IT Health Check

How we calculate comparison baselines

ToughBlue IT Health Check reports compare your scores against a reference baseline. This page documents the data, methodology, sources, and when values were last updated. For full scoring and risk formulas see Formulas.

Industry reference baseline

Last reviewed2026-08-07
Version1.1
ScopeSMEs with 10–200 staff in Uganda and East Africa (mixed sectors)
Overall reference36.4%

Methodology

  1. Each answer maps to Good = 100%, Partial = 50%, Needs work = 0%. Not applicable is excluded.
  2. Domain scores are weighted averages using question weights in the catalog.
  3. Industry reference uses a published Good/Partial/Poor profile per domain (configurable by admins).
  4. Synthetic responses from that profile are scored with the same engine as client assessments.
  5. Risk exposure uses gap severity × question weight × incident likelihood (see Formulas page).
  6. Peer averages are live means of other completed ToughBlue assessments when enough exist.

Current domain reference values

Published 2026-08-07 · version 1.1

DomainReference score
Governance & Ownership40.9%
Devices & Endpoints40.0%
Email & Files43.8%
Network39.3%
Backup & Recovery33.3%
Security38.2%
Infrastructure35.0%
Business Apps35.7%
IT Operations33.3%
Continuity & DR22.2%
Overall composite36.4%

Risk exposure reference

Higher index = greater exposure (weaker backup, security, and continuity). Lower is safer.

IndexIndustry reference
Data loss exposure71.1 / 100
Cyber attack exposure61.5 / 100

Sources we use

Industry reference values are calibrated by ToughBlue using these public frameworks and datasets. We do not claim to reproduce any single survey verbatim — we map their guidance to our question catalog.

ToughBlue peer average (live data)

No completed peer assessments in the system yet. Reports compare against the industry reference above until at least one other assessment is marked complete.

  1. When enough completed assessments exist, reports compare against the peer average.
  2. Peer scores are computed live from completed, non-archived assessments (no client names).
  3. Each peer report uses the same scoring and risk exposure engine.
  4. The current client is excluded from the peer pool on their own report.
  5. Low-confidence warning shown when sample size is below 3.

Transparency commitment

We update the industry reference when our question catalog or calibration review changes — the Last reviewed date above reflects that review. Peer averages always reflect the current pool of completed assessments. If you need a printed citation for an audit, reference this page and the report reference code.