Skip to content
CIM-023 Cyber Incidents & Offender Methods

What is a security risk score?

A security risk score is a numerical or categorical assessment produced by a product to indicate how strongly activity is associated with risk.

Avoid the dangerous assumption

The dangerous assumption is that a risk score is an objective measurement of guilt, compromise or harm.

It is not.

The score may combine several factors, such as unusual location, device reputation, failed logins, threat-intelligence matches, impossible travel, malware detections, privilege level, data sensitivity or behavioural anomalies.

Different products use different models, thresholds and labels. A score of 80 in one product may have no relationship to a score of 80 in another.

Some scores are calculated at event level. Others apply to a user, device, incident or organisation. Some change over time as new information is added.

Ask what entity the score relates to, which factors contributed, how the score is calculated, what time period it covers, whether the model changed, what threshold generated action and whether an analyst reviewed it.

The score may help prioritise enquiries and identify related events. It may also explain why an organisation escalated or contained activity.

It does not replace the underlying evidence.

A high score can be created by several weak signals. A low score can occur where serious activity was not visible to the product.

Avoid reporting that a person was “80 per cent likely” to be an offender unless the product genuinely supports that interpretation, which is unlikely.

Describe the score as a product assessment and state the factors that matter to the investigation.

Operational takeaway

Use risk scores for prioritisation and context, but base evidential conclusions on the contributing events and the product’s actual scoring method.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.