A risk score you can defend to auditors
Every score traces to its signals and sources
kinetic8 turns thousands of findings into a single risk score — and every score traces back to the signals and sources that produced it, so security teams can defend their numbers to auditors and executives.

Why it matters
Traceable to the source
Every score decomposes into the exact findings, assets, and sources behind it. When leadership asks 'why is this a 72?', you have the evidence chain — not a vendor's black box.
Standards-aligned methodology
A four-pillar model weighs exposure hygiene, identity & access risk, coverage & visibility, and impact on important assets — anchored to NIST SP 800-30, NIST CSF 2.0, CISA SSVC, and CVSS v4.0.
Know what changed and why
Risk timelines and AI change analysis show exactly which assets moved and why — e.g. "5 new critical CVEs in production databases" — with methodology versioning so deltas reflect real change, not recalculation noise.
Capabilities
- Full score explainability — traces to signals, findings, and sources
- Exposure-first four-pillar risk model (45% / 20% / 20% / 15%)
- Per-asset and rolled-up scores updated on every sync
- Risk timeline with historical snapshots and trend analysis
- AI-generated risk-change explanations between snapshots
- Standards alignment: NIST 800-30/39, CSF 2.0, CISA SSVC/KEV, CIS v8.1
Related
See Explainable Risk Scoring on your own estate
Request a live demo — we'll map your environment in the session.
Request Demo