What Can an Attacker Still Do to Us?
The Attack Surface Coverage Score (ASCS) weighs how real adversaries actually operate against the controls you have in place, one kill-chain phase at a time. The result is a single 0–100 score, and a phase-by-phase map of where you're exposed.
Compliance Tells You What You Did. ASCS Tells You What's Left.
A completed framework assessment reports how many controls you've implemented. It doesn't say which attacks those controls stop, or which ones still get through. Two organizations with the same compliance score can have very different exposure.
ASCS reads your controls from the attacker's side. Every control is linked to the MITRE ATT&CK® techniques it defends against, every technique is weighted by how often it's used against organizations like yours, and the result is grouped by the stage of an attack where it happens.
Scores your attack surface. Tells you what an attacker can still do.
ASCS is a derived view, not a third scoring engine. It re-reads the same controls UCPA prioritizes, through the lens of real adversary behavior.
The Information ASCS Uses
Four inputs describe the threat and your defenses. Two optional inputs narrow the view to a specific adversary or to the tools you already own.
Adversary techniques
The MITRE ATT&CK® Enterprise catalog: the documented record of how attackers get in, move around, and reach their goals. Each technique carries a prevalence score (how often it's seen in the wild) and a breadth measure (how many tracked adversary groups use it).
Kill-chain phases
ATT&CK's tactics are grouped into the seven stages of the Lockheed Martin Cyber Kill Chain®: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, and Actions on Objectives. This is what lets ASCS say where in an attack you're exposed.
Your industry's threat profile
A sector amplifier raises or lowers each technique's weight for your industry, so a technique used heavily against your industry counts for more than one that's rarely seen there. Each amplifier is recorded with its evidence and a confidence tier. Techniques without sector evidence stay at their baseline weight.
Control-to-technique map
Which framework controls defend which techniques. The mappings are transcribed from published, MITRE-vetted crosswalks, never written from control text alone, so a control only gets credit for a technique when an established crosswalk says it defends against it.
Your assessment answers
When you score a framework assessment, each control's implementation level becomes a value from 0 to 1. A half-implemented control earns half credit for the techniques it defends, so the score tracks what you've actually done, not what the framework could do.
Optional: an adversary or your tools
Choose a threat actor from the Threat Library and ASCS scores only the techniques that actor is known to use, weighted by how central each is to their playbook. Add your tool inventory and a second score shows how much of the exposure the tools you own address.
The ASCS Formula
Each technique gets an exposure weight. Each phase's weights are compared with how much of that weight your controls defend. The phases are then combined in proportion to how much of the total threat each one carries.
How the Score Is Built
Four steps, from a single technique to the headline score.
-
1
Weigh every technique
A technique's weight starts from its prevalence, plus a bounded bonus for how many adversary groups use it. That total is multiplied by your industry's amplifier and capped at 100. When you pick a threat actor, the weight is also multiplied by how central that technique is to the actor, and techniques the actor doesn't use drop out.
-
2
Measure each phase's share of the threat
Technique weights are summed within each kill-chain phase, and each phase's sum is divided by the total across all phases. The shares add up to 1, so a phase carrying 40% of the weighted threat counts for 40% of the final score.
-
3
Measure how much of each phase you defend
Coverage is the weighted share of the phase's techniques that are defended. What counts as defended depends on what's being scored:
- A framework: a technique is defended (1) if at least one of the framework's controls maps to it, and undefended (0) if none does.
- Your assessment: a technique is defended to the level of its best-implemented control. If three controls defend it and your strongest scores 0.8, the technique counts as 0.8 defended.
-
4
Combine the phases
Each phase's coverage is multiplied by its share of the threat, the results are summed, and the total is scaled to 0–100. A weak phase that carries most of the threat pulls the score down hard, while a weak phase that attackers rarely use barely moves it.
Weighted by Threat, Not Counted
The simplest measure would count how many techniques in a phase have a defending control. That measure fails badly. ATT&CK lists hundreds of techniques under some phases, most of them rarely seen, and no framework is designed to cover every one. Scored by count, every organization looks critically exposed everywhere, and the score stops telling anyone anything.
