The Executive summary at the top of your Dashboard answers one question at a glance: how healthy is our cybersecurity programme, and how much can we trust that number? It is built around two scores and two KPI widgets:
- Cyber Health Score — the big gauge. One percentage that summarises how much of your target cybersecurity posture you have achieved.
- Confidence Score — the badge under the gauge. It tells you how representative the Cyber Health Score is: how much of your environment has actually been assessed, recently enough.
- Performance KPIs — the four indicators the Cyber Health Score is made of.
- Coverage KPIs — the six indicators the Confidence Score is made of.
Every number on this page is computed live from your own workspace data, and every tile links to the module where you can act on it. This guide explains each calculation in plain terms, then shows how to customise the scores for your organisation.
The Cyber Health Score
The Cyber Health Score is a weighted average of the four performance KPIs, on a 0–100% scale. With the default weights:
Cyber Health Score = Risk score × 35% + Control performance × 30% + Framework compliance × 20% + Audit readiness × 15%
Two details matter:
- The risk component is inverted. Risk exposure is a "lower is better" number, so the score uses Risk score = 100 − Current Risk Exposure. Reducing your exposure raises your health score.
- A KPI with no data is left out, not counted as zero. If, say, you have not run any audit yet, Audit readiness is excluded and the remaining weights are re-scaled so they still total 100%. The score never punishes you for a module you have not started — that is the Confidence Score's job to reveal.
The score maps to a fixed five-tier vocabulary, used consistently across the dashboard:
| Score | Tier |
|---|---|
| 0 – 19% | Critical |
| 20 – 39% | Weak |
| 40 – 59% | Fair |
| 60 – 79% | Good |
| 80 – 100% | Excellent |
The four performance KPIs
Current Risk Exposure
How hot is your risk register right now? Every open risk that is placed on your workspace risk matrix (at its current level) contributes its cell score — likelihood × impact. The KPI is the total pressure as a share of the theoretical maximum:
Current Risk Exposure = sum of (likelihood × impact) ÷ (number of rated risks × the matrix's maximum cell score) × 100
Every rated open risk counts, including those in the lowest severity band — a portfolio of mostly low risks dilutes the figure instead of being ignored. Closed and cancelled risks never count. Lower is better — this is the one KPI whose bar shows green when the value is low.
Global Control Performance
How well are your controls doing against their targets? Each control that has both a current and a target maturity gets an achievement ratio:
Achieved = progress toward target maturity, plus the completion percentage applied to the remaining gap, capped at 100%
So a control at maturity 2 of target 4 that is 50% through its ongoing work counts as 50% + (50% × 50%) = 75% achieved. Controls are not all equal: each control's weighting (1 to 10, default 3 — set it in the control's properties) determines how much it counts in the average:
Global Control Performance = sum of (weighting × achieved) ÷ sum of weightings × 100
Controls that have never been evaluated are excluded here — they show up in the Confidence Score instead.
Framework Compliance
How close are you to your target maturity on your framework requirements? Each assessed requirement contributes current maturity ÷ target maturity (capped at 100%), weighted by the requirement's weighting (default 3):
Framework Compliance = sum of (weighting × min(current ÷ target, 1)) ÷ sum of weightings × 100
By default every framework in the workspace counts. If you designate a reporting framework (see Customising below), only that framework feeds this KPI — so importing a new, still-empty framework does not drag your compliance down.
Audit Readiness
How far along are you in closing the recommendations of your reference audit? Each recommendation is scored by its completion — done directly, or the share of its closed follow-up actions (weighted by action priority) — and recommendations are averaged weighted by their priority:
Audit Readiness = sum of (priority × completion) ÷ sum of priorities × 100
This KPI reads one audit: the designated reporting audit, or automatically the most recent audit in progress (see Customising below).
The Confidence Score
A health score computed from three assessed controls out of three hundred would be misleading. The Confidence Score exists to keep the Cyber Health Score honest: it measures how much of your environment has been assessed, and whether those assessments are still fresh. It is fully independent — it is never mixed into the Cyber Health Score.
