TruRisk™ Scoring

Most security teams have more vulnerabilities than they can fix. The question is not which findings are severe; it is which ones put your business at risk right now.

Qualys TruRisk™ answers that question by combining two things that traditional severity scores keep separate: how dangerous a finding is in the real world, and how important the affected asset is to your organization. A critical vulnerability on an isolated test machine may matter less than a medium-severity one on an internet-facing production system. TruRisk™ scoring reflects that difference.

Why Severity Alone Is Not Enough

CVSS scores severity in a vacuum rather than risk. A CVSS score tells you how bad a vulnerability could be if an attacker exploited it under conditions that favor them completely. That is a technical severity rating, not a risk assessment — but most organizations use it as though it were one.

There are three things a CVSS score cannot see:

  • Whether anyone is exploiting it. A vulnerability with a working exploit circulating today and one that no attacker has ever touched can carry the same CVSS score.
  • Whether your controls already block the path. CVSS describes the vulnerability, not your environment. It cannot know that the affected service is disabled, or that an EDR agent stops the technique the exploit depends on.
  • Whether the asset matters to you. The same vulnerability scores identically on a decommissioned lab machine and on the server that processes your payments.

Two practical problems follow from those blind spots:

  • Too many criticals. Ranking by CVSS alone produces far more critical findings than any team can remediate, with no way to tell them apart.
  • Missed risk. Vulnerabilities in the lower CVSS categories are still actively exploited. Severity does not tell you whether attackers are using something today.

What TruRisk™ Adds

TruRisk™ uses CVSS as one input and pairs it with the evidence it lacks.

What CVSS cannot see What TruRisk™ uses instead
Whether anyone is exploiting it Whether a working exploit exists, whether the vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, whether malware or ransomware campaigns use it, whether known threat actors are active against it, and the probability of exploitation predicted by EPSS — drawn from Qualys threat intelligence (TruLens).
Whether your controls already block the path Exploitability confirmed against the asset as it is actually configured (TruConfirm), and the compensating and mitigating controls you have in place, which lower the score for that finding on that asset.
Whether the asset matters to you The Asset Criticality Score you assign through tags, together with exposure factors such as whether the asset is internet-facing.

The result is a score that answers a different question from CVSS. Not "how severe could this be," but "how likely is this to be used against something I cannot afford to lose."

TruRisk™ uses CVSS as one input among many. It also weighs evidence of what is actually happening: whether a working exploit exists, whether the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog, whether malware or ransomware campaigns use it, whether known threat actors are active against it, and the probability of exploitation predicted by EPSS. Business context then shapes the result, so the findings that rise to the top are the ones most likely to be exploited on the systems that matter most to you.

Risk Is Measured at Four Levels

Asset, Finding, Business Entity, and organization are layers of aggregation rather than separate scoring systems. Each layer builds on the one below it, so you can move from an organization-wide number down to the individual finding driving it. The scores themselves — QVS, QDS, QVSS, and TruRisk™ — are described in The Scores You See.

Level What the score tells you Score at this level
Asset How much risk this asset carries, given its findings, how exposed it is, and how important it is to your business. TruRisk™ Score
Finding How dangerous is this vulnerability or misconfiguration, taking real-world attacker activity into account. QVS, QDS, QVSS
Business Entity How much risk a part of your business carries, a department, an application, a platform, and whether it sits within the risk appetite you set for it. Aggregated TruRisk™ Score
Organization How your organization’s overall risk position is determined and how it has changed over time. Aggregated TruRisk™ Score

Every finding is scored using the same model and the same threat intelligence, whatever produced it. Vulnerabilities and misconfigurations from Qualys sensors and from third-party tools you connect can therefore be compared and prioritized across your entire environment, without translating between scoring systems.

Which TruRisk™ Model Applies to You

The model that calculates your TruRisk™ scores depends on your subscription.

Your subscription Asset score Tag and Business Entity score
VMDR only (also CSAM) TruRisk™ 1.0 Platform v1
ETM enabled TruRisk™ 2.0 (turns on automatically, in all Qualys applications) Platform v1

Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.

The Scores You See

Score Scale What it measures
QVS
Qualys Vulnerability Score
1 – 100 The inherent risk of a specific CVE, based on Qualys threat intelligence.
QDS
Qualys Detection Score
1 – 100 The risk of a specific finding on your asset, adjusted for the controls you have in place.
QVSS
Qualys Vulnerability Scoring System
0.0 – 10.0 The same intelligence expressed on a familiar CVSS-style scale, so severity is easy to read and communicate.
ACS
Asset Criticality Score
1 – 5 How important an asset is to your business. ACS brings business impact into the scoring model: assets with a higher ACS contribute more heavily to the TruRisk™ calculation, so risk on the systems you depend on outweighs the same risk on systems you do not. You set this yourself, using tags.
TruRisk™ Score
(asset)
0 – 1000 The calculated risk of a single asset, combining the scores of the findings on that asset with its Asset Criticality Score. It is calculated with TruRisk™ 1.0 or TruRisk™ 2.0, depending on your subscription.
Aggregated TruRisk™ Score
(tag, Business Entity, organization)
0 – 1000 The combined risk of a group of assets. Individual asset TruRisk™ scores are rolled up to produce a score at the tag, Business Entity, or organization level.

