TruRisk™ Scoring
Most security teams have more vulnerabilities than they can fix. The question is not which findings are severe; it is which ones put your business at risk right now.
Qualys TruRisk™ answers that question by combining two things that traditional severity scores keep separate: how dangerous a finding is in the real world, and how important the affected asset is to your organization. A critical vulnerability on an isolated test machine may matter less than a medium-severity one on an internet-facing production system. TruRisk™ scoring reflects that difference.
Why Severity Alone Is Not Enough
CVSS scores severity in a vacuum rather than risk. A CVSS score tells you how bad a vulnerability could be if an attacker exploited it under conditions that favor them completely. That is a technical severity rating, not a risk assessment — but most organizations use it as though it were one.
There are three things a CVSS score cannot see:
- Whether anyone is exploiting it. A vulnerability with a working exploit circulating today and one that no attacker has ever touched can carry the same CVSS score.
- Whether your controls already block the path. CVSS describes the vulnerability, not your environment. It cannot know that the affected service is disabled, or that an EDR agent stops the technique the exploit depends on.
- Whether the asset matters to you. The same vulnerability scores identically on a decommissioned lab machine and on the server that processes your payments.
Two practical problems follow from those blind spots:
- Too many criticals. Ranking by CVSS alone produces far more critical findings than any team can remediate, with no way to tell them apart.
- Missed risk. Vulnerabilities in the lower CVSS categories are still actively exploited. Severity does not tell you whether attackers are using something today.
What TruRisk™ Adds
TruRisk™ uses CVSS as one input and pairs it with the evidence it lacks.
| What CVSS cannot see | What TruRisk™ uses instead |
|---|---|
| Whether anyone is exploiting it | Whether a working exploit exists, whether the vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, whether malware or ransomware campaigns use it, whether known threat actors are active against it, and the probability of exploitation predicted by EPSS — drawn from Qualys threat intelligence (TruLens). |
| Whether your controls already block the path | Exploitability confirmed against the asset as it is actually configured (TruConfirm), and the compensating and mitigating controls you have in place, which lower the score for that finding on that asset. |
| Whether the asset matters to you | The Asset Criticality Score you assign through tags, together with exposure factors such as whether the asset is internet-facing. |
The result is a score that answers a different question from CVSS. Not "how severe could this be," but "how likely is this to be used against something I cannot afford to lose."
TruRisk™ uses CVSS as one input among many. It also weighs evidence of what is actually happening: whether a working exploit exists, whether the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog, whether malware or ransomware campaigns use it, whether known threat actors are active against it, and the probability of exploitation predicted by EPSS. Business context then shapes the result, so the findings that rise to the top are the ones most likely to be exploited on the systems that matter most to you.
Risk Is Measured at Four Levels
Asset, Finding, Business Entity, and organization are layers of aggregation rather than separate scoring systems. Each layer builds on the one below it, so you can move from an organization-wide number down to the individual finding driving it. The scores themselves — QVS, QDS, QVSS, and TruRisk™ — are described in The Scores You See.
| Level | What the score tells you | Score at this level |
|---|---|---|
| Asset | How much risk this asset carries, given its findings, how exposed it is, and how important it is to your business. | TruRisk™ Score |
| Finding | How dangerous is this vulnerability or misconfiguration, taking real-world attacker activity into account. | QVS, QDS, QVSS |
| Business Entity | How much risk a part of your business carries, a department, an application, a platform, and whether it sits within the risk appetite you set for it. | Aggregated TruRisk™ Score |
| Organization | How your organization’s overall risk position is determined and how it has changed over time. | Aggregated TruRisk™ Score |
Every finding is scored using the same model and the same threat intelligence, whatever produced it. Vulnerabilities and misconfigurations from Qualys sensors and from third-party tools you connect can therefore be compared and prioritized across your entire environment, without translating between scoring systems.
Which TruRisk™ Model Applies to You
The model that calculates your TruRisk™ scores depends on your subscription.
| Your subscription | Asset score | Tag and Business Entity score |
|---|---|---|
| VMDR only (also CSAM) | TruRisk™ 1.0 | Platform v1 |
| ETM enabled | TruRisk™ 2.0 (turns on automatically, in all Qualys applications) | Platform v1 |
Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.
The Scores You See
| Score | Scale | What it measures |
|---|---|---|
| QVS Qualys Vulnerability Score |
1 – 100 | The inherent risk of a specific CVE, based on Qualys threat intelligence. |
| QDS Qualys Detection Score |
1 – 100 | The risk of a specific finding on your asset, adjusted for the controls you have in place. |
| QVSS Qualys Vulnerability Scoring System |
0.0 – 10.0 | The same intelligence expressed on a familiar CVSS-style scale, so severity is easy to read and communicate. |
| ACS Asset Criticality Score |
1 – 5 | How important an asset is to your business. ACS brings business impact into the scoring model: assets with a higher ACS contribute more heavily to the TruRisk™ calculation, so risk on the systems you depend on outweighs the same risk on systems you do not. You set this yourself, using tags. |
| TruRisk™ Score (asset) |
0 – 1000 | The calculated risk of a single asset, combining the scores of the findings on that asset with its Asset Criticality Score. It is calculated with TruRisk™ 1.0 or TruRisk™ 2.0, depending on your subscription. |
| Aggregated TruRisk™ Score (tag, Business Entity, organization) |
0 – 1000 | The combined risk of a group of assets. Individual asset TruRisk™ scores are rolled up to produce a score at the tag, Business Entity, or organization level. |
Both TruRisk™ scores use the same 0 – 1000 scale, so an asset score and a Business Entity score can be read the same way. What differs is how many assets the score covers.
