Getting Started with Security Scoring
Getting Started with Security Scoring
Where to Find It
URL: /dev/org-control/risk-configuration
How to get there:
- Go to Organisation Control in the left sidebar
- Click Risk Configuration
This opens the Risk Configuration page, which has five tabs at the top:
| Tab | What It's For |
|---|---|
| Dashboard | View your organization's security score, module scores, history charts, and risk signals |
| Modules | See which scoring modules are enabled and adjust their weights |
| Formulas | View or edit the mathematical formulas used to calculate scores (advanced) |
| Rules | Create rules that automatically boost risk when specific conditions are met |
| Documentation | Built-in reference documentation |
First Time Setup
If scoring has never been run for your organization, the Dashboard tab will show an "Enable AI Scoring" button. Clicking it opens the Quick Setup Wizard which walks you through:
- Selecting which modules to enable (ASM, Brand Protection, Detection)
- Setting module weights (how much each module affects the overall score)
- Running the first score computation
You can also trigger a score computation at any time by clicking the "Run Scoring" button in the top-right corner.
What Are the Modules?
The system scores your organization across three security areas:
| Module | Short Name | What It Measures |
|---|---|---|
| Attack Surface Management | ASM | Vulnerabilities, exposed ports, subdomains — your infrastructure risk |
| Brand Protection | BP | Phishing sites, dark web mentions, leaked credentials — brand abuse |
| General Detection | DETECTION | Unclassified detections still awaiting triage |
Each module gets its own score from 0 to 100. These are combined into one overall score based on the weights you assign.
Understanding the Score
- 100 = Excellent — no detected risk
- 70–99 = Good — low risk, some items to address
- 40–69 = Fair — moderate risk, action recommended
- 1–39 = Needs Attention — high risk, prioritize remediation
- 0 = Critical — maximum detected risk (very rare)
Higher is better. The score improves when you resolve detections and gets worse when new threats appear.