Enterprise Cybersecurity Health Score Calculator
Produce a board-level cybersecurity health score from capability, hygiene, resilience, governance, spend alignment and validation.
Inputs
From the enterprise readiness calculator
Patching, coverage, MFA, backups
Tested RTO and RPO achievement
Cybersecurity Health Score
62.7/ 100
Health Grade
C — Fair
Spend Alignment to Benchmark
80.0%
Confidence in the Score
Moderate — around half the score rests on self-assessment
Incident and Findings Penalty
9.2points
Weakest Pillar
Recovery and resilience
Message for the Board
Adequate with a clear weak pillar — a targeted investment in Recovery and resilience moves the score most
Step by step
Values used
Technical capability score = 68 / 100; Operational hygiene score = 82 / 100; Recovery and resilience score = 60 / 100; Governance and compliance score = 74 / 100; Security spend as a share of IT budget = 8 %; Sector benchmark = 10 %; Controls validated by testing in the last year = 55 %; Major incidents in the last 12 months = 1 incidents; Open high-severity audit findings = 5 findings; Cyber risk reported to the board at least quarterly = Yes
Enterprise Cybersecurity Health Score
health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting.
Spend alignment
spendAlignment = actualSpendShare ÷ sectorBenchmark, capped at 100 — spending above benchmark earns no extra credit, because outcomes rather than spend are what the score measures.
Cybersecurity Health Score
= 62.7 / 100
Health Grade
= C — Fair
Spend Alignment to Benchmark
= 80.0
Confidence in the Score
= Moderate — around half the score rests on self-assessment
Incident and Findings Penalty
= 9.2 points
Weakest Pillar
= Recovery and resilience
How it works
This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification. A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.
Formulas
Enterprise Cybersecurity Health Score
health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting.
- capability
- Technical control capability across domains
- hygiene
- Patch currency, coverage, MFA and backup reliability
- resilience
- Demonstrated ability to recover to agreed objectives
- validatedShare
- Controls proven by testing rather than asserted
- incidentPenalty
- 4 points per major incident plus a logarithmic penalty for open high-severity findings
Spend alignment
spendAlignment = actualSpendShare ÷ sectorBenchmark, capped at 100 — spending above benchmark earns no extra credit, because outcomes rather than spend are what the score measures.
- sectorBenchmark
- Sector security spend as a share of IT budget, typically 6–14%
Frequently Asked Questions
How is Enterprise Cybersecurity Health Score calculated?
health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting. This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification.
Why does Enterprise Cybersecurity Health Score matter?
A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.
What values do I need to enter?
This calculator takes 10 inputs: Technical capability score, Operational hygiene score, Recovery and resilience score, Governance and compliance score, Security spend as a share of IT budget, Sector benchmark, Controls validated by testing in the last year, Major incidents in the last 12 months, Open high-severity audit findings, Cyber risk reported to the board at least quarterly. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does spending above benchmark earn no extra credit?
Because spend is an input, not an outcome. Once you are at benchmark, more money only helps if it is well allocated, and that shows up through the capability, hygiene and resilience pillars instead.
Should this score be shared externally?
Not as assurance. It is a self-assessed internal management metric built on your own inputs, and the confidence level is there precisely to stop it being read as a certification. Customers and regulators want evidence — audit reports, test results, certifications — not an index.
You might also need
- Overall Security Posture CalculatorCommonly used together
- Cyber Risk Trend CalculatorCommonly used together
- Enterprise Security Readiness CalculatorCommonly used together
- Security KPI Dashboard CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats