Threats
How threats map to assets, and why a never-examined asset reads worse than a treated one.
A threat is linked to an asset
A threat is registered and linked to the assets it reaches. Each link carries a severity and a state: open, mitigated, or accepted. It is an asset's threat population that feeds the threat component of the risk calculation.
Three states, three readings
The most important distinction on this screen is not between severe and minor threats — it is between a treated asset and one never examined. They are opposite situations that a careless system would render identically.
Asset state | Result |
|---|---|
Threats mapped, all treated | Floor — examined and clean |
Threats mapped, some open or accepted | p95 of the population |
No threat mapped | Uncalculated — reads worse than the floor |
Why uncalculated reads worse
An asset with no mapped threat does not go to the floor: that is a failure of identification, not low risk. And it is shown as worse than the floor, sorting above it on screen.
The reason is incentive. If the never-examined asset showed up grey, empty, or outside the ranking, analyzing an asset could only make it look worse — and the assets nobody looked at would stay comfortable forever. Analysis coverage is therefore a number on the screen, not an internal column.
The count of mapped threats is stored alongside the score precisely so those two opposite stories — never examined, and examined and clean — are never confused, even though both sit near the bottom of the scale.