Methodology v1.0

How the Cyber Threat Status works

The threat status is calculated from what we have published. No editor can set it by hand. Each level is the sum of the signals below, and every point links back to the stories that produced it.

Principles

  • Only transparent, countable signals are used, such as confirmed exploitation, CISA KEV additions and government advisories.
  • Each signal has a cap, so a burst of minor news cannot inflate the level.
  • “Critical” also requires evidence of widespread exploitation or an active critical incident. Volume alone stops at “High”.
  • Six audience indicators (Home, Small Business, Enterprise, AI, Web/Apps, Critical Infrastructure) use the same rules on the stories labelled for that audience.
  • Classification errors are corrected by editors, and the status recalculates automatically.

Signals

SignalPoints eachCapWindow
Widespread exploitation
Stories reporting mass or widespread exploitation.
487 days
Critical, actively exploited
Critical-severity stories with confirmed exploitation.
3123 days
KEV additions used by ransomware
Vulnerabilities added to CISA KEV that are known to be used in ransomware campaigns.
267 days
New KEV additions
Vulnerabilities newly added to the CISA Known Exploited Vulnerabilities catalog.
167 days
Government / CERT advisories
High or critical advisories published by government agencies or CERTs.
147 days
Developing critical incidents
Critical stories that editors are actively tracking as developing or confirmed.
51014 days
High-severity news volume
All other high or critical severity stories.
0.543 days

A story counts toward only its most serious matching signal, except the KEV signals, which describe the catalog and always count.

Levels

LevelTotal points
Normal0+
Guarded4+
Elevated8+
High14+
Critical22+

Critical additionally requires at least one widespread-exploitation story or one developing critical incident; volume alone caps at High.

Current status and its evidence

Cyber threat status — United States

High

High: driven by 7 new CISA KEV additions and 11 government/CERT advisories.

Why is the status high?

Calculated 2 hours ago from published signals only. Nobody sets this level by hand. Methodology v1.0

  • Home
    Normal
    Driven by 2 government/CERT advisories and 1 new CISA KEV addition.
  • Small Business
    Guarded
    Driven by 2 new CISA KEV additions and 2 government/CERT advisories.
  • Enterprise
    Elevated
    Driven by 4 new CISA KEV additions and 1 critical actively exploited issue.
  • AI
    Normal
    No significant threat signals in the measurement windows.
  • Web / Apps
    Elevated
    Driven by 3 new CISA KEV additions and 3 government/CERT advisories.
  • Critical Infrastructure
    Guarded
    Driven by 5 government/CERT advisories and 1 KEV addition used by ransomware.

Current limits: the calculation uses what our sources have published and what we have classified. It is not a measure of attacks against any particular organization. Questions or corrections: see our editorial standards.