How we calculate scores and risk
Every ToughBlue IT Health Check uses the formulas documented here. Client reports, industry benchmarks, and peer comparisons all run through the same engine.
1. Answer scoring
| Answer | Score |
|---|---|
| Good | 100% |
| Partial | 50% |
| Needs work | 0% |
| N/A | excluded |
Not applicable (N/A) questions are excluded from averages. Important questions carry higher weight in the catalog.
2. Domain and overall score
- Domain score = weighted average of answered questions in that domain.
- Overall score = weighted average across all answered questions in active sections (after triage).
Domain % = 100 × (Σ answer_score × weight) / (Σ weight)
3. Risk exposure indices
Higher index = greater exposure if gaps are not resolved. Based on control gaps, severity (question weight), and incident likelihood — not incident history for this client.
Gap severity
| Answer | Gap factor |
|---|---|
| Good | 0.08 (residual risk — no organisation is zero-risk) |
| Partial | 0.55 |
| Needs work | 1.0 |
Formula
Exposure = 100 × Σ (gap × weight × likelihood) / Σ (weight × likelihood)
Separate indices are computed for data loss and cyber attack channels using domain likelihood tables below.
Domain likelihood (selected)
| Domain | Data loss | Cyber |
|---|---|---|
| backup | 0.92 | 0.15 |
| continuity | 0.88 | 0.2 |
| collaboration | 0.45 | 0.75 |
| security | 0.35 | 0.95 |
| network | 0.25 | 0.85 |
| devices | 0.3 | 0.8 |
| governance | 0.4 | 0.5 |
| infrastructure | 0.55 | 0.6 |
| applications | 0.5 | 0.45 |
| operations | 0.35 | 0.4 |
Incident data used for likelihood calibration
- Verizon Data Breach Investigations Report — Likelihood weighting for credential theft, phishing, and ransomware.
- Microsoft Digital Defense Report — SME identity and email compromise patterns.
- Coveware / industry ransomware statistics — Backup failure correlation with data-loss exposure.
4. Industry benchmark
- Admins publish a reference profile: expected Good / Partial / Poor mix per domain for a typical SME.
- The system builds synthetic answers from that profile and runs them through the same scoring engine.
- Published domain and overall reference scores are what you see on the benchmarks page.
5. Peer benchmark
- When enough other completed assessments exist, reports compare to the mean of those scores.
- The current client is excluded from their own peer pool.
- Same risk exposure model is averaged across peer reports.