User Risk Scoring
Learn how Behavior Threats calculates user risk scores from a transparent, fully
explainable model driven entirely by admin-configured weights.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
Behavior Threats® uses a transparent, fully explainable risk scoring model that gives you
complete control over how each user's risk score is calculated. We start with default
weights assigned to each policy, count of policy breach, thresholds measured by ML
policies, and the risk amplifier for the user (default is 1). Behavior Threats compiles
the risk score directly from these admin-configured weights, ensuring you always
understand exactly why a user was flagged.
How Weights Work
The scoring model is based on configurable admin controls for impacting risk scores. As
an admin, you can stack rank the policies by changing the default weights for each
policy. Higher the weight, higher the impact to risk score. You can also add users to a
watchlist and change the risk amplifier of the watchlist. Higher the risk amplifier,
higher the risk score for that user.
The Users Tab Dashboard
The
Users
tab dashboard displays a risk breakdown for each user, including their
overall score, severity level, incident count, and watchlist membership. You can filter
the list by risk level, policy type, or watchlist to focus your investigation on the
most critical users. The top risky users are prominently displayed for immediate
triage.
Severity-to-Score Mapping
The platform maps calculated risk scores to severity levels using the following
ranges:
| Risk Level | Score Range | Description |
| Very Low | 0–40 | Minimal risk; user behavior is within normal parameters. |
| Low | 41–60 | Slight elevation; minor anomalies detected but unlikely to indicate a
threat. |
| Medium | 61–80 | Moderate risk; multiple policy violations warrant
investigation. |
| High | 81–90 | Elevated risk; significant policy violations indicate potential
insider threat activity. |
| Critical | 91–100 | Severe risk; immediate investigation and remediation
recommended. |
Smart Decay Logic
To ensure that stale data does not trigger false positives, the platform applies
time-based decay to incident weights. Incidents are bucketed by recency, with more
recent incidents contributing more heavily to the overall score.
- Each incident contributes to your risk score based on its severity and the
associated policy weight.
- Over time, the contribution of each incident decays; that is, older incidents have
progressively less influence on your current score.
- The decay follows an exponential curve: an incident's influence reduces by
approximately half every 30 days.
- If no new incidents occur, a user's score gradually returns to the baseline score of
5.
Key Behaviors of Smart Decay Logic
- Recent incidents have the strongest impact on the score.
- Older incidents (for example, 60+ days) contribute very little to the score.
- New incidents increase the score immediately based on their severity.
- If an admin performs a manual score reset, all prior incidents stop contributing and
the score starts fresh from that point.
The risk score range is 5 (baseline, no risk) to 100 (maximum risk). Every day the decay
factor will decrease, it will not be same. This decay logic ensures that your risk
scores always reflect the current threat landscape rather than accumulating historical
noise.
Risk Amplifiers from Watchlists
If a user belongs to a
watchlist, their
risk amplifier multiplies the impact of policy
violations on their score. This contextual amplification ensures that high-priority
personas (departing employees, executives, vendors) receive proportionally higher
scrutiny.