We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Practical controls

Practical controls

How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It

Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.

Sam KhanSam Khan The Cyber MonkFounder and CEO7 September 2026 · 6 min read

The score came back at 58 and the argument started

The operations director of a 45-person structural engineering firm runs the three-minute test on a Tuesday afternoon. A client's procurement team has asked for evidence of basic cyber hygiene, and she wants to see the number before an auditor does.

Fifty-eight percent.

She is annoyed, and she has a case. The firm pays for a well-known endpoint product on every machine. Backups run nightly to a cloud account. Everyone has multi-factor authentication on email, set up two years ago by the IT company. Nothing has ever gone wrong.

Then she reads the twelve lines under the number. Backups run nightly, true, and nobody has restored a single file from them since the setup call in 2024. Multi-factor covers email and not the accounting system, the VPN, or the cloud drive where the drawings live. Two former employees still have active accounts, one of them a project manager who left in March. The endpoint product is installed on 41 machines out of 47. The six it missed are field laptops that never come back to the office.

Her score is not an opinion about her firm. It is six specific things she did not know on Monday and knows on Tuesday.

What the heck does a hygiene score measure

A hygiene score is coverage, not quality. For each control it asks one question: is this switched on everywhere it needs to be, or only in the places somebody remembered to set it up?

Control: a defensive practice with a name, like multi-factor authentication or offline backup.

Coverage: the share of accounts, systems and machines where the control is actually in force right now.

CIS Controls v8.1: the published list of safeguards most small-business scoring is built on, maintained by the Center for Internet Security.

Implementation Group 1: the 56 safeguards CIS marks as basic cyber hygiene for an organization with limited IT staff. That is the target set.

Drift: the slow decay of coverage as people join, leave, buy tools and rebuild laptops.

Three fixes move the number more than anything else, and they are the same three in almost every business we test. Extend the second factor past email. Close the accounts of people who left. Restore a file from backup to prove the backup exists. None of them requires a budget cycle.

The numbers that matter

The Center for Internet Security's Community Defense Model v2.0 found that Implementation Group 1, those 56 safeguards, defends against 77 percent of attack techniques overall and 78 percent of ransomware techniques. That is the ceiling your score points at. Five dozen ordinary practices, none of them exotic, stopping three quarters of what gets aimed at a business your size.

Vulnerability exploitation appeared in 31 percent of breaches and credential abuse in 13 percent, according to the Verizon 2026 Data Breach Investigations Report. Both are coverage problems in a costume. A patch that reached 90 percent of machines and a second factor that guards email but not the file share are exactly how those two numbers stay where they are.

Median time to remediate a known exploited vulnerability was 43 days in that same Verizon 2026 report. Six weeks. Attackers read the same advisories you do, and they read them the morning they come out.

What to do this week

  1. Restore something. Pick a real file from last Tuesday, restore it from backup to a clean machine, open it, and write the date and the person's name on the record. A backup nobody has restored from is a subscription, not a control. (CIS 11 Data Recovery)
  2. Take the second factor past email. List every place a login opens something that matters: accounting, payroll, the cloud drive, the VPN, the practice or project management system, the domain registrar. Turn it on for each, starting with anything that touches money. (CIS 6 Access Control Management)
  3. Pull the list of every account created in the last two years and cross it against payroll. Disable what does not match, today, including the shared "office" login and the account belonging to the project manager who left in March. (CIS 5 Account Management)
  4. Reconcile the security agent against the asset list, not against the vendor console's happy summary. The six laptops that never come back to the office are the six that will not be counted, patched or protected. (CIS 7 Continuous Vulnerability Management)
  5. Put the next check on the calendar 30 days out and give each gap an owner and a date. "Field laptops enrolled, office manager, 15 October" is a plan. "Improve coverage" is a wish. (CIS 7 Continuous Vulnerability Management)

Where AccuSights fits

The three-minute Cyber Hygiene Test is the fast version: twelve controls, a coverage number, and the specific gaps behind it. It is the same first question we ask in a paid engagement, without the paperwork.

Our assessment maps the same controls to your regulators, and the read-only compliance agent keeps the coverage picture current so you can prioritise. We have no access and we do not remediate. You or your IT partner fix it; we show you where.

Questions people ask

What is a good cyber hygiene score? There is no passing grade, because the score is coverage rather than an opinion. What matters is the direction and the gap list. A firm at 58 percent that closes four specific gaps in three weeks is in better shape than a firm sitting at 80 percent for two years with nobody watching the six machines that fell off. Read the twelve lines, not the headline number.

Why did my score drop when nothing changed? Something changed. A laptop was rebuilt and the security agent never went back on, a cloud app was added outside IT, a staff member left and kept an account, or a licence lapsed. Coverage decays on its own because businesses hire, buy and rebuild. That decay is the reason a once-a-year check tells you almost nothing useful.

Is a hygiene score the same as a risk assessment? No. The score tells you whether basic controls are switched on everywhere. A full risk assessment asks what data you hold, who wants it, what a failure would cost, and what your contracts and regulators require of you. Start with the score because it is fast and it finds real gaps. Move to the assessment when someone asks you to prove it.

A score is a mirror, not a verdict. The engineering director did not have a worse firm on Tuesday than she had on Monday. She had a shorter list of excuses, which is the only useful place to start.

Questions people ask

What is a good cyber hygiene score?

There is no passing grade, because the score is coverage rather than an opinion. What matters is the direction and the gap list. A firm at 58 percent that closes four specific gaps in three weeks is in better shape than a firm sitting at 80 percent for two years with nobody watching the six machines that fell off. Read the twelve lines, not the headline number.

Why did my score drop when nothing changed?

Something changed. A laptop was rebuilt and the security agent never went back on, a cloud app was added outside IT, a staff member left and kept an account, or a licence lapsed. Coverage decays on its own because businesses hire, buy and rebuild. That decay is the reason a once-a-year check tells you almost nothing useful.

Is a hygiene score the same as a risk assessment?

No. The score tells you whether basic controls are switched on everywhere. A full risk assessment asks what data you hold, who wants it, what a failure would cost, and what your contracts and regulators require of you. Start with the score because it is fast and it finds real gaps. Move to the assessment when someone asks you to prove it.

Controls this post maps to

CIS 6 Access Control ManagementCIS 7 Continuous Vulnerability ManagementCIS 11 Data Recovery

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.