Skip to main content

Business Context Score

What it is

The Business Context Score translates technical vulnerability severity into organizational business risk. The same CVE may be urgent for a large healthcare provider under compliance obligations but less urgent for a small internal tool.

What it produces

  • Business Context Score (0–100) — stored per vulnerability on each affected asset.
  • Risk Rating — Critical, High, Medium, or Low Business Risk.
  • Business Impact Summary — a short narrative describing potential compliance fines, operational disruption, and reputational impact.

Scoring factors

FactorMax contributionWhat it considers
CVSS severity20 pointsTechnical severity of the worst CVE in the group
Compliance scope20 pointsApplicable frameworks (e.g., CIS, ISO)
Company size15 pointsEmployee count
Industry criticality20 pointsRegulated sectors (finance, healthcare, government)
SLA urgency25 pointsSeverity-based MTTR targets from org profile

Risk rating labels

Score rangeRating
85–100Critical Business Risk
65–84High Business Risk
40–64Medium Business Risk
0–39Low Business Risk

Highlights

  • Organization-aware — uses industry, company size, compliance scope, and remediation SLAs from the org profile.
  • Threat-enriched — CVE data is enriched with Threat Exposure context before scoring.
  • Pairs with SC5SC5 tells you how dangerous the CVE is globally; Business Context tells you how dangerous it is for your organization.

Organization profile fields used for scoring are configured under Settings → Org info.