The CySec Pulse Index

One number a day, 0 to 100, for how busy the published security landscape is compared with its own last ninety days. It describes the world, not you. It is not a forecast.

What it is

CySec reads about seventy public sources every five minutes: national CERTs, government advisories, vendors across operating systems, cloud, networking, industrial control and applications, open-source ecosystems, leak sites, breach records and the trade press. The index turns one day of that into a single reading, so a reader with no background can see at a glance whether today is an ordinary day or an unusual one. Your own exposure is a different question, answered by the Radar inside the app.

The seven components

ComponentWeightWhat is counted in the last 24 hours
Exploitation25Additions to CISA's Known Exploited Vulnerabilities list and confirmed exploitation (three points each), public attack code and EPSS jumps (one each).
Vulnerability pressure20New CVEs and vendor advisories published, with those rated critical or high counted twice.
Ransomware and extortion15Victims posted to leak sites, plus the number of groups posting.
Threat-actor activity10Published items that name a known threat actor.
Breaches10Breaches added to Have I Been Pwned, each weighted by the size of its record count on a log scale.
Supply chain10Advisories from the GitHub Advisory Database and OSV.
Government and CERTs10Items from CISA, CISA ICS, NCSC UK, CERT-EU, JPCERT/CC and CERT/CC.

Every source in the catalogue counts and none is tagged to a sector, so nothing in the number is specific to healthcare, finance, or any other industry.

The arithmetic

Each component is a count over the last twenty-four hours, compared with the same twenty-four-hour window on each of the days before it that CySec was actually watching, up to ninety. The comparison uses the median of those days and a robust measure of their spread (1.4826 times the median absolute deviation, never less than 15% of the median or 1), so a single wild day in the past cannot distort the baseline. A component scores 50 on an ordinary day and moves 14 points for each usual amount of variation, clipped between three deviations below and three and a half above, so one extreme day cannot pin the needle.

The index is the weighted sum of the component scores. A component with fewer than seven watched days of history sits out, the weights renormalise over the rest, and the app names it. The bands are 0–24 Quiet, 25–49 Usual, 50–69 Busy, 70–84 Heavy and 85–100 Severe. Those cut points match the Internet Cyber Health Index, so the two can be read side by side.

When it is computed

Once a day, on the server, on the first run after 06:00 UTC, so everyone sees the same number. Each day's reading is stored as it was shown and never recomputed underneath the history; the app shows the last thirty days beside today's number.

What is not in it

CySec has no source for malware and command-and-control infrastructure, internet outages, or phishing volume, so none of those is in the number. Rather than estimate them, the app says so. The Internet Cyber Health Index, by Joe Bernik, does cover them; with his permission the app shows his daily reading on the same page as a second opinion. It is never blended into CySec's number.

Reading it honestly

In the first weeks after launch the baseline is short, so the number compares today with a few weeks rather than ninety days, and the app shows how many days each component has behind it. A high reading means the published landscape is busier than its recent usual; it does not mean anything about your own systems, and it does not predict tomorrow.