How we calculate comparison baselines
ToughBlue IT Health Check reports compare your scores against a reference baseline. This page documents the data, methodology, sources, and when values were last updated. For full scoring and risk formulas see Formulas.
Industry reference baseline
Methodology
- Each answer maps to Good = 100%, Partial = 50%, Needs work = 0%. Not applicable is excluded.
- Domain scores are weighted averages using question weights in the catalog.
- Industry reference uses a published Good/Partial/Poor profile per domain (configurable by admins).
- Synthetic responses from that profile are scored with the same engine as client assessments.
- Risk exposure uses gap severity × question weight × incident likelihood (see Formulas page).
- Peer averages are live means of other completed ToughBlue assessments when enough exist.
Current domain reference values
Published 2026-08-07 · version 1.1
| Domain | Reference score |
|---|---|
| Governance & Ownership | 40.9% |
| Devices & Endpoints | 40.0% |
| Email & Files | 43.8% |
| Network | 39.3% |
| Backup & Recovery | 33.3% |
| Security | 38.2% |
| Infrastructure | 35.0% |
| Business Apps | 35.7% |
| IT Operations | 33.3% |
| Continuity & DR | 22.2% |
| Overall composite | 36.4% |
Risk exposure reference
Higher index = greater exposure (weaker backup, security, and continuity). Lower is safer.
| Index | Industry reference |
|---|---|
| Data loss exposure | 71.1 / 100 |
| Cyber attack exposure | 61.5 / 100 |
Sources we use
Industry reference values are calibrated by ToughBlue using these public frameworks and datasets. We do not claim to reproduce any single survey verbatim — we map their guidance to our question catalog.
-
NIST Cybersecurity Framework (CSF) 2.0
Governance, security, and recovery maturity expectations.
https://www.nist.gov/cyberframework -
CIS Critical Security Controls v8
Endpoint, account, and monitoring baselines.
https://www.cisecurity.org/controls/v8 -
Microsoft Digital Defense Report
SME attack trends and identity risk.
https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report -
Verizon Data Breach Investigations Report
Incident likelihood calibration for risk exposure.
https://www.verizon.com/business/resources/reports/dbir/ -
NCSC Small Business Guide
Minimum practical controls for small organisations.
https://www.ncsc.gov.uk/collection/small-business-guide
ToughBlue peer average (live data)
No completed peer assessments in the system yet. Reports compare against the industry reference above until at least one other assessment is marked complete.
- When enough completed assessments exist, reports compare against the peer average.
- Peer scores are computed live from completed, non-archived assessments (no client names).
- Each peer report uses the same scoring and risk exposure engine.
- The current client is excluded from the peer pool on their own report.
- Low-confidence warning shown when sample size is below 3.
Transparency commitment
We update the industry reference when our question catalog or calibration review changes — the Last reviewed date above reflects that review. Peer averages always reflect the current pool of completed assessments. If you need a printed citation for an audit, reference this page and the report reference code.