TruRisk™ Score for Assets

An asset's TruRisk™ score answers one question: how much risk does this machine carry right now? It combines the findings on the asset with its exposure and importance to your business, and expresses the result on a 0–1000 scale.

Two formulas produce that score. TruRisk™ 1.0 is the model used by a VMDR-only subscription, and it also applies to CSAM. TruRisk™ 2.0 comes with ETM and applies automatically once ETM is enabled. The difference between them is not cosmetic, and the example below shows why it matters before we get to the formulas themselves.

Which TruRisk™ Model Applies to You

The model that calculates your TruRisk™ scores depends on your subscription.

Your subscription Asset score Tag and Business Entity score
VMDR only (also CSAM) TruRisk™ 1.0 Platform v1
ETM enabled TruRisk™ 2.0 (turns on automatically, in all Qualys applications) Platform v1

Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.

This page covers scoring for a single asset. For how asset scores roll up into tags, Business Entities, and an organization-wide number, see TruRisk™ Score for Tags and Business Entities.

Why Averaging Hides Your Worst Finding

Consider two production assets. Both carry ten critical detections. Both have the same asset criticality and neither is internet-facing. In terms of findings count, they are identical.

Asset Critical detections Detection scores What is actually there
Asset A 10 All ten at 90 Ten serious vulnerabilities, none with a public exploit
Asset B 10 One at 100, nine at 90 The same nine, plus one weaponized vulnerability listed in CISA KEV and used in ransomware campaigns

Asset B is the one an attacker can compromise today. Now look at what each model sees.

Model What it takes from the critical detections Asset A Asset B Separation
TruRisk™ 1.0 Average of the scores in the critical bin 90.0 91.0 1 point
TruRisk™ 2.0 Maximum score in the bin, amplified by g and multiplied by criticality 90 × 1.3 = 117 100 × 1.3 = 130 13 points, before the criticality multiplier scales it further

Averaging compresses the two assets into near-identical scores, and the compression worsens as the asset accumulates more moderate criticals: every additional detection at 90 pulls Asset B's average back toward 90, while the weaponized vulnerability at 100 remains. A model built on the maximum does the opposite. The worst finding sets the floor, and the count of findings adds to it rather than washing it out.

This is the core change from 1.0 to 2.0. Everything else in the two formulas follows from it.

How the Two Models Compare

Aspect TruRisk™ 1.0 TruRisk™ 2.0
Used by VMDR-only subscriptions; also applies to CSAM ETM subscriptions 
Aggregation method Average of scores per severity bin, damped by count Maximum score, plus weighted counts per severity bin
Input score QDS for managed assets; QVS for externally exposed unmanaged assets QDS (MaxDetectionScore, range 1 – 100)
Business context ACS multiplier; External × 1.2 ACS multiplier; External × 1.2
g value Not used g(MaxDetectionScore) — amplifies: 1.3 / 1.2 / 1.0
Volume caps None; count damped by a power function instead Medium and Low counts capped at 2000
How to enable Default for VMDR Automatic on ETM enablement; no action needed
Customizable An alternative max-based variant exists on request Using Risk and Compensatory Factors

The Formulas

TruRisk™ 1.0 — Managed Asset

TruRisk™ Score = ACS *External * [(wc* Avg(QDSc) * func(count(QDSc))+

wh* Avg(QDSh) * func(count(QDSh))+

wm* Avg(QDSm) * func(count(QDSm))+

wl* Avg(QDSl) * func(count(QDSl))]

where,

  • ACS: Asset Criticality Score
  • w: Weighing factors fine-tuned by the Qualys TruRisk™ algorithm for each severity level [critical(c), high(h), medium(m), low(l)]. Where 1.0 is Critical, 0.6 is High, 0.4 is Medium, and 0.2 is Low.
  • func(): Non-linear function that increases as the number of vulnerabilities increases.
  • External: If an asset is external (internet-facing) or discoverable by Shodan, the score gets a 20% higher weight.

