Cyber Hygiene Score
One score that tells you exactly where you stand. Your cyber hygiene score reflects your overall security posture — from vulnerability counts to remediation speed.
Security posture
Recalculated 2 min ago · example.com
B+
78/100
+4 this week
HTTP Headers
A
92/100
TLS Configuration
B
84/100
DNS Setup
B+
87/100
Exposure Signals
C+
68/100
How your score is calculated
Your cyber hygiene score combines multiple security signals into a single A-F grade. It weighs vulnerability severity, remediation speed, scan coverage, and configuration hygiene.
- Vulnerability Severity:Weighted by CVSS score and exploitability — critical issues impact your score more than low-severity ones
- Remediation Speed:How quickly your team fixes issues relative to SLA deadlines
- Scan Coverage:Percentage of your assets actively scanned on schedule
- Configuration Hygiene:SSL/TLS strength, security headers, DNS records, and sensitive file exposure
Track progress over time
Your score isn't a snapshot — it's a trend. See how your security posture improves week over week as you fix issues and harden your infrastructure.
- Weekly and monthly score history with trend visualization
- Score breakdown by category to identify weak areas
- Per-project scores for teams managing multiple environments
- Improvement milestones that celebrate progress
Executive reporting
Your cyber hygiene score is designed for stakeholders who need to understand security posture without reading CVE reports. One grade, one glance.
- Include in board presentations and investor updates
- Client-facing security posture reports
- SOC 2 and compliance audit evidence
- Benchmarking against industry standards



Actionable, not just informational
Your score isn't just a number — it comes with specific recommendations on what to fix next to improve it the most.
- Prioritized list of actions that will raise your score
- Impact estimation for each recommended fix
- Integrated with issue tracking for one-click assignment
- Score recalculates in real time as issues are resolved
Frequently asked questions
Answers to the most common questions about cyber hygiene scoring, HTTP security headers, and baseline posture checks.
What is cyber hygiene in FortWatch?+
Cyber hygiene is the set of baseline security practices every internet-facing asset should have in place — correct HTTP security headers, strong TLS configuration, sane DNS records, no exposed sensitive files, and a responsive remediation workflow. FortWatch continuously checks these signals across your assets and rolls them into a single A–F score so you can see whether your overall security posture is improving or regressing at a glance.
What checks run as part of the cyber hygiene score?+
The score combines HTTP security header coverage (Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy), TLS/SSL strength and certificate validity, DNS hygiene (SPF, DKIM, DMARC, CAA), sensitive file and directory exposure, open port posture, vulnerability severity distribution, remediation speed against SLA, and scan coverage across your asset inventory.
Which frameworks and standards does the hygiene score map to?+
The underlying checks align with OWASP Secure Headers Project, Mozilla Observatory guidance, CIS Benchmarks for web server configuration, and the relevant controls in SOC 2 (CC6 Logical and Physical Access), ISO 27001 Annex A.8, and PCI DSS 4.0 requirements 2 and 6. The score is a practical rollup of these frameworks rather than a certification of any one of them.
How do I fix HTTP security header issues flagged by the scanner?+
Each header finding comes with a specific remediation: the exact header name, a recommended value tuned to your stack, the server or CDN location to set it in (Nginx, Apache, Cloudflare, Vercel, etc.), and an AI-generated explanation of the risk if it stays missing. For headers like Content-Security-Policy that require careful rollout, FortWatch suggests a report-only policy first and tracks violation reports over time before you enforce.
How is the A–F score calculated?+
The score weighs four buckets: vulnerability severity (CVSS-weighted, critical issues dominate), remediation speed (how quickly you close findings relative to SLA), scan coverage (percentage of assets actively scanned on schedule), and configuration hygiene (headers, TLS, DNS, exposures). Each bucket is normalized, combined, and mapped to a letter grade. The algorithm is deterministic — the same inputs always produce the same score.
Is the cyber hygiene score relevant for SOC 2 or ISO 27001 audits?+
Yes. The score and its underlying evidence — timestamped header checks, TLS scans, remediation history — are exportable as audit artifacts and map directly to SOC 2 CC7.1 (system monitoring), CC6.6 (network security), and ISO 27001 controls for secure configuration and vulnerability management. Many teams use the score trend as continuous evidence between audits rather than relying on point-in-time snapshots.
How often are cyber hygiene checks re-run?+
Baseline checks run on your scan schedule — typically daily for hygiene signals like headers, TLS, and DNS, and per full scan for deeper vulnerability and exposure checks. Any asset change (new subdomain, new IP, certificate renewal) triggers an immediate re-check so the score reflects your current posture rather than a stale snapshot.
Does the score update in real time as I fix issues?+
Yes. Marking a finding as fixed triggers a re-check of that specific control, and the score recalculates as soon as the new evidence arrives. You see the impact of each remediation immediately, which makes it easy to prioritize the fixes that will raise your grade the most.
Secure your entire stack today
Start scanning in under 5 minutes. No credit card required. 14-day free trial included.