← All articles
EXPLAINED

How to read your HackRisk report: a walkthrough

Your report gives you a lot in one place. Here's what each part means and what to do with it.

Header: How to read your HackRisk Report

Your HackRisk Score

Your HackRisk Report leads with one figure: your HackRisk Score.

The score runs 0–100%. Higher means more risk – zero is a clean bill of health, and anything at 75% or above is critical.

Alongside it sits a letter grade, which runs the other way: an A* is the best score you can get.

Low (0–24%, grade A*–A):

Few or minor findings. Worth addressing, not urgent.

Medium (25–49%, grade B–C):

Findings a determined attacker could chain together. Worth planning for.

High (50–74%, grade D–E):

Significant exposure. Wants attention soon.

Critical (75%+, grade F):

Severe exposure. Immediate remediation advised.

The score itself is an average across your active modules, then adjusted by a factor tied to your worst-performing module's band.

In short: your weakest area carries the most weight. A strong score in four modules won't offset a critical finding in the fifth.

What's in your free report

Your free HackRisk Report covers every service except Phishing Simulations and Security Awareness Training, which is a paid add-on for subscribers.

For Dark Web Scan, Vulnerability Scan, and Recon Scan, the free report surfaces your top 5 findings for each – the issues that matter most, not an exhaustive list.

Supply Chain Risk appears in your report once you've added a supplier. Add one, and you'll see the risk they carry too.

It's a snapshot of where you stand, delivered free of charge and within 24 hours.

If you want the complete picture rather than the top 5 – every finding, not just the headline ones – and continuous monitoring rather than a single snapshot, upgrading your account unlocks that across all five modules.

The modules behind the score

Dark Web Scan – active monitoring for your business's credentials and data appearing in breach dumps, with alerts typically within six hours of a match.

Vulnerability Scan – checks your systems daily for known, exploitable flaws.

Recon Scan – maps what's visible and reachable on your network from outside.

Supply Chain Risk – free on every plan, including the trial. Add your suppliers to see the risk they carry.

Phishing Simulations and Security Awareness Training – a paid add-on for subscribers, testing and training your team against real-world phishing attempts.

Reading an individual finding

Each finding in your report follows the same pattern: a technical reference, then a plain-English explanation underneath. For example:

CVE-2024-31345 · Auth bypass · mail.acme
A known flaw that lets attackers past the login.

You don't need to understand the technical reference to act on the finding. The line underneath tells you what it actually means, and our AI-powered remediation guide tells you how to fix it in plain English.

If your Dark Web Scan finds something

A Dark Web Scan finding can be unsettling to read on its own – an email address, a password, or company data showing up somewhere it shouldn't.

If that happens, our Data Breach Support Hub walks you through what to do next: the immediate steps to take, how to investigate what's actually been exposed, and how to stop it happening again.

What to do with the results

Work through the findings by severity. Critical and high findings first, medium next, low when you have time.

Because Vulnerability Scan runs daily and Dark Web Scan monitors continuously, your report changes as your environment does – a score you saw last month may not be the score you'd get today.