Hi everyone. I've been reading about Recorded Future for a few weeks now, trying to understand if it could help our team with security monitoring. I keep seeing the term "Risk Score" everywhere in the reviews and materials, but honestly, it's losing its meaning for me. It feels like one of those jargon terms everyone assumes you already get.
Could someone please explain it to me like I'm new to this? I'm coming from a project management background, so I'm used to risk registers and severity matrices, but this seems different.
Specifically:
* What is the score actually made *of*? Is it just one number, or are there parts to it?
* How is it supposed to be used day-to-day? Is it for prioritizing alerts for my team, or more for reporting to management?
* If a score changes, what does that usually tell me I should *do*?
I work with spreadsheets and reports a lot, so analogies to those kinds of tools might really help it click for me. Thanks in advance for any clarity you can offer.
That's a great question, and your project management background is actually a perfect starting point. Think of the Risk Score not as a single data point in your register, but as a pre-calculated, weighted sum of several columns.
It's made of factors like the credibility of the source reporting a threat, the relevance to your industry, the technical severity of the exploit, and how fresh the intel is. It's one number that rolls all that up, like an overall priority rating assigned automatically instead of manually in your spreadsheet.
For day-to-day use, yes, it's absolutely for prioritizing your team's alerts. It helps you sift through the noise. A score change usually means one of those underlying factors was updated, maybe new evidence came in making a threat more credible. That's your cue to re-assess that item's place in your queue; a big jump means it likely needs attention sooner. For management, you'd use the aggregate data, like weekly averages or trends, not the individual scores.
A common pitfall is treating it as an absolute truth instead of a guide. A low score doesn't mean "ignore," it means "less urgent." You still have to apply your own context.
Keep it civil, keep it real.
Your spreadsheet analogy is solid, but you need to think less about data entry and more about that one conditional formatting rule you forgot to set. The score is the automatic formatting.
It's a composite number, usually derived from source reliability, observed threat activity, and relevance. The day-to-day use is triage: anything above your internal threshold gets a human look, everything below gets logged. Reporting to management is a byproduct, not the primary goal.
If the score changes, it's because the machine learned something new. Your job is to ask why. Did the source get downgraded? Was the exploit weaponized? That delta is your action item. Treat it like a cell value that just turned red.
Trust but verify – and audit