Enter assessment inputs
Use organizational counts, control coverage, detection metrics, and business context to estimate credential misuse risk.
Example data table
These sample records show how different identity conditions can change the final risk position.
| Scenario | Active | Privileged | MFA % | PAM % | Anomalies | Overall Risk | Rating |
|---|---|---|---|---|---|---|---|
| Well-governed finance team | 140 | 8 | 98 | 92 | 6 | 22.40 | Moderate |
| Mixed maturity operations unit | 300 | 24 | 82 | 58 | 31 | 51.85 | Elevated |
| Legacy admin environment | 420 | 44 | 60 | 35 | 67 | 79.30 | High |
Formula used
Exposure Score = 0.20 × Active Surface + 0.25 × Privileged Ratio + 0.20 × Dormant Ratio + 0.20 × Shared Ratio + 0.15 × Vendor Ratio
Control Gap Score = 0.24 × MFA Gap + 0.18 × PAM Gap + 0.16 × Logging Gap + 0.14 × Conditional Gap + 0.14 × Rotation Gap + 0.14 × Review Gap
Anomaly Score = 0.26 × Failed Login Score + 0.22 × Geolocation Score + 0.18 × Off-hours Score + 0.20 × Incident History Score + 0.14 × Deprovisioning Delay Score
Likelihood Score = 0.30 × Exposure + 0.32 × Anomaly + 0.23 × Control Gap + 0.15 × Detection Weakness
Impact Score = 0.40 × Business Criticality + 0.35 × Data Sensitivity + 0.25 × Lateral Movement Ease
Overall Risk = 0.55 × Likelihood + 0.45 × Impact
All component values are normalized to a 0–100 range. Higher scores indicate more exposure, weaker controls, stronger anomaly pressure, or greater business damage potential.
The risk-adjusted exposure value is estimated as exposed asset value × overall risk percentage. It is a screening estimate, not a replacement for formal loss modeling.
How to use this calculator
- Enter the total active identities in scope.
- Add privileged, dormant, shared, and vendor account counts.
- Provide coverage percentages for MFA, PAM, logging, and conditional access.
- Enter operational timings for credential rotation, access review, detection, response, and deprovisioning.
- Add behavioral indicators such as failed login spikes, geolocation anomalies, and off-hours activity.
- Score business criticality, data sensitivity, and lateral movement ease from 1 to 5.
- Press Calculate Risk to show the result above the form.
- Use the CSV or PDF button to export the current assessment.
Frequently asked questions
1. What does this calculator estimate?
It estimates the relative risk of credential misuse by combining identity exposure, control coverage, suspicious activity, operational speed, and business impact into one weighted score.
2. Is the result a compliance score?
No. It is a decision-support score for prioritization. You can use it beside audit frameworks, but it does not certify compliance on its own.
3. Why do shared accounts increase risk heavily?
Shared identities weaken attribution, slow investigations, and often bypass least-privilege design. That makes misuse harder to detect and contain.
4. How should I score conditional access strength?
Use a practical percentage representing policy breadth, enforcement consistency, device checks, location logic, session controls, and privileged user coverage.
5. Can I use this for vendors and contractors?
Yes. Third-party identities are included because they expand trust boundaries and may have weaker lifecycle control than internal accounts.
6. What is a good risk-adjusted exposure value?
Lower is better. Use it to compare scenarios, justify control investment, and highlight which identity population creates the largest potential loss.
7. How often should the inputs be refreshed?
Refresh after major access changes, new privileged roles, vendor onboarding, security incidents, or at least during each quarterly access governance review.
8. Can this replace incident investigation?
No. It helps with planning and prioritization. Actual investigations still require logs, identity telemetry, forensic evidence, and business context.