Enterprise Security Readiness Calculator
Score enterprise readiness across identity, endpoint, network, cloud, data, detection, response, governance and resilience.
Inputs
Enterprise Readiness Score
62.6/ 100
Readiness Rating
C — Fair
Maturity Level
Level 3 — Defined
Weakest Domain
Third-party and supply chain
Domains Below 60
3domains
Balance Across Domains
70.0/ 100
Priority Investment
Raise Third-party and supply chain first — the weakest domain caps what every other investment achieves
Step by step
Values used
Identity and access management = 70 / 100; Endpoint protection and hardening = 75 / 100; Network security and segmentation = 60 / 100; Cloud security posture = 65 / 100; Data protection and classification = 55 / 100; Detection and monitoring = 68 / 100; Incident response and recovery = 62 / 100; Governance, risk and compliance = 72 / 100; Vulnerability and patch management = 58 / 100; Third-party and supply chain = 45 / 100
Enterprise Security Readiness
readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%.
Enterprise Readiness Score
= 62.6 / 100
Readiness Rating
= C — Fair
Maturity Level
= Level 3 — Defined
Weakest Domain
= Third-party and supply chain
Domains Below 60
= 3 domains
Balance Across Domains
= 70.0 / 100
How it works
Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification. Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.
Formula
Enterprise Security Readiness
readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%.
- domainScore
- Self-assessed or audited capability score out of 100
- weakLinkPenalty
- Up to 9 points deducted where any domain sits below 60
- balanceIndex
- 100 minus the spread between the strongest and weakest domain
Frequently Asked Questions
How is Enterprise Security Readiness calculated?
readiness = Σ(domainScore × weight) − weakLinkPenalty, with identity at 16%, endpoint and detection at 13%, cloud and response at 11%, network and data at 10%, governance and vulnerability management at 6%, third party at 4%. Domain weights follow where incidents actually originate, which is why identity carries the most and third-party the least in direct control terms. The weak-link penalty exists because attackers choose the weakest domain rather than the average: an estate that is excellent everywhere except unmanaged cloud accounts is not a high-readiness estate. The result is a prioritisation estimate to sequence investment, not an audit conclusion or a certification.
Why does Enterprise Security Readiness matter?
Balance beats peaks — an even 70 across ten domains is materially harder to attack than a set of 90s with one 35.
What values do I need to enter?
This calculator takes 10 inputs: Identity and access management, Endpoint protection and hardening, Network security and segmentation, Cloud security posture, Data protection and classification, Detection and monitoring, Incident response and recovery, Governance, risk and compliance, Vulnerability and patch management, Third-party and supply chain. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Are self-assessed domain scores meaningful?
Only if they are evidenced. Anchor each score to something observable — coverage percentages, tested playbooks, audit findings — otherwise the exercise measures optimism. Independent validation on the two or three weakest domains is the usual compromise.
Why is governance weighted low?
Because it enables rather than prevents. Good governance makes the technical domains improve faster and stay improved, but no policy has ever blocked an exploit — so it earns weight for sustainment, not for defence.
You might also need
- Quantum Threat Readiness CalculatorCommonly used together
- Enterprise Cybersecurity Health Score CalculatorCommonly used together
- Overall Security Posture CalculatorCommonly used together
- Security Budget CalculatorCommonly used together
- Zero Trust Maturity CalculatorCommonly used together
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats