Skip to content

// RITIS · Methodology

How the RITIS Score is calculated

The whole method, published. Weights, inputs, what moves the number and what it deliberately is not. If a provider gives you a score they will not explain, it is a sales tool, not a measurement.

What the score is

The RITIS Score is a single number from 0 to 100 summarising the state of an IT environment across four scored domains: Users, Devices, Support and Productivity. Each domain is itself a percentage built from per-record checks, one row per person, per machine, per ticket. The domains are weighted and summed. That is the entire calculation.

Nothing in it is entered by hand. RITIS reads live from the PSA, RMM, patching, security, backup and Microsoft 365 tooling we already operate, so the score cannot be quietly up between the incident and the report.

Licences are tracked in RITIS but reported in dollars rather than folded into the score. Unused spend is a decision for you, not a health defect, so it stays a dollar figure on the Licences module instead of diluting the number.

The four scored domains and their weights

Weights reflect how much damage a failure in that domain does, not how easy it is to score well in.

Domain Weight What it measures
Users 30% MFA coverage, account activity, breach exposure and security training, per person.
Devices 25% Health and standards, patch compliance, agent coverage and backup success, per machine.
Support 30% Response and resolution SLA attainment against your agreement, plus satisfaction on closed tickets.
Productivity 15% Real use of Email, Teams, Files and Copilot across licensed people, service accounts excluded.

What each domain measures

Every domain percentage is a count, not a survey. Users at 93% means the per-person checks passed 93% of the time across every licensed account. Devices at 93% means the same across every managed machine. Support counts every ticket against the clock in your contract. Productivity counts people who actually used each service in the last 30 days.

Because the inputs are per-record, every percentage decomposes into names. That is what the Find action on each finding does: it lists the exact users, devices or tickets on the wrong side of the number.

What moves the score

Up

  • Users completing assigned security training
  • MFA enrolment on every remaining account
  • Missing agents deployed, lagging devices patched
  • Tickets assigned and responded to inside the SLA clock
  • Real adoption of the services already licensed

Down

  • New accounts created without MFA
  • Devices that stop checking in or fall behind on patches
  • Missed response or resolution SLAs
  • Training campaigns left incomplete
  • Licensed services going unused

There is no grace period and no smoothing. When the underlying record drops, the score drops the same day, which is why the sample environment shows a 67% training figure and a 17% Copilot figure rather than a page of green.

Refresh frequency

Continuous. Each source system is read on its own cycle, most within minutes, all within a day. There is no monthly compile step and no human in the loop between the source system and the score.

What the score is not

It is not a compliance certification. It is not an audit, and it is not a substitute for one. No number computed by the party being measured can certify that party, which is also why we publish the method.

What it does do for compliance work: the evidence an auditor asks for, MFA coverage, patch state, training completion, backup success, is already collected per record and datestamped. A high score does not pass an audit, it makes preparing for one shorter.

A worked example: reaching 91

The sample environment shown across these pages scores 91. Here is the arithmetic, with nothing hidden.

Domain Score Weight Contribution
Users 93% 30% 27.90
Devices 93% 25% 23.25
Support 96% 30% 28.80
Productivity 72% 15% 10.80
RITIS Score 100% 90.75 → 91

Sample environment shown. The 72% Productivity score is dragged down by Copilot adoption at 17%, and it stays on the page. If the method only ever produced flattering numbers, it would not be worth publishing.

Questions we get about the score

What is the RITIS Score?
A single number from 0 to 100 summarising an IT environment across Users, Devices, Support and Productivity, calculated continuously from the systems we already operate for you.
Which domains make up the score and what are their weights?
Users 30%, Devices 25%, Support 30%, Productivity 15%. Licences are tracked in dollars, not folded into the score.
What moves the RITIS Score up?
Closing the gaps the findings name: training completed, MFA enrolled, agents deployed, devices patched, tickets answered inside the clock, services actually used.
What moves the RITIS Score down?
New accounts without MFA, devices falling behind, missed SLAs, incomplete training and unused services. The drop happens the same day as the record, with no grace period.
How often does it refresh?
Continuously. Every source system is read live, most within minutes, all within a day.
Is it a compliance certification?
No. It is an operational health measure. It shortens audit preparation because the evidence is already collected, but it certifies nothing.
How does the sample environment reach 91?
93 × 0.30 + 93 × 0.25 + 96 × 0.30 + 72 × 0.15 = 90.75, displayed as 91.

See your own environment scored

A discovery call, then RITIS pointed at your tenant. You keep the findings list whether or not you work with us.