Everything below is computed from the selected framework and public threat intelligence for the selected industry. It assumes an organization that has fully implemented every control in the framework, and it does not read your assessments, scores, or tools. To see how your implementation measures up against these threats, run a framework assessment.
Primary TTPs
Vertical Focus
Sources
If you were fully protected by every control in this framework, the score below is your attack-surface score. It measures the framework's best case — not your organization's current state.
Even with a perfectly compliant framework implementation, you are still vulnerable. No framework reaches every phase of an attack — some, like Reconnaissance, happen entirely on the attacker's side before anything touches your network. A score under 100 at full compliance is honesty, not failure.
Changing the industry vertical re-weights the threats — not the framework. Threat intelligence tells us which attack techniques adversaries actually use against each industry. Switching industries asks how the same framework holds up against a different adversary playbook: the framework's controls don't change, but which gaps matter most does.
Attack Surface Coverage Score
—
Vertical-weighted defended share across the Kill Chain. Higher = more of the threat exposure adversaries actually use against your sector is covered by at least one framework control. 100 means full coverage of all non-empty phases.
See the full kill-chain breakdown
The score above is free to explore. The per-phase exposure, coverage, defense-in-depth, and threat-actor analysis are available to signed-in FrameworkMapper accounts.
Log in or create a free accountDefense by Kill Chain phase
How each phase stacks up — framework ceiling, your tools, and what would close the gap.
Methodology: coverage is exposure-weighted — a framework gets credit for addressing the techniques that actually drive threat in this vertical, rather than being penalized for missing low-prevalence variants.
Built on public threat intelligence: MITRE ATT&CK, the Lockheed Martin Cyber Kill Chain®, CISA advisories (incl. KEV and ransomware bulletins), MS-ISAC, and the Verizon DBIR. Framework control coverage is derived from MITRE-vetted control crosswalks.