Skip to main content
Category: Vulnerability & Exposure Management

Severity Rating

Also known as: Severity Score, Severity Scale
Simply put

A severity rating is a way of scoring how serious a problem, issue, or risk is based on the impact it could have. Organizations use these ratings to compare issues and decide which ones deserve attention first. The scale used can vary widely depending on the organization and what is being evaluated.

Formal definition

A severity rating is a structured measure used to evaluate the seriousness or potential impact of an issue, defect, or risk, often expressed on an ordinal scale (for example, 1 to 10, or discrete coded values) where higher values indicate greater severity. It is commonly applied within risk assessment and prioritization processes to rank issues by their effect, such as impact on the user experience or on organizational operations. Severity scales are frequently customized to a specific organization or domain rather than following a single universal standard; a generic scale typically serves as a starting point for developing organization-specific criteria. Severity ratings often represent only one dimension of overall risk and may be combined with other factors during prioritization.

Why it matters

Severity ratings give organizations a common language for comparing very different problems and deciding where to direct limited attention and resources. Without a structured way to score seriousness, teams tend to react to whatever is loudest or most recent rather than to what carries the greatest potential impact. A consistent severity scale supports more defensible prioritization, allowing leaders to explain why one issue is being addressed ahead of another based on its likely effect on users or on operations.

The value of a severity rating depends heavily on how well the scale is defined and how consistently it is applied. Because severity scales are frequently customized to a specific organization or domain rather than following a single universal standard, two organizations using the same nominal scale, such as 1 to 10, may mean quite different things by a given number. A generic scale typically serves only as a starting point for developing organization-specific criteria, and its usefulness erodes when the underlying definitions are vague or interpreted differently across teams.

It is also important to recognize that severity often represents only one dimension of overall risk. Rating how serious an issue could be is not the same as determining how likely it is to occur or how urgently it must be handled, and treating a severity number as a complete risk verdict can lead to misallocated effort. In practice, severity ratings are most effective when they are combined with other factors during prioritization rather than used in isolation.

Who it's relevant to

Risk and Quality Teams
Teams responsible for risk assessment and prioritization use severity ratings to rank issues by their potential effect and to decide which deserve attention first. They also carry the responsibility of adapting generic scales into organization-specific criteria so that ratings remain consistent and meaningful.
Security and Governance Leaders
Leaders who oversee security and risk programs rely on severity ratings as one input to prioritization decisions. They should treat severity as a single dimension of risk to be combined with other factors, rather than as a standalone measure of how urgent or likely an issue is.
Domain and Operational Specialists
Practitioners in specific fields apply severity scales tailored to their domain, including coded schemes that capture domain-specific meanings of seriousness. Their input helps ensure that the criteria behind each rating level accurately reflect real impact on users or operations.

Inside Severity Rating

Severity Classification Levels
A tiered scheme, often expressed as Critical, High, Medium, Low, or numeric bands, used to categorize the seriousness of a vulnerability, security finding, or incident. The specific labels and thresholds may vary by organization and by the source framework applied.
Impact Assessment
An evaluation of the potential consequence to confidentiality, integrity, or availability, and to business operations, should the issue be exploited or realized. In many vCISO engagements this is where technical findings are translated into business risk terms for executive decision-making.
Likelihood or Exploitability
A judgment of how probable or feasible exploitation is, factoring in exposure, attacker skill required, and existing controls. Combined with impact, this typically informs the overall severity rating.
Scoring Methodology
The underlying model used to derive the rating, such as CVSS for vulnerabilities or a qualitative risk matrix for broader findings. The chosen method should be stated so that ratings remain consistent and defensible across assessments; methodologies may vary by provider.
Contextual Adjustment
Refinement of a base rating to reflect the client's specific environment, asset value, data sensitivity, and compensating controls. A base score from a generic tool often does not equal the organization's actual severity until context is applied.
Remediation Priority Linkage
The connection between a severity rating and the urgency or ordering of remediation activity, frequently used to drive service-level expectations and resource allocation. The rating advises prioritization but does not itself remediate the issue.

Common questions

Answers to the questions practitioners most commonly ask about Severity Rating.

