Overview
The Risk Score Settings page is found by navigating to Administration > Settings > Risk Score Settings. This page allows you to configure various settings relating to your accounts risk score calculations.
Click to jump to your desired section:
Risk Score tab
The Risk Score tab allows you to configure the following:
- Customize factor weights - Dictates the proportion at which the individual factors are weighed in the final risk score. These factors include Phishing Simulation, Training Engagement, and Security Signals. Please note that the total weight of all three factors must add up to 100, and any factor can be set to 0 (assuming that the rest add up to 100).
- Impact Modifier Sources - Allows for the configuration of sources for impact modifiers; choose which fields are used to calculate each target's impact modifier. The impact modifier is a multiplier added to the target's score based on the selected fields.
- Customize level scores - Allows you to set custom ranges for what makes a given score "high", "low", etc. Further, you can customize the color of each risk score (the default for Critical Risk is a dark red, for instance) as well defining the range for each level (e.g., setting 60-100 as "high" risk), along with the name of each level category.
At the bottom of the Risk Score tab, the "Score Precision Displayed" dropdown allows for the configuration of the number of decimal places to display risk scores.
Exposure tab
The Exposure tab allows you to configuring the following Dark Web Monitoring settings:
- "Have I Been Pwned" toggle: When toggled on, this will scan against the HIBP breach dataset. Further, selecting from the dropdown will allow you to dictate the cadence of these scans.
Account Findings tab
The Account Findings tab contains a table of findings for the account. On the top-right of the table, the following actions can be done:
- Findings can be filtered by status using the "All Statuses" (default option) dropdown. The statuses available are: Open, Dismissed, Mitigated, and Expired.
- Findings can be filtered by factors using the "All Factors" (default option) dropdown. The factors available are: Security Signals, Phishing Simulation, and Training Engagement.
- The "+ Add" button allows for findings to be manually added. The "Add Finding" modal will appear, where the Target Email, Target UUID, Finding Rule, and Incident Date will need to be configured before creating the finding.
- The "Import" button allows for the importing of manual findings via a CSV file.
- The "Export" button allows for the exporting of the table via a PDF file, Excel file, CSV file, or simply copied to the clipboard.
The Account Findings table itself contains the following columns:
- Mass Selection option - Checkbox for each finding (selecting the top checkbox will select ALL findings), allowing for mass actions.
- Date - The date of the finding.
- Factor - The factor associated with the finding.
- Finding - The finding of the respective target.
- Target - The target email address.
- Raw Score - The raw score of the finding.
- Decay - The amount of decay, in percentage, of the finding.
- Score - The score of the finding.
- Status - The status of the finding.
-
Actions - An options dropdown that contains the following:
- Set Dismissed - This option sets the finding as "Dismissed" in status.
- Set Mitigated - This option sets the finding as "Mitigated" in status.
Please note that the score follows golf-style rules (the lower the score the better). I.e., things that increase risk add to the score, and things that reduce risk are subtracted from the score.