AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Practical controls

Practical controls

How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It

Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 7, 2026 · 6 min read

The score came back at 58 and the argument started

The operations director of a 45-person structural engineering firm runs the three-minute test on a Tuesday afternoon. A client's procurement team has asked for evidence of basic cyber hygiene, and she wants to see the number before an auditor does.

Fifty-eight percent.

She is annoyed, and she has a case. The firm pays for a well-known endpoint product on every machine. Backups run nightly to a cloud account. Everyone has multi-factor authentication on email, set up two years ago by the IT company. Nothing has ever gone wrong.

Then she reads the twelve lines under the number. Backups run nightly, true, and nobody has restored a single file from them since the setup call in 2024. Multi-factor covers email and not the accounting system, the VPN, or the cloud drive where the drawings live. Two former employees still have active accounts, one of them a project manager who left in March. The endpoint product is installed on 41 machines out of 47. The six it missed are field laptops that never come back to the office.

Her score is not an opinion about her firm. It is six specific things she did not know on Monday and knows on Tuesday.

What the heck does a hygiene score measure

A hygiene score is coverage, not quality. For each control it asks one question: is this switched on everywhere it needs to be, or only in the places somebody remembered to set it up?

Control: a defensive practice with a name, like multi-factor authentication or offline backup.

Coverage: the share of accounts, systems and machines where the control is actually in force right now.

CIS Controls v8.1: the published list of safeguards most small-business scoring is built on, maintained by the Center for Internet Security.

Implementation Group 1: the 56 safeguards CIS marks as basic cyber hygiene for an organization with limited IT staff. That is the target set.

Drift: the slow decay of coverage as people join, leave, buy tools and rebuild laptops.

Three fixes move the number more than anything else, and they are the same three in almost every business we test. Extend the second factor past email. Close the accounts of people who left. Restore a file from backup to prove the backup exists. None of them requires a budget cycle.

The numbers that matter

The Center for Internet Security's Community Defense Model v2.0 found that Implementation Group 1, those 56 safeguards, defends against 77 percent of attack techniques overall and 78 percent of ransomware techniques. That is the ceiling your score points at. Five dozen ordinary practices, none of them exotic, stopping three quarters of what gets aimed at a business your size.

Vulnerability exploitation appeared in 31 percent of breaches and credential abuse in 13 percent, according to the Verizon 2026 Data Breach Investigations Report. Both are coverage problems in a costume. A patch that reached 90 percent of machines and a second factor that guards email but not the file share are exactly how those two numbers stay where they are.

Median time to remediate a known exploited vulnerability was 43 days in that same Verizon 2026 report. Six weeks. Attackers read the same advisories you do, and they read them the morning they come out.

What to do this week

  1. Restore something. Pick a real file from last Tuesday, restore it from backup to a clean machine, open it, and write the date and the person's name on the record. A backup nobody has restored from is a subscription, not a control. (CIS 11 Data Recovery)
  2. Take the second factor past email. List every place a login opens something that matters: accounting, payroll, the cloud drive, the VPN, the practice or project management system, the domain registrar. Turn it on for each, starting with anything that touches money. (CIS 6 Access Control Management)
  3. Pull the list of every account created in the last two years and cross it against payroll. Disable what does not match, today, including the shared "office" login and the account belonging to the project manager who left in March. (CIS 5 Account Management)
  4. Reconcile the security agent against the asset list, not against the vendor console's happy summary. The six laptops that never come back to the office are the six that will not be counted, patched or protected. (CIS 7 Continuous Vulnerability Management)
  5. Put the next check on the calendar 30 days out and give each gap an owner and a date. "Field laptops enrolled, office manager, 15 October" is a plan. "Improve coverage" is a wish. (CIS 7 Continuous Vulnerability Management)

Where AccuSights fits

The three-minute Cyber Hygiene Test is the fast version: twelve controls, a coverage number, and the specific gaps behind it. It is the same first question we ask in a paid engagement, without the paperwork.

Our team implements the controls the score exposes at a reasonable rate, from data loss prevention to vulnerability scanning to protecting the assets that hold your records, and you can book 15 minutes with an engineer to walk through your gap list.

Questions people ask

What is a good cyber hygiene score? There is no passing grade, because the score is coverage rather than an opinion. What matters is the direction and the gap list. A firm at 58 percent that closes four specific gaps in three weeks is in better shape than a firm sitting at 80 percent for two years with nobody watching the six machines that fell off. Read the twelve lines, not the headline number.

Why did my score drop when nothing changed? Something changed. A laptop was rebuilt and the security agent never went back on, a cloud app was added outside IT, a staff member left and kept an account, or a licence lapsed. Coverage decays on its own because businesses hire, buy and rebuild. That decay is the reason a once-a-year check tells you almost nothing useful.

Is a hygiene score the same as a risk assessment? No. The score tells you whether basic controls are switched on everywhere. A full risk assessment asks what data you hold, who wants it, what a failure would cost, and what your contracts and regulators require of you. Start with the score because it is fast and it finds real gaps. Move to the assessment when someone asks you to prove it.

A score is a mirror, not a verdict. The engineering director did not have a worse firm on Tuesday than she had on Monday. She had a shorter list of excuses, which is the only useful place to start.

Controls this post maps to

CIS 6 Access Control ManagementCIS 7 Continuous Vulnerability ManagementCIS 11 Data Recovery

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.