Cyber Resilience Calculator
Score cyber resilience across anticipate, withstand, detect, respond and recover, using MTTD, MTTR, segmentation and proven immutable restores.
Inputs
Cyber Resilience Index
63.1%
Anticipate
44.0%
Withstand
54.5%
Detect
60.0%
Respond
60.0%
Recover
87.4%
Detection Plus Containment Time
21.5hours
Grade
C — Fair
Weakest Pillar
Anticipate — dependency knowledge and exercising
Ransomware Recovery Verdict
Partial — immutable copies exist but the restore success rate is now the binding constraint, so test restores rather than buying more storage
Step by step
Values used
Mean time to detect = 210 minutes; Mean time to respond and contain = 18 hours; Immutable or offline copy of critical data = Yes; Restore success rate in the last four attempts = 82 %; Critical systems behind enforced segmentation = 45 %; Critical services with no single point of failure = 70 %; Critical processes with a documented degraded mode = 55 %; Critical services with a current dependency map = 40 %; Incident exercises run per year = 2 exercises
Cyber Resilience
Resilience index = 0.25 × withstand + 0.25 × recover + 0.20 × detect + 0.15 × anticipate + 0.15 × respond, each pillar scored 0–100.
Recover and anticipate
Recover = 0.7 × restore success rate + 30 if an immutable or offline copy exists; anticipate = 0.6 × dependency mapping + 10 per exercise up to four.
Cyber Resilience Index
= 63.1
Anticipate
= 44.0
Withstand
= 54.5
Detect
= 60.0
Respond
= 60.0
Recover
= 87.4
How it works
Withstand and recover carry the heaviest weights because resilience is about continuing to operate and getting back, not about preventing every intrusion — that is what the preventive controls elsewhere are for. Detection and response are banded rather than scaled linearly, since the difference between fifteen minutes and an hour matters enormously while the difference between three days and four does not. Resilience is the question regulators and boards now ask instead of are we secure, and it has a different answer: an organisation with modest prevention and excellent segmentation and restores survives events that flatten a well-defended flat network. These are management estimates from your own metrics, not a tested recovery capability.
Formulas
Cyber Resilience
Resilience index = 0.25 × withstand + 0.25 × recover + 0.20 × detect + 0.15 × anticipate + 0.15 × respond, each pillar scored 0–100.
- detect
- Banded from mean time to detect: 15 minutes scores 100, a day scores 35
- respond
- Banded from mean time to contain: 4 hours scores 100, three days scores 10
- withstand
- 0.5 × segmentation + 0.3 × redundancy + 0.2 × degraded-mode capability
Recover and anticipate
Recover = 0.7 × restore success rate + 30 if an immutable or offline copy exists; anticipate = 0.6 × dependency mapping + 10 per exercise up to four.
- immutability
- Worth 30 points on its own, because without it the other recovery investments can be encrypted too
- exercises
- Capped at four a year, past which the returns fall off sharply
Frequently Asked Questions
How is Cyber Resilience calculated?
Resilience index = 0.25 × withstand + 0.25 × recover + 0.20 × detect + 0.15 × anticipate + 0.15 × respond, each pillar scored 0–100. Withstand and recover carry the heaviest weights because resilience is about continuing to operate and getting back, not about preventing every intrusion — that is what the preventive controls elsewhere are for. Detection and response are banded rather than scaled linearly, since the difference between fifteen minutes and an hour matters enormously while the difference between three days and four does not.
Why does Cyber Resilience matter?
Resilience is the question regulators and boards now ask instead of are we secure, and it has a different answer: an organisation with modest prevention and excellent segmentation and restores survives events that flatten a well-defended flat network. These are management estimates from your own metrics, not a tested recovery capability.
What values do I need to enter?
This calculator takes 9 inputs: Mean time to detect, Mean time to respond and contain, Immutable or offline copy of critical data, Restore success rate in the last four attempts, Critical systems behind enforced segmentation, Critical services with no single point of failure, Critical processes with a documented degraded mode, Critical services with a current dependency map, Incident exercises run per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does immutability get its own 30 points?
Because it is the difference between an outage and an extinction event. Attackers target backup infrastructure deliberately, and a backup reachable with the same credentials as production is not a recovery option. Immutable or genuinely offline copies are the control that makes every other recovery investment worth having.
Is a low MTTD always bad?
It is bad if it is real, and it is also the metric most often flattered by how you measure it. If MTTD is timed from the first alert rather than from initial access, you are measuring your ticket queue rather than your detection capability — and the resilience answer depends on the honest number.
You might also need
- Disaster Recovery RTO CalculatorCommonly used together
- Business Continuity CalculatorCommonly used together
- CIS Controls Coverage CalculatorCommonly used together
- Disaster Recovery RPO CalculatorCommonly used together
- Security Investment ROI CalculatorAlso in Compliance & GRC
- ISO 27001 Compliance CalculatorAlso in Compliance & GRC