How Your Internet Perimeter Score and Grade Are Calculated

How the A–F letter grade and 0–100 Internet Perimeter Score on Insights → Metrics are calculated, what risks count, and when the score updates.

The Internet Perimeter Score widget on the Metrics page (Insights → Metrics) displays a letter grade (A–F) and a 0–100 score summarizing your external risk exposure. This article explains exactly what feeds the score, how the math works, and when it updates.

What the Score Measures

The score measures current, validated risk on your internet-facing perimeter — not platform engagement, scan volume, or historical activity. Points are deducted from a perfect 100 for each open demonstrated vulnerability, weighted by severity and by how long it has been open relative to its remediation SLA.

What Counts and What Does Not

Counted against your score:

  • Risks in the Demonstrated state — findings Praetorian engineers have confirmed as true positives

  • Only external (internet-facing) risks

Not counted:

  • Detected risks that have not yet been validated (no penalty for unconfirmed findings)

  • Accepted risks — tracked and reported alongside the grade, but they do not deduct points

  • Rejected (false positive / out of scope) and Resolved risks

  • Internal-only risks

Your asset base: the denominator of the calculation is the number of active external assets observed in your most recent scan window. This normalizes risk density so organizations of different sizes are graded fairly.

The Deduction Model

Step 1 — Base severity weights

Each demonstrated risk starts with a base deduction weight:

SeverityBase

WeightRemediation

SLA

Critical

10.0

7 days

High

5.0

30 days

Medium

2.0

60 days

Low

0.5

90 days

Exposure

0.1

45 days

Info

0

Step 2 — Age multiplier

Each risk's weight is multiplied by an age factor based on how long it has been open relative to its SLA:

  • Within SLA: multiplier near 1.0 (little added penalty)

  • At the SLA boundary: multiplier near 2.0

  • Well past SLA: multiplier approaches the cap of 3.0

A Critical open for a day costs about 10 points of raw deduction; the same Critical open for a month costs nearly 30. Fixing findings within SLA is the single biggest lever for protecting your grade.

Step 3 — Two views of risk, blended

Two components are computed and blended:

  • Density component (40%): total deductions divided by your active external asset count, then compressed on an exponential curve. This reflects how concentrated risk is across your perimeter.

  • Worst-case component (60%): deductions from your ten most severe findings, independent of asset count. Security is asymmetric — an attacker only needs one vulnerability — so severe findings are never diluted by a large asset base. This mirrors the approach used by industry scoring systems where the worst detection dominates.

The exponential compression in both components means a flood of low-severity findings saturates rather than driving the score to zero, while the first few severe findings have clearly visible impact.

Step 4 — Minimum deduction floors

Critical and High findings guarantee a minimum penalty that a large asset base cannot divide away:

Finding

Minimum deduction

Each Critical

8 points

Each High

3 points

Each Medium

1 point

Each Low

0.25 points

Step 5 — Confidence adjustment

A confidence factor based on your asset count — (assets + 1) / (assets + 10) — pulls the score toward 70 (a C) when the monitored perimeter is very small. With only a handful of assets there is limited evidence either way, so neither a perfect A nor a hard F is statistically justified. At 100+ assets the adjustment is negligible.

Step 6 — Severity caps

Certain finding counts cap the maximum achievable score regardless of everything else:

Open demonstrated findings

Maximum score

1 Critical or 3+ Highs

89.9 (no A)

2 Criticals or 1 Critical + 3 Highs

79.9 (no B)

3 Criticals or 2 Criticals + 3 Highs

74.9

5 Criticals or 3 Criticals + 5 Highs

69.9 (no C or above)

Step 7 — Score floor

The final score never displays below 30, consistent with industry rating platforms.

Score-to-Grade Mapping

Grade Score

Range

A

90 – 100

B

80 – 89.9

C

70 – 79.9

D

60 – 69.9

F

Below 60

Special States

  • No active external assets yet: the score defaults to 100 (grade A) with zero confidence.

  • No score recorded yet: the widget shows "--" with a Pending label until the first calculation runs.

When the Score Updates

  • In real time whenever a risk transitions into or out of the Demonstrated or Resolved state — validating a new finding or resolving one recalculates the grade immediately.

  • Daily via a scheduled recalculation, so aging findings are re-weighted even when nothing else changes.

  • Daily snapshots of the score are stored for trending. These power the Health Grade Risk Score Trend and Internet Perimeter Risk Score Trend widgets, and the up/down delta arrow shown next to the score compares the current value against the most recent snapshot.

Other Letter Grades on the Metrics Page

Two other widget families on the same page also display A–F letters, but they are separate rating systems and do not affect your Internet Perimeter Score:

  • SecurityScorecard (SSC) widgets — such as SSC Grade Distribution and SSC Portfolio Score — show third-party vendor ratings imported from your SecurityScorecard integration. Those grades are calculated by SecurityScorecard, not by Guard.

  • The peer percentile widget compares your posture against other organizations on the platform and displays a percentile, not a letter grade.

How to Improve Your Grade

  1. Remediate Critical and High findings first — they carry the largest weights, the minimum floors, and the severity caps.

  2. Fix findings within their SLA — the age multiplier can triple a finding's impact once it lingers past its remediation window.

  3. Use the Accepted state deliberately — a risk your organization formally accepts stops deducting points, but it remains visible alongside your grade for transparency.

  4. Keep resolved findings resolved — a re-detected finding automatically reopens as Demonstrated and immediately affects your score again.

Questions?

If you have questions about your score or believe a finding is affecting your grade incorrectly, reach out to our support team at support@praetorian.com.