# How Security Scores Work

What the A to F security grades mean, how asset weight feeds your organization's score, and where you see organization, asset, domain and issue-type scores.

Source: https://docs.deepinfo.com/guide/easm/security-score/

Last updated: 2026-09-26

---
External Attack Surface Management (EASM) gives a security score and an A to F grade to your organization, to each asset and to each issue type. A
higher score is better. This page explains the grades, how asset weight affects your organization's score, and
where each score appears.

## Before You Start

- **Package:** EASM.
- **Role:** Admin or Member.

## Where You See Scores

A score appears as a grade letter with the number next to it.

| Score | Where |
|---|---|
| Your organization | The radar on the [Global dashboard](/guide/global-dashboard/) and the dial on the [EASM dashboard](/guide/easm/dashboard/) |
| One asset | The **SECURITY RATING** column on the **ASSETS LIST** tab of Inventory, the **INSIGHTS** block in the asset drawer, and the **SCORE** widget on the asset's **OVERVIEW** tab (see [Investigate an asset](/guide/easm/asset-details/)) |
| One domain with its subdomains | The **SCORE** widget of a domain, with **Include the impact of subdomains** turned on |
| One issue type | **SCORE** on the issue type page (see [Issue type details](/guide/easm/issue-types/)) |

The **SCORE** widgets on the asset and issue type pages include a **TIMELINE** chart. Choose **DAILY**,
**WEEKLY** or **MONTHLY** in its drop-down to change the interval.

Inventory also has an **INCLUDE SUBDOMAIN SCORES** checkbox above the list. It is not shown on the
**SUBDOMAINS** and **IP ADDRESSES** tabs.

## Grades

| Score | Grade | Colour |
|---|---|---|
| 800 and above | A | green |
| 700 and above | B | light green |
| 600 and above | C | yellow |
| 500 and above | D | orange |
| 400 and above | E | red |
| 300 and above | F | dark red |
| below 300 or no score | `-` (no grade) | grey |

Asset and issue-type scores use the same bands. An inactive asset has no score and shows `-`.

## A Grade Is Not the Whole Story

A grade sums up an asset, but it does not list what is wrong. An asset with a good grade can still have
active high or critical issues. Before you move on from an asset, check its **ISSUES** column in Inventory,
or the **ISSUES** block in its drawer, for red and orange severities.

![An Inventory row with a good security rating next to an ISSUES cell whose tooltip shows a high-severity issue.](/img/guide/easm/security-score-01.png)

## Asset Weight

Asset weight tells EASM how important an asset is to your organization. A higher weight marks a more critical
asset, and the weight affects your organization's overall security score.

- **SYSTEM WEIGHT** is calculated automatically from hundreds of criteria. It is not limited to 100, so you
  may see higher values.
- **USER WEIGHT** is a value from 1 to 100 that you enter to override it.

The weight shown on an asset is the user weight if one is set, otherwise the system weight. You find it as
**ASSET WEIGHT** in the asset drawer and on the asset's **OVERVIEW** tab, and as the **ASSET WEIGHT** column
in Inventory.

### Change an Asset's Weight

1. Open the asset's **…** menu: in the Inventory row, in the asset drawer header or on the asset detail page.
2. Under **ASSET SETTINGS**, select **SET ASSET WEIGHT**. The popup shows the **SYSTEM WEIGHT** with its
   **LAST UPDATE:** date, and your **USER WEIGHT** if you have set one.
3. In **NEW WEIGHT**, enter a value from 1 to 100. To remove your override and go back to the system weight,
   leave the field empty.
4. Select **SAVE**. A message confirms that the asset weight has been updated. To close without a change,
   select **CANCEL**.

![The SET ASSET WEIGHT dialog with the system weight, its last update and the NEW WEIGHT field.](/img/guide/easm/asset-settings-03.png)

## Domain-Level Score

For a domain that has subdomains, the **SCORE** widget on its **OVERVIEW** tab has the switch
**Include the impact of subdomains**. Next to it, the widget says how many subdomains the domain has and how
many extra issues, technologies and open ports they bring. Turn the switch on to show the domain-level score,
which includes that impact.

![The SCORE widget of a domain with the Include the impact of subdomains switch, the grade and the TIMELINE drop-down.](/img/guide/easm/security-score-03.png)

## Issue-Type Scores

Each issue type also has a score and a grade. The issue type page shows it under **SCORE**, with its
**TIMELINE**.

## Good to Know

> [!NOTE]
> Other scores in the platform use different scales. Do not compare them with the security score:
> the Brand Risk Protection (BRP) risk score runs from 0 to 100, a CVSS score from 0 to 10, and EPSS and the average exploitability
> score are percentages.

## Do This With the API

- Organization score over time: [Security Score Timeline](/reference/easm/security-score-timeline/)
- One asset's score over time: [Asset Security Score Timeline](/reference/easm/asset-security-score-timeline/)
- A domain with its subdomains: [Domain Security Score Timeline](/reference/easm/domain-security-score-timeline/)
- One issue type's score over time: [Issue Type Security Score Timeline](/reference/easm/issue-type-security-score-timeline/)
- Change asset weights: [Asset Set Weight](/reference/easm/asset-set-weight/)
