How Our Calculator Works

Fully transparent methodology — 11 weighted security domains, industry-specific calibration, and security control bonuses that reflect how carriers actually underwrite cyber risk in 2026.

11
Security Domains
7
Carriers
3
Policy Tiers
~5 min
To Complete

The 4-Step Assessment Flow

1

Organization Profile

Company name, industry, size, financial health, and recent incident history. These establish your baseline risk multipliers before the technical questions begin.

2

11-Domain Security Assessment

Detailed questions across all 11 security domains. Each answer is weighted by domain importance and question impact. Takes about 5 minutes.

3

Risk Score & Gap Analysis

Your weighted answers are scored, industry-calibrated, and security bonuses applied. Critical gaps are identified with NIST-referenced remediation steps and premium impact estimates.

4

Report + Carrier Matching

Your personalized 2026 Cyber Insurance Readiness Report is generated and emailed to you. Includes your policy tier match, premium range, and direct carrier links with your risk context pre-loaded.

The 11 Security Domains

Each domain carries a weight multiplier reflecting its impact on claims likelihood and severity, based on cyber insurance actuarial data.

Company Profile

1.2×

Data volume, sensitivity, and breach exposure baseline

Network Security

1.5×

Firewalls, segmentation, monitoring, patch cadence

Access Management

1.4×

MFA, privileged access, password policy, least privilege

Backup & Recovery

1.3×

Frequency, offline/immutable copies, recovery testing

Incident Response

1.3×

IR plan, tabletop exercises, business continuity

Third-Party Risk

1.1×

Vendor assessment, contract requirements, monitoring

Cloud Security

1.2×

Config management, data encryption, access controls

Employee Training

1.0×

Frequency, phishing simulation, policy education

Endpoint Security

1.2×

EDR/XDR, mobile device management, hardening

AI & Emerging Tech

1.1×

AI governance, data protection, model risk oversight

Data Privacy & Compliance

1.3×

Regulatory obligations, compliance program maturity

How the Score Is Calculated

Step 1 — Weighted Question Scoring

Category Score = Σ (question_score × question_weight) / total_question_weight

Each question has a per-question weight (1.0–1.8×) reflecting its individual security impact. Boolean and select questions map directly to risk scores; multi-select questions accumulate scores per selected item. MFA gets special handling — any MFA implementation applies a risk reduction immediately.

Step 2 — Org Profile Modifiers

Adjusted Score = Base Score × Industry Multiplier × Geographic Factor + Financial Health Adjustment + Incident History

Industry and company size add baseline points before technical scoring. Recent security incidents add 5–15 points depending on frequency. Poor financial health adds 5–15 points (proxy for reduced security investment capacity).

Step 3 — Security Control Bonuses

Final Score = Adjusted Score − Σ(applicable bonus values)

Organizations with comprehensive control implementations earn point reductions. Bonuses reward holistic security — having excellent controls in one domain while neglecting others earns less than balanced coverage across domains.

Step 4 — Normalization to 0–100

Risk Score (0–100) = min(max(round(raw_score / (max_possible × industry_normalization_factor) × 100), 0), 100)

Higher = higher risk. The normalization factor varies by industry (0.55–0.65) so that a healthcare organization needs stronger controls to achieve the same score as a tech company — reflecting real-world carrier underwriting expectations.

< 25
Low Risk
25–49
Moderate
50–74
High Risk
75–100
Critical

Step 5 — Premium Estimate

Premium Range = Size Base Range × (1 + risk_score/100) × Industry Premium Factor × Policy Base Multiplier

Base ranges are anchored by company size (micro: $750–$2.5K, small: $1.5K–$5K, medium: $7.5K–$25K, large: $25K–$75K, enterprise: $75K–$350K). The risk score multiplier scales the range upward for higher-risk organizations. Industry and policy-tier factors are applied on top.

Security Control Bonuses

These bonuses are applied automatically when the relevant controls are detected in your answers. They reduce your risk score directly — and each maps to a real premium impact range carriers use in underwriting.

BonusTrigger ConditionScore ImpactEst. Premium Impact
Defense-in-DepthStrong controls across 4+ domains−15 pts10–20% off
Comprehensive MFAMFA on 3+ critical system types−10 pts15–20% off
Full Network Security StackNGFW + segmentation + SIEM/IDS + monthly patching−12 pts10–18% off
Offline Backups + Daily Frequency3-2-1 backup with immutable copy−8 pts15–25% off
Tested Incident ResponseIR plan + BCP + annual/biannual drills−10 pts10–15% off
Advanced Cloud SecurityAutomated configs + encryption + IAM+MFA−9 pts8–15% off
EDR/XDR + MDMModern endpoint protection with management−8 pts10–15% off
AI Governance FrameworkFormal AI policy + data protection controls−5 pts5–10% off

Bonuses stack — an organization with defense-in-depth + comprehensive MFA + offline backups + tested IR plan could reduce their score by up to 45 points.

