Skip to content
Calcrivo

Network Security Score Calculator

Roll segmentation, firewall hygiene, inspection, DDoS, VPN, DNS and monitoring into one weighted network security score.

Inputs

%
%
%
%
%
%
%
/100

Network Security Score

67.4/100

Grade

C — Fair

Residual Risk Exposure

32.6/100

Risk Level

Low

Highest-Leverage Domain

Segmentation

Weakest Domain

Segmentation

Points to Target

17.6

Step by step

  1. Values used

    Segmentation and micro-segmentation coverage = 55 %; Firewall rule hygiene (no any-any, reviewed rules) = 72 %; Traffic under IPS and TLS inspection = 62 %; DDoS mitigation readiness = 80 %; VPN and remote access posture = 75 %; DNS security controls in place = 68 %; Network telemetry and monitoring coverage = 70 %; Target score = 85 /100

  2. Network Security Score

    score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS.

  3. Network Security Score

    = 67.4 /100

  4. Grade

    = C — Fair

  5. Residual Risk Exposure

    = 32.6 /100

  6. Risk Level

    = Low

  7. Highest-Leverage Domain

    = Segmentation

  8. Weakest Domain

    = Segmentation

How it works

Segmentation and monitoring carry the heaviest weight because they respectively bound and reveal every incident — one limits how far an attacker gets, the other determines whether you find out. The highest-leverage domain is not simply the weakest one: it is where weight multiplied by the remaining gap is largest, which is where the next point of investment buys the most score. A single composite number is what gets a network security programme funded, but only the leverage breakdown tells you which control to buy next.

Formula

Network Security Score

score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS.

segmentation
Coverage of network and workload segmentation policy
monitoring
Share of the estate producing usable security telemetry
highest-leverage domain
Domain where weight × remaining gap is largest

Frequently Asked Questions

How is Network Security Score calculated?

score = 0.20·segmentation + 0.20·monitoring + 0.15·firewall hygiene + 0.15·inspection + 0.10·DDoS + 0.10·VPN + 0.10·DNS. Segmentation and monitoring carry the heaviest weight because they respectively bound and reveal every incident — one limits how far an attacker gets, the other determines whether you find out. The highest-leverage domain is not simply the weakest one: it is where weight multiplied by the remaining gap is largest, which is where the next point of investment buys the most score.

Why does Network Security Score matter?

A single composite number is what gets a network security programme funded, but only the leverage breakdown tells you which control to buy next.

What values do I need to enter?

This calculator takes 8 inputs: Segmentation and micro-segmentation coverage, Firewall rule hygiene (no any-any, reviewed rules), Traffic under IPS and TLS inspection, DDoS mitigation readiness, VPN and remote access posture, DNS security controls in place, Network telemetry and monitoring coverage, Target score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does the weakest domain differ from the highest-leverage one?

Weakest is the lowest raw percentage; highest-leverage is weight × gap. A DNS security domain at 40% contributes 0.10 × 60 = 6 points of loss, while monitoring at 60% contributes 0.20 × 40 = 8. Fixing monitoring moves the score more even though DNS looks worse, which is exactly the sort of prioritisation a flat scorecard hides.

You might also need