QS-WAN · Security dashboard

Risk scoring you can read line by line

Risk scoring in QS-WAN is built from 19 drivers of equal weight, roughly 5.26 points each. Three are posture, eight are findings and eight are pressure. The score lands in one of four bands, and the console shows which drivers moved it. Company risk is an average, never a sum.

What it is

The problem is a number you cannot take apart

Security scores are cheap to produce and hard to defend. The number moves overnight, nobody can name what changed, and the honest answer to why is that the model decided it should. That holds up fine until somebody asks. An auditor asks. Your board asks, usually in the one meeting where you had a completely different slide ready. The platform calculates it sounds worse every time you say it out loud.

Posture, three drivers

How the network is configured, and what the defaults were left at. The slow-moving part of the number, and usually the part that is somebody decision rather than an event.

Findings, eight drivers

What the evidence turned up: scan results, configuration checks, assessment outcomes. This is the half you work through, and it is where a plan comes from.

Pressure, eight drivers

What is happening right now, or happened in the last few days. This is the half that moves overnight, and it is also the half that fades on its own.

The quieter half of the problem is that a number you cannot take apart is a number you cannot act on. A score that went up tells you nothing about what to fix on Monday.

The mechanism

Light the drivers, count them, and get the same number we did

That is a low bar, and most scores do not clear it. Then press the Tuesday burst and wait until Wednesday, and watch the pressure drain without anyone clearing anything.

Company risk 19 drivers, equal weight, about 5.26 points each Posture3 driversFindings8 driversPressure8 drivers 0 out of 100 low 70 critical · 40 elevated 15 guarded · under 15 low
0 drivers lit. Count them and you get the same number.

The score is built from nineteen drivers of equal weight, about 5.26 points each: three posture, eight findings and eight pressure. Each driver is scaled by how close it sits to its own saturation point, which is where more of the same bad thing stops making the score meaningfully worse. Pressure drivers decay exponentially with a time constant of about seven hours across a three-day window, so a burst of alerts on Tuesday has mostly drained away by Wednesday without anyone clearing or acknowledging anything. The bands are published: 70 and above is critical, 40 to 70 is elevated, 15 to 40 is guarded and under 15 is low. Company risk is an average, never a sum.

Why this exists

Four things that go wrong without it

Nobody can name what changed overnight

A score that moves without an explanation is a score you have to defend in a meeting with nothing but the vendor word for it.

A hidden coefficient makes the demo look better

Weights nobody publishes are weights somebody tuned. Equal weight is not laziness, it is the thing that makes the arithmetic checkable.

A score that only climbs stops being read

Without decay it turns into a wall of red by the second week, and by month six nobody opens the page at all.

A colour is not something you can put in a runbook

Without published thresholds you cannot write escalate at elevated and have it mean the same thing to the person on shift as it does to you.

What you get

One number, and two people who can both defend it

The person who runs the network wants a list for Monday. The person who presents it wants a sentence that survives the follow-up question. Same 19 drivers, read two different ways.

For the network

You can rebuild the number by hand

Open the score, count the drivers that are lit, multiply by about 5.26. If it does not match, one of us is wrong and it is findable.

Monday has a list, not a mood

The findings drivers are the eight you can actually work through. The score going down is the receipt for having done it.

The noise clears itself

Pressure decays exponentially with a time constant of about seven hours across a three-day window. Nobody acknowledges anything to make a number go back down.

For the business

An answer that survives the question

Nineteen drivers, equal weight, published thresholds. That is a sentence you can finish in a board meeting without reaching for the vendor.

A threshold you can write into a process

Escalate at elevated means the same thing to everyone, because 40 is written down rather than interpreted from a colour.

Company risk is an average, not a sum

Adding a site does not make the company look worse by arithmetic alone, which is the failure mode that makes group scores useless.

How it works

Three steps, and all three are arithmetic

Nineteen drivers, each worth the same

About 5.26 points out of 100 each. No hidden coefficients, and no driver that quietly counts triple because it made a demo look better. Three are posture, eight are findings from monitoring and the assessments, and eight are pressure.

Each one is scaled by how saturated it is

A driver is scaled by how close it sits to its own saturation point, which is where more of the same bad thing stops making the score meaningfully worse. Fifty open findings is a genuinely bad week. The five hundredth does not tell you anything the fiftieth did not already say.

