# Risk360 score then the factor

Source: https://ai.techclick.in/blog_zscaler_risk360_exposure_scoring
Markdown: https://ai.techclick.in/blog_zscaler_risk360_exposure_scoring.md
Publisher: Techclick Infosec Pvt Ltd

Risk360 org score is the average of four attack-stage categories. Drill the factor, entity and recommended action, then prove the Last 30 Days trend — not a closed ticket. Factor Your Score 0 is healthy.

Lessons  ·  Zscaler series  · Risk360 exposure scoring

   This page vs ZIA User Risk Score and EASM

   This lesson is  Risk360 organisation exposure scoring : four attack-stage categories, weighted factors, recommended actions. ZIA User Risk Score is a different object (pre-/post-infection behaviour on a user, can feed Risk360). Internet-facing inventory without a Risk360 factor is a different product class — see Xpanse if that is the ticket.

    Zero Trust Exchange factory  ·  ZIA DLP  ·  Cortex Xpanse attack surface

   Hero · four categories average into one org score; work is the factor

   Mood, not a field list. Exact objects are in the SVG: org score is the average of four categories; High Impact Recommendations and the Factors drawer are where the ticket lives. No tenant integers are invented on this page.

   Quick answer

   Risk360 scores cyber risk at organisation level as the  average  of  External Attack Surface ,  Compromise ,  Lateral Propagation  and  Data Loss . Documented org bands: Low 0–25, Medium 26–50, High 51–75, Critical 76–100. Each contributing  factor  has a risk weight, a  Your Score  (0 = healthy), severity (critical / high / medium), entities (workforce, 3rd parties, applications, assets), a  Licensed?  flag and a  recommended action . Fix the owning control (ZIA, ZPA, seed domain, or a Data Fabric connector). Proof is the factor’s Last 30 Days trend and Your Score moving toward 0 — not peer rank and not a closed ticket.

## Why the org number is not a ticket

 The day-one ticket is always the same: “Risk360 is High, make it green.” Wrong object. The dashboard number is an average across four attack stages. Owners cannot patch an average. They can patch an exposed server, a malware outbreak, a segmentation gap, or uploads to a risky app — the examples Zscaler itself uses as score inputs.

 Three silent-stuck states look identical from the board pack (a High tile):

- External Attack Surface moved because Seeds Management has no domain (or the 24–48 h first scan has not finished). Compromise is quiet. The average still looks “the org.”

- A factor’s Recommended Action needs a Zscaler feature you are not subscribed to — Licensed? = N . The factor is real; the click-path in this tenant is not.

- Someone excluded an entity from score computation (Include toggle) so the board number dropped. The server is still on the internet. Exclusion is an override, not a fix.

   Do not invent a tenant score, and do not chase peer

   This page never assigns a fake integer to lab.example. Use the documented band (High = 51–75) and the factor fields. Peer score is a comparison strategy (default Zscaler-defined, or custom industry / region / revenue). Beating peers is not remediation. Monte Carlo dollars on Financial Risk are a loss estimate, not the org score.

## Score, category, factor, entity

 An  organisation risk score  is the average of the four category scores. Hover the dollar symbol for financial estimates;  View Details  opens Financial Risk. That is a different page. Category scores still have to be explained by factors.

 A  factor  is the quantified condition. Risk360 weights it, adds it to the org score, and maps it to frameworks such as MITRE and NIST.  Your Score  on the factor depends on severity;  0 is a healthy score . Last 30 Days is the trend graph. Entities name who or what is affected. Recommended Actions are how you drive the factor toward healthy — if Licensed? is Y.

   Path · score, then category, then factor, then the fix

   Feel of the order. Exact Admin objects — Dashboard bands, Top 10 Factors, Insights Explore, Seeds Management — are in the SVG and runbook. Do not read “Fix” as “exclude the entity.”

#### Org score

 Average of four categories. Bands: Low 0–25, Medium 26–50, High 51–75, Critical 76–100. GUI:  Dashboard  (Experience Center:  Analytics › Risk360 ).

#### Category

 External Attack Surface (exposed servers, ASNs). Compromise (events, configs, traffic). Lateral Propagation (private access / segmentation). Data Loss (sensitive-data attributes).

#### Factor

 Weighted input. Fields: Factor Name, Category, Your Score, Last 30 Days, Entities, Licensed?, Recommended Actions. List View = attack-based; Tree View = entity-based.

