The index turns a short questionnaire into one exposure score across five weighted signals. The scoring is transparent, and the full question set publishes with the assessment.
Your answers are scored across five signals. Each carries a weight set by how much that control, present or absent, moves real exposure. A visibility gap raises the score more than an audit gap, which is why the two are not weighted the same.
Each answer is worth exposure points from 0 to 100, where 0 means the control is fully in place and 100 means it is absent. A signal subscore is the average of its questions. The index is the weighted sum of the five subscores, so it also runs 0 to 100, and higher means more exposed.
This is a self-reported, directional read, not an audit. It is built to be consistent, so the number you record this quarter is comparable to the one you record next.
The score places an organization in one of five bands. The bands run from controls holding across the board to little visibility or control at all.
Every statistic on this site is attributed to a primary source, and we cite only major research organizations and established players in the field. We do not cite security startups or vendors marketing a competing product. The figures behind the index today are drawn from:
Where a number appears on this site, its source appears next to it. We never invent a figure or round past what the source says.
The AI Insider Risk Index is built and maintained by Anzenna, an AI security company. We say that plainly because a benchmark is only useful if you can trust it. The scoring never asks about or rewards any vendor's product, Anzenna's included. More on how we handle this is on the about page.
Fifteen questions, about ten minutes, no registration to see your result.
Take the assessment