ThreatNexaris

Risk prioritization

A score you can take apart.

Severity ratings written for the whole world tell you nothing about your week. Nexaris scores a vulnerability out of 100 from four contributing categories, shows the arithmetic on the record, and lets an analyst overrule any of it in writing.

The scoring model is visible in the product on day one of an evaluation. Bring a vulnerability your team disagreed on and check it against your own judgement.

  1. 01

    The number resolves into its parts

    Four category totals that add to the score, each one arguable on its own. A disagreement becomes "this part is wrong", which is a conversation, instead of "the tool is wrong", which is not.

  2. 02

    Exploitation is weighted over theory

    Confirmed in-the-wild exploitation and the probability of it moves the score far more than a headline severity rating does. A critical-rated bug nobody is exploiting does not outrank an actively exploited one in your estate.

  3. 03

    Analysts can overrule it, on the record

    Set your own risk on any record. The override, who made it and why are stored with it, so the next person to look does not have to guess whether the number was deliberate.

  4. 04

    Weightings are yours to tune

    The balance between the four categories is configurable per organisation. A manufacturer and a bank do not weigh the same evidence the same way.

On every scored record
Score
Out of 100, with the four category totals that produced it
Band
Critical, high, medium or low, with the threshold shown
Exploitation
Whether it is being exploited, and how likely that is
Exposure
Which of your assets carry the affected software
Override
Any analyst adjustment, with author and reason
History
What the score was before, and what changed it

What we commit to

Things that stay true, or they are defects.

  • The parts always add up

    No normalisation, no floors, no hidden multiplier. If the four totals do not sum to the score, that is a defect.

  • Reproducible

    The same evidence produces the same score. Two analysts running it separately get the same answer.

  • Never silently changed

    When a score moves, the record shows what moved it and when.

See it against your own estate.

The useful version of this conversation uses your data, not ours. Bring a vulnerability, a supplier or a domain you already care about.