#### Entity

 Workforce (risky user activity), 3rd Parties (contractors), Applications (unsanctioned / weaker SaaS), Assets (exposed organisational assets). Filter tiles on Tree View.

   Say this out loud

   The org score is an average of four stages. I do not fix the average. I open the factor, read the entity and the recommended action, change the owning control, then watch Your Score toward 0.

## Dashboard → factor → recommended action

 Read the dashboard first, but do not stop there. Identify which of the four categories moved. Open  Top 10 Factors  (View All → Factors) or  High Impact Recommendations  (Explore / View All → Insights). On the factor, the drawer has Details (severity, recommended actions, description, help link, jump to the responsible Zscaler service), Notes, and related problems. Insights lists the problem statement plus the recommendation. Investigate is where you can include or exclude an entity — with an Entity Override Note, which lands in audit logs.

   Flow 1 · High band on the org tile, owners say “not a ticket”

       Dashboard org score to category to factor to recommended action to owning control to Last 30 Days proof

- 1 Dashboard org · High 51–75 2 Category which of four moved 3 Factor Your Score · 0 = ok 4 Action Licensed? Y / N 5 Control ZIA / ZPA / seed 6 Proof = Last 30 Days + Your Score toward 0 Lab: External Attack Surface · factor example “exposed servers” · entity Assets · seed lab.example Insights Explore → Investigate. Include/exclude requires Entity Override Note (audit). Stop at step 1: owners get a High tile and no factor. That is the original ticket. Do not globally block ZIA to “move the average.” Do not exclude the entity to fake a drop. Licensed? = N: the factor is still scored; the recommended action needs a feature this tenant does not have. Source: About the Dashboard in Risk360; About Factors; About Insights. Read left → right, then the gold bar. Route the human to the factor before anyone debates the average. Object Lab / documented value If missing Org score band High (51–75) — documented range, not an invented tenant integer You are arguing a colour. Open the four category scores. Category External Attack Surface (lab) — exposed servers / ASNs Average hides a quiet Compromise next to a loud External. Seed domain lab.example · max 10 domains · first scan 24–48 h · weekly after EAS factors stay empty or stale. Score is not “safe”; it is under-fed. Factor Dashboard example: exposed servers · Your Score not 0 · Severity High No work item. Owners are correct that the org tile is not actionable. Entities Assets (lab). Also Workforce, 3rd Parties, Applications Cannot assign an owner. Tree View filter tiles are empty of meaning. Licensed? Y or N for the feature the recommended action needs N: do not call the factor a false positive. Escalate licence or pick another action. Recommended action Drawer + Insights problem/recommendation · Explore You will change the wrong ZIA rule. Follow the jump link to the responsible service. Closure proof Last 30 Days down · Your Score toward 0 Jira Resolved while the factor graph is flat. Board pack still High. ## Factor vs peer vs dollars vs asset score Pick the pane for the question you are actually answering. Mixing them is the usual “we beat peers so the exposed server is fine” ticket. Flow 2 · four numbers, four jobs Org average versus factor Your Score versus peer versus financial exposure Org score average of 4 stages Low 0–25 … Crit 76–100 Dashboard tile Factor score Your Score · 0 = healthy weight + severity this is the work item Peer score comparison strategy industry / region / revenue not a recommended action Financial risk Monte Carlo $ estimate hover dollar · View Details not the org average Asset-level risk (Assets page) is a later drill — 65+ indicators, pre- and post-infection behaviour — not a substitute for the org average. ZIA User Risk Score is a user object that can feed Risk360. Do not reset a user to Low and call the org factor closed. Third-party factors (CrowdStrike CrowdScore, Qualys/Tenable/Rapid7/Wiz/MDE vulns) need a Data Fabric connector. Empty connector ≠ healthy factor. Source: About the Dashboard; About Factors; Viewing Asset-Level Risk; Integrating 3rd-Party Connectors. Four columns, four tickets. The gold panel is the only one that names a recommended action. Need Use Skip What should ops do this week? Factors List View + High Impact Recommendations / Insights Org tile alone, or peer rank. Who is affected? Tree View entity tiles: Workforce, 3rd Parties, Applications, Assets Mailing security@ with the average. Board $ exposure Financial Risk · Monte Carlo (optionally Simulate breach probability) Treating the dollar hover as a factor score. Are we worse than industry? Peer Score Settings (default Zscaler-defined, or custom vertical / region / revenue) Using “better than peer” as closure of an exposed-server factor. EDR / vuln scanner input Data Fabric connector, then the named Risk360 factor (e.g. CrowdStrike - Zero Trust Score) Assuming ZTE telemetry already covers CrowdStrike unmanaged devices. ## Runbook Side A / B / C Side A is feed and dashboard read. Side B is the factor and the recommended action. Side C is the owning control and the re-score. Do not start at C, and do not start in Jira. ### Side A — seed the surface, read the average #### Admin role, then Seeds Management Experience Center: add a Risk360 admin role and assign it via ZIdentity / Authentication Service entitlements. Then Administration › Admin Management › Administrator Management › Seeds Management . Add lab.example (max 10 domains, or CSV). First scan 24–48 h; then weekly. Source: Step-by-Step Configuration Guide for Risk360; Adding a Domain for External Attack Surface Analysis.

