Business Context Score
What it is
The Business Context Score translates technical vulnerability severity into organizational business risk. The same CVE may be urgent for a large healthcare provider under compliance obligations but less urgent for a small internal tool.
What it produces
- Business Context Score (0–100) — stored per vulnerability on each affected asset.
- Risk Rating — Critical, High, Medium, or Low Business Risk.
- Business Impact Summary — a short narrative describing potential compliance fines, operational disruption, and reputational impact.
Scoring factors
| Factor | Max contribution | What it considers |
|---|---|---|
| CVSS severity | 20 points | Technical severity of the worst CVE in the group |
| Compliance scope | 20 points | Applicable frameworks (e.g., CIS, ISO) |
| Company size | 15 points | Employee count |
| Industry criticality | 20 points | Regulated sectors (finance, healthcare, government) |
| SLA urgency | 25 points | Severity-based MTTR targets from org profile |
Risk rating labels
| Score range | Rating |
|---|---|
| 85–100 | Critical Business Risk |
| 65–84 | High Business Risk |
| 40–64 | Medium Business Risk |
| 0–39 | Low Business Risk |
Highlights
- Organization-aware — uses industry, company size, compliance scope, and remediation SLAs from the org profile.
- Threat-enriched — CVE data is enriched with Threat Exposure context before scoring.
- Pairs with SC5 — SC5 tells you how dangerous the CVE is globally; Business Context tells you how dangerous it is for your organization.
Organization profile fields used for scoring are configured under Settings → Org info.