It is a weighted average of the six coverage KPIs. Default weights: Framework assessment 17%, Policies review 17%, Controls evaluation 17%, Third parties evaluation 17%, Systems evaluation 16%, Audit scope 16%. Like the health score, a module with no entities at all drops out and the weights re-scale; but a module whose coverage is genuinely 0% stays in and pulls the score down.
The three coverage states
Every item in scope is in exactly one state:
| State | Meaning |
|---|---|
| Covered | Assessed, and the assessment is still valid — its scheduled review date (if any) has not passed. |
| Overdue | Assessed in the past, but the scheduled review date has passed. A stale assessment no longer counts as covered. |
| Never evaluated | No assessment yet. |
Only Covered items count toward the percentage. This is why a score can drift down with no change in your data: reviews falling past their due date move items from Covered to Overdue.
What "covered" means per KPI
| Coverage KPI | An item is covered when… | Weighting |
|---|---|---|
| Framework assessment | The requirement has a maturity assessment and its periodic review (if scheduled) is not past due. Requirements marked "not applicable" are excluded from the calculation entirely. Respects the reporting framework designation. | Equal |
| Policies review | The policy (current version) has a review schedule whose next review date is in the future. | Equal |
| Controls evaluation | The control has a current maturity and its periodic review (if scheduled) is not past due. | Equal |
| Third parties evaluation | The third party is linked to a risk assessment whose validity date is in the future. | By tier: Tier 1 ×5, Tier 2 ×3, others ×1 |
| Systems evaluation | The system is linked to a risk assessment whose validity date is in the future. | By criticality: Critical ×5, standard ×3, Non-critical ×1 |
| Audit scope | The reporting audit's element has been decided "in scope", counted against all elements still awaiting a decision. Elements consciously ruled out of scope do not count against you. | Equal |
Note: in the Coverage KPIs widget, a row whose value is zero is hidden to keep the widget readable — but it still weighs into the Confidence Score.
Customising the scores — Score settings
Everything configurable lives behind the gear icon on the Cyber Health Score widget. It is visible to users who hold the Workspace Settings · Update permission, and every change is recorded in the workspace activity feed.
Weights
Both weighting sections — the four Cyber Health Score weights and the six Confidence Score weights — can be tuned to your organisation's priorities. Each section must total exactly 100, and a "Restore defaults" action puts back the standard weighting (35/30/20/15 and 17/17/17/17/16/16). A risk-driven organisation might push the risk weight up; an audit-driven one might favour audit readiness.
Reporting entities
Two designations pin which entities feed the executive KPIs:
- Reporting framework — the framework used for Framework Compliance and Framework assessment coverage. With no designation, all frameworks count, so adding a new (still empty) framework immediately lowers both — designate your reference framework to keep the score stable.
- Reporting audit — the audit used for Audit Readiness and Audit scope coverage. The default, Automatic, picks the most recent audit in progress (or, failing that, the most recent audit).
Monthly history and trends
On the last day of each month, the platform stores a snapshot of all executive KPIs. The Score evolution widget charts the Cyber Health Score over the last six months (the current month always shows the live value), and the "vs last month" chips on the gauge and the performance KPIs compare today's live value with last month's snapshot.
A new workspace shows "History builds up from next month" until its first month-end snapshot exists — that is expected, not an error. Missing months are shown as gaps, never invented.
Common questions
- My score dropped right after I imported a framework — why? Without a reporting framework designation, every framework counts in Framework Compliance and coverage. Designate your reference framework in Score settings.
- A KPI shows no data. Nothing has been evaluated in that module yet, so it is excluded from the Cyber Health Score and the other weights re-scale. Start assessing and it joins the average.
- The score changed but nobody touched anything. Coverage is time-aware: when scheduled reviews pass their due date, items move from Covered to Overdue and the Confidence Score drops. Weight changes are also possible — check the activity feed, every Score settings change is logged there.
- Two people see different numbers. The dashboard respects each user's read permissions: a user without access to a module will not see the blocks that depend on it.