Combine cyber, operational, compliance, third-party, financial and strategic risk into one weighted enterprise score against your stated appetite.
The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile. Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.
Enterprise Risk Score
Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity).
Inherent composite = weighted mean of six domain scores (cyber 25, operational 20, compliance 15, third-party 15, financial 15, strategic 10); residual = inherent × (1 − 0.6 × control maturity). The weights lean towards cyber and operational risk because that is where most organisations' loss events actually originate, and control maturity is capped at removing 60% of the composite since no control estate addresses strategic or market risk at all. Dispersion is reported because a moderate composite built from one severe domain and five mild ones needs a completely different response from an evenly moderate profile.
Boards want one number and then immediately want to know which domain drives it, and an average that hides a single severe domain is worse than no number at all. This is a management roll-up of your own domain assessments, not a modelled loss distribution.
This calculator takes 8 inputs: Cyber and information security risk, Operational and technology resilience risk, Regulatory compliance risk, Third-party and supply chain risk, Financial risk, Strategic and market risk, Overall control maturity, Appetite threshold on the 100-point scale. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
You should, if your risk profile justifies it — a bank will weight financial risk far higher, a manufacturer operational risk. Just fix the weights, document them and keep them stable, because a composite whose weights move each quarter cannot show a trend, which is the main reason to compute it.
Because controls do not touch every domain equally. They act strongly on cyber and compliance risk, partially on operational and third-party risk, and barely at all on strategic and market risk. A cap keeps a high maturity score from producing a comfortable composite that ignores the risks controls cannot reach.