Risk Score Report

Introduction

Field Effect Risk Score Reports provide a monthly summary of your organization's endpoint security posture. The report combines software, operating system, and configuration risk data to calculate your overall Device Risk score.


This article covers the following topics: 


How to Use Your Risk Score Report

Your monthly Risk Score Report helps you:

  • Track changes in your organization's overall security posture
  • Identify which risk factors are contributing most to device risk
  • Detect emerging security concerns before they become more significant issues
  • Monitor the effectiveness of remediation efforts over time
  • Prioritize investigations and corrective actions based on observed risk levels


The report evaluates three primary risk factors:

  • Software Risk measures the risk associated with software installed on monitored devices.
  • Operating System Risk measures risks associated with operating system versions, patch levels, and security controls.
  • Configuration Risk measures risks related to device configuration, enabled features, utilities, and operational behavior.


These three factors contribute to your organization's overall Device Risk score.


Access Risk Score Reports

Direct Clients

When a Risk Score Report is published, it becomes available in MDR Portal - Insights > Reports. From there, you can:

  1. View reports directly within the portal
  2. Download reports for offline review
  3. Share reports with stakeholders and leadership teams



Partners

When the organization selector is set to the partner view, reports for all managed clients are available from the Reports page. This allows partners to review and download reports across all client environments simultaneously.



Understand Your Risk Score Report

The Risk Score Report is divided into two pages:

  • Page 1: Overall Device Risk and organizational trends
  • Page 2: Contributing risk factors and detailed findings


Page 1: Understanding Your Overall Device Risk

Page 1 provides a high-level summary of your organization's security posture and highlights significant trends observed during the reporting period.



Device Risk

Device Risk is the average measure of risk across all Field Effect monitored devices and is presented on a scale of 0 to 100. Scores above 90 indicate the presence of Critical Risk.


Use this section to:

  • Understand your current overall risk level
  • Identify whether risk has increased or decreased since the previous report
  • Review key findings summarized for the reporting period


Review any significant month-over-month increases in Device Risk, especially when accompanied by increases in Software, Operating System, or Configuration Risk scores. Sudden increases may indicate emerging vulnerabilities, outdated systems, or widespread configuration concerns requiring investigation.


Last 3 Months

The Last 3 Months section tracks changes in your organization's Device Risk score over time.


Use this section to:

  • Identify long-term trends
  • Determine whether remediation efforts are reducing risk
  • Recognize sudden changes that may require investigation


Investigate large increases in risk or sustained upward trends. If risk levels continue to rise over multiple reporting periods, review the contributing risk factors on Page 2 to determine the underlying causes.


Observed Devices

This section summarizes the devices observed during the previous 30 days and groups them according to their Device Risk level. Device counts are also organized by operating system.


Use this section to:

  • Understand how risk is distributed across the organization
  • Identify whether risk is concentrated among a small number of devices or more broadly distributed
  • Review device inventory trends by operating system


Focus on environments with a large number of high-risk devices. These systems should be prioritized for further investigation and remediation.


Device Location

The Device Location section displays the geographic distribution of monitored devices and highlights risk levels by location.


Use this section to:

  • Understand where monitored devices are operating
  • Identify geographic concentrations of high-risk devices
  • Detect unusual patterns in user distribution and risk exposure


Investigate regions with a disproportionately high concentration of elevated-risk devices, especially when those locations differ significantly from previous reporting periods.


Page 2: Understanding Risk Factors

Page 2 examines the factors contributing to your organization's Device Risk score and highlights the findings that require attention.



Device Risk Factors

This section shows how Software Risk, Operating System Risk, and Configuration Risk contribute to your overall Device Risk score and how these measurements have changed over the previous three months.


Use this section to:

  • Identify which risk category is driving increases in risk
  • Prioritize remediation efforts
  • Measure whether improvement efforts are reducing specific risk categories over time


Software Risk

Software Risk measures the risk associated with software installed on devices within your environment. Factors include known vulnerabilities, software behavior patterns, software usage, and other contextual indicators.


Use this section to:

Identify vulnerable software affecting multiple devices

  • Prioritize remediation of high-severity vulnerabilities
  • Understand which software is driving elevated risk levels


Prioritize software vulnerabilities with high CVSS scores and focus remediation efforts on software affecting large numbers of devices.


To investigate further, select See all devices with vulnerable software to open a filtered Endpoint Devices view.


Operating System Risk

Operating System Risk measures the risk associated with operating systems deployed throughout your environment, including patch status and operating system security controls.


Use this section to:

  • Identify outdated or unsupported operating systems
  • Monitor operating system-related security concerns
  • Prioritize patching activities across the organization


Devices running outdated or unpatched operating systems should be prioritized because they may be exposed to known vulnerabilities.


To investigate further, select See all devices with out-of-date operating systems to open a filtered Endpoint Devices view.


Configuration Risk

Configuration Risk measures the risk associated with device activity, configuration changes, enabled features, utilities, and network usage patterns.


Use this section to:

  • Review configuration-related security concerns
  • Identify devices with potentially unsafe configurations
  • Prioritize corrective actions related to device settings and operational practices


Investigate devices with outdated security tools, disabled protections, infrequent scans, or other configuration issues that increase exposure to threats.


To investigate further, select See all devices with configuration issues to open a filtered Endpoint Devices view.


Next Steps

After reviewing your Risk Score Report:

  • Identify which risk factor is contributing most to your overall Device Risk score.
  • Review significant month-over-month increases in risk.
  • Investigate affected devices using the provided filtered views.
  • Prioritize remediation activities based on severity and impact.
  • Review future reports to confirm that risk levels are decreasing over time.


Regular review of your Risk Score Reports can help you understand changes in your security posture, focus remediation efforts, and reduce risk across your organization.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article