Executive summary
A security score is useful only if a reader can answer five questions: What was in scope? When was it assessed? Which evidence supports it? How was it calculated? What important uncertainty remains?
Argus Ready separates commercial qualification from security assessment. Public business records and historical observations may help identify an organization that could benefit from a conversation. They cannot support a claim that the organization is vulnerable, breached, noncompliant, or unsafe. The customer-facing 1-10 score exists only after written authorization and evidence collection inside the agreed boundary.
The current score uses five required dimensions:
- External exposure.
- Identity and access.
- Data protection.
- Patch and configuration.
- Detection and response.
Each dimension contains four required criteria, for 20/20 closed rubric coverage. A professional records a published state, criterion-specific observable anchor, rationale, and exact source or finding references for every criterion. The software derives all numeric dimension values; no assessor-entered number can reach score model v3. Missing or extra criteria, unknown states or references, blank evidence identities, or an unreferenced open critical or high finding causes scoring to fail.
Measured threat context: rising reported loss and AI amplification
FBI Internet Crime Complaint Center annual data show a large increase in complaint-reported losses from 2020 through 2025. The series rises from $4.2 billion in 2020 to $20.877 billion in 2025, approximately 4.97 times the starting value. Complaint counts rose overall but not every year. The data support a measured increase in reported losses; they do not by themselves prove exponential growth, measure every cybercrime, or identify one cause.
| IC3 reporting year | Complaints | Reported losses |
|---|---|---|
| 2020 | 791,790 | $4.2 billion |
| 2021 | 847,376 | $6.9 billion |
| 2022 | 800,944 | $10.3 billion |
| 2023 | 880,418 | $12.5 billion |
| 2024 | 859,532 | $16.6 billion |
| 2025 | 1,008,597 | $20.877 billion |
| 2026 | Year in progress; comparable full-year IC3 annual data pending. | |
AI is best described here as a force multiplier, not the sole cause of the broader trend. The FBI's 2025 report says widely available AI can produce convincing synthetic profiles and personalized conversations in mass quantities, and that investment scammers can quickly generate thousands of distinct-looking conversations. IC3 recorded 22,364 complaints with the tracking descriptor "AI Related" and $893,346,472 in adjusted losses in 2025. Because that label is a descriptor attached after a crime type is selected, those figures are context, not a separate census of AI-caused crime.
The mechanism is consistent with official qualitative assessments. An NSA transition brief describes the cost to attack as a fraction of the cost to defend. A June 22, 2026 Five Eyes statement published by NSA says AI lowers barriers for malicious actors, accelerates the speed, scale, and sophistication of cyber threats, and shortens the interval between vulnerability discovery and exploitation. AlomSec therefore treats lower skill, time, and cost for producing code, preparing exploit attempts, personalizing lures, and operating at scale as a reason to reassess exposure quickly. That is an evidence-based inference about amplification, not a claim that AI alone produced the IC3 trend or that every AI-assisted attempt succeeds.
1. The authorization boundary
NIST SP 800-115 describes planning, conducting, analyzing, and using technical security tests and assessments. AlomSec turns planning into a hard product boundary. An engagement cannot proceed without:
- A named legal entity and authorizing person.
- A content digest of the signed agreement.
- A non-empty structured scope identifying targets and exclusions.
- Explicit start and end times.
- Active status and rules of engagement.
- An engagement identity that matches the authorized customer.
The gate is not satisfied by an email conversation, form submission, public asset, salesperson's note, or payment. It rejects expired, revoked, empty, or mismatched authorization records.
1.1 Rules of engagement
The rules define permitted techniques, identities and test accounts, source addresses, request limits, maintenance windows, fragile systems, data handling, evidence retention, communication paths, stop conditions, emergency contacts, and procedures for unexpected access.
1.2 Scope changes
New assets or techniques are not absorbed informally. A scope change updates the written authorization, dates, rules, and commercial terms before work crosses the original boundary.
2. Evidence quality
The assessment record distinguishes evidence classes:
- Provided context: architecture, inventory, policy, or configuration supplied by the customer.
- Source observation: a bounded collector, scanner, artifact parser, or approved external source.
- Analyst validation: reviewed behavior or configuration supporting affectedness, reachability, control state, or impact.
- Reproduction evidence: a controlled demonstration within scope, with exact request, response, artifact, or state transition.
- Remediation evidence: a verified before-and-after observation after corrective work.
Evidence should identify source, time, target, method, reviewer where appropriate, and a stable reference or digest. Sensitive values are redacted or stored in a separately controlled evidence environment; credentials do not belong in the exposure database or public report.
Score model version 3 captures one logical SQLite snapshot of sources, assets, findings, relationships, provenance links, and ingest runs. It records bounded row counts and deterministic table digests, the project and schema versions, open findings by severity, normalized rubric observations, and a canonical derivation digest. Every report and portal publication recaptures the evidence binding and re-derives the score through one shared verifier. A later evidence or derivation change causes refusal until a new assessment is recorded.
2.1 Coverage is part of the result
A dimension cannot receive a polished score from missing data. If a required dimension cannot be assessed to the agreed depth, the model refuses the overall score or the report clearly narrows scope. Unknown coverage is not treated as a passing control.
3. The five dimensions
3.1 External exposure
Measures asset visibility, ownership, internet reachability, service minimization, secure edge configuration, external dependencies, and verified remediation of reachable weaknesses. Evidence may include asset and DNS inventory, service configuration, approved observations, certificates, and attack paths.
3.2 Identity and access
Measures identity inventory, privileged access, phishing-resistant authentication, lifecycle, service accounts, conditional access, session control, least privilege, recovery, and review. The focus is whether trust can be established, limited, revoked, and audited.