How These Compare with CVSS
Let us see how the Qualys scoring system compares to CVSS
| Does the score account for | CVSS Industry standard |
QVS | QDS | QVSS | TruRisk™ Score |
|---|---|---|---|---|---|
| Technical severity of the vulnerability | Yes | Yes, as one input | Yes | Yes | Yes |
| Real-world exploitation activity KEV, EPSS, malware, threat actors |
No | Yes | Yes | Yes | Yes |
| Controls you have in place | No | No | Yes | Yes | Yes |
| Business importance of the asset | No | No | No | Yes, through environmental adjustments | Yes, through the Asset Criticality Score |
| Change as threat intelligence changes | No, the base score is fixed at publication | Yes | Yes | Yes | Yes |
The last three rows are where prioritization is won or lost. CVSS answers only the first question, and answers it once. The Qualys scores keep answering as your environment and the threat landscape change.
CVSS is not discarded. It is an input to QVS, and it remains visible on finding details so you can see the industry severity and the Qualys score side by side. For a worked example of a medium-severity CVE that becomes a critical finding, see Finding-Level Scores: QVS, QDS, and QVSS.
What You Can Control
TruRisk™ is not a fixed number handed to you. These are things you configure to shape the result:
- Asset criticality
Tag your assets so that the score reflects what each one is actually worth to your business. Because a higher ACS gives an asset more weight in the TruRisk™ calculation, criticality is what makes the difference between a finding on a test machine and the same finding on a production system. Assets without a criticality score are assigned a default criticality of 2, so setting this deliberately makes prioritization far more accurate.
- Risk appetite
Set the score your organization is willing to accept for each Business Entity. Comparing the score against that threshold turns a number into a decision about where to act.
-
TruRisk™ Customization
Set a customizable rule that adjusts the TruRisk™ score of an asset based on specific conditions without changing the raw security data itself. This aligns security scoring with business priorities and risk appetite. Learn more
Scores Stay Updated
TruRisk™ scores are recalculated automatically as new findings are ingested and as you remediate existing ones. Your score reflects what you fix, not just what you find. Threat intelligence also changes over time, so the score for a finding can rise when attackers begin exploiting it, or fall when you apply a control that reduces its risk on that asset.
Explore the Scoring Model
The following topics explain each part of the model in detail.
| Topic | What it covers |
|---|---|
| Finding-Level Scores: QVS, QDS, and QVSS | How the three finding-level scores relate, the threat signals behind them, and how a medium-severity CVE can become a critical finding when attackers start using it. |
| Asset Criticality Score | How to assign criticality using static and dynamic tags, asset groups, CMDB integration, or the API — including tagging rules that adjust criticality automatically as your estate changes. |
| TruRisk™ Score for Assets | How an asset's score is calculated, what raises and lowers it, and how exposure and finding volume are taken into account. |
| TruRisk™ Score for Tags and Business Entities | How asset scores roll up to a Business Entity, how to define entities using tags, and how risk appetite is applied. |
| Exploitability and Exposure Metrics | How to measure the race between attacker and defender, using the Window of Weaponization, Average Window of Exposure, and Remediation Efficiency Gap. |
Where to Start
Business context is what turns a severity score into a risk score, and that context has to come from a source you trust. Work in this order.
- Sync your CMDB.
Where a CMDB is available, it is the most reliable source of the business criticality that drives asset criticality placement. Get the sync current and accurate before you tune anything else, so criticality reflects what the business has already recorded about each asset rather than a judgment made in the console. If you do not have a CMDB to sync, set criticality with static and dynamic tags instead.
- Let asset criticality follow from it.
Map the business criticality held in your CMDB to the Asset Criticality Score, so business context flows into every score beneath it. Assets you never set are scored at the default criticality of 2, which is why an accurate source matters more than the tagging method you choose.
- Define your business entities around business needs.
Build entities that match how your organization is actually structured and funded, a department, an application, a platform, so risk is reported to the people who can act on it.
- Set a risk appetite for each entity.
Comparing an entity score against the threshold you set turns a number you observe into a decision about where to act.
- Prioritize by TruRisk™ score.
Rank by risk rather than by severity counts, and track the reduction over time.
The order matters because each step feeds the next. Once criticality is grounded in the CMDB and entities are built around business needs, everything else falls under assets whose business value is already known: threat intelligence from TruLens, confirmed exploitability from TruConfirm, the coverage your deployed agents provide, and the environmental factors of your own estate. That combination is what makes the resulting priority list worth acting on.
Related Topics
Finding-Level Scores: QVS, QDS, and QVSS
TruRisk™ Score for Tags and Business Entities
TruRisk™ Scoring: Consolidated Formula Reference