Industry-Specific Calibration

The same answers score differently depending on your industry. Healthcare and financial services have stricter normalization because carriers set higher baseline expectations for those sectors.

IndustryRisk MultiplierNormalization FactorWhy
Healthcare1.20×0.65HIPAA exposure, PHI breach costs
Financial Services1.15×0.65PCI/SOX obligations, fraud exposure
Government1.15×0.65Nation-state targeting, compliance burden
Technology0.95×0.55Stronger baseline security assumed
Retail1.10×0.60PCI scope, supply chain exposure
Manufacturing1.05×0.60OT/IT convergence risk
Education0.90×0.60Lower revenue exposure
Professional Services1.00×0.60Standard baseline

Policy Tier Matching

Your risk score determines which coverage tiers you're eligible for and which carriers are the best match.

Cyber Essential

Eligible when: Score ≤ 80
Coverage Limits
$250K – $1M
Ideal For

Small businesses with basic security controls

Matched Carriers
HiscoxCoalition

Cyber Standard

Eligible when: Score ≤ 60
Coverage Limits
$1M – $5M
Ideal For

Mid-market with established security practices

Matched Carriers
ChubbTravelersBeazley

Cyber Enterprise

Eligible when: Score ≤ 40
Coverage Limits
$5M – $50M
Ideal For

Enterprise and regulated industries

Matched Carriers
AIGChubbBeazley

How We're Different from Traditional Calculators

FactorTraditional ApproachOur Approach
Domains evaluated3–4 (industry, revenue, headcount)11 weighted security domains
Industry calibrationOne multiplier applied uniformlySeparate risk multiplier + normalization factor per industry
Security bonusesNone — controls not evaluated8 compound bonuses reflecting real underwriting discounts
RecommendationsGeneric or noneNIST-referenced, with cost estimates and premium impact per gap
Policy matchingGeneric quote formScore-based eligibility mapped to 3 tiers and 7 carriers
Report deliveryOn-screen onlyPersonalized PDF report emailed to you with carrier referral links
2026 coverageRarely updatedAI governance domain, updated premium ranges, At-Bay included

Ready to See Your Score?

Takes about 5 minutes. Get your personalized 2026 Cyber Insurance Readiness Report with your risk score, premium estimate, and carrier recommendations.

Frequently Asked Questions

How much does it cost?

The calculator runs on your CISO Marketplace account: it's included free with membership, or you can run it with wallet credits / a one-time purchase. Signing in also saves your report to your member portal at my.cisomarketplace.com, alongside reports from every other tool in the ecosystem. See microsec.tools/pricing for plans.

How accurate is the premium estimate?

Our calculator provides an estimated range based on your answers. Actual premiums vary by carrier, coverage options, and detailed underwriting. Our estimates typically fall within 15–25% of real quotes — close enough to know which tier you should be shopping in.

Why do you ask about financial health and recent incidents?

Carriers ask these questions in every application. Recent incidents increase your score by 5–15 points; poor financial health suggests reduced security investment capacity. Including them makes our estimate more realistic.

What is the AI & Emerging Tech domain?

Added in 2026, this domain evaluates whether your AI/ML systems have governance policies, data protection controls, and oversight procedures. Carriers are increasingly asking about AI risk — organizations using AI without governance are a growing exposure.

How often should I retake the assessment?

Annually, or after any significant infrastructure change (cloud migration, new SaaS stack, acquisition, major incident). Your score can improve materially by addressing critical gaps — retaking shows your progress.

Does this replace a broker?

No — it prepares you for one. Use your score and report to walk into a broker conversation knowing your gaps and what tier you should qualify for. A specialized cyber insurance broker can negotiate terms and coverage details that a calculator cannot.

Is my data secure?

All data is encrypted in transit (TLS) and at rest on Cloudflare. Completed assessments are stored as anonymized analytics only. We do not share your specific answers with carriers without your consent. Your email is used to send your report and relevant updates — you can unsubscribe anytime.

Disclaimer: Premium estimates are for informational purposes only and do not constitute a quote, offer, or guarantee of coverage. Actual premiums depend on carrier underwriting, coverage selections, and factors not captured in this assessment.

Methodology: Scoring weights, industry multipliers, and bonus thresholds are reviewed annually. This version reflects 2026 carrier underwriting trends including AI governance requirements and updated premium ranges. Last updated: May 2026.