Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a security risk score?

A security risk score is a product’s way of combining signals into a numerical or categorical assessment of risk.

It can be useful for prioritisation.

It is not an objective percentage that tells you how guilty, compromised or harmful something is.

Find out what was actually scored

A risk score might apply to:

  • one login;
  • one account;
  • one device;
  • one incident;
  • one user;
  • one application.

And it may combine several factors:

SignalsLocation, device, failed logins, intelligenceObservable inputs.
ModelWeights and thresholdsProduct-specific logic.
ScoreHigh / 87 / CriticalA prioritisation output.

Two products may use completely different scoring systems.

Go back to the contributing events

If a score matters, capture:

  • the entity being scored;
  • contributing factors;
  • time period;
  • model or rule version;
  • threshold;
  • any analyst review;
  • changes to the score over time.

A high score may be built from several weak signals.

A low score may simply reflect poor visibility.

Use the score for what it does well

A score can explain:

  • why an alert was prioritised;
  • why a responder escalated;
  • why an account was challenged;
  • why an incident was opened.

But the evidential conclusion should still come from the underlying events.

The practical point is: treat a risk score as product context. Reconstruct the signals behind it before relying on what the score appears to imply.

Reference: CIM-023Cyber Incidents & Offender Methods