How Our Calculator Works
Fully transparent methodology — 11 weighted security domains, industry-specific calibration, and security control bonuses that reflect how carriers actually underwrite cyber risk in 2026.
The 4-Step Assessment Flow
Organization Profile
Company name, industry, size, financial health, and recent incident history. These establish your baseline risk multipliers before the technical questions begin.
11-Domain Security Assessment
Detailed questions across all 11 security domains. Each answer is weighted by domain importance and question impact. Takes about 5 minutes.
Risk Score & Gap Analysis
Your weighted answers are scored, industry-calibrated, and security bonuses applied. Critical gaps are identified with NIST-referenced remediation steps and premium impact estimates.
Report + Carrier Matching
Your personalized 2026 Cyber Insurance Readiness Report is generated and emailed to you. Includes your policy tier match, premium range, and direct carrier links with your risk context pre-loaded.
The 11 Security Domains
Each domain carries a weight multiplier reflecting its impact on claims likelihood and severity, based on cyber insurance actuarial data.
Company Profile
1.2×Data volume, sensitivity, and breach exposure baseline
Network Security
1.5×Firewalls, segmentation, monitoring, patch cadence
Access Management
1.4×MFA, privileged access, password policy, least privilege
Backup & Recovery
1.3×Frequency, offline/immutable copies, recovery testing
Incident Response
1.3×IR plan, tabletop exercises, business continuity
Third-Party Risk
1.1×Vendor assessment, contract requirements, monitoring
Cloud Security
1.2×Config management, data encryption, access controls
Employee Training
1.0×Frequency, phishing simulation, policy education
Endpoint Security
1.2×EDR/XDR, mobile device management, hardening
AI & Emerging Tech
1.1×AI governance, data protection, model risk oversight
Data Privacy & Compliance
1.3×Regulatory obligations, compliance program maturity
How the Score Is Calculated
Step 1 — Weighted Question Scoring
Each question has a per-question weight (1.0–1.8×) reflecting its individual security impact. Boolean and select questions map directly to risk scores; multi-select questions accumulate scores per selected item. MFA gets special handling — any MFA implementation applies a risk reduction immediately.
Step 2 — Org Profile Modifiers
Industry and company size add baseline points before technical scoring. Recent security incidents add 5–15 points depending on frequency. Poor financial health adds 5–15 points (proxy for reduced security investment capacity).
Step 3 — Security Control Bonuses
Organizations with comprehensive control implementations earn point reductions. Bonuses reward holistic security — having excellent controls in one domain while neglecting others earns less than balanced coverage across domains.
Step 4 — Normalization to 0–100
Higher = higher risk. The normalization factor varies by industry (0.55–0.65) so that a healthcare organization needs stronger controls to achieve the same score as a tech company — reflecting real-world carrier underwriting expectations.
Step 5 — Premium Estimate
Base ranges are anchored by company size (micro: $750–$2.5K, small: $1.5K–$5K, medium: $7.5K–$25K, large: $25K–$75K, enterprise: $75K–$350K). The risk score multiplier scales the range upward for higher-risk organizations. Industry and policy-tier factors are applied on top.
Security Control Bonuses
These bonuses are applied automatically when the relevant controls are detected in your answers. They reduce your risk score directly — and each maps to a real premium impact range carriers use in underwriting.
| Bonus | Trigger Condition | Score Impact | Est. Premium Impact |
|---|---|---|---|
| Defense-in-Depth | Strong controls across 4+ domains | −15 pts | 10–20% off |
| Comprehensive MFA | MFA on 3+ critical system types | −10 pts | 15–20% off |
| Full Network Security Stack | NGFW + segmentation + SIEM/IDS + monthly patching | −12 pts | 10–18% off |
| Offline Backups + Daily Frequency | 3-2-1 backup with immutable copy | −8 pts | 15–25% off |
| Tested Incident Response | IR plan + BCP + annual/biannual drills | −10 pts | 10–15% off |
| Advanced Cloud Security | Automated configs + encryption + IAM+MFA | −9 pts | 8–15% off |
| EDR/XDR + MDM | Modern endpoint protection with management | −8 pts | 10–15% off |
| AI Governance Framework | Formal AI policy + data protection controls | −5 pts | 5–10% off |
Bonuses stack — an organization with defense-in-depth + comprehensive MFA + offline backups + tested IR plan could reduce their score by up to 45 points.
