Understanding Your Cyber Resilience Score
How CyberHQ arrives at your Cyber Resilience Score, what moves it, and what the bands mean
Your Cyber Resilience Score is the single number CyberHQ uses to express your overall security position. It appears on your posture scorecard, leads the Executive Report, and is usually the figure a board remembers. This article explains what goes into it, so you can answer the question that always follows: what would move it.
How the score is built
Resilience is the average of two halves:
-
Your risk position. For each of your risk categories, CyberHQ takes the worst residual score in that category, meaning the likelihood and impact remaining after your controls and remediation are accounted for. It averages those category figures and converts the result to a 0 to 100 scale where higher is better. A low amount of residual risk produces a high number.
-
Your capability position. Your overall maturity against your primary framework, also expressed from 0 to 100.
The two are averaged. That is the whole formula, and its simplicity is deliberate: the score is intended to be explainable to a board rather than defensible to a statistician.
One consequence worth understanding is that the score is equally sensitive to both halves. Improving your control maturity while your residual risk stays flat moves the number half as far as you might expect. Teams who are surprised by a small improvement after a large programme of work are usually looking at one half moving and the other standing still.
What the bands mean
| Score | Band |
| 90 to 100 | Great |
| 75 to 89 | Good |
| 50 to 74 | Acceptable |
| 25 to 49 | Needs work |
| 0 to 24 | Poor |
The same bands colour the score wherever it appears. Note that where CyberHQ shows a raw risk figure rather than the resilience score, the colours run the other way, because a low raw risk number is a good outcome.
When CyberHQ will not give you a score
If there is not enough underlying data, you will see Not enough data to score rather than a number. This is deliberate and worth knowing about, because the alternative would be worse: a workspace with no scored risk categories would otherwise read as having no risk, and produce a flattering resilience score that means nothing.
For the same reason, where part of your history cannot be reconstructed the trend line shows a gap rather than dropping to zero. A resilience line falling to zero would read as a crisis. CyberHQ does not draw one it cannot substantiate.
If your score is not displaying, the usual cause is that no risk category has been scored yet. Link your risks to categories and the score will appear. See Getting Started With The Risk Register.
Where else this score appears
The same figure drives the four tiles on your posture scorecard, alongside your risk category score, your capability score and your programme progress. They are calculated once and displayed in both places, so the scorecard and the detailed section of the Executive Report can never disagree with each other.
Where to go next
-
For the report this score leads, see Understanding the Executive Report
-
For the maturity half, see Understanding Your Capabilities Scoring
-
For the risk half, see Getting Started With The Risk Register