Cyber Liability Risk Scoring Tool (2025)
Assess your organization's cyber liability exposure and find your overall Cyber Risk Score, based on data protection, employee practices, and incident readiness.
This estimator helps organizations understand their cyber exposure and insurance readiness by quantifying internal vulnerabilities, business context, and security maturity. It's based on models inspired by NIST CSF, ISO 27001, and insurance underwriting frameworks used by carriers like Chubb and AXA XL.
| Score Range | Rating | Meaning |
|---|---|---|
| 0–40 | High Risk | Vulnerable; needs immediate controls |
| 41–70 | Moderate Risk | Some protections, but gaps exist |
| 71–90 | Low Risk | Strong controls, insurable |
| 91–100 | Excellent | Minimal exposure; optimized policies |
| Industry | Typical Threats | Average Breach Cost |
|---|---|---|
| Healthcare | Ransomware, PHI exposure | $10.9M |
| Finance | Data exfiltration, insider fraud | $9.5M |
| Retail | POS malware, phishing | $3.3M |
| Education | Credential theft | $2.7M |
| Tech | Cloud misconfigurations | $4.8M |
Source: IBM Cost of a Data Breach Report 2024
Coverage Benefits
- • Data recovery and forensics
- • Legal defense and notification costs
- • Business interruption coverage
- • Public relations and reputation management
Modern Protection
- • Ransomware and social engineering coverage
- • 24/7 incident response support
- • Security assessments and tools
- • Employee training resources
Premiums scale with risk score, revenue, and security controls.Organizations with strong security postures often qualify for preferred rates.
What is a good cyber risk score?
Scores above 70 indicate solid security maturity and strong insurability.
Can this score be used for insurance applications?
It's for educational use, but it aligns with key insurer evaluation factors.
Does having cyber insurance lower breach probability?
Not directly, but insurers often provide resources and assessments to reduce risk.
How often should I reassess?
Every 6–12 months or after major tech or staff changes.
What's included in cyber insurance coverage?
Data recovery, legal defense, notification costs, and business interruption.
Do small businesses need cyber insurance?
Yes - 43% of cyber attacks target small businesses.