Portfolio Avg Score
—
Enter KPIs to score
Target Avg
—
Revenue tier baseline
Critical Domains
0
Score 17–25
High Domains
0
Score 13–16
| Domain | L | I | Score | Target | Zone | Evidence / KPI Signal |
|---|
Scoring Model
CALIBR scores each domain by averaging the Likelihood (L) values produced by all populated KPI inputs. Unpopulated fields are excluded from the calculation. Impact is revenue-scaled per domain and fixed at framework design.
Risk Score = Likelihood (L) × Impact (I)
L = ROUND( AVG(L_input1, L_input2, ..., L_inputN) )
where each L_input ∈ {1, 2, 3, 4, 5}
Unpopulated inputs are excluded from the average
Floor Rule:
If any single input = L5, domain L cannot be below L3
This prevents one critical failure from being fully
masked by averaging with healthy inputs
Findings urgency — universal input (all domains):
Any findings ≥ 70 present → L3 (weight 1.0)
Only <70 findings present → L2 (weight 0.5)
No findings → excluded
Risk Zone Heat Map
| Score | Zone | Response |
|---|---|---|
17–25 | Critical | Immediate escalation; executive sponsor; 30-day plan |
13–16 | High | Active remediation; monthly tracking; risk acceptance memo if deferred |
5–12 | Medium | Managed mitigation; quarterly review |
3–4 | Low | Monitor; annual review sufficient |
1–2 | Very Low | Minimal risk; maintain controls |
0 | None | No open findings — maintain controls |
Revenue-Scaled Impact Reference
Impact scales with revenue tier. Higher-revenue entities face greater regulatory, financial, and operational consequences from the same domain failure. Impact updates automatically when you change the Revenue Tier setting.
| Domain | <$100M | $100M–$500M | $500M–$1B | $1B–$5B | $5B+ |
|---|---|---|---|---|---|
| IAM | 2 | 3 | 4 | 4 | 5 |
| Vulnerability | 2 | 3 | 4 | 4 | 5 |
| ASM | 2 | 3 | 4 | 4 | 5 |
| Application Security | 2 | 3 | 3 | 4 | 4 |
| Data Management | 2 | 2 | 3 | 4 | 4 |
| TPRM | 2 | 3 | 4 | 4 | 5 |
| Business Resiliency | 2 | 3 | 4 | 4 | 5 |
| Network / Infrastructure | 2 | 3 | 4 | 4 | 5 |
| Compliance & Regulatory | 2 | 3 | 3 | 4 | 5 |
| Cloud Security | 1 | 2 | 2 | 3 | 3 |
| Endpoint Security | 1 | 2 | 3 | 3 | 4 |
| M&A / Strategic Risk | 1 | 2 | 2 | 3 | 4 |
Revenue Tier — Target Baselines
| Revenue | Target Avg | Rationale |
|---|---|---|
| Under $100M | 6 | Emerging program |
| $100M – $500M | 7 | Mid-market; formalized program expected |
| $500M – $1B | 8 | Enterprise; board-level oversight required |
| $1B – $5B | 9 | Large enterprise; regulatory scrutiny high |
| $5B+ | 10 | Global enterprise; continuous monitoring standard |
KPI Threshold Reference
| KPI | Green | Amber | Red |
|---|---|---|---|
| MFA Enrollment % | ≥ 98% | 95–97% | < 90% |
| Privileged Accts Managed % | ≥ 100% | 95–99% | < 85% |
| Domain Admin Managed % | ≥ 100% | 95–99% | < 85% |
| Service Accts Vaulted % | ≥ 95% | 85–94% | < 70% |
| Servers Onboarded % | ≥ 95% | 85–94% | < 70% |
| SSO Coverage % | ≥ 95% | 85–94% | < 75% |
| IGA/RBAC Coverage % | ≥ 90% | 75–89% | < 60% |
| Vuln MTTR — Internal | ≤ 60 days | 61–90 days | > 90 days |
| Vuln MTTR — External | ≤ 30 days | 31–60 days | > 60 days |
| Int Avg Days Open | ≤ 60 days | 61–120 days | > 120 days |
| Ext Avg Days Open | ≤ 30 days | 31–90 days | > 90 days |
| Phish Prone % | < 5.2% | 5.3–10.6% | > 10.6% |
| Phish Reporting % | ≥ 15% | 5–14% | < 5% |
| Security Stack Coverage % | ≥ 95% | 85–94% | < 85% |
| Asset Visibility % | ≥ 95% | 85–94% | < 85% |
| Incident SLA Compliance % | ≥ 95% | 90–95% | < 80% |
| Contractor Access % | ≥ 95% | 85–94% | < 70% |
| 3rd Party External Score | ≥ 90 | 70–89 | < 60 |
| Cookie Compliance Rate % | ≥ 98% | 90–97% | < 80% |
| Non-Compliant Domain Count | 0 | 1–15 | > 30 |