How we calculate comparison baselines
ToughBlue IT Health Check reports compare your scores against a reference baseline. This page documents the data, methodology, sources, and when values were last updated — so clients and auditors can verify our approach.
Industry reference baseline
Methodology
- Each questionnaire answer maps to a score: Good = 100%, Partial = 50%, Needs work = 0%. Not applicable questions are excluded from the average.
- Domain scores are weighted averages of answered questions in that domain (see question weights in our catalog).
- The overall industry reference (55%) is the typical composite for SMEs that have basic IT but limited formal policies, monitoring, or tested recovery — common in our field work.
- Per-domain reference values below were calibrated by ToughBlue engineers using the sources listed, then adjusted for patterns seen across on-site assessments in Uganda. They are reference baselines, not a statistical mean from a single public dataset.
- Risk exposure indices (data loss, cyber attack) are derived from backup, security, network, and continuity domain health — higher exposure means weaker controls in those areas.
Current domain reference values
Published 2026-08-05 · version 1.0
| Domain | Reference score |
|---|---|
| Governance & Ownership | 48% |
| Devices & Endpoints | 54% |
| Email & Files | 52% |
| Network | 50% |
| Backup & Recovery | 42% |
| Security | 45% |
| Infrastructure | 47% |
| Business Apps | 51% |
| IT Operations | 46% |
| Continuity & DR | 40% |
| Overall composite | 55.0% |
Risk exposure reference
Higher index = greater exposure (weaker backup, security, and continuity). Lower is safer.
| Index | Industry reference |
|---|---|
| Data loss exposure | 65 / 100 |
| Cyber attack exposure | 62 / 100 |
Sources we use
Industry reference values are calibrated by ToughBlue using these public frameworks and datasets. We do not claim to reproduce any single survey verbatim — we map their guidance to our question catalog.
-
NIST Cybersecurity Framework (CSF) 2.0
Structure for security, backup, and governance maturity expectations.
https://www.nist.gov/cyberframework -
CIS Critical Security Controls v8
Baseline technical controls for endpoints, accounts, and monitoring.
https://www.cisecurity.org/controls/v8 -
Microsoft Digital Defense Report
Global SME attack trends, identity and email risk patterns.
https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report -
ITU Global Cybersecurity Index 2024
Regional cyber readiness context for Africa and developing economies.
https://www.itu.int/epublications/publication/D-STR-GCI.01-2024-HTM-E -
World Bank Enterprise Surveys
Firm-level technology adoption and formal process benchmarks in emerging markets.
https://www.enterprisesurveys.org/ -
NCSC Small Business Guide
Practical minimum standards for small organisations.
https://www.ncsc.gov.uk/collection/small-business-guide -
ISO/IEC 27001:2022 — Information security management
Policy, asset, and continuity expectations mapped to our governance domains.
https://www.iso.org/standard/82875.html
ToughBlue peer average (live data)
How peer averages are calculated
- When at least one other completed ToughBlue IT Health Check exists, reports compare against the peer average instead of the industry reference.
- Peer scores are computed live from completed, non-archived assessments in this system (client names are never shown on this page).
- Each peer report uses the same scoring engine and question catalog as the client report.
- The current client is excluded from the peer pool when viewing their own report.
Sectors represented (count only — no client names)
| Sector | Assessments |
|---|---|
| technology | 1 |
Current peer domain averages
| Domain | Peer average |
|---|---|
| Governance & Ownership | 85.7% |
| Devices & Endpoints | 66.7% |
| Email & Files | 100.0% |
| Network | 21.4% |
| Backup & Recovery | 11.1% |
| Security | 72.7% |
| Infrastructure | 100.0% |
| Business Apps | 100.0% |
| IT Operations | 100.0% |
| Continuity & DR | 10.0% |
Transparency commitment
We update the industry reference when our question catalog or calibration review changes — the Last reviewed date above reflects that review. Peer averages always reflect the current pool of completed assessments. If you need a printed citation for an audit, reference this page and the report reference code.