SecurityAssess & Improve Security

How Mondoo Scores and Prioritizes Findings

How Mondoo turns each finding into a 0-100 risk score that drives prioritization.

A static severity rating ("this CVE is Critical") doesn't tell you whether to fix it before lunch or next quarter. Mondoo turns every finding into a contextual risk score that reflects how dangerous the finding actually is on the specific asset where it appears. Those scores roll up into your asset and space risk scores, and they power Initiatives, the ranked list of fixes that most improve your security posture.

What is a finding?

A finding is a potential security issue Mondoo discovers during a scan. There are three kinds:

  • Misconfigurations detected by failed policy checks
  • Known vulnerabilities (CVEs) in software installed on the asset
  • Vendor advisories (advisories) published for software on the asset

Every finding shows up in the Mondoo App on each asset where it appears.

How a finding is scored

Each finding receives a risk score from 0 to 100 (higher means more risk). The score is built in two steps.

Step 1: Base score

The base score reflects the severity of the issue in isolation.

Finding typeBase score source
MisconfigurationThe impact of the failed check in a Mondoo policy (Critical, High, Medium, Low)
CVEThe CVSS score
AdvisoryThe CVSS score of the underlying vulnerability

Step 2: Risk categories

Base scores are blind to context. A Critical CVE on an internet-facing production database is not the same threat as the same CVE on a developer's laptop behind a VPN. Mondoo adjusts the score across five risk categories:

CategoryWhat it captures
Attack surfaceHow exposed the asset is (internet, network, local, system, none)
Blast radiusWhat kind of service the asset runs (database, web server, identity, storage, Kubernetes, keys)
Business priorityAnnotations like business-critical or CIA ratings that you apply
ExploitabilityEPSS probability and CISA KEV status (vulnerabilities only)
In the NewsWhether the vulnerability is trending in the media (vulnerabilities only)

Risk categories can raise or lower the score. An internet-facing production database with a trending exploit climbs the list; the same CVE on an isolated test VM falls. Read Risk Categories for the full model, including how to override Mondoo's automatic detection.

Severity bands

Risk scores map to severity bands you'll see throughout the Mondoo App:

Score rangeSeverityMeaning
90–100CriticalExtreme risk
70–89HighSignificant risk
40–69MediumModerate risk
1–39LowMinor risk
0NoneNo risk

Blast radius

The blast radius of a finding is the number of assets in the space where the finding appears. A misconfiguration on 500 assets has a much larger blast radius than the same misconfiguration on a single sandbox host. Use blast radius to compare two findings with similar risk scores: fixing the one with the wider blast radius removes risk from more assets at once.

From individual scores to Initiatives

Mondoo combines finding risk scores across every asset in the space to identify which fixes would most improve your overall posture. The result is Initiatives: remediation goals, such as updating a vulnerable package on every asset that runs it, ranked by how much each one lowers your Space Risk Score.

See also

On this page