Portfolio Avg Score
Enter KPIs to score
Target Avg
Revenue tier baseline
Critical Domains
0
Score 17–25
High Domains
0
Score 13–16
Domain LIScoreTargetZone Evidence / KPI Signal

Scoring Model

CALIBR scores each domain by averaging the Likelihood (L) values produced by all populated KPI inputs. Unpopulated fields are excluded from the calculation. Impact is revenue-scaled per domain and fixed at framework design.

Risk Score = Likelihood (L) × Impact (I) L = ROUND( AVG(L_input1, L_input2, ..., L_inputN) ) where each L_input ∈ {1, 2, 3, 4, 5} Unpopulated inputs are excluded from the average Floor Rule: If any single input = L5, domain L cannot be below L3 This prevents one critical failure from being fully masked by averaging with healthy inputs Findings urgency — universal input (all domains): Any findings ≥ 70 present → L3 (weight 1.0) Only <70 findings present → L2 (weight 0.5) No findings → excluded

Risk Zone Heat Map

ScoreZoneResponse
17–25CriticalImmediate escalation; executive sponsor; 30-day plan
13–16HighActive remediation; monthly tracking; risk acceptance memo if deferred
5–12MediumManaged mitigation; quarterly review
3–4LowMonitor; annual review sufficient
1–2Very LowMinimal risk; maintain controls
0NoneNo open findings — maintain controls

Revenue-Scaled Impact Reference

Impact scales with revenue tier. Higher-revenue entities face greater regulatory, financial, and operational consequences from the same domain failure. Impact updates automatically when you change the Revenue Tier setting.

Domain<$100M$100M–$500M$500M–$1B$1B–$5B$5B+
IAM23445
Vulnerability23445
ASM23445
Application Security23344
Data Management22344
TPRM23445
Business Resiliency23445
Network / Infrastructure23445
Compliance & Regulatory23345
Cloud Security12233
Endpoint Security12334
M&A / Strategic Risk12234

Revenue Tier — Target Baselines

RevenueTarget AvgRationale
Under $100M6Emerging program
$100M – $500M7Mid-market; formalized program expected
$500M – $1B8Enterprise; board-level oversight required
$1B – $5B9Large enterprise; regulatory scrutiny high
$5B+10Global enterprise; continuous monitoring standard

KPI Threshold Reference

KPIGreenAmberRed
MFA Enrollment %≥ 98%95–97%< 90%
Privileged Accts Managed %≥ 100%95–99%< 85%
Domain Admin Managed %≥ 100%95–99%< 85%
Service Accts Vaulted %≥ 95%85–94%< 70%
Servers Onboarded %≥ 95%85–94%< 70%
SSO Coverage %≥ 95%85–94%< 75%
IGA/RBAC Coverage %≥ 90%75–89%< 60%
Vuln MTTR — Internal≤ 60 days61–90 days> 90 days
Vuln MTTR — External≤ 30 days31–60 days> 60 days
Int Avg Days Open≤ 60 days61–120 days> 120 days
Ext Avg Days Open≤ 30 days31–90 days> 90 days
Phish Prone %< 5.2%5.3–10.6%> 10.6%
Phish Reporting %≥ 15%5–14%< 5%
Security Stack Coverage %≥ 95%85–94%< 85%
Asset Visibility %≥ 95%85–94%< 85%
Incident SLA Compliance %≥ 95%90–95%< 80%
Contractor Access %≥ 95%85–94%< 70%
3rd Party External Score≥ 9070–89< 60
Cookie Compliance Rate %≥ 98%90–97%< 80%
Non-Compliant Domain Count01–15> 30
CALIBR — KPI-Driven Cyber Risk Framework  |  calibrframework.com  |  Revenue-scaled · Urgency-driven · Audit-defensible