Both TruRisk™ scores use the same 0 – 1000 scale, so an asset score and a Business Entity score can be read the same way. What differs is how many assets the score covers.

How These Compare with CVSS

Let us see how the Qualys scoring system compares to CVSS

Does the score account for CVSS
Industry standard
QVS QDS QVSS TruRisk™ Score
Technical severity of the vulnerability Yes Yes, as one input Yes Yes Yes
Real-world exploitation activity
KEV, EPSS, malware, threat actors
No Yes Yes Yes Yes
Controls you have in place No No Yes Yes Yes
Business importance of the asset No No No Yes, through environmental adjustments Yes, through the Asset Criticality Score
Change as threat intelligence changes No, the base score is fixed at publication Yes Yes Yes Yes

The last three rows are where prioritization is won or lost. CVSS answers only the first question, and answers it once. The Qualys scores keep answering as your environment and the threat landscape change.

CVSS is not discarded. It is an input to QVS, and it remains visible on finding details so you can see the industry severity and the Qualys score side by side. For a worked example of a medium-severity CVE that becomes a critical finding, see Finding-Level Scores: QVS, QDS, and QVSS.

What You Can Control

TruRisk™ is not a fixed number handed to you. These are things you configure to shape the result:

  • Asset criticality

    Tag your assets so that the score reflects what each one is actually worth to your business. Because a higher ACS gives an asset more weight in the TruRisk™ calculation, criticality is what makes the difference between a finding on a test machine and the same finding on a production system. Assets without a criticality score are assigned a default criticality of 2, so setting this deliberately makes prioritization far more accurate.

  • Risk appetite

    Set the score your organization is willing to accept for each Business Entity. Comparing the score against that threshold turns a number into a decision about where to act.

  • TruRisk™ Customization

    Set a customizable rule that adjusts the TruRisk™ score of an asset based on specific conditions without changing the raw security data itself. This aligns security scoring with business priorities and risk appetite. Learn more

Scores Stay Updated

TruRisk™ scores are recalculated automatically as new findings are ingested and as you remediate existing ones. Your score reflects what you fix, not just what you find. Threat intelligence also changes over time, so the score for a finding can rise when attackers begin exploiting it, or fall when you apply a control that reduces its risk on that asset.

Explore the Scoring Model

The following topics explain each part of the model in detail.

Topic What it covers
Finding-Level Scores: QVS, QDS, and QVSS How the three finding-level scores relate, the threat signals behind them, and how a medium-severity CVE can become a critical finding when attackers start using it.
Asset Criticality Score How to assign criticality using static and dynamic tags, asset groups, CMDB integration, or the API — including tagging rules that adjust criticality automatically as your estate changes.
TruRisk™ Score for Assets How an asset's score is calculated, what raises and lowers it, and how exposure and finding volume are taken into account.
TruRisk™ Score for Tags and Business Entities How asset scores roll up to a Business Entity, how to define entities using tags, and how risk appetite is applied.
Exploitability and Exposure Metrics How to measure the race between attacker and defender, using the Window of Weaponization, Average Window of Exposure, and Remediation Efficiency Gap.

Where to Start

Business context is what turns a severity score into a risk score, and that context has to come from a source you trust. Work in this order.

  1. Sync your CMDB.

    Where a CMDB is available, it is the most reliable source of the business criticality that drives asset criticality placement. Get the sync current and accurate before you tune anything else, so criticality reflects what the business has already recorded about each asset rather than a judgment made in the console. If you do not have a CMDB to sync, set criticality with static and dynamic tags instead.

  2. Let asset criticality follow from it.

    Map the business criticality held in your CMDB to the Asset Criticality Score, so business context flows into every score beneath it. Assets you never set are scored at the default criticality of 2, which is why an accurate source matters more than the tagging method you choose.

  3. Define your business entities around business needs.

    Build entities that match how your organization is actually structured and funded, a department, an application, a platform, so risk is reported to the people who can act on it.

  4. Set a risk appetite for each entity.

    Comparing an entity score against the threshold you set turns a number you observe into a decision about where to act.

  5. Prioritize by TruRisk™ score.

    Rank by risk rather than by severity counts, and track the reduction over time.

The order matters because each step feeds the next. Once criticality is grounded in the CMDB and entities are built around business needs, everything else falls under assets whose business value is already known: threat intelligence from TruLens, confirmed exploitability from TruConfirm, the coverage your deployed agents provide, and the environmental factors of your own estate. That combination is what makes the resulting priority list worth acting on.

Related Topics

Finding-Level Scores: QVS, QDS, and QVSS

TruRisk™ Score for Assets

TruRisk™ Score for Tags and Business Entities

TruRisk™ Scoring: Consolidated Formula Reference