Overall Security Posture Calculator
Combine prevention, detection, response and recovery capability with exposure and threat level into one posture score.
Inputs
Higher means more exposed
Overall Security Posture
40.7/ 100
Posture Rating
D — Weak
Capability Score
66.4/ 100
Total Deductions
16.7points
Residual Risk
59.3/ 100
Assurance Level
Partially evidenced — around half the score rests on untested assumptions
Priority Action
Clear the critical vulnerabilities past SLA — known and unpatched is the most common initial access
Step by step
Values used
Prevention capability = 72 / 100; Detection capability = 65 / 100; Response capability = 60 / 100; Recovery capability = 68 / 100; External attack surface exposure = 55 / 100; Critical vulnerabilities past SLA = 18 vulnerabilities; Threat level facing the organisation = Elevated — targeted criminal interest — 1.15×; Controls validated by testing in the last year = 55 %
Overall Security Posture
capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty.
Overall Security Posture
= 40.7 / 100
Posture Rating
= D — Weak
Capability Score
= 66.4 / 100
Total Deductions
= 16.7 points
Residual Risk
= 59.3 / 100
Assurance Level
= Partially evidenced — around half the score rests on untested assumptions
How it works
Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail. Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.
Formula
Overall Security Posture
capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty.
- validationFactor
- 0.7 to 1.0 depending on the share of controls proven by testing
- attackSurface penalty
- 0.08 points per point of external exposure
- vulnerability penalty
- Logarithmic penalty for overdue critical vulnerabilities, capped at 14 points
- threat penalty
- 20 points per unit above a moderate threat level — up to 6 points at high threat
Frequently Asked Questions
How is Overall Security Posture calculated?
capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty. Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail.
Why does Overall Security Posture matter?
Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.
What values do I need to enter?
This calculator takes 8 inputs: Prevention capability, Detection capability, Response capability, Recovery capability, External attack surface exposure, Critical vulnerabilities past SLA, Threat level facing the organisation, Controls validated by testing in the last year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does the threat level change the score?
Because the same gap has different consequences depending on who is probing it. A 10-point weakness against opportunistic attackers is survivable; against a determined targeted adversary it is where the intrusion starts, so an elevated threat level deducts directly.
Why does untested capability score lower?
Because self-reported capability is systematically optimistic. Validation by red team, purple team or breach simulation is what separates a control that exists on a diagram from one that fires — so the model caps unvalidated capability at 70% of its claimed value.
You might also need
- Enterprise Cybersecurity Health Score CalculatorCommonly used together
- Threat Modeling CalculatorCommonly used together
- Enterprise Security Readiness CalculatorCommonly used together
- Cyber Risk Trend CalculatorCommonly used together
- Security KPI Dashboard CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats