The Risk Scores are graded as below:

The Company Score is the sum of Vulnerability, External Vulnerability, Compliance, Security Report Card & Active Directory.

Company Risk Score Grade: A ( 0 - 40 ): Very Low

Company Risk Score Grade: B ( 40 - 45 ): Low

Company Risk Score Grade: C ( 45 - 60 ): Medium

Company Risk Score Grade : D ( 60 - 75 ): High

Company Risk Score Grade: E ( 75 - 90 ): Critical

Company Risk Score Grade: F ( 90 - 100 ): Very Critical

(blue star) Risk Score Grade: A (0 - 40):
  A represents Very Low (Issues are present and an organization should aim to be in the 0-40 range, however broadly all significant issues have been taken care of).

(blue star) Risk Score Grade: B (40 - 45):
  B represents Low (Issues are present and the value ranges from 40-45, however, significant issues have been taken care of).

(blue star) Risk Score Grade: C (45 - 60):
  C represents Medium (A small number of issues that need immediate attention and the value ranges from 45-60).

(blue star) Risk Score Grade: D (60 - 75):
  D represents High (Significant number of issues that require attention and the value ranges from 60-75).

(blue star) Risk Score Grade: E (75 - 90):
  E represents Critical (The network is susceptible to attack and needs remediation to be performed on a war footing and the value ranges from 75-90).

(blue star) Risk Score Grade: F (90 - 100):
  F represents Very Critical (The network is highly susceptible to attack and needs remediation to be performed on a war footing and the value ranges from 90-100).

Calculation of Vulnerability Risk:

(blue star) CyberCNS uses CVSS 3.0 as a base system for the calculation of vulnerability risk.

CVSS Base score 50 percent.
CVSS Exploitability Score 20 percent.
Asset Importance Score 10 percent.
Impact based on actual malware being released 10 per cent.
Impact score 10 percent.

For example,

=>(Vulnerability Maximum BaseScore * 5) + (Vulnerability Maximum exploitabilityScore * 2) + (Asset Importance / 10) * 3

Asset Importance values for severity:

Critical -100

High - 75

Medium - 50

Low - 25

=>(9.8 * 5) + (3.9 * 2) + (25 / 10) * 3

=>49 + 7.8 + 7.5

=>64.3

CyberCNS Vulnerability Risk Score is 64.3

How to Improve the Risk Grade of any asset:

Please act on the recommendations provided in the Remediation Plan.

HeatMap ( Graphical representation)

(blue star) Green represents Low (Issues are present and an organisation should aim to be in the 0-50 range however broadly all significant issues have been taken care of).

(blue star) Yellow represents Medium (A small number of issues that need immediate attention and the value ranges from 50-70).

(blue star) Orange represents a High (Significant number of issues that require attention and the value ranges from 70-85).

(blue star) Red represents Critical (The network is susceptible to attack and needs remediation to be performed on a war footing and the value ranges from 85-100).