Network Security Score Calculator
Roll segmentation, firewall hygiene, inspection, DDoS, VPN, DNS and monitoring into one weighted network security score.
Inputs
Network Security Score
67.4/100
Grade
C — Fair
Residual Risk Exposure
32.6/100
Risk Level
Low
Highest-Leverage Domain
Segmentation
Weakest Domain
Segmentation
Points to Target
17.6
Step by step
Values used
Segmentation and micro-segmentation coverage = 55 %; Firewall rule hygiene (no any-any, reviewed rules) = 72 %; Traffic under IPS and TLS inspection = 62 %; DDoS mitigation readiness = 80 %; VPN and remote access posture = 75 %; DNS security controls in place = 68 %; Network telemetry and monitoring coverage = 70 %; Target score = 85 /100
Network Security Score
score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS.
Network Security Score
= 67.4 /100
Grade
= C — Fair
Residual Risk Exposure
= 32.6 /100
Risk Level
= Low
Highest-Leverage Domain
= Segmentation
Weakest Domain
= Segmentation
How it works
Segmentation and monitoring carry the heaviest weight because they respectively bound and reveal every incident — one limits how far an attacker gets, the other determines whether you find out. The highest-leverage domain is not simply the weakest one: it is where weight multiplied by the remaining gap is largest, which is where the next point of investment buys the most score. A single composite number is what gets a network security programme funded, but only the leverage breakdown tells you which control to buy next.
Formula
Network Security Score
score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS.
- segmentation
- Coverage of network and workload segmentation policy
- monitoring
- Share of the estate producing usable security telemetry
- highest-leverage domain
- Domain where weight × remaining gap is largest
Frequently Asked Questions
How is Network Security Score calculated?
score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS. Segmentation and monitoring carry the heaviest weight because they respectively bound and reveal every incident — one limits how far an attacker gets, the other determines whether you find out. The highest-leverage domain is not simply the weakest one: it is where weight multiplied by the remaining gap is largest, which is where the next point of investment buys the most score.
Why does Network Security Score matter?
A single composite number is what gets a network security programme funded, but only the leverage breakdown tells you which control to buy next.
What values do I need to enter?
This calculator takes 8 inputs: Segmentation and micro-segmentation coverage, Firewall rule hygiene (no any-any, reviewed rules), Traffic under IPS and TLS inspection, DDoS mitigation readiness, VPN and remote access posture, DNS security controls in place, Network telemetry and monitoring coverage, Target score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does the weakest domain differ from the highest-leverage one?
Weakest is the lowest raw percentage; highest-leverage is weight × gap. A DNS security domain at 40% contributes 0.10 × 60 = 6 points of loss, while monitoring at 60% contributes 0.20 × 40 = 8. Fixing monitoring moves the score more even though DNS looks worse, which is exactly the sort of prioritisation a flat scorecard hides.
You might also need
- Zero Trust Readiness CalculatorCommonly used together
- North-South Security CalculatorCommonly used together
- Port Scan Coverage CalculatorCommonly used together
- MAC Spoofing Risk CalculatorCommonly used together
- East-West Security CalculatorCommonly used together
- ARP Spoofing Risk CalculatorAlso in Network Security