Pressure fades, and the band is published

Pressure drivers decay exponentially, with a time constant of about seven hours across a three-day window. The result lands in one of four bands whose thresholds are written down, so you can build a runbook on them instead of interpreting a colour.

Before you start

The score reads from what QS-WAN already collects, so there is nothing extra to install. What it is worth depends on how much of the estate the agent is on, which is the honest dependency rather than a hidden one.

In detail

The decay, and the four thresholds

Decay

Why the score relaxes when the noise stops

Pressure drivers decay exponentially, with a time constant of about seven hours, across a three-day window. In practice a burst of alerts on Tuesday morning pushes the score up hard, and by Wednesday almost all of that push has drained away on its own.

Nobody clears it. Nobody acknowledges anything to make a number go back down. This matters more than it sounds: a score that only ever climbs turns into a wall of red that people stop reading by the second week, and one that relaxes when the noise stops still means something in month six.

Bands

The four thresholds, written down

70 and above is critical. 40 to 70 is elevated. 15 to 40 is guarded. Under 15 is low.

Published thresholds are the difference between a score you can build a process on and a colour you have to interpret. You can write escalate at elevated into a runbook, hand it to somebody on shift, and it means the same thing to them as it does to you. Company risk across sites is an average rather than a sum, so adding a site does not make the group look worse by arithmetic alone.

Where this earns its place

Four mornings this changes

The board asks why the number moved

You open the score, name the drivers that lit, and the meeting moves on. That is the whole use case, and it is the one that comes up most.

A burst of alerts on a Tuesday morning

The score climbs, and by Wednesday it has mostly drained. Nobody spent the afternoon acknowledging things to make a dashboard look calmer.

Somebody wants escalate at elevated in a runbook

It is 40, it is written down, and the person on shift reads it the same way you do.

A second site joins the group

Company risk is an average, so the group number reflects the state of the estate rather than how many sites are in it.

Works better with

Where the drivers come from

Where most of the findings and pressure drivers come from. The score is a reading of that feed, not a separate opinion.

The same evidence, scored against frameworks instead of against risk. Two readings of one set of facts.

The per host checks behind the passed, failed and not applicable counts that several drivers read.

The exposure findings that arrive from outside rather than from the estate you can see.

What this does not do

The limits, because they are what make the rest believable

It is not a certification and not an assurance

A low score is our arithmetic on our evidence. It is not a signature from anybody, and no regulator has agreed that 14 is safe and 16 is not.

It only knows what the agent can see

A machine without the agent is not in the number. The score describes the estate you have instrumented, and how much of the estate that is remains your question to answer.

Equal weight is a choice, not a law of nature

We weigh the drivers equally because it makes the arithmetic checkable. Someone could argue a particular driver deserves more, and that argument is a real one. We would rather be checkable than subtly wrong.

It does not fix what it finds

The score names the drivers. Changing what is enforced on a machine happens in security policy management, and that stays your call.

Questions people ask

The ones that come up first

How is the risk score calculated?

From 19 drivers of equal weight, about 5.26 points each: three posture, eight findings and eight pressure. Each driver is scaled by how close it sits to its own saturation point. You can open the score, count the drivers that are lit, and arrive at the same number the console did.

Why do all the drivers weigh the same?

Because it makes the arithmetic checkable. Hidden coefficients are what turn a score into something you have to take on trust, and a number you cannot take apart is a number you cannot act on or defend.

Why does the score go down without me doing anything?

Pressure drivers decay exponentially, with a time constant of about seven hours across a three-day window. A burst of alerts on Tuesday has mostly drained by Wednesday. Nobody clears it and nobody acknowledges anything to make it happen.

What are the bands?

70 and above is critical, 40 to 70 is elevated, 15 to 40 is guarded, and under 15 is low. The thresholds are published so you can write them into a runbook rather than interpret a colour.

How is company risk calculated across sites?

As an average, never a sum. Adding a site does not make the company look worse by arithmetic alone, which is the failure mode that makes most group scores useless.

Does a low score mean we are compliant?

No. It is our arithmetic on our evidence, not a certification and not an assurance from anybody. Compliance is scored separately against frameworks, and neither number is a signature.

Bring the score you have now. We will take ours apart beside it.

An engineer, the console, and as long as you need. Pick any driver and ask what it reads from. It is free and there is nothing to sign.

Scroll to Top