
FORTIS Logic
Overview
This page provides an explanation of how Risk Scores are calculated for various cybersecurity-related reports in Power BI. These scores are designed to help prioritize security events based on severity, action type, and IP classifications.
Risk Score Range
Detected malware or direct threat activity.
Strong indicators of potentially malicious behavior.
Suspicious behavior needing further investigation.
Benign but logged for visibility.
General activity.
Report - Key Conditions
Anti-Malware Report
Condition | Risk Score |
---|---|
[Firewall Action] is "detected" AND [Event Type] is NOT in the excluded list* | 5 |
[Firewall Action] is "monitored" AND [Event Type] is NOT in the excluded list* | 5 |
[Firewall Action] is "passthrough" AND [Event Type] is NOT in the excluded list* | 5 |
[Firewall Action] is "blocked" AND both Source & Destination IPs are private | 4 |
[Firewall Action] is "dropped" AND both Source & Destination IPs are private | 4 |
[Firewall Action] is "blocked" (all other cases) | 2 |
[Firewall Action] is "dropped" (all other cases) | 2 |
Anything else | 1 |
No Logs | 1 |
Excluded Event Types*
- FortiGate-antivirus-file-oversize
- FortiGate-antivirus-scan-archive-oversize-notif
- FortiGate-antivirus-scan-archive-corrupted-notif
- FortiGate-antivirus-file-submitted
- FortiGate-antivirus-scan-archive-multipart-notif
- FortiGate-antivirus-file-monitored
IDS / IPS Report
Firewall Action | Severity | Source/Destination IP | Risk Score |
---|---|---|---|
Allowed | "Critical" / "High" / "1" | — | 5 |
Blocked | Not "Low" / not "Informational" / not "3" | Both are private | 4 |
Allowed | "Medium" / "2" | — | 3 |
Others | — | — | 1 |
Any | No Logs | N/A | 5 |
Web Filter Report
Firewall Action | WF Security Risk | Count | Risk Score |
---|---|---|---|
Passthrough | Yes | > 10,000 | 5 |
Allowed | Yes | > 10,000 | 5 |
Passthrough | Yes | ≤ 10,000 | 4 |
Allowed | Yes | ≤ 10,000 | 4 |
Blocked | Yes | Any | 3 |
Blocked | No | Any | 2 |
Passthrough | No | Any | 1 |
Allowed | No | Any | 1 |
No Logs | N/A | Any | 5 |
Application Control Report
Firewall Action | AppCtrl Security Risk | Count | Risk Score |
---|---|---|---|
Pass | Yes | > 10,000 | 5 |
Pass | Yes | ≤ 10,000 | 4 |
Block | Yes | Any | 3 |
Block | No | Any | 2 |
Pass | No | Any | 1 |
No Logs | N/A | Any | 5 |
Firewall Config Changes Report
Source IP | Risk Score |
---|---|
Public IP | 3 |
Private IP | 1 |
No Logs | 1 |
Credentials Compromise Report
Currently N/A - we are still working on the logic to calculate scores for this category, and it will be available shortly. |
EDR Report
Currently N/A - we are still working on the logic to calculate scores for this category, and it will be available shortly. |
FW Bandwidth Report
Currently N/A - we are still working on the logic to calculate scores for this category, and it will be available shortly. |
Security Risk References
WebFilter Security Risk
The following categories are considered security risk and affect the risk score for the mentioned reports.
AppCtrl Security Risk
The following categories are considered security risk and affect the risk score for the mentioned reports.

Are you protected?
Connect with our experts to start your Cybersecurity Assessment.
LCM -A Leader In Security
Stay updated with the latest news and trends in cybersecurity