Skip to content
Calcrivo

Overall Security Posture Calculator

Combine prevention, detection, response and recovery capability with exposure and threat level into one posture score.

Inputs

/ 100
/ 100
/ 100
/ 100
/ 100

Higher means more exposed

vulnerabilities
%

Overall Security Posture

40.7/ 100

Posture Rating

D — Weak

Capability Score

66.4/ 100

Total Deductions

16.7points

Residual Risk

59.3/ 100

Assurance Level

Partially evidenced — around half the score rests on untested assumptions

Priority Action

Clear the critical vulnerabilities past SLA — known and unpatched is the most common initial access

Step by step

  1. Values used

    Prevention capability = 72 / 100; Detection capability = 65 / 100; Response capability = 60 / 100; Recovery capability = 68 / 100; External attack surface exposure = 55 / 100; Critical vulnerabilities past SLA = 18 vulnerabilities; Threat level facing the organisation = Elevated — targeted criminal interest — 1.15×; Controls validated by testing in the last year = 55 %

  2. Overall Security Posture

    capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty.

  3. Overall Security Posture

    = 40.7 / 100

  4. Posture Rating

    = D — Weak

  5. Capability Score

    = 66.4 / 100

  6. Total Deductions

    = 16.7 points

  7. Residual Risk

    = 59.3 / 100

  8. Assurance Level

    = Partially evidenced — around half the score rests on untested assumptions

How it works

Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail. Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.

Formula

Overall Security Posture

capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty.

validationFactor
0.7 to 1.0 depending on the share of controls proven by testing
attackSurface penalty
0.08 points per point of external exposure
vulnerability penalty
Logarithmic penalty for overdue critical vulnerabilities, capped at 14 points
threat penalty
20 points per unit above a moderate threat level — up to 6 points at high threat

Frequently Asked Questions

How is Overall Security Posture calculated?

capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty. Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail.

Why does Overall Security Posture matter?

Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.

What values do I need to enter?

This calculator takes 8 inputs: Prevention capability, Detection capability, Response capability, Recovery capability, External attack surface exposure, Critical vulnerabilities past SLA, Threat level facing the organisation, Controls validated by testing in the last year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does the threat level change the score?

Because the same gap has different consequences depending on who is probing it. A 10-point weakness against opportunistic attackers is survivable; against a determined targeted adversary it is where the intrusion starts, so an elevated threat level deducts directly.

Why does untested capability score lower?

Because self-reported capability is systematically optimistic. Validation by red team, purple team or breach simulation is what separates a control that exists on a diagram from one that fires — so the model caps unvalidated capability at 70% of its claimed value.

You might also need