TruRisk™ Score for Assets
An asset's TruRisk™ score answers one question: how much risk does this machine carry right now? It combines the findings on the asset with its exposure and importance to your business, and expresses the result on a 0–1000 scale.
Two formulas produce that score. TruRisk™ 1.0 is the model used by a VMDR-only subscription, and it also applies to CSAM. TruRisk™ 2.0 comes with ETM and applies automatically once ETM is enabled. The difference between them is not cosmetic, and the example below shows why it matters before we get to the formulas themselves.
Which TruRisk™ Model Applies to You
The model that calculates your TruRisk™ scores depends on your subscription.
| Your subscription | Asset score | Tag and Business Entity score |
|---|---|---|
| VMDR only (also CSAM) | TruRisk™ 1.0 | Platform v1 |
| ETM enabled | TruRisk™ 2.0 (turns on automatically, in all Qualys applications) | Platform v1 |
Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.
This page covers scoring for a single asset. For how asset scores roll up into tags, Business Entities, and an organization-wide number, see TruRisk™ Score for Tags and Business Entities.
Why Averaging Hides Your Worst Finding
Consider two production assets. Both carry ten critical detections. Both have the same asset criticality and neither is internet-facing. In terms of findings count, they are identical.
| Asset | Critical detections | Detection scores | What is actually there |
|---|---|---|---|
| Asset A | 10 | All ten at 90 | Ten serious vulnerabilities, none with a public exploit |
| Asset B | 10 | One at 100, nine at 90 | The same nine, plus one weaponized vulnerability listed in CISA KEV and used in ransomware campaigns |
Asset B is the one an attacker can compromise today. Now look at what each model sees.
| Model | What it takes from the critical detections | Asset A | Asset B | Separation |
|---|---|---|---|---|
| TruRisk™ 1.0 | Average of the scores in the critical bin | 90.0 | 91.0 | 1 point |
| TruRisk™ 2.0 | Maximum score in the bin, amplified by g and multiplied by criticality | 90 × 1.3 = 117 | 100 × 1.3 = 130 | 13 points, before the criticality multiplier scales it further |
Averaging compresses the two assets into near-identical scores, and the compression worsens as the asset accumulates more moderate criticals: every additional detection at 90 pulls Asset B's average back toward 90, while the weaponized vulnerability at 100 remains. A model built on the maximum does the opposite. The worst finding sets the floor, and the count of findings adds to it rather than washing it out.
This is the core change from 1.0 to 2.0. Everything else in the two formulas follows from it.
How the Two Models Compare
| Aspect | TruRisk™ 1.0 | TruRisk™ 2.0 |
|---|---|---|
| Used by | VMDR-only subscriptions; also applies to CSAM | ETM subscriptions |
| Aggregation method | Average of scores per severity bin, damped by count | Maximum score, plus weighted counts per severity bin |
| Input score | QDS for managed assets; QVS for externally exposed unmanaged assets | QDS (MaxDetectionScore, range 1 – 100) |
| Business context | ACS multiplier; External × 1.2 | ACS multiplier; External × 1.2 |
| g value | Not used | g(MaxDetectionScore) — amplifies: 1.3 / 1.2 / 1.0 |
| Volume caps | None; count damped by a power function instead | Medium and Low counts capped at 2000 |
| How to enable | Default for VMDR | Automatic on ETM enablement; no action needed |
| Customizable | An alternative max-based variant exists on request | Using Risk and Compensatory Factors |
The Formulas
TruRisk™ 1.0 — Managed Asset
TruRisk™ Score = ACS *External * [(wc* Avg(QDSc) * func(count(QDSc))+
wh* Avg(QDSh) * func(count(QDSh))+
wm* Avg(QDSm) * func(count(QDSm))+
wl* Avg(QDSl) * func(count(QDSl))]
where,
- ACS: Asset Criticality Score
- w: Weighing factors fine-tuned by the Qualys TruRisk™ algorithm for each severity level [critical(c), high(h), medium(m), low(l)]. Where 1.0 is Critical, 0.6 is High, 0.4 is Medium, and 0.2 is Low.
- func(): Non-linear function that increases as the number of vulnerabilities increases.
- External: If an asset is external (internet-facing) or discoverable by Shodan, the score gets a 20% higher weight.
