Understanding Unique Finding Score

Prev Next

About This Document

This document explains how SAFE incorporates environmental context and organizational prevalence into Unique Finding Scores using a transparent, standards-based evaluation model.

It outlines how technical, business, threat intelligence, and prevalence signals are systematically combined to produce grouped exposure scores that are explainable, consistent, and actionable.

The methodology extends the Finding Instance Score model to evaluate broader systemic exposure created by vulnerabilities or misconfigurations distributed across multiple assets.

Summary

SAFE's scoring methodology combines technical severity, exploitability, asset business context, threat intelligence, and organizational prevalence to quantify and prioritize cyber risk. The methodology produces consistent, explainable, and auditable risk scores that support remediation prioritization across technical and business stakeholders.

While the Finding Instance Score measures the risk associated with a specific finding on an individual asset, the Unique Finding Score aggregates the risk of the same vulnerability or misconfiguration across all affected assets. This enables identification of systemic control weaknesses, widespread exposures, remediation efforts with the greatest risk reduction potential, and issues that contribute most significantly to enterprise-wide risk.

Understanding Finding Scores

A Finding Score is a 0–10 exposure metric that combines vulnerability characteristics with real-world environmental context to answer the question:

“How much risk does this vulnerability pose to my organization right now?”

Unlike generic severity scores (CVSS), which assume all vulnerabilities exist in identical environments, Finding Scores reflect the organization’s actual environment, including:

  • Asset Impact – business impact and operational importance of the affected asset.

  • Severity of Vulnerability – the inherent technical severity and potential impact of the vulnerability.

  • Accessibility  – how reachable and exploitable the vulnerability is within the organization's environment.

  • Threat – real-world exploitation likelihood based on threat intelligence, EPSS, and known exploit activity.

  • Age – temporal exposure, considering vulnerability age, exploit maturity, and attack complexity.

Finding Scores provide intuitive exposure categorization:

Finding Score Range

Finding Severity

Action Required

9.0–10.0

Critical

Immediate remediation required

7.0–8.9

High

Prioritize for near-term remediation

4.0–6.9

Medium

Plan remediation in regular cycles

0–3.9

Low

Routine patching, no urgency

Refer to Understanding Finding Score to learn more.

Finding Score Component Breakdown

SAFE exposes the Finding Score through these explainable component groups: Access, Threat, Age, Severity of Vulnerability, Asset Impact and Mitigation.

These components help users understand why a finding is prioritized and what remediation teams should act on first.

Access

The Access component evaluates how reachable or exploitable a finding is from an attacker’s perspective.

Inputs include:

  • Attack Vector (network, adjacent, local, physical)

  • Zone and Sub-Zone (internet-facing, internal, segmented environments)

  • Privileges Required

  • User Interaction

SAFE uses CVSS v2.0/v3.x vectors for CVEs and inferred vectors for misconfigurations to evaluate accessibility characteristics.

Examples:

  • Network-accessible vulnerabilities receive higher accessibility weighting than local-only vulnerabilities

  • Findings requiring no user interaction or privileges receive higher exposure weighting

  • Internet-facing assets receive greater accessibility exposure than segmented internal systems

  • Accessibility is intentionally modeled independently from threat intelligence to preserve technical accuracy.

Threat

The Threat component evaluates the likelihood of real-world exploitation using active threat intelligence and exploit evidence.

Threat modeling incorporates:

  • Threat Level

  • Finding Age

  • Attack Complexity

  • EPSS

  • CISA KEV

  • HEV (Highly Exploitable Vulnerabilities)

  • TIIF (Threat Intel Informed Findings)

  • Threat Tags

  • Exploit intelligence signals

Threat tags may include:

  • Known Exploit

  • Ransomware Linked

  • Malware Linked

  • OWASP Top 10

  • End-of-Life Risk

SAFE uses a multi-signal consensus approach to threat scoring.

No single signal independently drives a critical exposure score. Instead, multiple corroborating signals contribute to elevated threat exposure.

This improves prioritization precision while reducing false positives.

Age

Represents the temporal exposure of the vulnerability.

Inputs include:

  • Raw Vulnerability Age (time since first observed on the asset)

  • Attack Complexity

  • Exploit Maturity

It captures how risk evolves over time, accounting for the increasing availability and maturity of exploit techniques.

Severity of Vulnerability

Represents the inherent severity of the vulnerability based on its technical characteristics.

Inputs include:

  • Confidentiality, Integrity, and Availability impact

  • Scope of impact (localized vs. broader system impact)

  • Component type (e.g., user vs. kernel-level impact)

Asset Impact

Represents the business impact of the affected asset.

Inputs include:

  • Asset role (e.g., workstation, server, network device)

  • Operational context (production, staging, development; active or decommissioned)

SAFE strongly incorporates CMDB and operational metadata into asset criticality evaluation to better align scoring with real organizational priorities.

This ensures exposure reflects actual enterprise impact rather than generic technical severity alone.

