What a risk score represents
Every finding in the CyberNova Attack Surface Monitoring platform is assigned a risk score, not just a severity label. The score combines exploitability — how easily an attacker could act on the exposure — with business impact, so your team can triage in the order that actually matters.
How the score is built
- Exploitability: is this exposed to the internet, does it have a known vulnerability, is exploit code publicly available
- Asset context: is this asset production-facing, does it handle customer data
- Change signal: is this a new exposure since the last scan, or a long-standing one that has already been risk-accepted
Reading the dashboard
Findings are grouped into Critical, High, Medium, and Low bands. Critical and High findings are the ones an attacker running the same outside-in reconnaissance would find first, and are the recommended starting point for any remediation sprint.
Why the score changes over time
A finding’s score can shift without any change on your side — for example, if a vulnerability affecting an exposed service gets a public exploit released, its exploitability score rises. This is why continuous scanning matters more than a one-time assessment.
Acting on a finding
Each finding links to a remediation playbook with the specific steps to close it, written for the engineer who has to fix it rather than the auditor who has to report it. Findings can also be pushed directly into Splunk, Microsoft Sentinel, Jira, or ServiceNow.