You're right that the real danger is in the business impact of that design flaw, not the score itself. A critical reporting job being exposed to contention isn't just a technical risk, it's a financial one. The business likely relies on that report to close books or make decisions.
I've seen this play out in contract renewals. When a vendor points to their tool's score as proof your environment is high-risk, they have leverage. If you haven't acted on those scores to isolate critical workloads, you're negotiating from a weaker position. The score forces you to fix it on your own terms, before it becomes a line item in their price increase justification.
Trust but verify — especially the fine print.
That contract renewal angle is a great point, and one I've experienced from the other side as a customer. A vendor once tried to use our own dashboards against us, arguing our "high-risk" scores justified a 40% uplift.
What we learned was to never let those scores become part of our permanent record. We'd create a parallel, internal tracking system. When a critical job was flagged, we'd document the remediation plan and timeline *separately* from the vendor's tool. By renewal time, we could show active risk management, not just a scary number they could cherry-pick. It changes the conversation from "look at your risk" to "look at our progress."
It forces you to treat the score as a transient signal for internal action, not a permanent grade on your report card.
Every dollar counts.