Skip to main content

Security Score

The security score is a 0–100 measure of an asset's security posture and the risk it creates for your environment. A score of 100% means that Cyscale has not detected risk for the asset. A lower score means that the asset has failed one or more relevant controls, has a more severe failure, or affects other assets through its relationships.

The score is shown in the asset list as a gauge. As the score decreases, the gauge moves from minimal risk toward high risk. The score is recalculated after each assessment, so it reflects the latest control results and asset relationships.

Security score gauge showing how failed controls and impacted assets change the score

How is the asset score calculated?

The asset score is calculated based on the:

  • number of controls the asset has failed
  • severity of each failed control
  • number of assets impacted when the asset fails a control

The calculation is multiplicative: each risk factor reduces the current score, rather than subtracting from the original 100. For example, a high-severity failure reduces 100% to 50%. A second high-severity failure reduces the remaining 50% to 25%.

Example Asset

If the asset also increases the risk of other assets, each impacted asset is counted as an additional risk factor, as if another control failure had been found on the asset.

For example, if an asset has one high-severity failure and impacts two other assets, the score is reduced three times: 100% × 0.5 × 0.5 × 0.5 = 12.5%, which is displayed as 13% after rounding.

You can see the number of impacted assets when you hover over the score. A value of 0 means that the asset does not impact any other assets besides itself.

Example Asset

For this example, we can see that the misconfigurations on this asset also impact 12 other assets, 6 for one control and 6 for another control.
Impacted assets are not guaranteed to be distinct, meaning that of the 12 impacted assets, some of them may be the same asset, but impacted by different controls.

Score bands and severity factors

Use these bands to prioritize investigation:

  • Minimal Risk — 100% (or no risk detected by Cyscale)
  • Low Risk — 76–99%
  • Medium Risk — 51–75%
  • High Risk — 0–50%

Each failed control has a severity factor. The factor is applied to the current score for the asset:

  • Low — the current score is reduced by 10% (multiplied by 0.90)
  • Medium — the current score is reduced by 25% (multiplied by 0.75)
  • High — the current score is reduced by 50% (multiplied by 0.50)

How can I improve my asset score?

You can improve the asset score by following the remediation steps for the controls that the asset has failed. The asset score will be recalculated after the next assessment.