Score enterprise readiness across identity, endpoint, network, cloud, data, detection, response, governance and resilience.
Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification. Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.
Enterprise Security Readiness
readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%.
readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%. Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification.
Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.
This calculator takes 10 inputs: Identity and access management, Endpoint protection and hardening, Network security and segmentation, Cloud security posture, Data protection and classification, Detection and monitoring, Incident response and recovery, Governance, risk and compliance, Vulnerability and patch management, Third-party and supply chain. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Only if they are evidenced. Anchor each score to something observable — coverage percentages, tested playbooks, audit findings — otherwise the exercise measures optimism. Independent validation on the two or three weakest domains is the usual compromise.
Because it enables rather than prevents. Good governance makes the technical domains improve faster and stay improved, but no policy has ever blocked an exploit — so it earns weight for sustainment, not for defence.