- #### Open Dashboard — name the band and the category Analytics › Risk360 › Dashboard (or Risk360 Admin Portal › Dashboard). Read the org band (Low / Medium / High / Critical). Identify which of the four categories is driving it. Do not quote a made-up integer in the ticket. Source: About the Dashboard in Risk360.

     https://admin.zscaler.net/ · Analytics › Risk360 › Dashboard

     Training mock · not live

       Analytics / Risk360 / Dashboard

### Organisation risk score

          Org band  High (51–75)

          Peer  Default (Zscaler-defined)

          Category driving movement  External Attack Surface

          Financial estimate  $ hover → View Details

        Top 10 Factors (excerpt)  exposed servers · Category External Attack Surface · Your Score ≠ 0 · Entities Assets · Licensed? Y

         View All Factors
         High Impact Recommendations

   Training mock. Band is documented; no tenant integer is invented. Next click: View All → Factors, or Explore on a High Impact Recommendation. Source: About the Dashboard in Risk360.

### Side B — factor drawer, then Insights

- #### Open the factor — List View first Factors . Attack-based List View is one list you can CSV-export (export ignores UI filters). Tree View is entity-based. Columns: Factor Name, Category, Your Score, Last 30 Days, Entities, Licensed?, Recommended Actions. Click a column (not Licensed?, Include, or Entities) for the drawer. Source: About Factors.

- #### Read Details before changing policy Drawer: severity (critical / high / medium), recommended actions, description, help article, link to the Zscaler service responsible for the factor. Notes are yours. Related problems jump to Insights. If Licensed? is N, stop and name the missing feature — do not “tune” an unrelated ZIA rule.

- #### Insights = the remediation queue Insights : problem title, category, generated day, problem statement, recommendation, trend, Explore. High Impact Recommendations on the dashboard View All lands here. Source: About Insights in Risk360.

     https://admin.zscaler.net/ · Risk360 › Factors › drawer

     Training mock · not live

       Factors / List View / exposed servers

### Factor drawer · Details

          Factor Name  exposed servers

          Category  External Attack Surface

          Your Score  not 0 (0 = healthy)

          Severity  High

          Entities  Assets

          Licensed?  Y

        Recommended Actions  Follow Insights recommendation; jump to the responsible Zscaler service. Do not exclude the entity to drop the average.

         Notes
         Explore problem

   Training mock. “exposed servers” is a dashboard example of an underlying factor, not a made-up product SKU. Your Score is shown as not-0 on purpose — this page does not invent a tenant integer. Source: About Factors; About the Dashboard.

   Investigation notes (ticket body — copy the fields, not a fake score)
   Tenant: lab.example (seed)
Org band: High (51-75)     # documented range, not a made-up integer
Category moved: External Attack Surface
Factor: exposed servers
Your Score: not 0 (0 = healthy)
Severity: High
Entities: Assets
Licensed?: Y
Last 30 Days: rising
Recommended action: (paste from drawer / Insights)
Owning control: (ZIA / ZPA / seed / Data Fabric connector)
Proof after change: Last 30 Days + Your Score toward 0
Do not: exclude entity without Entity Override Note; do not quote peer as closure

### Side C — change the owning control, then re-score

- #### Fix where the factor is generated Use the drawer’s jump to the responsible Zscaler service. External Attack Surface often means take the host off the internet (or correct the seed). Compromise / Data Loss often means ZIA threat or DLP policy. Lateral Propagation often means ZPA / segmentation. Third-party named factors need the Data Fabric connector actually ingesting (CrowdStrike CrowdScore, Qualys, Tenable, Rapid7 InsightVM, Wiz, Microsoft Defender for Endpoint — as documented). Source: Integrating 3rd-Party Connectors for Risk Factors; What is Risk360.

