Methodology
Authored by Dr. James Carlopio, Ph.D.
CyberScore measures how attractive your business looks to a cybercriminal — not how many compliance boxes you can tick. We use the FAIR (Factor Analysis of Information Risk) methodology, the open standard for quantitative cyber-risk measurement, combined with open-source and proprietary data, to produce a single, comparable risk score in under five minutes.
Your CyberScore is built from four building blocks, each derived from your answers to 22 plain-English questions:
Derived from your industry (Q1). Different industries face different baseline rates of cyber incidents. A financial services firm and a retail shop are not equally likely to be targeted.
Derived from your security-control answers (Q5–Q22) across technology, processes, and people. This measures how exposed your business is given the controls you have (or don't have) in place.
Event Frequency × Vulnerability. This combines how often incidents happen in your industry with how well-defended your business is, giving the probability of a successful breach.
Types of Information (Q4) × Amount of Information (Q2). This measures the impact severity if a breach occurs — how sensitive your data is and how much of it you hold.
Your raw CyberScore combines Likelihood and Magnitude through a lookup table, then is normalised to a 0–15 scale. The result maps to one of five risk bands — Low, Moderately Low, Medium, Moderately High, or High — and a traffic-light indicator (green, amber, red).
FAIR (Factor Analysis of Information Risk) is the leading open standard for quantitative cyber-risk measurement. Unlike compliance frameworks (NIST, ISO 27001, the ACSC Essential Eight) that tell you what controls to implement, FAIR tells you how much risk you actually face — in numbers you can compare and track over time. It was published as a technical standard by The Open Group in 2009 and is widely adopted by risk professionals globally.
We chose FAIR because it produces a repeatable, defensible calculation rather than a subjective opinion. It lets a small business owner answer the question that matters: "How much risk am I really exposed to, and where should I invest first?"
The Australian Cyber Security Centre's Essential Eight is a set of eight mitigation strategies (application control, patching, MFA, backups, and so on). CyberScore does not audit your Essential Eight compliance directly. Instead, your answers to the 22 questions map onto the same control areas the Essential Eight covers — but from the perspective of how much risk each gap creates, not whether you pass or fail a checklist.
For higher-risk results, the report recommends aligning with all eight strategies. For lower-risk results, a pragmatic baseline is sufficient. This risk-based approach helps you prioritise investment proportionate to your actual exposure.
Nearly a decade of OAIC Notifiable Data Breach Reports confirms that the overwhelming majority of breaches — roughly 95% — trace back to human behaviour, not technology failure. Phishing, misdirected emails, lost devices, weak passwords, and social engineering are people problems, not firewall problems.
CyberScore is built by Dr. James Carlopio, an organisational psychologist who teaches in the University of Queensland's Master of Cyber Security program. The assessment deliberately includes questions about people and processes — not just technology — because that is where the majority of risk actually lives.
Many risk tools ask hundreds of questions and produce reports nobody reads. CyberScore asks only 22 because we focus on the factors that most strongly predict risk: your industry, your data, and your human and process behaviours. Every question maps directly to a FAIR input variable. Fewer questions means higher completion rates, which means more businesses actually get a useful answer.
22 questions. 5 minutes. An honest, vendor-independent answer.
Get Your CyberScore