Skip to content
Calcrivo

Enterprise Security Readiness Calculator

Score enterprise readiness across identity, endpoint, network, cloud, data, detection, response, governance and resilience.

Inputs

/ 100
/ 100
/ 100
/ 100
/ 100
/ 100
/ 100
/ 100
/ 100
/ 100

Enterprise Readiness Score

62.6/ 100

Readiness Rating

C — Fair

Maturity Level

Level 3 — Defined

Weakest Domain

Third-party and supply chain

Domains Below 60

3domains

Balance Across Domains

70.0/ 100

Priority Investment

Raise Third-party and supply chain first — the weakest domain caps what every other investment achieves

Step by step

  1. Values used

    Identity and access management = 70 / 100; Endpoint protection and hardening = 75 / 100; Network security and segmentation = 60 / 100; Cloud security posture = 65 / 100; Data protection and classification = 55 / 100; Detection and monitoring = 68 / 100; Incident response and recovery = 62 / 100; Governance, risk and compliance = 72 / 100; Vulnerability and patch management = 58 / 100; Third-party and supply chain = 45 / 100

  2. Enterprise Security Readiness

    readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%.

  3. Enterprise Readiness Score

    = 62.6 / 100

  4. Readiness Rating

    = C — Fair

  5. Maturity Level

    = Level 3 — Defined

  6. Weakest Domain

    = Third-party and supply chain

  7. Domains Below 60

    = 3 domains

  8. Balance Across Domains

    = 70.0 / 100

How it works

Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification. Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.

Formula

Enterprise Security Readiness

readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%.

domainScore
Self-assessed or audited capability score out of 100
weakLinkPenalty
Up to 9 points deducted where any domain sits below 60
balanceIndex
100 minus the spread between the strongest and weakest domain

Frequently Asked Questions

How is Enterprise Security Readiness calculated?

readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%. Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification.

Why does Enterprise Security Readiness matter?

Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.

What values do I need to enter?

This calculator takes 10 inputs: Identity and access management, Endpoint protection and hardening, Network security and segmentation, Cloud security posture, Data protection and classification, Detection and monitoring, Incident response and recovery, Governance, risk and compliance, Vulnerability and patch management, Third-party and supply chain. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Are self-assessed domain scores meaningful?

Only if they are evidenced. Anchor each score to something observable — coverage percentages, tested playbooks, audit findings — otherwise the exercise measures optimism. Independent validation on the two or three weakest domains is the usual compromise.

Why is governance weighted low?

Because it enables rather than prevents. Good governance makes the technical domains improve faster and stay improved, but no policy has ever blocked an exploit — so it earns weight for sustainment, not for defence.

You might also need