Cyber Risk Trend Calculator
Track cyber risk direction over time: period-on-period change, run rate, projected score and time to reach a target.
Inputs
Higher means more risk
Trend Direction
Improving consistently — risk is falling both this period and year on year
Change This Period
-6.0points
Annualised Change
-24.0points/year
Time to Reach Target
11.0months
Projected Score in 12 Months
38.0/ 100
Register Burn-Down Rate
3.0risks/period
Time to Clear the Register
84.0months
Step by step
Values used
Current risk score = 62 / 100; Score one period ago = 68 / 100; Score a year ago = 74 / 100; Length of one period = 3 months; Target risk score = 40 / 100; New risks accepted per period = 6 risks; Risks remediated per period = 9 risks; Open risks on the register = 84 risks
Cyber Risk Trend
monthlyRate = (currentScore − previousScore) ÷ periodMonths; monthsToTarget = (currentScore − targetScore) ÷ |monthlyRate| when the rate is negative.
Register burn-down
registerMonths = openRisks × periodMonths ÷ (closed − new) — an infinite figure means the register is growing, whatever the score says.
Trend Direction
= Improving consistently — risk is falling both this period and year on year
Change This Period
= -6.0 points
Annualised Change
= -24.0 points/year
Time to Reach Target
= 11.0 months
Projected Score in 12 Months
= 38.0 / 100
Register Burn-Down Rate
= 3.0 risks/period
How it works
A single risk score is nearly meaningless; the direction and the rate are what tell you whether the programme is working. Comparing both to the previous period and to a year ago separates genuine improvement from seasonal noise, and the register burn-down is tracked independently because a falling score with a growing register usually means risks are being accepted rather than fixed. Boards fund trajectory, not position — a 62 that has fallen twelve points in a year is a well-run programme, and a 62 that has been 62 for three years is a stalled one.
Formulas
Cyber Risk Trend
monthlyRate = (currentScore − previousScore) ÷ periodMonths; monthsToTarget = (currentScore − targetScore) ÷ |monthlyRate| when the rate is negative.
- monthlyRate
- Points of risk reduction per month at the current pace
- projectedScore
- Current score plus twelve months at the current rate
- registerBurnRate
- Risks closed minus risks newly accepted per period
Register burn-down
registerMonths = openRisks × periodMonths ÷ (closed − new) — an infinite figure means the register is growing, whatever the score says.
- registerBurnRate
- Net risks removed per period
Frequently Asked Questions
How is Cyber Risk Trend calculated?
monthlyRate = (currentScore − previousScore) ÷ periodMonths; monthsToTarget = (currentScore − targetScore) ÷ |monthlyRate| when the rate is negative. A single risk score is nearly meaningless; the direction and the rate are what tell you whether the programme is working. Comparing both to the previous period and to a year ago separates genuine improvement from seasonal noise, and the register burn-down is tracked independently because a falling score with a growing register usually means risks are being accepted rather than fixed.
Why does Cyber Risk Trend matter?
Boards fund trajectory, not position — a 62 that has fallen twelve points in a year is a well-run programme, and a 62 that has been 62 for three years is a stalled one.
What values do I need to enter?
This calculator takes 8 inputs: Current risk score, Score one period ago, Score a year ago, Length of one period, Target risk score, New risks accepted per period, Risks remediated per period, Open risks on the register. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why compare against both last period and last year?
Because quarterly movement is noisy — an audit, a new tool or a reclassification can move the score several points without anything real changing. The year-on-year figure is what confirms a trend.
What if the score improves while the register grows?
That is the classic warning sign that risks are being accepted rather than remediated, or that scoring is drifting. Trust the register burn-down over the score when the two disagree.
You might also need
- Enterprise Cybersecurity Health Score CalculatorCommonly used together
- Overall Security Posture CalculatorCommonly used together
- Security KPI Dashboard CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Ransomware Impact CalculatorAlso in Forensics & Emerging Threats
- Quantum Threat Readiness CalculatorAlso in Forensics & Emerging Threats