>> All posts

What a BreachRisk Score is (and isn't)

Every serious security program eventually gets asked for the number. Boards want it. Insurers want something like it. CISOs want a way to show trajectory without a 60-page appendix.

The BreachRisk Score is our answer to that ask. It only works if everyone knows what it is — and what it is not.

What it is

A measurement / estimate of breach risk for the organization (or scope) you assessed — rolled up from continuous outside-in discovery, assessment, and attacker-emulated verification of what's actually exploitable.

In practice that means:

  • One primary number you can compare and trend over time
  • Breakdown by risk pillars (how the score is composed across the surfaces you test — perimeter, and where in scope, social, cloud, exposure)
  • Driven by findings that matter to break-in, not by a collage of soft perimeter trivia

It answers a leadership-friendly version of: how exposed are we to a real breach path right now, and is that getting better or worse?

What it isn't

Not a guarantee. A score is a measurement based on testing at a point in time (and on a recurring cadence). It is not a warranty that you won't be breached, and it isn't a claim that you are "secure."

Not a CVSS average. Averaging CVE severities would recreate the "Critical ≠ our risk" problem. The score is about organizational breach risk from verified exposure — not a digest of the NVD.

Not a security-rating letter grade. Ratings-style products estimate from outside-in signals. Useful as a conversation starter; different from proving intrusion paths. We are in the proof / measurement lane.

Not a compliance certification. Mapping findings to control language can support audit evidence. The score itself does not mean you "passed" SOC 2, PCI, HIPAA, ISO, or anything else.

Not a substitute for judgment. It ranks and trends. You still decide spend, accept risk, and sequence work.

How to say it out loud (without overselling)

Good: "Our BreachRisk Score is a continuous measurement of breach risk from what we can verify on the tested surface. Here's the trend and the top paths behind it."

Bad: "The score means we can't be breached" / "We're a 4.2 so we're safe" / "This replaces our auditor."

Precision builds trust. Hype burns it — especially with boards and underwriters who've heard every vendor promise in the catalog.

Why one number still helps

Security work is detailed. Leadership attention is not. A single, honest score — paired with a short list of verified paths and a trend — lets you move the conversation from "we have hundreds of highs" to "here's what drives our breach risk and what we fixed since last time."

That is the job. Measurement you can act on — not theater, not a guarantee.

See your cyber risk, proven.