Risk Scoring

Getting Started with Security Scoring

Getting Started with Security Scoring

Where to Find It

URL: /dev/org-control/risk-configuration

How to get there:

  1. Go to Organisation Control in the left sidebar
  2. Click Risk Configuration

This opens the Risk Configuration page, which has five tabs at the top:

Tab What It's For
Dashboard View your organization's security score, module scores, history charts, and risk signals
Modules See which scoring modules are enabled and adjust their weights
Formulas View or edit the mathematical formulas used to calculate scores (advanced)
Rules Create rules that automatically boost risk when specific conditions are met
Documentation Built-in reference documentation

First Time Setup

If scoring has never been run for your organization, the Dashboard tab will show an "Enable AI Scoring" button. Clicking it opens the Quick Setup Wizard which walks you through:

  1. Selecting which modules to enable (ASM, Brand Protection, Detection)
  2. Setting module weights (how much each module affects the overall score)
  3. Running the first score computation

You can also trigger a score computation at any time by clicking the "Run Scoring" button in the top-right corner.


What Are the Modules?

The system scores your organization across three security areas:

Module Short Name What It Measures
Attack Surface Management ASM Vulnerabilities, exposed ports, subdomains — your infrastructure risk
Brand Protection BP Phishing sites, dark web mentions, leaked credentials — brand abuse
General Detection DETECTION Unclassified detections still awaiting triage

Each module gets its own score from 0 to 100. These are combined into one overall score based on the weights you assign.


Understanding the Score

  • 100 = Excellent — no detected risk
  • 70–99 = Good — low risk, some items to address
  • 40–69 = Fair — moderate risk, action recommended
  • 1–39 = Needs Attention — high risk, prioritize remediation
  • 0 = Critical — maximum detected risk (very rare)

Higher is better. The score improves when you resolve detections and gets worse when new threats appear.