Weighting fixes that. Defending a technique attackers use constantly earns far more coverage than defending one that's almost never observed. You're credited for stopping the attacks that drive real risk, and not penalized for obscure ones.
"You defend 40 of 400 Installation techniques: 10%."
Accurate, but it says nothing about which 40.
"Those 40 are the ones attackers actually use: 72% of Installation's weighted threat is defended."
This is the number ASCS reports.
Worked Example
Illustrative numbers, shortened to three phases so every step fits on screen. A real score uses all seven phases and the full technique catalog.
Step 1: one technique's weight
| Prevalence | 60 | How often the technique is seen in the wild |
| + Breadth bonus | 10 | Used by about half the tracked adversary groups |
| = Base | 70 | |
| × Sector amplifier | 1.3 | Seen more often in this industry than average |
| = Weight (capped at 100) | 91 |
Steps 2–4: phases to score
| Phase | Weight sum | ÷ Total = Share | Coverage | Share × Coverage | Status |
|---|---|---|---|---|---|
| Reconnaissance | 50 | 50 / 500 = 0.10 | 1.00 | 0.10 | Adequate |
| Delivery | 150 | 150 / 500 = 0.30 | 0.80 | 0.24 | Adequate |
| Exploitation | 300 | 300 / 500 = 0.60 | 0.50 | 0.30 | Critical |
| Total | 500 | 1.00 | 0.64 | ||
| ASCS = round(100 × 0.64) | 64 | Moderate | |||
Exploitation is half defended, which alone would read as Warning. It's marked Critical because it carries 60% of the threat. Any phase below 60% coverage that also carries at least 20% of the total threat is escalated, so a big exposure can't hide behind a middling ratio.
Phase Status
Every phase gets a status from its coverage, so an executive can see at a glance where attention belongs.
| Status | Rule | What it means |
|---|---|---|
| Adequate | coverage ≥ 75% | Most of this phase's weighted threat is defended. |
| Warning | 40% ≤ coverage < 75% | Meaningful gaps. Worth planning for. |
| Critical | coverage < 40%, or coverage < 60% and share ≥ 20% |
Low coverage, or a large share of the threat left partly open. |
| Capped | tool view only | Your tools already cover everything any tool in our catalog can address here. The rest needs process or policy, not another purchase. |
| n/a | nothing to score | No weighted techniques fall in this phase, for example when an adversary view excludes it. In the tool view, also used where no security product can help, such as Weaponization, which happens on the attacker's own systems. An n/a phase is left out of the overall score. |
Overall score bands
Three Ways to Read an ASCS
The same math answers three different questions, depending on what you feed it.
"If we fully implemented this framework, how exposed would we still be?"
Scores a framework against your industry's threat profile. Useful for choosing a framework, or for showing that even perfect compliance leaves some phases open.
"Given what we've actually implemented, how exposed are we?"
Uses your scored answers. This is the number on your Threat-Informed Executive Report, along with the highest-weighted techniques you haven't yet defended.
"How well do we hold up against this particular group?"
Scores only the techniques one threat actor uses. We always show how many of that actor's techniques your framework addresses at all, because a high score over a narrow slice can overstate your protection.
What ASCS Is Not
Not a probability
An ASCS of 64 doesn't mean a 64% chance of stopping an attack. It means 64% of the weighted threat against your industry falls on techniques you defend. The math supports the second statement, not the first.
Not a model's opinion
The score is computed deterministically from the inputs above. The same framework, industry and answers always produce the same number, and every weight can be traced back to its source.
Not a replacement for testing
ASCS measures whether defenses are in place against the right techniques. Whether they work as configured is a question for penetration testing and red-team exercises.
Primary Data Sources
See Your Attack Surface
Pick a framework and your industry in the Threat-Gap Visualizer to see its headline ASCS. Sign in for the phase-by-phase breakdown, or run an assessment to score your own controls.