Skip to main content

Reading your Qorionix Score

One number from 0 to 100, built from the same posture checks as your report. How it is calculated, what a lost point means, how to fix one with undo, and why only the modules you have bought count towards it.

Written for the business owner8 min readUpdated

The Score is one number from 0 to 100 on your Overview page. It answers a question a posture report full of findings does not answer quickly: how are we doing, overall, right now? It is not a second assessment — it is the same checks your posture report already runs, read a different way.

How the number is calculated

Every one of the roughly 80 posture checks has a published point value. A tenant that passes every check it can be measured on reaches 100; each open finding subtracts its check's point value. The point value for a check is not picked by hand — it comes from a small formula, so the reasoning behind any single number can always be re-derived rather than taken on trust:

How a check's severity becomes its starting point value, before it is scaled up
SeverityStarting points
Critical10
High6
Medium3
Low1.5
Info0

That starting value is then scaled up by two tags every check carries: how directly it matters to a ransomware attacker (0-3) and how directly it answers a question a cyber-insurance underwriter asks on a proposal form (0-3). A critical check that both attackers and underwriters care about a great deal is worth more than a critical check that is real but narrower. Every check's value is finally scaled so the whole set adds up to exactly 100 — which is why the numbers are not round.

What a lost point means

Every point your Score is missing traces back to one specific, open finding about your own tenant, in the same plain language your posture report already uses — never a vaguer, score-specific sentence. Open any lost-point item and you see the real people, devices or applications it is about, exactly as your posture report names them.

The Score page lists your open findings worst-first by ransomware and insurer relevance, not by severity alone — a different order from the one your posture report uses. Severity, blast radius, and what to fix first explains the report's own ordering; the Score's ordering exists because "which of these would a ransomware operator or an underwriter ask about first" is a genuinely different question from "which of these is most severe", and a medium-severity finding both audiences care about a great deal can sit above a critical finding neither does.

criticalZQ-M365-PRIV-002

Administrator accounts are also used for daily email

Why it matters
An account that reads email all day is exposed to every phishing message that arrives. When that same account can delete everything the business has in Microsoft 365, one bad click is the end of the business rather than an inconvenience.
What the attacker does
The attacker sends a convincing invoice. The admin opens it on the account that can disable every other account and switch off the audit log, so nobody can see what was taken or undo it.
The fix
Give each of these people an ordinary account for daily work and keep the admin account for admin only, with a hardware-backed passkey on it. About ten minutes per person.
Mapped obligations:NIS2 Art 21(2)(i)NIS2 Art 20CIS M365 1.1.4ISO 27001 A.8.2

This is one of the highest-weighted checks in the whole catalogue for exactly the reason its rationale states: attackers target it directly, and it is one of the first questions most cyber-insurance proposal forms ask about. It is why it appears near the top of most tenants' Score pages rather than buried under lower-severity noise.

"Fix it", with undo

Every open finding shows one of two things, never a locked padlock and never a dead end:

A typed fix
When your posture report already proposed a specific, executable change for this finding, the Score page offers the same Approve fix and Undo controls the report itself uses — see Done, approve, decide. Approving records who decided and when; nothing here bypasses that trail or invents a second approval path.
How to fix it yourself
When no automatic change exists for a check yet, the finding carries the same plain-English "how to fix it yourself" instructions your posture report shows, so you are never told only what is wrong and not what to do about it. On a plan with AI, a Walk me through it control turns that same paragraph into a numbered guide written around your own names and devices — see The Fix-it coach.

Only what your plan covers counts

The Score never counts, and never lists, a check tied to a module your plan does not include — it is left out of the total entirely rather than shown locked. A Free-plan tenant's Score is out of the identity checks alone; upgrading to add device or log-source coverage widens what the Score measures, it does not retroactively mark you down for coverage you never had. See Choosing which modules to turn on and Plans and what each includes.

A check your plan does cover but that could not run this time — a permission your Microsoft 365 licence does not grant, a dataset that was not readable — is treated the same way your posture report treats a coverage gap: named, explained, and left out of both the total and the points lost. It is never counted as a silent pass.

History

Your Score page shows the number at each of your past completed assessments, so you can see whether you are trending up or down rather than only where you stand today. History is read against today's weights and today's plan, so it answers "am I improving", not "what would this have scored on an old version of the checklist".

What to do next

  1. Reading your posture report — the full report the Score is built from.
  2. Done, approve, decide — what approving a fix actually commits to.
  3. Undo a change — reversing a fix, in full.
  4. Choosing which modules to turn on — widen what your Score can see.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in your posture report