Free Tool
Cyber Risk Score Calculator
Answer six questions about your organization's size, training cadence, and incident history to get an illustrative risk score, benchmarked against the TRISA readiness model.
If someone asked you right now how exposed your organization actually is, could you answer with more than a guess?
Why run this now
- See where your human risk, infrastructure risk, and compliance readiness actually stand — separately, not blended into one vague number
- Compare yourself against a same-model peer baseline, so the score means something instead of floating in isolation
- Walk away with a concrete next question to bring to your next security or budget conversation
Illustrative Score
50/100
Moderate
Organizations with annual training and a typical posture otherwise score around 58 on this model — there's room to close that gap.
This is an illustrative estimate for directional guidance only, not a certified risk assessment. A full readiness audit accounts for far more signal than six questions.
This model is informed by the same signal used in TRISA.
FAQ
Common questions
What does the Cyber Risk Score Calculator measure?
It produces three separate scores — Human Risk, Infrastructure Risk, and Compliance Readiness — plus an overall average, from six questions about your organization's size, training cadence, and incident history.
Is the Cyber Risk Score a certified risk assessment?
No — it's an illustrative estimate for directional guidance only, not a certified risk assessment. A full readiness audit accounts for far more signal than six questions.
How is the peer benchmark calculated?
It compares your score against organizations with the same training cadence and a typical (not best-case) posture on every other input — a same-model comparison point, not an external industry statistic.
What information do I need to provide?
Six questions: employee count, how often your team runs security awareness training, whether MFA is enforced everywhere, whether you've had an incident in the last 12 months, how many compliance frameworks you're required to meet, and whether you have a dedicated security function.