# Risk Scores

In cybersecurity, risk is more than just the number of findings. It’s the combination of findings, the threat landscape, and the value of the assets to your business.

In the NetSPI Platform, you'll find your risk score presented in the following three ways to help maximize your coverage.

  • Engagement risk score: The Engagement Risk Score represents to severity of all the findings in your engagement.

  • Asset risk score: The risk of any given asset is determined by the number and severity of findings associated with that asset.

  • Overall Client Risk Score: The overall risk to your organization, as measured by your vulnerability score, remediation score, and industry score.

See the sections below for details.

# Risk score methodology

NetSPI Platform risk scores are assessed on a scale from 0 to 1000. The higher the score, the higher your risk, where 0 means no risk and 1000 means the maximum risk.

The number and severity of findings are at the root of all risk scores. A finding may be deemed “critical” in the sense that it’s easy to exploit, but if the asset that is impacted by that finding/exploit is not essential to business continuity or data privacy, then the risk of that asset should be considered minimal.

The NetSPI Platform provides three overall scores (Engagement Risk Score, Asset Risk Score, and Client Risk Score), each of which is derived from differing percentage values of three underlying risk scores: vulnerability risk score, remediation score, and industry score.

The underlying risk scores can most clearly be seen on the Overview tab for any of your engagements, when you expand the Risk Score card to display them.

Engagement Risk score
Engagement Risk score

The table below provides a brief description of how the underlying risk scores are derived.

Underlying risk score Risk score derivation
Vulnerability score The vulnerability score is based on a formula, applied over all of your findings across engagements and modules, and is represented as a value between 1 and 1000.
Remediation score The remediation score is based on a formula involving a percentage of overdue open findings and non-overdue open findings, asset, or engagement and is represented as a number between 0 and 1,000.
Industry score The industry score based on a percentage of the vulnerability score and a percentage of the remediation score, and then compared across the industry as a percentile.

# Engagement risk score

The engagement risk score can be seen in the Engagements table (PTaaS -> Engagements (Engagements table)) and the Engagement details page.

Engagement risk score
Engagement risk score

The Engagement risk score is determined by the severity weight of all the findings in the engagement. Each severity level has a weight associated with it.

Finding severity levels are set to one of the following:

  • Urgent
  • Critical
  • High
  • Medium
  • Low
  • None
  • Informational
  • Ignore

# Asset risk score

Asset risk scores are determined by the severity level of the findings on that asset.

This risk score is available across all modules (PTaaS, EASM, BAS, and CAASM) and can be seen in the following places:

Asset risk score
Asset risk score

# Overall/Client risk score

The overall risk score can be seen on the Risk Overview dashboard (Dashboards -> Risk Overview dashboard) in the Risk Score chart.

Risk Overview dashboard
Risk Overview dashboard

The Risk Overview dashboard also breaks down risk into the following categories:

# How do I use the risk score?

Use the three overall risk scores to asses the true risk to your business so you can prioritize remediation and allocation of your resources.

The risk scores also provide security leaders a quantitative metric to prioritize, measure, and track cybersecurity risk over time.