Portfolio Avg Score
—
Enter KPIs to score
Target Avg
—
Revenue tier baseline
Critical Domains
0
Score ≥ 16
Elevated Domains
0
Score 10–15
| Domain | L | I | Score | Target | Zone | Evidence / KPI Signal |
|---|
Scoring Model
CALIBR uses an urgency-based model. Findings ≥ 70 are "Urgent"; findings < 70 need attention but are not immediately urgent.
Risk Score = Likelihood × Impact
Likelihood = base_L × urgency_multiplier
Urgency multiplier:
Any findings ≥ 70 present → 1.5×
Only <70 findings present → 1.0×
No findings → 0×
Risk Zone Heat Map
| Score | Zone | Response |
|---|---|---|
≥ 16 | Critical | Immediate escalation; executive sponsor; 30-day plan |
10–15 | Elevated | Active remediation; monthly tracking |
5–9 | Moderate | Managed mitigation; quarterly review |
1–4 | Low | Monitor; annual review sufficient |
0 | None | No open findings — maintain controls |
Revenue Tier — Target Baselines
| Revenue | Target Avg | Rationale |
|---|---|---|
| Under $100M | 6 | Emerging program |
| $100M – $500M | 7 | Mid-market; formalized program expected |
| $500M – $1B | 8 | Enterprise; board-level oversight required |
| $1B – $5B | 9 | Large enterprise; regulatory scrutiny high |
| $5B+ | 10 | Global enterprise; continuous monitoring standard |
KPI Threshold Reference
| KPI | Green | Amber | Red |
|---|---|---|---|
| MFA Enrollment % | ≥ 98% | 95–97% | < 90% |
| Privileged Accts Managed % | ≥ 100% | 95–99% | < 85% |
| Domain Admin Managed % | ≥ 100% | 95–99% | < 85% |
| Service Accts Vaulted % | ≥ 95% | 85–94% | < 70% |
| Servers Onboarded % | ≥ 95% | 85–94% | < 70% |
| SSO Coverage % | ≥ 95% | 85–94% | < 75% |
| IGA/RBAC Coverage % | ≥ 90% | 75–89% | < 60% |
| Vuln MTTR — Internal | ≤ 60 days | 61–90 days | > 90 days |
| Vuln MTTR — External | ≤ 30 days | 31–60 days | > 60 days |
| Int Avg Days Open | ≤ 60 days | 61–120 days | > 120 days |
| Ext Avg Days Open | ≤ 30 days | 31–90 days | > 90 days |
| Phish Prone % | < 5.2% | 5.3–10.6% | > 10.6% |
| Phish Reporting % | ≥ 15% | 5–14% | < 5% |
| Security Stack Coverage % | ≥ 95% | 85–94% | < 85% |
| Asset Visibility % | ≥ 95% | 85–94% | < 85% |
| Incident SLA Compliance % | ≥ 95% | 90–95% | < 80% |
| Contractor Access % | ≥ 95% | 85–94% | < 70% |
| 3rd Party External Score | ≥ 90 | 70–89 | < 60 |