Skip to main content

Understanding Likelihood of Breach V3: How Remediation Progress Reduces Your Risk

Understand how remediation progress, asset importance, and severity work together to lower your Likelihood of Breach.

Overview

Likelihood of Breach represents the probability—from 1% to 100%—that a specific Business Asset will be compromised. The Cye Platform calculates this score based on active attack paths and your current remediation progress.

This is a continuous model: your score reflects the work currently in progress. As you resolve individual remediation assets, your Likelihood score improves incrementally. You do not have to wait for an entire finding to be "Fixed" to see a reduction in risk.


How Likelihood Is Calculated

  • The Logic: Importance and Severity

    Not all remediation work impacts your risk profile equally. The platform uses both Importance and Severity weighting to ensure your score accurately reflects your security posture.

    • Importance (1–5): Assigned to the asset to reflect its criticality to your operations.

    • Severity: Reflects the technical gravity of the vulnerability itself.

The synergy between these two factors determines the total impact on your
score. For example, resolving an asset with Importance 5 and Critical severity
will result in a significantly higher reduction in Likelihood than an asset with
​ Importance 5 and High severity. This ensures your progress is driven by the
actions that most effectively block the most dangerous attack paths.

Note:
​
The platform assigns Importance automatically using heuristic rules. If needed, you can override the automatically assigned Importance value from the finding detail view to better reflect your specific environment.

  • How Progress is Determined

    Progress is the completion ratio of a finding's remediation assets. You can manage this through two modes, identified by the A (Automatic) or M (Manual) icons.

    • Automatic Calculation (Default): Cye Platform tracks the real-time status of remediation assets. The resolution of individual assets automatically determines progress. For example, if a finding has four remediation assets and three of the four are marked Fixed, progress is 75%. Progress reaches 100% only when every remediation asset is Fixed. While even one asset is still open, the finding shows 99% at most.

    • Findings Without Assets: For findings without specific technical assets, the platform cannot track progress automatically. Progress shows 0% while the finding is open and 100% once you mark the finding Fixed, unless you set a manual value.

    • Manual Override: A progress percentage can be set manually when the automatic calculation does not reflect the true state of efforts. This allows the dashboard to align with real-world progress if automated assessments are deemed inaccurate. A manual value remains until it is updated or reset to Automatic.

  • How Remediation Asset Status Affects Your Score

    The specific status you assign to a remediation asset dictates its impact on your overall score:

    • Fixed: This status confirms the work is completed. It is the only status that increases progress and lowers your Likelihood of Breach.

    • Acceptable Risk: This is a management acknowledgment, not a mitigation. Because the asset still contributes active risk to the attack path, it does not increase progress or reduce the Likelihood score.

    • Not Relevant: This removes the asset from the risk equation entirely. It is excluded from the calculation so it does not hold back the progress percentage, but it does not represent a technical mitigation of risk.

  • Marking a Finding Fixed Before It's 100% Complete

    You can mark a finding as Fixed even if some of its remediation assets are still open. When you do:

    • The finding behaves as Fixed everywhere in the platform, including the Org Attack Graph.

    • Its Exposure Reduction and Priority are calculated from the progress achieved so far, then frozen at that value.

    • A short warning appears before the change goes through. It informs you; it does not block the change.

    For the full list of what changes, see Changing the status of a finding.


Exposure Reduction in Remediation Assets

Each remediation asset is assigned an Exposure Reduction value, representing the estimated drop in risk exposure that resolving that specific asset will deliver. Each value is calculated independently, without assuming that any other finding or remediation asset has already been fixed.

  • High-Volume Environments: In environments with a high volume of assets (typical with integrations), many remediation assets may share the same Exposure Reduction value. This is expected and reflects the platform's optimized calculation across large datasets.

  • Calculation Variance: Exposure reduction is estimated per item. Due to rounding and optimized calculation logic, the sum of individual remediation assets may not perfectly match the finding's total Exposure Reduction. Small discrepancies between these totals are normal and expected.

  • Fixed Items Keep Their Last Value: Once a remediation asset or finding is Fixed, its last recorded Exposure Reduction stays visible, grayed out, for reference only. It no longer affects your organization's exposure. The Exposure Reduction column is always shown; None appears only when a value cannot be calculated.


Priority Follows Exposure Reduction

Recommended Priority ranks findings by their own Exposure Reduction, highest first. It does not assume that higher-priority findings have already been fixed, so the Priority and Exposure Reduction columns always agree.

Critical to Block marks a finding on a route that must be cut to sever the attack paths to a Business Asset. It is assigned only to findings on the Org Attack Graph and does not change a finding's Priority.


Monitoring Business Assets

Likelihood is aggregated at the Business Asset level. Any score exceeding 50% is displayed in red to signal high-priority risk. As remediation assets are moved to Fixed, the Likelihood score for every connected Business Asset updates automatically.

At the organization level, the ribbon displays Total Exposure, Total Cost of Breach, and Average Likelihood: the average of the Likelihood scores across all your Business Assets. Updating a Business Asset's Cost of Breach value does not change Average Likelihood. In Root Cause Analysis the same figure is labeled Likelihood average.


Moving From Likelihood V2 to V3

When your organization switches to V3, your Likelihood and Exposure figures may move up or down, and the order of your findings may change, in some cases significantly. Four things drive the change:

  • Partial remediation now counts toward Likelihood.

  • Importance now weights each remediation asset.

  • Some integration findings now carry their full weight.

  • The Industry Attack Graph has been updated.

Your past remediation work still counts. In the Root Cause Timeline, the line stays continuous across the switch, with an explanation in Major Days and the Executive Summary on the day of the change if the shift is significant.

For how to switch versions and a side-by-side comparison of V2 and V3, see Switch Likelihood calculation versions in the Cye platform.


Wrap-up/ Next Steps

To drive effective risk reduction, prioritize your actions based on the platform's logic:

  1. Target Highest Exposure Reduction First: Prioritize remediation assets with the highest Exposure Reduction values. These provide the most substantial and immediate impact on your overall score. The Recommended Priority column gives you the same order.

  2. Correct Importance When Necessary: If the automated Importance doesn't align with your internal priorities, override it from the finding detail view. This ensures your Likelihood score reflects real-world risk.

  3. Understand the "Acceptable Risk" Limit: Use this status for tracking and internal acknowledgment, but recognize it is not a mitigation tool. Only Fixed statuses will actively improve your security metrics and lower your Likelihood score.

Did this answer your question?