Industry-Specific Calibration
The same answers score differently depending on your industry. Healthcare and financial services have stricter normalization because carriers set higher baseline expectations for those sectors.
| Industry | Risk Multiplier | Normalization Factor | Why |
|---|---|---|---|
| Healthcare | 1.20× | 0.65 | HIPAA exposure, PHI breach costs |
| Financial Services | 1.15× | 0.65 | PCI/SOX obligations, fraud exposure |
| Government | 1.15× | 0.65 | Nation-state targeting, compliance burden |
| Technology | 0.95× | 0.55 | Stronger baseline security assumed |
| Retail | 1.10× | 0.60 | PCI scope, supply chain exposure |
| Manufacturing | 1.05× | 0.60 | OT/IT convergence risk |
| Education | 0.90× | 0.60 | Lower revenue exposure |
| Professional Services | 1.00× | 0.60 | Standard baseline |
Policy Tier Matching
Your risk score determines which coverage tiers you're eligible for and which carriers are the best match.
Cyber Essential
Small businesses with basic security controls
Cyber Standard
Mid-market with established security practices
Cyber Enterprise
Enterprise and regulated industries
How We're Different from Traditional Calculators
| Factor | Traditional Approach | Our Approach |
|---|---|---|
| Domains evaluated | 3–4 (industry, revenue, headcount) | 11 weighted security domains |
| Industry calibration | One multiplier applied uniformly | Separate risk multiplier + normalization factor per industry |
| Security bonuses | None — controls not evaluated | 8 compound bonuses reflecting real underwriting discounts |
| Recommendations | Generic or none | NIST-referenced, with cost estimates and premium impact per gap |
| Policy matching | Generic quote form | Score-based eligibility mapped to 3 tiers and 7 carriers |
| Report delivery | On-screen only | Personalized PDF report emailed to you with carrier referral links |
| 2026 coverage | Rarely updated | AI governance domain, updated premium ranges, At-Bay included |
Ready to See Your Score?
Takes about 5 minutes. Get your personalized 2026 Cyber Insurance Readiness Report with your risk score, premium estimate, and carrier recommendations.
Frequently Asked Questions
How much does it cost?
The calculator runs on your CISO Marketplace account: it's included free with membership, or you can run it with wallet credits / a one-time purchase. Signing in also saves your report to your member portal at my.cisomarketplace.com, alongside reports from every other tool in the ecosystem. See microsec.tools/pricing for plans.
How accurate is the premium estimate?
Our calculator provides an estimated range based on your answers. Actual premiums vary by carrier, coverage options, and detailed underwriting. Our estimates typically fall within 15–25% of real quotes — close enough to know which tier you should be shopping in.
Why do you ask about financial health and recent incidents?
Carriers ask these questions in every application. Recent incidents increase your score by 5–15 points; poor financial health suggests reduced security investment capacity. Including them makes our estimate more realistic.
What is the AI & Emerging Tech domain?
Added in 2026, this domain evaluates whether your AI/ML systems have governance policies, data protection controls, and oversight procedures. Carriers are increasingly asking about AI risk — organizations using AI without governance are a growing exposure.
How often should I retake the assessment?
Annually, or after any significant infrastructure change (cloud migration, new SaaS stack, acquisition, major incident). Your score can improve materially by addressing critical gaps — retaking shows your progress.
Does this replace a broker?
No — it prepares you for one. Use your score and report to walk into a broker conversation knowing your gaps and what tier you should qualify for. A specialized cyber insurance broker can negotiate terms and coverage details that a calculator cannot.
Is my data secure?
All data is encrypted in transit (TLS) and at rest on Cloudflare. Completed assessments are stored as anonymized analytics only. We do not share your specific answers with carriers without your consent. Your email is used to send your report and relevant updates — you can unsubscribe anytime.
Disclaimer: Premium estimates are for informational purposes only and do not constitute a quote, offer, or guarantee of coverage. Actual premiums depend on carrier underwriting, coverage selections, and factors not captured in this assessment.
Methodology: Scoring weights, industry multipliers, and bonus thresholds are reviewed annually. This version reflects 2026 carrier underwriting trends including AI governance requirements and updated premium ranges. Last updated: May 2026.