Severity rubric, version 1.0
Every breach on this site carries a severity score from 0 to 100, computed by a fixed, published formula. The score is always displayed with its component breakdown โ a bare number with no math shown reads as invented. When the rubric changes, the version number changes, and existing scores record which version produced them.
score = min(100, data_class_subtotal + scale_mod + remediation_gap_mod + notification_lag_mod)
Component 1: data class subtotal (capped at 70)
The sum of the weights of every data class the breach exposed. Weights reflect permanence: a Social Security number cannot be rotated the way a payment card can.
| Data class | Permanence | Weight |
|---|---|---|
| Biometric identifiers | permanent | 30 |
| Social Security number | permanent | 30 |
| Financial account and routing number | semi-permanent | 25 |
| Medical records or diagnoses | permanent | 22 |
| Government ID (passport, driver's license) | semi-permanent | 20 |
| Payment card, full PAN and CVV | rotatable | 18 |
| Date of birth | permanent | 15 |
| Credentials, plaintext or reversible | rotatable | 14 |
| Credentials, properly hashed | rotatable | 8 |
| Physical address | semi-permanent | 4 |
| Phone number | semi-permanent | 3 |
| Email address | rotatable | 3 |
| Name only | permanent | 2 |
Component 2: scale modifier (0–15)
Log-scaled on the number of records affected. Bands include their lower bound and exclude their upper bound. When the record count is undisclosed, this component scores 0 and the breakdown says so.
| Records affected | Points |
|---|---|
| under 1,000 | 0 |
| 1,000 to 10,000 | 3 |
| 10,000 to 100,000 | 6 |
| 100,000 to 1,000,000 | 9 |
| 1,000,000 to 10,000,000 | 12 |
| over 10,000,000 | 15 |
Component 3: remediation gap modifier (0–10)
Scores the gap between what was exposed and what the notifying entity offered affected people.
| Condition | Points |
|---|---|
| no monitoring offered | 10 |
| months < 12 | 5 |
| 12 <= months < 24 | 2 |
| months >= 24 | 0 |
Component 4: notification lag modifier (0–5)
Days between the entity's stated discovery date and its notification date. When either date is undisclosed, this component scores 0 and the breakdown says so.
| Lag | Points |
|---|---|
| 0 to 30 days | 0 |
| 31 to 60 days | 2 |
| 61 to 90 days | 3 |
| over 90 days | 5 |
Rubric provenance
The rubric is editorial policy, not a government source: it is maintained in the site repository as
packages/severity/rubric.json and applied by a deterministic scoring function. Scores are
reproducible from the published inputs on each breach page. The citation blocks used elsewhere on this site
are reserved for government and court documents.