Skip to content
English
  • There are no suggestions because the search field is empty.

Understanding Your Cyber Resilience Score

How CyberHQ arrives at your Cyber Resilience Score, what moves it, and what the bands mean

Your Cyber Resilience Score is the single number CyberHQ uses to express your overall security position. It appears on your posture scorecard, leads the Executive Report, and is usually the figure a board remembers. This article explains what goes into it, so you can answer the question that always follows: what would move it.

How the score is built

Resilience is the average of two halves:

  • Your risk position. For each of your risk categories, CyberHQ takes the worst residual score in that category, meaning the likelihood and impact remaining after your controls and remediation are accounted for. It averages those category figures and converts the result to a 0 to 100 scale where higher is better. A low amount of residual risk produces a high number.

  • Your capability position. Your overall maturity against your primary framework, also expressed from 0 to 100.

    The two are averaged. That is the whole formula, and its simplicity is deliberate: the score is intended to be explainable to a board rather than defensible to a statistician.

One consequence worth understanding is that the score is equally sensitive to both halves. Improving your control maturity while your residual risk stays flat moves the number half as far as you might expect. Teams who are surprised by a small improvement after a large programme of work are usually looking at one half moving and the other standing still.

What the bands mean

Score Band
90 to 100 Great
75 to 89 Good
50 to 74 Acceptable
25 to 49 Needs work
0 to 24 Poor

The same bands colour the score wherever it appears. Note that where CyberHQ shows a raw risk figure rather than the resilience score, the colours run the other way, because a low raw risk number is a good outcome.

When CyberHQ will not give you a score

If there is not enough underlying data, you will see Not enough data to score rather than a number. This is deliberate and worth knowing about, because the alternative would be worse: a workspace with no scored risk categories would  otherwise read as having no risk, and produce a flattering resilience score that means nothing.

For the same reason, where part of your history cannot be reconstructed the trend line shows a gap rather than dropping to zero. A resilience line falling to zero would read as a crisis. CyberHQ does not draw one it cannot substantiate.

If your score is not displaying, the usual cause is that no risk category has been scored yet. Link your risks to categories and the score will appear. See Getting Started With The Risk Register.

Where else this score appears

The same figure drives the four tiles on your posture scorecard, alongside your risk category score, your capability score and your programme progress. They are calculated once and displayed in both places, so the scorecard and the detailed section of the Executive Report can never disagree with each other.

Where to go next