Skip to main content

Updates to Risk Score Calculations and Issue Severities | May 2025

Changing risk for clearer prioritization

Nick Hemenway avatar
Written by Nick Hemenway
Updated over 3 months ago

Based on customer feedback, we’re refining the way our vulnerability scanner factors certain findings into your overall Risk Score. A small set of hygiene and best-practice items will now be classified as Informational.

You’ll still be able to view, track, and resolve these findings—but they will no longer impact your Risk Score.

We believe this adjustment will give you a clearer picture of your true security posture while still highlighting areas for ongoing improvement.

What it means for you

  • Clearer priorities – Remediation teams can zero in on High and Critical vulnerabilities.

  • More accurate trend lines – Risk-Score movements will map to issues that actually raise exposure.

  • Less alert fatigue – Fewer low-impact findings competing for attention.

You may notice a decrease in your overall Risk Score after your first scans following June 2, 2025. This is expected and reflects the removal of non-threatening items from the calculation.

Issues Impacted

The following issues will be classified as Informational and no longer affect your Risk Score:

  • Missing Header: X-Frame-Options

  • Missing Header: X-Content-Type-Options

  • Missing Header: Strict-Transport-Security

  • Missing Header: Referrer-Policy

  • Missing Header: Content-Security-Policy

  • Cookie missing Security Attributes

  • Link using Non-HTTPS Connection

  • Certificate using Weak Ciphers

  • Subresource Integrity (SRI) Blocked

Frequently Asked Questions

Will these changes affect historical scan data?

No, historical data will remain unchanged. The new classification will apply to scans performed on or after June 2, 2025.

Can I still view informational issues?

Yes, all findings—regardless of severity—will remain visible in your scan results and issue inventory.

Can I customize how issues are scored for my organization?

You can easily set custom severity overrides for the issues you'd like.

Does this apply to PCI-DSS compliance findings?

No. Findings generated from PCI compliance scans remain classified and scored exactly as before; only non-PCI hygiene/best-practice items are shifting to Informational.

Did this answer your question?