What is a risk score?¶
A risk score is a value assigned by a system to indicate how strongly available information matches configured risk factors.
It may be expressed as a number, percentage, category or label such as low, medium or high.
Avoid the dangerous assumption¶
The dangerous assumption is that a risk score is an objective measurement of guilt, maliciousness or probability.
It is not.
The score is produced by a model, rule set or vendor method. It may consider device familiarity, IP reputation, impossible travel, threat intelligence, account behaviour, authentication method and other signals.
A high score can help prioritise investigation. But the calculation may combine uncertain or inferred data. Several weak signals can produce a high result, while a sophisticated attacker may generate a low one.
Investigators should ask what inputs contributed to the score, how they were weighted and what the score was designed to predict. Establish whether the value was calculated at event time or updated later.
The same numeric value may mean different things in different products. A score of 80 is not automatically an 80 percent chance that an incident occurred.
Preserve the component signals, source events, model or rule version and any analyst explanation. Examine each significant input independently, particularly where it affects attribution or location.
Use the score to guide enquiries, not replace them. Reporting should state that the platform assigned the score and identify the known basis and limitations.
Operational takeaway¶
A risk score is a system-generated prioritisation based on selected signals, so investigators must examine the contributing evidence rather than treating the number as proof or a measured probability.