Isn't a severity rating the same thing as a vulnerability's risk to my organization?
Not necessarily. A severity rating typically describes the intrinsic seriousness of a finding, incident, or vulnerability, often derived from standardized scoring such as CVSS base metrics or an internal severity scale. Risk, by contrast, incorporates context such as asset value, exploitability in your environment, existing compensating controls, and business impact. A high-severity vulnerability on an isolated, non-critical system may present lower actual risk than a medium-severity issue on an internet-facing system holding regulated data. In many engagements, a virtual CISO helps translate raw severity ratings into contextualized risk so that prioritization reflects business reality rather than the score alone. Treating severity as a direct substitute for risk is a common mistake an experienced practitioner would correct.
Does a high severity rating mean the issue must be fixed immediately, no matter what?
Not automatically. Severity often informs urgency, but it does not by itself dictate remediation timelines. Many organizations define service level expectations that pair severity with additional factors such as exploit availability, exposure, and operational constraints. A vCISO typically advises on how severity feeds into prioritization and remediation policy, but the accountability for accepting, deferring, or funding remediation generally remains with the client organization and its officers. Severity is an input to a decision, not the decision itself, and rigidly equating high severity with drop-everything action can distort limited remediation capacity.
How should we define severity levels so they are consistent across our program?
In many engagements, consistency comes from documenting a defined severity scale with explicit criteria for each level, such as what distinguishes critical from high or medium. Organizations often anchor these definitions to a recognized method like CVSS for vulnerabilities, while adding qualitative descriptors for incidents and audit findings. A virtual CISO can help establish these definitions, but the value depends heavily on organizational maturity and stakeholder cooperation to apply them uniformly. It is worth noting that a vCISO advises on and directs the framework; they typically do not perform the hands-on scanning or tool administration that generates the underlying scores unless that is explicitly contracted.
Who should assign and validate severity ratings within our organization?
Assignment often begins with the tool, tester, or analyst that identifies a finding, but validation and adjustment usually involve the security function applying environmental context. A virtual CISO commonly advises on governance for this process, including who has authority to raise or lower a rating and how those decisions are documented. Because a vCISO operates in an advisory and directive capacity rather than performing operational monitoring, the routine assignment and triage typically sit with internal staff or a contracted operational provider. The vCISO helps ensure the process is defensible and consistent, while accountability for the resulting decisions remains with the client.
How do severity ratings relate to compliance frameworks like PCI DSS or ISO 27001?
Several frameworks and standards expect organizations to prioritize and address findings in a risk-informed way, and severity ratings often support that. For example, PCI DSS requires ranking vulnerabilities so that the most serious are addressed appropriately, and ISO 27001 supports a risk treatment process that severity data can feed. However, a well-defined severity scale supports readiness and demonstrable process; it does not by itself guarantee compliance or certification. A vCISO can help align your severity practices with framework expectations, but asserting that a rating system alone satisfies a standard would overstate its role.
Can severity ratings be adjusted after they are initially assigned?
Yes, and in practice they often should be. Initial ratings, particularly automated ones, may not reflect compensating controls, actual exposure, or newly available exploit information. Many programs allow documented adjustment, sometimes called environmental scoring or contextual re-rating, provided the rationale is recorded and approved through defined governance. A virtual CISO typically advises on when and how such adjustments are appropriate to avoid inconsistency or the appearance of downgrading findings to avoid work. The effectiveness of this depends on clear scope, defined authority, and stakeholder access, and the final decisions remain the accountability of the client organization.

Common misconceptions

A severity rating is an objective, universal number that means the same thing everywhere.
Severity ratings are influenced by the scoring methodology chosen and by organizational context. A high base score, such as one from CVSS, may be lower in practical severity where compensating controls exist, and thresholds and labels can vary by provider and framework. Ratings are best treated as a structured judgment, not an absolute fact.
Assigning a high severity rating means the vCISO is now accountable for fixing or preventing the underlying issue.
A virtual or fractional CISO typically advises on and directs prioritization based on severity, but legal and organizational accountability for acting on those ratings and for security decisions generally remains with the client organization and its officers. Hands-on remediation, monitoring, or incident response execution is usually out of scope unless explicitly contracted.
A high severity rating on a finding means the organization is out of compliance or cannot achieve certification.
Severity ratings support risk prioritization and readiness efforts rather than determining compliance status by themselves. Frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, or HIPAA have their own criteria, and a vCISO engagement can support readiness without guaranteeing certification or asserting that a given rating alone establishes pass or fail against a standard.

Best practices

Document and consistently apply a defined scoring methodology, such as CVSS for vulnerabilities or a documented qualitative risk matrix, so that severity ratings are repeatable and defensible across assessments.
Adjust base ratings for the client's specific context, including asset value, data sensitivity, exposure, and compensating controls, rather than reporting generic tool output as final severity.
Translate severity into business risk language for executive stakeholders, since security leadership is a governance and business risk function and not a purely technical exercise.
Clarify in the engagement scope who is responsible for remediation tied to each severity level, recognizing that the vCISO typically advises and prioritizes while the client organization retains accountability for acting on the findings.
Link severity ratings to remediation timelines or priority tiers so stakeholders understand the expected urgency, while avoiding guarantees of breach prevention or fixed outcomes.
Recognize that the reliability of severity ratings depends on organizational maturity, client cooperation, and access to accurate asset and control information, and note these dependencies when reporting.