Skip to content
Calcrivo

Enterprise Cybersecurity Health Score Calculator

Produce a board-level cybersecurity health score from capability, hygiene, resilience, governance, spend alignment and validation.

Inputs

/ 100

From the enterprise readiness calculator

/ 100

Patching, coverage, MFA, backups

/ 100

Tested RTO and RPO achievement

/ 100
%
%
%
incidents
findings

Cybersecurity Health Score

62.7/ 100

Health Grade

C — Fair

Spend Alignment to Benchmark

80.0%

Confidence in the Score

Moderate — around half the score rests on self-assessment

Incident and Findings Penalty

9.2points

Weakest Pillar

Recovery and resilience

Message for the Board

Adequate with a clear weak pillar — a targeted investment in Recovery and resilience moves the score most

Step by step

  1. Values used

    Technical capability score = 68 / 100; Operational hygiene score = 82 / 100; Recovery and resilience score = 60 / 100; Governance and compliance score = 74 / 100; Security spend as a share of IT budget = 8 %; Sector benchmark = 10 %; Controls validated by testing in the last year = 55 %; Major incidents in the last 12 months = 1 incidents; Open high-severity audit findings = 5 findings; Cyber risk reported to the board at least quarterly = Yes

  2. Enterprise Cybersecurity Health Score

    health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting.

  3. Spend alignment

    spendAlignment = actualSpendShare ÷ sectorBenchmark, capped at 100 — spending above benchmark earns no extra credit, because outcomes rather than spend are what the score measures.

  4. Cybersecurity Health Score

    = 62.7 / 100

  5. Health Grade

    = C — Fair

  6. Spend Alignment to Benchmark

    = 80.0

  7. Confidence in the Score

    = Moderate — around half the score rests on self-assessment

  8. Incident and Findings Penalty

    = 9.2 points

  9. Weakest Pillar

    = Recovery and resilience

How it works

This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification. A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.

Formulas

Enterprise Cybersecurity Health Score

health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting.

capability
Technical control capability across domains
hygiene
Patch currency, coverage, MFA and backup reliability
resilience
Demonstrated ability to recover to agreed objectives
validatedShare
Controls proven by testing rather than asserted
incidentPenalty
4 points per major incident plus a logarithmic penalty for open high-severity findings

Spend alignment

spendAlignment = actualSpendShare ÷ sectorBenchmark, capped at 100 — spending above benchmark earns no extra credit, because outcomes rather than spend are what the score measures.

sectorBenchmark
Sector security spend as a share of IT budget, typically 6–14%

Frequently Asked Questions

How is Enterprise Cybersecurity Health Score calculated?

health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting. This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification.

Why does Enterprise Cybersecurity Health Score matter?

A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.

What values do I need to enter?

This calculator takes 10 inputs: Technical capability score, Operational hygiene score, Recovery and resilience score, Governance and compliance score, Security spend as a share of IT budget, Sector benchmark, Controls validated by testing in the last year, Major incidents in the last 12 months, Open high-severity audit findings, Cyber risk reported to the board at least quarterly. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does spending above benchmark earn no extra credit?

Because spend is an input, not an outcome. Once you are at benchmark, more money only helps if it is well allocated, and that shows up through the capability, hygiene and resilience pillars instead.

Should this score be shared externally?

Not as assurance. It is a self-assessed internal management metric built on your own inputs, and the confidence level is there precisely to stop it being read as a certification. Customers and regulators want evidence — audit reports, test results, certifications — not an index.

You might also need