TruRisk™ 1.0 — Externally Exposed Unmanaged Asset
TruRisk™ Score = MIN((Asset exposure)*ACS*
(wc* Avg(QVSc)*func(count(QVSc)) +
wh* Avg(QVSh)*func(count(QVSh)) +
wm* Avg(QVSm)*func(count(QVSm)) +
wl* Avg(QVSl)*func(count(QVSl))),1000)
where,
- ACS: Asset Criticality Score
- w: Weighing factor for each severity level of QVS [critical(c), high(h), medium(m), low(l)]
- Avg(QVS): Average of the Qualys Vulnerability Score for each severity level of CVEs
Same shape as the managed formula, but built on QVS rather than QDS, because an unmanaged asset has no Qualys detections. This is the only formula in the set that takes QVS directly.
TruRisk™ 2.0 — Asset
The TruRisk™ Score is the overall risk score for an asset. Qualys calculates it for managed assets and for externally exposed, unmanaged assets found by External Attack Surface.
The score is based on these factors:
- Asset Criticality Score (ACS)
- Detection scores (shown as QVSS in the UI) for each severity level: Critical, High, Medium, and Low
- Weighting factors for each severity level, which Qualys assigns automatically
TruRisk™ Score = MIN({[ACS * External] * [MaxDetectionScore * g(MaxDetectionScore)]}
+ numCriticalDetections * WtCrit
+ numHighDetections * WtHigh
+ min(numMediumDetections,2000) * WtMed
+ min(numLowDetections,2000) * WtLow, 1000)
where,
- ACS: Asset Criticality Score
- External: 1.2 if the asset is internet-facing, 1.0 if internal
- MaxDetectionScore (MaxQVSS): Highest detection score among all detections on the asset (range 1 – 100)
- g(MaxDetectionScore): A multiplier that prioritizes higher-severity detections — 1.3 when critical detections are present, 1.2 for high, and 1.0 when only medium and low are present
- numCriticalDetections: Number of detections with a detection score of 90 – 100
- numHighDetections: Number of detections with a detection score of 70 – 89
- numMediumDetections: Number of detections with a detection score of 40 – 69
- numLowDetections: Number of detections with a detection score of 1 – 39
- WtCrit, WtHigh, WtMed, WtLow: Contributions from each severity category; current weights are 0.80, 0.15, 0.03, and 0.02 respectively
Medium and Low counts are capped at 2000 so that a large volume of minor findings cannot push the score disproportionately high.
The final score is capped at 1000.
TruRisk™ Score Range
The TruRisk™ Score ranges from 0 to 1000:
| Score | Risk Level |
|---|---|
| 850 – 1000 | Critical |
| 700 – 849 | High |
| 500 – 699 | Medium |
| 0 – 499 | Low |
Example
An internet-facing asset has these values:
- ACS: 5
- External: 1.2
- MaxDetectionScore: 100, with critical detections present, so g(MaxDetectionScore) is 1.3
- Detections: 56 Critical, 23 High, 112 Medium, and 1013 Low
TruRisk™ Score = MIN({[5 * 1.2] * [100 * 1.3]} + 56 * 0.80 + 23 * 0.15 + min(112,2000) * 0.03 + min(1013,2000) * 0.02, 1000)
= MIN(780 + 44.8 + 3.45 + 3.36 + 20.26, 1000)
= 852
This asset has a score of 852, so its risk level is Critical.
To see how the score is calculated for any asset, open the What is TruRisk™ Score? dialog in the UI. It shows the formula with that asset’s own values.
What Changes When You Enable ETM
| Area | Before ETM | After ETM |
|---|---|---|
| Asset formula | TruRisk™ 1.0 | TruRisk™ 2.0, across all Qualys applications |
| Findings view | QID-based | CVE-based in ETM; VMDR keeps its QID view |
| Displayed finding score | QDS | QVSS on the Vulnerabilities page; QDS still on Misconfiguration Details |
| Contributing-factor counts | By QID | By CVE in ETM, still by QID in VMDR — so the two products show different counts for the same subscription |
| APIs and integrations | — | Unchanged; ServiceNow and Jira integrations continue on QIDs |
Enabling ETM changes the asset formula only. The formula used to score tags and Business Entities stays on Platform v1 unless you request v2 from Qualys Support. See TruRisk™ Score for Tags and Business Entities.
Next
Now that you know how a single asset is scored, see how those scores roll up: TruRisk™ Score for Tags and Business Entities.
Related Topics
Finding-Level Scores: QVS, QDS, and QVSS