Incident Response Readiness Score Calculator

Evaluate your organization's incident response preparedness across six critical domains. Answer each question on a scale of 0–4 to receive a weighted readiness score and maturity rating.

1. IR Plan & Documentation (Weight: 20%)
2. Detection & Analysis Capabilities (Weight: 20%)
3. Containment, Eradication & Recovery (Weight: 20%)
4. Communication & Escalation (Weight: 15%)
5. Training & Exercises (Weight: 15%)
6. Post-Incident & Continuous Improvement (Weight: 10%)

Formula

Domain Score (%) = (Sum of question scores in domain) / (4 × number of questions in domain) × 100

Weighted Domain Contribution = Domain Score (%) × Domain Weight

Final IR Readiness Score (0–100) = Σ (Weighted Domain Contributions)

Domain Weights: IR Plan & Documentation (20%) + Detection & Analysis (20%) + Containment/Eradication/Recovery (20%) + Communication & Escalation (15%) + Training & Exercises (15%) + Post-Incident & Improvement (10%) = 100%

Assumptions & References

  • Each question is scored 0–4 (0 = none/unknown, 4 = fully implemented and tested), giving a maximum raw score of 4 per question.
  • Domain weights reflect the relative criticality of each phase per NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide) and the SANS Incident Response Process.
  • Maturity levels align with the CMMI Maturity Model (Levels 1–5) adapted for IR programs.
  • MTTD benchmarks reference the IBM Cost of a Data Breach Report 2023 (average MTTD: 204 days; best-in-class: <24 hours).
  • EDR coverage thresholds are based on CIS Control 10 (Malware Defenses) recommendations.
  • Backup/recovery RTO/RPO requirements reference ISO/IEC 27031 (ICT Readiness for Business Continuity).
  • Legal/regulatory notification requirements reference GDPR Article 33 (72-hour notification), HIPAA Breach Notification Rule, and SEC Cybersecurity Disclosure Rules (2023).
  • Score of ≥85 = Optimized, 70–84 = Managed, 50–69 = Defined, 30–49 = Developing, <30 = Initial/Ad Hoc.
  • This calculator is a self-assessment tool and does not replace a formal IR program audit or third-party assessment.

In the network