skip to content

Two Qualys VMDR assets carry the same critical QIDs, yet one has a TruRisk Score of 900 and the other 350 — what explains the gap?

level: seniorimportance: should knowfreq 18%

answer

  1. same findings, different asset
  2. criticality multiplies everything
  3. highest tag wins, new assets start at 2
  4. QVS minus mitigations
  5. external exposure and the 1000 cap

basics

~20 s

TruRisk Score multiplies the asset's criticality (ACS, 1 to 5) by severity-weighted QDS averages, capped at 1000. Identical QIDs on an ACS 5 and an ACS 2 asset differ about 2.5 times. Mitigation controls and external exposure explain the rest.

solid answer

~50 s

TruRisk Score is a per-asset score from 0 to 1000: Severe 850-1000, High 700-849, Medium 500-699, Low 0-499. For a managed asset it is the **Asset Criticality Score** (ACS, 1 to 5) times a sum over the critical, high, medium and low QIDs. Each term is a weight times the average **QDS** times the count raised to the power 1/100, and the result is capped at 1000. ACS is a multiplier, so the same QIDs with the same QDS on an ACS 5 asset and an ACS 2 asset differ by about 2.5 times, close to 900 against 350. Check ACS first. It comes from the highest-valued tag, and newly discovered assets default to 2. Then check QDS (QVS minus mitigation controls) and whether external tags apply the 1.2 exposure multiplier. Changes show up after the next asset scan.

go deeper

for a junior

Recall that TruRisk is a per-asset score from 0 to 1000, built from asset criticality (1 to 5) and the QDS of each detected QID.

for a middle

Explain the formula's shape: ACS as a multiplier, severity-weighted QDS averages, a near-flat count term, the 1000 cap and the 1.2 external multiplier.

for a senior

Show the diagnosis: read the TruRisk Score Details, check the highest-ACS tag and the default ACS of 2, mitigation controls lowering QDS, and the rescore timing after an asset scan.

for a principal

Discuss governance: who sets ACS, how dynamic tags keep it current, and how to stop a mis-tagged estate turning the risk score into false precision.

## What TruRisk Score is Qualys VMDR attaches a **TruRisk Score** to each asset, so you can prioritise by the risk to that asset rather than by technical severity alone. The help page "Calculating TruRisk Score" notes the score was formerly called Asset Risk Score. It runs from 0 to 1000 in four bands: | Band | Range | |---|---| | Severe | 850-1000 | | High | 700-849 | | Medium | 500-699 | | Low | 0-499 | It is built from three inputs: 1. **Asset Criticality Score (ACS)**: 1 to 5, set by you through asset tags. 2. **Qualys Detection Score (QDS)**: 1 to 100 for each QID detected on the asset. 3. **A weighting factor (w)**: assigned automatically for each severity level of QID (critical, high, medium, low). ## The formula for a managed asset For a managed asset, Qualys's help gives: ``` TruRisk = MIN( ACS * ( wc*Avg(QDSc)*Count(QDSc)^(1/100) + wh*Avg(QDSh)*Count(QDSh)^(1/100) + wm*Avg(QDSm)*Count(QDSm)^(1/100) + wl*Avg(QDSl)*Count(QDSl)^(1/100) ), 1000) ``` Three things follow: - **ACS is a straight multiplier.** Two assets with identical findings and identical QDS values differ by the ratio of their ACS, unless the cap or the external multiplier intervenes: 5 against 2 is 2.5 times. - **The count barely matters.** A count raised to the power 1/100 grows very slowly: 100 findings give about 1.05, and 1,000 give about 1.07. More vulnerabilities still raise the score, but the average QDS per severity drives it. - **The cap is 1000.** Past it, more findings change nothing. An asset marked external has its whole TruRisk Score multiplied by 1.2, and the score details list its External Tags. Externally exposed unmanaged assets use a separate formula built on QVS and an asset-exposure factor. ## Where the gap usually comes from A ratio near 900:350 is close to 5:2, so start with criticality. - **ACS from tags.** ACS is defined on tags. If an asset has several, the highest ACS wins: six tags valued 1 to 5 contribute their maximum. The onboarding guide warns that **newly discovered assets get a default ACS of 2** until you assign one. A crown-jewel server never tagged sits at 2, and its score understates the risk. - **QDS per detection.** QDS comes from the highest **Qualys Vulnerability Score (QVS)** among the QID's CVEs, from threat intelligence (exploit code maturity, malware, active threat actors, trending), and from mitigation controls. The help states `QDS = QVS - CID`: mitigation controls (CIDs) applied through Qualys compliance modules lower the score. With no CID applied, QDS equals QVS. The same QID can therefore score lower on a host where a mitigating control is in place. - **Exposure.** An external tag multiplies the result by 1.2. - **Timing.** Asset changes update QDS and the TruRisk calculation **after an asset scan**. If you raised one asset's ACS this morning, the two scores may simply not have been recalculated yet. ## A worked example Suppose the bracketed sum (the weighted QDS averages with their count terms) comes to 180 on both assets, because they carry the same QIDs with the same QDS values. Then: - The asset tagged with ACS 5 scores 5 x 180 = 900, which is Severe. - The untagged asset, still on the default ACS 2, scores 2 x 180 = 360, which is Low. That matches the gap in the question almost exactly. The likely fix is a missing criticality tag, not a scoring fault. ## How to read it in the console 1. Open the asset from the Vulnerabilities tab (Asset view). The TruRisk Score Details page lists the contributing factors: Business Criticality (the ACS), Asset Exposure (shown only when an external tag exists) and Risk Factors. 2. Open the Risk Calculation to see the formula with the asset's own numbers. 3. Sort the asset's vulnerabilities by QDS, the default sort, and open the top QID's QDS Details. It shows the highest-contributing CVE, associated malware and threat actors, and exploitability. 4. In the Prioritization report, TruRisk mode filters by ACS range (1 to 5), by QDS band and by TruRisk band. ## Judgement The score is only as good as your tagging. Assign ACS to the most valuable assets first, use dynamic tags so new assets are classified on discovery, and review anything still at the default 2. When two scores disagree, explain the inputs before you question the vendor's maths.

  • You raise a server's ACS from 2 to 5, but its TruRisk Score does not move. Is something broken?
    Probably not. Qualys applies asset changes to the QDS and TruRisk calculation after an asset scan, so the new criticality appears after the next scheduled scan. Also check that the tag carrying ACS 5 actually matches the asset. With several tags, the highest ACS wins, but only for tags the asset really carries.
  • Why might the same QID show QDS 95 on one host and a lower QDS on another?
    QDS starts from the QID's highest-scoring CVE, through its QVS, plus threat intelligence. It is then reduced by mitigation controls applied through Qualys compliance modules: QDS = QVS - CID. A host with a mitigating control in place scores lower for the same QID. Without any CID, QDS equals QVS.

TruRisk works like an insurance premium. The same hazard costs far more to insure on the most valuable building on the street, and asset criticality is that building's value. You change the premium by valuing the building correctly, not by recounting the hazards.

saying these in an interview costs you the question

  • TruRisk Score is just CVSS rescaled to 1000
  • An asset with several tags averages their criticality scores
  • Doubling the number of findings roughly doubles the score
  • New assets start at the lowest criticality, 1
  • A criticality change rescores the asset the moment you save it