Produce a board-level cybersecurity health score from capability, hygiene, resilience, governance, spend alignment and validation.
This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification. A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.
Enterprise Cybersecurity Health Score
health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting.
Spend alignment
spendAlignment = actualSpendShare ÷ sectorBenchmark, capped at 100 — spending above benchmark earns no extra credit, because outcomes rather than spend are what the score measures.
health = 0.28×capability + 0.24×hygiene + 0.20×resilience + 0.12×governance + 0.10×validatedShare + 0.06×spendAlignment, less an incident and audit-findings penalty of up to 20 points, plus 2 for quarterly board reporting. This is the roll-up for board reporting: capability and hygiene dominate, resilience carries a fifth of the weight because recovery is what converts an incident into an inconvenience, and the share of controls validated by testing is scored explicitly so the number carries its own confidence statement. Major incidents and open high-severity findings deduct directly, since a good self-assessed score alongside repeated incidents is not credible. It is a prioritisation estimate for direction and funding, not assurance and not a certification.
A single defensible number with a stated confidence level and a named weakest pillar is what turns a board conversation from a technology briefing into a funding decision.
This calculator takes 10 inputs: Technical capability score, Operational hygiene score, Recovery and resilience score, Governance and compliance score, Security spend as a share of IT budget, Sector benchmark, Controls validated by testing in the last year, Major incidents in the last 12 months, Open high-severity audit findings, Cyber risk reported to the board at least quarterly. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because spend is an input, not an outcome. Once you are at benchmark, more money only helps if it is well allocated, and that shows up through the capability, hygiene and resilience pillars instead.
Not as assurance. It is a self-assessed internal management metric built on your own inputs, and the confidence level is there precisely to stop it being read as a certification. Customers and regulators want evidence — audit reports, test results, certifications — not an index.