The CySec Pulse Index
One number a day, 0 to 100, for how busy the published security landscape is compared with its own last ninety days. It describes the world, not you. It is not a forecast.
What it is
CySec reads about seventy public sources every five minutes: national CERTs, government advisories, vendors across operating systems, cloud, networking, industrial control and applications, open-source ecosystems, leak sites, breach records and the trade press. The index turns one day of that into a single reading, so a reader with no background can see at a glance whether today is an ordinary day or an unusual one. Your own exposure is a different question, answered by the Radar inside the app.
The seven components
| Component | Weight | What is counted in the last 24 hours |
|---|---|---|
| Exploitation | 25 | Additions to CISA's Known Exploited Vulnerabilities list and confirmed exploitation (three points each), public attack code and EPSS jumps (one each). |
| Vulnerability pressure | 20 | New CVEs and vendor advisories published, with those rated critical or high counted twice. |
| Ransomware and extortion | 15 | Victims posted to leak sites, plus the number of groups posting. |
| Threat-actor activity | 10 | Published items that name a known threat actor. |
| Breaches | 10 | Breaches added to Have I Been Pwned, each weighted by the size of its record count on a log scale. |
| Supply chain | 10 | Advisories from the GitHub Advisory Database and OSV. |
| Government and CERTs | 10 | Items from CISA, CISA ICS, NCSC UK, CERT-EU, JPCERT/CC and CERT/CC. |
Every source in the catalogue counts and none is tagged to a sector, so nothing in the number is specific to healthcare, finance, or any other industry.
The arithmetic
Each component is a count over the last twenty-four hours, compared with the same twenty-four-hour window on each of the days before it that CySec was actually watching, up to ninety. The comparison uses the median of those days and a robust measure of their spread (1.4826 times the median absolute deviation, never less than 15% of the median or 1), so a single wild day in the past cannot distort the baseline. A component scores 50 on an ordinary day and moves 14 points for each usual amount of variation, clipped between three deviations below and three and a half above, so one extreme day cannot pin the needle.
The index is the weighted sum of the component scores. A component with fewer than seven watched days of history sits out, the weights renormalise over the rest, and the app names it. The bands are 0–24 Quiet, 25–49 Usual, 50–69 Busy, 70–84 Heavy and 85–100 Severe. Those cut points match the Internet Cyber Health Index, so the two can be read side by side.
When it is computed
Once a day, on the server, on the first run after 06:00 UTC, so everyone sees the same number. Each day's reading is stored as it was shown and never recomputed underneath the history; the app shows the last thirty days beside today's number.
What is not in it
CySec has no source for malware and command-and-control infrastructure, internet outages, or phishing volume, so none of those is in the number. Rather than estimate them, the app says so. The Internet Cyber Health Index, by Joe Bernik, does cover them; with his permission the app shows his daily reading on the same page as a second opinion. It is never blended into CySec's number.
Reading it honestly
In the first weeks after launch the baseline is short, so the number compares today with a few weeks rather than ninety days, and the app shows how many days each component has behind it. A high reading means the published landscape is busier than its recent usual; it does not mean anything about your own systems, and it does not predict tomorrow.