Mitigation or Compensatory Control Evaluation

Mitigation Efficacy measures how effectively deployed controls reduce exploitability and attacker success probability.

SAFE evaluates mitigation effectiveness using relationships between:

  • Findings

  • MITRE ATT&CK Techniques

  • Security Controls

Mitigation inputs may include:

  • EDR coverage

  • CIS benchmark compliance

  • Secure configuration controls

  • ATT&CK technique coverage

Findings are mapped to ATT&CK techniques using:

  • External intelligence sources

  • SAFE inference models

  • Vulnerability descriptions

Controls are then evaluated against the mapped ATT&CK techniques to determine mitigation effectiveness.

The model evaluates the weakest protected technique within the attack chain because attackers only require one viable path to succeed.

This allows strong compensating controls to significantly reduce exposure even when vulnerabilities remain present.

Why Environmental Context Matters

The same vulnerability can have drastically different exposure profiles depending on context.

Example: CVE-2025-24813 (Apache Tomcat Path Traversal, CVSS 8.1)

  • Internet-facing production server → Critical exposure

  • Internal low-impact system → Medium or Low exposure

Without environmental context, both findings would receive identical prioritization.

With contextual scoring, remediation decisions align more closely with actual organizational exposure.

Prioritization

Finding Scores enable organizations to:

  • Focus Resources: Remediate vulnerabilities that create the highest actual exposure rather than only the highest theoretical severity.

  • Reduce Alert Fatigue: Filter low-risk findings and prioritize the vulnerabilities that matter operationally.

  • Communicate Business Risk: Translate technical findings into exposure-centric prioritization understandable to leadership and operational stakeholders.

  • Maintain Compliance: Demonstrate risk-based prioritization aligned with frameworks such as:

    • CIS

    • NIST

    • ISO 27001

Understanding Unique Finding Scores

While Finding Scores evaluate exposure at the individual asset level, organizations frequently encounter the same issue across many systems.

A Unique Finding Score represents the aggregated exposure of a single vulnerability or misconfiguration across all affected assets.

The score answers the question:

“How much systemic exposure does this issue create across the organization?”

The score consolidates the exposure associated with every occurrence of the same vulnerability or misconfiguration into a single metric that reflects both the risk of individual instances and the breadth of their impact across the organization.

From Finding Instance to Unique Finding Score

  • Each finding instance is first evaluated independently using contextual exposure modeling. This ensures:

    • Granular exposure evaluation

    • Asset-level accuracy

    • Context-aware prioritization

  • All findings associated with the same CVE, Configuration ID, and Security weakness, are then grouped together for aggregation.

  • The grouped score reflects both:

    • Severity of the finding

    • Distribution across assets

Aggregation Methodology

SAFE uses a transform → aggregate → normalize modeling approach for grouped scoring.

The aggregation model intentionally avoids direct linear addition of scores because additive models can create:

  • Rapid score saturation

  • Excessive inflation at large asset counts

  • Poor differentiation between moderate and extreme exposure

Instead, SAFE applies controlled non-linear aggregation behavior.

This allows prevalence to amplify exposure while preserving meaningful score interpretation.

Severity and Prevalence Modeling

The Unique Finding Score is influenced by both:

  • Severity of individual finding instances

  • Prevalence across the organization

Higher-risk findings contribute more to the aggregated score, while broader distribution increases the organization's overall exposure. Prevalence is modeled as an ”exposure amplifier”, highlighting systemic issues rather than simply counting affected assets.

Score Interpretation

The Unique Finding Score should be interpreted as an organizational exposure metric rather than purely a technical severity rating.

Higher grouped scores generally indicate:

  • Broader environmental distribution

  • Larger attack surface exposure

  • Increased remediation importance

  • Greater operational impact potential

The score is designed to identify findings where remediation can produce the largest reduction in organizational exposure.

Example: Unique Finding Score Behavior

The screenshots below illustrate how SAFE transitions from individual Finding Instance Scores to a single Unique Finding Score representing systemic organizational exposure.

The unique finding (CVE-2025-40242) has 5 finding instances with individual scores:

Finding Instance

Score

Severity

Asset 1

9.71

Critical

Asset 2

9.60

Critical

Asset 3

8.03

High

Asset 4

7.92

High

Asset 5

7.79

High

The resulting Unique Finding Score = 9.57.

Unique Finding Score Analysis

The Unique Finding Score is derived by aggregating the exposure of all instances of the same vulnerability across affected assets. Each instance contributes according to its contextual exposure (Asset Impact, Vulnerability Severity, Accessibility, Threat, and Age), while the number of affected assets amplifies the overall organizational exposure.

In this example:

  • The vulnerability exists on 5 assets (5 finding instances).

  • Two instances have critical exposure (>9.6), while the remaining three are high exposure (7.8–8.0).

  • The aggregated score of 9.57 remains close to the highest individual scores, reflecting that multiple high-risk instances reinforce the organization's exposure rather than being averaged down.

  • The score therefore represents the combined impact of severity and distribution, prioritizing vulnerabilities that are both highly risky and present across multiple assets.