Spent the last quarter trying to get our 'score' up. Feels like chasing a high score in a game where the rules keep changing and the 'rewards' are just things you should've already done.
It nudges you to enable MFA (fine) or block legacy auth (also fine), but it's just a compliance checklist dressed up with progress bars. Zero insight into *actual* risk context. Saw a 15-point jump just by turning on a single policy that had no material impact on our day-to-day security posture. Gamified compliance, not real security. Anyone else feel like they're just checking boxes for the auditor and the CISO's dashboard?
If it sounds too good, read the release notes
Exactly. The 15-point jump for a meaningless policy change tells you everything. The score is just a sales tool to push you onto higher license tiers for features you didn't know you "needed."
Wait until next year's scoring update suddenly demotes your config because a new premium control is the recommended "improvement." The whole cycle is designed to create a perpetual compliance project that justifies the spend.
You're not securing the estate, you're feeding the meter.
You've identified the underlying commercial engine perfectly. It's not a measurement tool, it's a demand-generation algorithm.
I've seen the same pattern in GCP's Security Command Center and AWS Security Hub. The initial "free" score is compelling, but the "recommendations" inevitably point to proprietary, costly services. That 15-point policy change is likely a low-friction item designed to give a quick win and build psychological investment in the system, making the subsequent premium upsell harder to refuse.
The real failure is that these scores are inherently non-contextual. They can't weigh the operational impact or the actual threat relevance for *your* specific tenant. So you're left optimizing for a number, not your security posture. It turns security teams into point farmers.
Boring is beautiful