Back to home

Methodology

How Your CyberScore Is Calculated

Authored by Dr. James Carlopio, Ph.D.

The approach in brief

CyberScore measures how attractive your business looks to a cybercriminal — not how many compliance boxes you can tick. We use the FAIR (Factor Analysis of Information Risk) methodology, the open standard for quantitative cyber-risk measurement, combined with open-source and proprietary data, to produce a single, comparable risk score in under five minutes.

How the score is calculated

Your CyberScore is built from four building blocks, each derived from your answers to 22 plain-English questions:

1. Event Frequency

Derived from your industry (Q1). Different industries face different baseline rates of cyber incidents. A financial services firm and a retail shop are not equally likely to be targeted.

2. Vulnerability

Derived from your security-control answers (Q5–Q22) across technology, processes, and people. This measures how exposed your business is given the controls you have (or don't have) in place.

3. Likelihood

Event Frequency × Vulnerability. This combines how often incidents happen in your industry with how well-defended your business is, giving the probability of a successful breach.

4. Magnitude

Types of Information (Q4) × Amount of Information (Q2). This measures the impact severity if a breach occurs — how sensitive your data is and how much of it you hold.

Your raw CyberScore combines Likelihood and Magnitude through a lookup table, then is normalised to a 0–15 scale. The result maps to one of five risk bands — Low, Moderately Low, Medium, Moderately High, or High — and a traffic-light indicator (green, amber, red).

Why FAIR is the right standard

FAIR (Factor Analysis of Information Risk) is the leading open standard for quantitative cyber-risk measurement. Unlike compliance frameworks (NIST, ISO 27001, the ACSC Essential Eight) that tell you what controls to implement, FAIR tells you how much risk you actually face — in numbers you can compare and track over time. It was published as a technical standard by The Open Group in 2009 and is widely adopted by risk professionals globally.

We chose FAIR because it produces a repeatable, defensible calculation rather than a subjective opinion. It lets a small business owner answer the question that matters: "How much risk am I really exposed to, and where should I invest first?"

How the ACSC Essential Eight maps in

The Australian Cyber Security Centre's Essential Eight is a set of eight mitigation strategies (application control, patching, MFA, backups, and so on). CyberScore does not audit your Essential Eight compliance directly. Instead, your answers to the 22 questions map onto the same control areas the Essential Eight covers — but from the perspective of how much risk each gap creates, not whether you pass or fail a checklist.

For higher-risk results, the report recommends aligning with all eight strategies. For lower-risk results, a pragmatic baseline is sufficient. This risk-based approach helps you prioritise investment proportionate to your actual exposure.

The human-factors layer

Nearly a decade of OAIC Notifiable Data Breach Reports confirms that the overwhelming majority of breaches — roughly 95% — trace back to human behaviour, not technology failure. Phishing, misdirected emails, lost devices, weak passwords, and social engineering are people problems, not firewall problems.

CyberScore is built by Dr. James Carlopio, an organisational psychologist who teaches in the University of Queensland's Master of Cyber Security program. The assessment deliberately includes questions about people and processes — not just technology — because that is where the majority of risk actually lives.

Why 22 questions is sufficient

Many risk tools ask hundreds of questions and produce reports nobody reads. CyberScore asks only 22 because we focus on the factors that most strongly predict risk: your industry, your data, and your human and process behaviours. Every question maps directly to a FAIR input variable. Fewer questions means higher completion rates, which means more businesses actually get a useful answer.

What this score does and does not tell you

What it does

  • • Estimates your true cyber-risk exposure from an attacker's perspective
  • • Compares your risk to a standard 0–15 scale
  • • Identifies your weakest areas across people, processes, and technology
  • • Prioritises the top 3 actions that will reduce your risk most
  • • Gives you a repeatable, trackable baseline you can improve over time

What it does not

  • • It is not a security audit or penetration test
  • • It is not a certification or compliance guarantee
  • • It does not scan your network or test your systems
  • • It is based on self-reported information, not technical verification
  • • It is general guidance, not legal, financial, or insurance advice

Ready to know your risk?

22 questions. 5 minutes. An honest, vendor-independent answer.

Get Your CyberScore
CyberScore — a product of Holistic Management Pty. Limited (ABN 81 065 813 434, ACN 065 813 434)

Based on FAIR methodology — The Open Group Copyright © 2009