3.3 Data protection
Measures data classification, collection minimization, access boundaries, encryption and key ownership, backup protection, retention, deletion, leakage controls, and recovery requirements. Controls are evaluated against the data and business process actually in scope.
3.4 Patch and configuration
Measures inventory-to-update linkage, vulnerability prioritization, configuration baselines, exception handling, supported versions, software and device lifecycle, cloud posture, and verification. CISA KEV and EPSS can inform order but do not replace local affectedness and impact.
3.5 Detection and response
Measures useful telemetry, alert coverage, triage, containment authority, incident roles, communication, restoration, exercises, lessons learned, and proof that critical services can recover.
3.6 Closed observation states
| State | Value | Published meaning |
|---|---|---|
| Absent | 0.00 | No evidence of the criterion's control object was produced. |
| Ad hoc | 0.25 | The object exists informally or for part of scope, without an owner or cadence. |
| Partial | 0.50 | The object is owned, but coverage or cadence has evidenced gaps. |
| Managed | 0.80 | The object is owned, covered, and operated on a documented cadence. |
| Verified | 1.00 | The object is managed and passes the criterion-specific published test. |
There is no not-applicable or unknown state. A state token and persuasive prose are not sufficient: the observation must cite the exact published anchor for that criterion and state. Managed and verified observations also require a source reference from the bound evidence revision.
4. Score model version 3
Each dimension is the equally weighted mean of its four state values, multiplied by 100. Open priority findings then apply a ceiling to every dimension: 60 when any critical is open, otherwise 85 when any high is open, otherwise 100. Let D be the arithmetic mean of the five resulting dimension values.
Base score = 1 + (D x 9 / 100)
The model then applies an explicit priority-finding penalty:
- 1.0 point for each open critical finding.
- 0.25 point for each open high finding.
- Total penalty capped at 4.0 points.
- Final score clamped to 1.0-10.0 and rounded half up to one decimal place.
Open critical and high counts are recaptured from the bound authorized evidence store, and their key set must agree with those counts. Every such finding must be referenced by at least one scored criterion. Public prospect data and stale historical signals cannot enter this score.
Why both a ceiling and a penalty?
The ceiling prevents a perfect-looking dimension profile from coexisting with an unresolved priority condition. The separate penalty makes the count and urgency visible in the final 1-10 result. The detailed register still carries every finding.
5. Worked example
Consider an illustrative 20/20 assessment whose four-state calculations produce raw dimension values of 90, 65, 77.5, 65, and 65. The evidence contains one open high finding. The 85 ceiling changes the first dimension from 90 to 85, producing a dimension mean of 71.5. The base is 7.435 and the high-finding penalty is 0.25. The final half-up result is 7.2.
The report does not stop at 7.2. It shows the five values, any applied ceiling, the penalty, 20/20 rubric coverage, derivation digest, evidence revision, scope, priority actions, and what a retest could change.
6. Reporting and remediation
The customer package separates audiences while preserving one record:
- Executive view: scope, score, dimension profile, material attack paths, business impact, and priority decisions.
- Technical register: affected assets, evidence, reproduction where appropriate, severity, risk factors, remediation, owner, and verification requirement.
- Coverage statement: sources used, inaccessible areas, exclusions, stale evidence, and assumptions.
- Remediation plan: immediate containment, near-term correction, architectural work, accepted risk, and target dates.
- Retest statement: what will be repeated, what constitutes closure, and how the score and risk delta will be recalculated.
A score is dated. Changes after the assessment do not silently rewrite it. A verified reassessment creates a new result and retains the previous model inputs for comparison.
7. Interpretation and limitations
The Argus Ready score is not a certification, warranty, breach prediction, compliance attestation, or substitute for a framework-specific audit. It describes the authorized scope and available evidence at a point in time. Two organizations with different scopes should not compare the number without the dimension and coverage context.
Equal weighting is intentionally simple and reproducible in model version 3. It may not match every organization's risk appetite. Professional judgment remains in selecting an observation state; the evidence does not automatically prove that selection correct. The result is defended by the closed anchors, recorded rationale, exact references, complete rubric coverage, finding reconciliation, canonical derivation, and evidence revision. Any future formula change requires a new version, published method, migration rule, and side-by-side impact analysis. Historic v2 scores remain labeled v2 and are never reinterpreted as v3.
The criterion crosswalk to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals is informative only. It is not an endorsement, certification, conformance determination, audit result, CSF Profile, or statement by NIST or CISA. Framework identifiers never contribute to score arithmetic.
Conclusion
The 1-10 view is a communication layer over an evidence record. Its value comes from the authorization gate, 20/20 closed rubric coverage, published anchors, transparent formula, explicit finding ceilings and penalties, scope statement, canonical derivation, and verified follow-up. Removing any of those turns a clear score into false precision.
References
- National Institute of Standards and Technology, SP 800-115: Technical Guide to Information Security Testing and Assessment, September 2008.
- National Institute of Standards and Technology, Cybersecurity Framework 2.0, February 26, 2024.
- Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals, version 1.0.1.
- Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog, accessed August 3, 2026.
- FIRST EPSS, Frequently Asked Questions and limits of EPSS as a risk input, accessed August 3, 2026.
- Federal Bureau of Investigation, Internet Crime Complaint Center Annual Reports, 2020-2025 editions.
- Federal Bureau of Investigation, 2025 IC3 Annual Report, including the AI-related descriptor and adjusted-loss discussion.
- National Security Agency, Cyber: A Growing and Persistent Threat, presidential transition brief.
- Five Eyes Cyber Security Agencies Statement, published by the National Security Agency, June 22, 2026.