Three years of paid security audit work, turned into a repeatable scoring system instead of a one-off PDF per client. Every engagement produces the same structured inputs — vulnerability severity, patch velocity, authentication hygiene, exposure surface — so risk becomes a number you can track over time, not a report you file away.
-- One row per audit engagement: severity -- counts and remediation timing SELECT e.engagement_id, e.client_label, SUM(CASE WHEN f.severity = 'critical' THEN 1 ELSE 0 END) AS critical_count, SUM(CASE WHEN f.severity = 'high' THEN 1 ELSE 0 END) AS high_count, AVG( CASE WHEN f.resolved_date IS NOT NULL THEN f.resolved_date - f.found_date END ) AS avg_days_to_remediate, AVG(CAST(a.mfa_enforced AS INT)) AS mfa_coverage, BOOL_OR(a.has_incident_response_plan) AS has_irp FROM engagements e JOIN findings f ON f.engagement_id = e.engagement_id JOIN account_hygiene a ON a.engagement_id = e.engagement_id GROUP BY e.engagement_id, e.client_label;
# Lower is riskier for each raw input, so # everything is normalized to a 0-1 "good" scale weights <- c( mfa_coverage = 0.30, critical_vulns = 0.30, patch_velocity = 0.25, irp_documented = 0.15 ) risk_score <- function(mfa, crit_count, days_to_patch, has_irp) { s_mfa <- mfa / 100 s_crit <- 1 - pmin(crit_count / 6, 1) s_patch <- 1 - pmin(days_to_patch / 60, 1) s_irp <- as.numeric(has_irp) raw <- s_mfa * weights["mfa_coverage"] + s_crit * weights["critical_vulns"] + s_patch * weights["patch_velocity"] + s_irp * weights["irp_documented"] round(raw * 100) }
This scorecard is built on the real scoring methodology used across three paid audit engagements (fintech, e-commerce, SaaS). Client names are withheld — they did not respond to a request to be named publicly, and audit engagements are confidential by default without explicit sign-off. Findings shown here are illustrative examples structured on the same categories the real audits covered (authentication hygiene, TLS configuration, exposure surface, incident response readiness), not verbatim client findings.
No live breach-monitoring data is shown for these clients: a domain-level Have I Been Pwned lookup requires verified ownership of the domain, which isn't available for confidential client engagements. A live version of this panel is straightforward to add for any domain Digital Kuwala directly controls.