TruRisk™ 1.0 — Externally Exposed Unmanaged Asset

TruRisk™ Score = MIN((Asset exposure)*ACS*

(wc* Avg(QVSc)*func(count(QVSc)) +

wh* Avg(QVSh)*func(count(QVSh)) +

wm* Avg(QVSm)*func(count(QVSm)) +

wl* Avg(QVSl)*func(count(QVSl))),1000)

where,

  • ACS: Asset Criticality Score
  • w: Weighing factor for each severity level of QVS [critical(c), high(h), medium(m), low(l)]
  • Avg(QVS): Average of the Qualys Vulnerability Score for each severity level of CVEs

Same shape as the managed formula, but built on QVS rather than QDS, because an unmanaged asset has no Qualys detections. This is the only formula in the set that takes QVS directly.

TruRisk™ 2.0 — Asset

The TruRisk™ Score is the overall risk score for an asset. Qualys calculates it for managed assets and for externally exposed, unmanaged assets found by External Attack Surface.

The score is based on these factors:

  • Asset Criticality Score (ACS)
  • Detection scores (shown as QVSS in the UI) for each severity level: Critical, High, Medium, and Low
  • Weighting factors for each severity level, which Qualys assigns automatically

TruRisk™ Score = MIN({[ACS * External] * [MaxDetectionScore * g(MaxDetectionScore)]}

+ numCriticalDetections * WtCrit

+ numHighDetections * WtHigh

+ min(numMediumDetections,2000) * WtMed

+ min(numLowDetections,2000) * WtLow, 1000)

where,

  • ACS: Asset Criticality Score
  • External: 1.2 if the asset is internet-facing, 1.0 if internal
  • MaxDetectionScore (MaxQVSS): Highest detection score among all detections on the asset (range 1 – 100) 
  • g(MaxDetectionScore): A multiplier that prioritizes higher-severity detections — 1.3 when critical detections are present, 1.2 for high, and 1.0 when only medium and low are present
  • numCriticalDetections: Number of detections with a detection score of 90 – 100
  • numHighDetections: Number of detections with a detection score of 70 – 89
  • numMediumDetections: Number of detections with a detection score of 40 – 69
  • numLowDetections: Number of detections with a detection score of 1 – 39
  • WtCrit, WtHigh, WtMed, WtLow: Contributions from each severity category; current weights are 0.80, 0.15, 0.03, and 0.02 respectively

Medium and Low counts are capped at 2000 so that a large volume of minor findings cannot push the score disproportionately high.

The final score is capped at 1000.

TruRisk™ Score Range

The TruRisk™ Score ranges from 0 to 1000:

Score Risk Level
850 – 1000 Critical
700 – 849 High
500 – 699 Medium
0 – 499 Low

Example

An internet-facing asset has these values:

  • ACS: 5
  • External: 1.2
  • MaxDetectionScore: 100, with critical detections present, so g(MaxDetectionScore) is 1.3
  • Detections: 56 Critical, 23 High, 112 Medium, and 1013 Low

TruRisk™ Score = MIN({[5 * 1.2] * [100 * 1.3]} + 56 * 0.80 + 23 * 0.15 + min(112,2000) * 0.03 + min(1013,2000) * 0.02, 1000)

= MIN(780 + 44.8 + 3.45 + 3.36 + 20.26, 1000)

= 852

This asset has a score of 852, so its risk level is Critical.

To see how the score is calculated for any asset, open the What is TruRisk™ Score? dialog in the UI. It shows the formula with that asset’s own values.

What Changes When You Enable ETM

Area Before ETM After ETM
Asset formula TruRisk™ 1.0 TruRisk™ 2.0, across all Qualys applications
Findings view QID-based CVE-based in ETM; VMDR keeps its QID view
Displayed finding score QDS QVSS on the Vulnerabilities page; QDS still on Misconfiguration Details
Contributing-factor counts By QID By CVE in ETM, still by QID in VMDR — so the two products show different counts for the same subscription
APIs and integrations — Unchanged; ServiceNow and Jira integrations continue on QIDs

Enabling ETM changes the asset formula only. The formula used to score tags and Business Entities stays on Platform v1 unless you request v2 from Qualys Support. See TruRisk™ Score for Tags and Business Entities.

Next

Now that you know how a single asset is scored, see how those scores roll up: TruRisk™ Score for Tags and Business Entities.

Related Topics

TruRisk™ Scoring

Finding-Level Scores: QVS, QDS, and QVSS

TruRisk™ Score for Tags and Business Entities

TruRisk™ Scoring: Consolidated Formula Reference