- #### Include / exclude is an override, not a patch On Investigate, Include toggle + Entity Override Note (reason required). Multi-entity edits share one note. Username and reason go to audit logs. Use this for false attribution, not to paint the board pack green. Source: Investigating Sections of a Problem.

- #### Prove on the factor, not on Jira Re-open the same factor. Last 30 Days should bend. Your Score should move toward 0. Org band may lag because it is an average of four categories. Optional: alert rule on org / factor-group / factor score change, or on potential financial loss — email or webhook (Analytics › Risk360 › Alerts › Webhooks). Source: About Alerts; About Factors.

   Green proof

   Same factor row: Last 30 Days no longer rising, Your Score toward 0, Licensed? still Y, entity still included. Org band may still be High if another category did not move — that is the average working as designed, not a failed fix.

## One investigation after go-live

 Monday: Dashboard High (51–75). External Attack Surface is the category that moved. Top 10 shows exposed servers, entity Assets, Licensed? Y, Your Score not 0. Drawer recommended action plus Insights Explore name the internet-facing asset on seed  lab.example . Owner takes the host off the public edge (or you wait out the 24–48 h if the seed was only just added). You do not exclude the entity. You do not reset a ZIA User Risk Score to Low.

 Wednesday: same factor, Last 30 Days bending down, Your Score nearer 0. Compromise and Data Loss unchanged, so the org average may still sit in High. That is expected. File residual risk against the other two categories, not against this factor.

   Proof · factor trend toward healthy, not a closed ticket

   Ops feel. The actual evidence is the factor’s Last 30 Days graph and Your Score toward 0. Artwork checkmarks are not Risk360.

   Alert on the factor, not only the average

   Alert rules can fire on change in risk score at organisation, factor-group, and factor levels, and on change in potential financial loss. If you only alert on the org tile, a loud External factor can be cancelled in the average by a quiet Data Loss category until it is too late for the owner.

## Traps + proof

       Symptom  Likely cause  Proof

        High org tile, owners refuse the ticket  Nobody opened the factor / entity / recommended action  Dashboard Top 10 + Factors drawer fields in the ticket body
        EAS category empty or stale  No seed domain, or still inside 24–48 h first scan  Seeds Management list; scan frequency weekly after add
        Recommended action does nothing  Licensed? = N, or jump link ignored and a random ZIA rule was edited  Licensed? column; drawer link to the responsible service
        Org number dropped overnight, server still public  Include toggle excluded the entity  Audit log: username + Entity Override Note
        “We beat industry”  Peer strategy used as closure  Peer Score Settings (default vs custom). Factor Last 30 Days unchanged
        CrowdStrike / Qualys factor silent  Data Fabric connector not ingesting  Connector config; named factors in the 3rd-party table
        Jira Resolved, board still High  Average of four categories; other category still loud — or factor never moved  Same factor Your Score still not 0; check the other three categories
        User Risk Score reset to Low  Wrong object. That is ZIA user behaviour, not the org factor  Factors page still lists the org factor

   Do not globally block to “move the average”

   The recommended action is scoped to the factor and the responsible service. A tenant-wide ZIA block to paint the org tile is how you create the next outage ticket. Follow Insights, then prove on that factor’s Last 30 Days.

   Pilot checklist

- Risk360 admin role assigned. Seeds Management has lab.example (≤ 10). Wait 24–48 h before calling EAS “empty.”

- Dashboard: org band named (not an invented integer). Category that moved named.

- Factor row captured: name, category, Your Score (0 = healthy), Last 30 Days, entities, Licensed?, recommended action.

- Insights Explore opened. If Include/exclude used: Entity Override Note in audit.

- Owning control changed. Re-read the same factor. Your Score toward 0. Org band allowed to lag.

## Knowledge check

   Six judgment items. Submit once. Reasons point back at the section to re-read.

       Q1
       Dashboard shows High (51–75). Application owners say the number is not a work item. First move?

           Enable a global ZIA block so the average drops this week.
           Name which of the four categories moved, then open Top 10 Factors / the factor drawer.
           Switch peer strategy until the tile is below industry.
           Reset ZIA User Risk Score to Low for the VIP users.

