Calculate the assessment to generate an executive risk summary.
Score updates after calculation.Risk & Compliance
Cyber Risk Score Calculator
Quantify cyber posture, business exposure, target gaps, and remediation priorities using a NIST CSF 2.0 aligned model.
This professional planning tool assesses Govern, Identify, Protect, Detect, Respond, and Recover across current maturity, target maturity, evidence strength, business impact, threat pressure, and regulatory exposure. It produces a board-ready risk posture summary, target profile gap, residual risk estimate, and prioritized remediation roadmap.
Assessment Results
Complete the CSF 2.0 profile and business exposure inputs to calculate.
Security Posture Scorecard
At-a-glance risk posture with key metrics, driver trends, and executive priorities.
Evidence-backed target readiness.
Critical-priority gaps needing leadership visibility.
Protect function and evidence quality.
Risk Composition
Awaiting calculationRisk Trend Over Time
Current assessment profileRisk by Severity
0 total risksTop Risk Priorities
Highest action drivers- Calculate to list priority risks.
Control Maturity Overview
Awaiting current and target profileCalculate to generate control maturity bars.
Posture Summary
Comprehensive Standards-Directed Response
Executive Interpretation
Calculate to generate a board-ready interpretation.
Actual Current State
Calculate to summarize current maturity, target gap, evidence quality, and exposure context.
Risk Rationale
Calculate to explain how likelihood, impact, control maturity, and evidence affect the residual risk estimate.
Governance Direction
Calculate to generate governance and risk treatment direction.
Current vs Target Domain Gap
| CSF Function | Current | Target | Evidence | Priority |
|---|---|---|---|---|
| Calculate to generate profile gaps. | ||||
Risk Composition
Balances threat pressure, impact, exposure, and current control maturity.
Current vs Target Maturity Trend
The chart will show whether the current profile is balanced or concentrated in a few stronger functions.
Prioritized Roadmap
- Calculate to generate top remediation moves.
Framework Mapping
- NIST CSF 2.0: GV, ID, PR, DE, RS, RC current and target profile.
- NIST SP 800-30: likelihood, impact, vulnerability, and uncertainty planning inputs.
- CIS Controls: prioritized safeguard planning through implementation maturity.
- ISO/IEC 27001: governance, risk treatment, monitoring, incident, and continuity control evidence.
Enterprise Risk Register
| Risk ID | Risk statement | Treatment | Owner | Due |
|---|---|---|---|---|
| Calculate to generate risk register items. | ||||
Control and Standards Mapping
| Function | NIST CSF 2.0 | CIS Controls | ISO 27001 Area | Evidence package |
|---|---|---|---|---|
| Calculate to generate standards mapping. | ||||
Enterprise Governance Package
Management Actions
- Calculate to generate management actions.
Audit Trail Needs
- Calculate to generate audit trail needs.
Board Pack Notes
- Calculate to generate board pack notes.
Evidence, Assurance, and Professional Use
Evidence Gaps
- Calculate to identify weak evidence areas.
Assurance Actions
- Calculate to generate validation actions.
Decision Use
- Calculate to generate professional use guidance.
Cybersecurity Disclaimer
This tool supports planning, prioritization, and executive communication. It does not certify compliance, prove control operating effectiveness, or replace formal audit, penetration testing, tabletop exercises, or cyber risk quantification using verified loss data.
Framework Disclaimer
This calculator is aligned with NIST CSF 2.0 concepts but remains a planning model. Treat the score as a decision aid, not as proof of compliance or control operating effectiveness.
- A formal assessment should validate each material answer with evidence, testing, and responsible control owners.
- Use this score to guide board reporting, target-profile planning, remediation budgets, and risk treatment decisions.
- Coordinate major security architecture, regulatory, or insurance decisions with qualified security, legal, and risk professionals.
Search topics covered
- cyber risk scoring model
- NIST CSF maturity assessment
- organizational security posture calculator
- NIST cybersecurity framework metrics
- govern identify protect detect respond recover
- GRC risk assessment tool
- CISO reporting metrics dashboard
- cybersecurity audit readiness checklist
- enterprise risk management (ERM) maturity
- security maturity index calculator
- incident response planning tool
- IT risk management framework
- cybersecurity maturity model (CMMC) mapping
- quantifying operational cyber risk
How to use this calculator
1. Set Context
Start with industry, organization size, regulatory pressure, data sensitivity, threat pressure, and business impact. These inputs stop the score from pretending that every organization has the same risk profile.
