable or offline copy of critical data, Restore success rate in the last four attempts, Critical systems behind enforced segmentation, Critical services with no single point of failure, Critical processes with a documented degraded mode, Critical services with a current dependency map, Incident exercises run per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because it is the difference between an outage and an extinction event. Attackers target backup infrastructure deliberately, and a backup reachable with the same credentials as production is not a recovery option. Immutable or genuinely offline copies are the control that makes every other recovery investment worth having.
It is bad if it is real, and it is also the metric most often flattered by how you measure it. If MTTD is timed from the first alert rather than from initial access, you are measuring your ticket queue rather than your detection capability — and the resilience answer depends on the honest number.