       Correct:  b . Org score is an average of four stages. The work item is the factor. Re-read Why the org number is not a ticket and Flow 1.

       Q2
       On a factor row, what does Your Score of 0 mean?

           Healthy score for that factor. The total depends on severity; 0 is healthy.
           The organisation is in the Critical band (76–100).
           Licensed? is N, so the factor is ignored.
           Peer average for your industry vertical.

       Correct:  a . Documented: the total score for a factor depends on its severity, 0 being a healthy score. Licensed? and peer are different columns. Re-read Score, category, factor, entity.

       Q3
       Licensed? shows N on the factor you want to fix. What is true?

           The recommended action is already complete.
           The factor is a false positive and should be deleted from MITRE mapping.
           You are not subscribed to the feature the recommended action needs. The factor can still score.
           Exclude the entity immediately; no note required.

       Correct:  c . Licensed? is whether you subscribed to the feature required to implement the recommended action (Y/N). It is not a health bit. Re-read Flow 1 and Side B.

       Q4
       Which answer treats the board-pack number as separate from fixing the factor?

           Email the org band. Owners should already know what to patch.
           Quote the Monte Carlo dollar hover as the remediation target.
           Hide the factor from Reports so the CISO pack is quieter.
           Open the factor drawer: entities, recommended action, jump to the responsible service, then Insights Explore.

       Correct:  d . Actionable means factor fields plus Insights, not the average, not dollars, not a hidden row. Re-read Flow 2 and Side B.

       Q5
       What is proof that remediation on this factor actually landed?

           Jira status Resolved.
           Peer score now better than industry.
           Same factor: Last 30 Days bending and Your Score moving toward 0 after the owning control changed.
           Seeds Management shows 10 domains, regardless of the factor graph.

       Correct:  c . Closure is the factor trend and Your Score toward healthy. Org band may lag because it averages four categories. Re-read Side C and Traps.

       Q6
       You want to drop an entity out of score computation. What is the documented path?

           Investigate → Include toggle → Entity Override Note (reason). Audit stores username and reason. This is not a patch.
           Silent Licensed? flip to N.
           Change peer strategy to a different revenue range.
           Reset the user’s ZIA User Risk Score to Low.

       Correct:  a . Include/exclude requires an explanation and is audited. Exclusion is an override, not remediation. Re-read Side C and Traps.

       Check answers
       Reset

## Sources

- Zscaler Help — What is Risk360 (four attack stages: External Attack Surface, Compromise, Lateral Propagation, Data Loss)

- Zscaler Help — About the Dashboard in Risk360 (org score is the average of four categories; bands Low 0–25, Medium 26–50, High 51–75, Critical 76–100; Top 10 Factors; High Impact Recommendations; entities Workforce / 3rd Parties / Applications / Assets; Your Score 0 = healthy)

- Zscaler Help — Viewing the Risk360 Dashboard (Experience Center: Analytics › Risk360)

- Zscaler Help — About Factors (risk weight; List View / Tree View; drawer Details; Licensed?; MITRE / NIST mapping)

- Zscaler Help — About Insights in Risk360 (problem + recommendation + Explore)

- Zscaler Help — Investigating Sections of a Problem (Include toggle, Entity Override Note, audit)

- Zscaler Help — Adding a Domain for External Attack Surface Analysis and About Seeds Management (≤ 10 domains, 24–48 h, weekly scans)

- Zscaler Help — Step-by-Step Configuration Guide for Risk360

- Zscaler Help — Accessing and Navigating the Risk360 Admin Portal (Dashboard, Factors, Assets, Insights, Financial Risk, Frameworks, Reports)

- Zscaler Help — Integrating 3rd-Party Connectors for Risk Factors (Data Fabric; CrowdStrike, Qualys, Tenable, Rapid7, Wiz, MDE)

- Zscaler Help — About Alerts and Configuring Alert Webhooks

- Zscaler Help — Viewing Asset-Level Risk (asset-level model is separate from the org average)

- Zscaler Help — Managing Peer Score Settings

- Zscaler — Risk360 product and Risk360 solution brief (100+ factors; 0–100 with 100 critical — marketing scale; this lesson uses Help bands for operations)

 Related:  Zero Trust Exchange factory  ·  ZIA authentication (SAML + SCIM)  ·  ZIA DLP  ·  ZPA access policy  ·  Cortex Xpanse — internet-facing asset

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
