Combine prevention, detection, response and recovery capability with exposure and threat level into one posture score.
Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail. Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.
Overall Security Posture
capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty.
capability = 0.30×prevention + 0.28×detection + 0.24×response + 0.18×recovery; posture = capability × validationFactor − attackSurface penalty − vulnerability penalty − threat penalty. Posture is capability adjusted for reality: what you can do, discounted by how much of it has actually been tested, then reduced by exposed attack surface, known-unpatched vulnerabilities and the threat level you face. The vulnerability penalty is logarithmic because the first few overdue criticals matter far more than the difference between eighty and a hundred. The score is a prioritisation estimate for sequencing work, not assurance that an attack would fail.
Two organisations with identical controls have different postures if one faces state-aligned targeting and the other does not — posture is only meaningful relative to the adversary.
This calculator takes 8 inputs: Prevention capability, Detection capability, Response capability, Recovery capability, External attack surface exposure, Critical vulnerabilities past SLA, Threat level facing the organisation, Controls validated by testing in the last year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because the same gap has different consequences depending on who is probing it. A 10-point weakness against opportunistic attackers is survivable; against a determined targeted adversary it is where the intrusion starts, so an elevated threat level deducts directly.
Because self-reported capability is systematically optimistic. Validation by red team, purple team or breach simulation is what separates a control that exists on a diagram from one that fires — so the model caps unvalidated capability at 70% of its claimed value.