2. Evaluate Govern (GV)
Govern covers strategy, policy, roles, accountability, supplier oversight, and risk appetite. If security ownership is unclear, policies are stale, or the board receives no usable risk reporting, this area should score below target even if technical tooling is strong.
3. Evaluate Identify (ID)
You cannot protect what you cannot see. This pillar evaluates your asset management and risk understanding. If your IT team uses spreadsheets to track laptops and servers, select "Partial." If you use automated discovery tools and conduct annual risk assessments, select "Managed."
4. Assess Protect (PR)
This covers your active defenses. Are you using Multi-Factor Authentication (MFA) everywhere? Is data encrypted at rest? Are employees trained to spot phishing? Select "Optimized" only if you have implemented strict Zero Trust network access.
5. Review Detect (DE)
If a hacker bypasses your protections, how long will it take you to notice? This pillar measures your visibility. Relying solely on antivirus is "Partial." Using an Endpoint Detection and Response (EDR) tool with centralized logging is "Managed."
6. Analyze Respond (RS)
When the alarms go off, what happens? "None" means panic and confusion. "Managed" means you have a documented Incident Response plan and assigned roles. "Optimized" means your systems automatically isolate infected machines without human intervention.
7. Check Recover (RC)
If ransomware wipes your primary network, can you rebuild? This is the ultimate safety net. Select "Partial" if you have backups but have never tested restoring them. "Managed" requires tested, off-site backups. "Optimized" requires immutable backups that cannot be destroyed by hackers.
Analyze the Maturity Tier
The calculator combines the six CSF 2.0 functions into a weighted maturity score, compares current state to target state, adjusts confidence based on evidence, and estimates residual risk using threat, impact, sensitivity, and regulatory context.
Advantages of this calculator
Global Standard Alignment
By shifting from generic risk concepts to the six NIST CSF 2.0 functions, this tool gives leaders a shared language for security governance, control maturity, response readiness, and risk treatment.
Identifies Weakest Links
Many companies spend heavily on "Protect" but underfund Govern, Detect, Respond, and Recover. The current-vs-target table highlights unbalanced security investment and shows where weak evidence makes the score less trustworthy.
Executive Communication
Board members rarely understand the technical difference between EDR and Antivirus. However, they easily understand a score out of 100 and a maturity tier. This tool translates technical configurations into business risk metrics.
Data-Driven Budgeting
Use this tool to justify security spend. If Recover or Detect is below target, the roadmap makes the budget ask more concrete: what to fix, why it matters, and how it changes maturity, residual risk, and evidence confidence.
Governing bodies & standards
- NIST: Cybersecurity Framework (CSF)
- ISO/IEC 27001 Information Security Standard
- CISA: Cybersecurity & Infrastructure Security Agency
- CIS: Critical Security Controls
Related Security Calculators
Q&A
What is the NIST Cybersecurity Framework?
It is a set of guidelines, best practices, and standards created by the US National Institute of Standards and Technology (NIST) to help organizations manage and reduce cybersecurity risk.
What are the 6 core functions of NIST CSF 2.0?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern emphasizes risk strategy, policy, roles, oversight, and accountability.
Why is the 'Identify' pillar important?
You cannot defend what you don't know you have. The Identify pillar ensures you have a full inventory of all hardware, software, and data assets, which is the foundation of any security program.
What does 'Immutable Backup' mean in the Recover pillar?
An immutable backup is mathematically locked and cannot be altered or deleted for a set period, even by an administrator. This ensures ransomware actors cannot encrypt your backups.
What is the difference between Protect and Detect?
Protect involves setting up walls (firewalls, MFA, encryption) to stop attackers. Detect involves setting up cameras and alarms (logging, EDR) to notice when an attacker has climbed over those walls.
What is Tier 3 (Repeatable) maturity?
It means your security processes are formally documented, consistently enforced across the organization, and regularly reviewed. It is the target state for most non-defense organizations.
Does this tool guarantee compliance?
No. This is a high-level self-assessment tool. True compliance (like SOC 2 or HIPAA) requires a formal audit by a certified third-party firm.
How can a small business use this framework?
While designed for enterprises, the core concepts apply to anyone. A small business can hit Tier 2/3 by using cloud services that handle much of the heavy lifting (like Office 365 or Google Workspace with strict security settings enabled).
What is an Incident Response Plan?
A written document outlining exactly who does what when a cyber attack occurs. It includes technical steps for containment, legal requirements for reporting, and PR steps for customer communication.
Why is my score so low?
Most organizations overestimate their security until they measure it against a strict framework. A low score usually indicates an over-reliance on basic tools (like simple antivirus) and a lack of formal governance or testing.