Reading your Qorionix Score
One number from 0 to 100, built from the same posture checks as your report. How it is calculated, what a lost point means, how to fix one with undo, and why only the modules you have bought count towards it.
The Score is one number from 0 to 100 on your Overview page. It answers a question a posture report full of findings does not answer quickly: how are we doing, overall, right now? It is not a second assessment — it is the same checks your posture report already runs, read a different way.
How the number is calculated
Every one of the roughly 80 posture checks has a published point value. A tenant that passes every check it can be measured on reaches 100; each open finding subtracts its check's point value. The point value for a check is not picked by hand — it comes from a small formula, so the reasoning behind any single number can always be re-derived rather than taken on trust:
| Severity | Starting points |
|---|---|
| Critical | 10 |
| High | 6 |
| Medium | 3 |
| Low | 1.5 |
| Info | 0 |
That starting value is then scaled up by two tags every check carries: how directly it matters to a ransomware attacker (0-3) and how directly it answers a question a cyber-insurance underwriter asks on a proposal form (0-3). A critical check that both attackers and underwriters care about a great deal is worth more than a critical check that is real but narrower. Every check's value is finally scaled so the whole set adds up to exactly 100 — which is why the numbers are not round.
What a lost point means
Every point your Score is missing traces back to one specific, open finding about your own tenant, in the same plain language your posture report already uses — never a vaguer, score-specific sentence. Open any lost-point item and you see the real people, devices or applications it is about, exactly as your posture report names them.
The Score page lists your open findings worst-first by ransomware and insurer relevance, not by severity alone — a different order from the one your posture report uses. Severity, blast radius, and what to fix first explains the report's own ordering; the Score's ordering exists because "which of these would a ransomware operator or an underwriter ask about first" is a genuinely different question from "which of these is most severe", and a medium-severity finding both audiences care about a great deal can sit above a critical finding neither does.
ZQ-M365-PRIV-002Administrator accounts are also used for daily email
- Why it matters
- An account that reads email all day is exposed to every phishing message that arrives. When that same account can delete everything the business has in Microsoft 365, one bad click is the end of the business rather than an inconvenience.
- What the attacker does
- The attacker sends a convincing invoice. The admin opens it on the account that can disable every other account and switch off the audit log, so nobody can see what was taken or undo it.
- The fix
- Give each of these people an ordinary account for daily work and keep the admin account for admin only, with a hardware-backed passkey on it. About ten minutes per person.
This is one of the highest-weighted checks in the whole catalogue for exactly the reason its rationale states: attackers target it directly, and it is one of the first questions most cyber-insurance proposal forms ask about. It is why it appears near the top of most tenants' Score pages rather than buried under lower-severity noise.
"Fix it", with undo
Every open finding shows one of two things, never a locked padlock and never a dead end:
- A typed fix
- When your posture report already proposed a specific, executable change for this finding, the Score page offers the same Approve fix and Undo controls the report itself uses — see Done, approve, decide. Approving records who decided and when; nothing here bypasses that trail or invents a second approval path.
- How to fix it yourself
- When no automatic change exists for a check yet, the finding carries the same plain-English "how to fix it yourself" instructions your posture report shows, so you are never told only what is wrong and not what to do about it. On a plan with AI, a Walk me through it control turns that same paragraph into a numbered guide written around your own names and devices — see The Fix-it coach.
Only what your plan covers counts
The Score never counts, and never lists, a check tied to a module your plan does not include — it is left out of the total entirely rather than shown locked. A Free-plan tenant's Score is out of the identity checks alone; upgrading to add device or log-source coverage widens what the Score measures, it does not retroactively mark you down for coverage you never had. See Choosing which modules to turn on and Plans and what each includes.
A check your plan does cover but that could not run this time — a permission your Microsoft 365 licence does not grant, a dataset that was not readable — is treated the same way your posture report treats a coverage gap: named, explained, and left out of both the total and the points lost. It is never counted as a silent pass.
History
Your Score page shows the number at each of your past completed assessments, so you can see whether you are trending up or down rather than only where you stand today. History is read against today's weights and today's plan, so it answers "am I improving", not "what would this have scored on an old version of the checklist".
What to do next
- Reading your posture report — the full report the Score is built from.
- Done, approve, decide — what approving a fix actually commits to.
- Undo a change — reversing a fix, in full.
- Choosing which modules to turn on — widen what your Score can see.