Version 6.4 · VECTORS six-dimension scored composite (V E C T R S) · Outages informational · Updated Jun 30, 2026
A defensible, outside-in measurement of the daily condition of the digital ecosystem, derived entirely from public, authoritative, machine-readable sources. Not a company-specific internal risk score.
The Internet Cyber Health Index (ICHI) aggregates signals across six scored dimensions of cyber threat activity into a single 0–100 composite score updated continuously as data arrives. It answers the question an executive would actually ask: how bad is it out there today, and what should I do differently?
The index is deliberately outside-in. It does not measure your organization's posture — it measures the condition of the broader Internet ecosystem your organization depends on: the vulnerabilities being weaponized right now, the infrastructure failing, the adversary machinery in motion, and the software supply chain you import from.
ICHI now uses the VECTORS model as its headline scoring base. VECTORS evaluates six scored pressure areas across the digital ecosystem: Vulnerability Pressure, Exploitation, C2 / Malware Infrastructure, Threat Actors, Ransomware, and Supply Chain. Outages is retained as an informational dimension — tracked and displayed, but not scored (see the revision note and dimension table below).
The previous production model, TVIEWS, was a broader six-dimension composite covering Threat Activity, Vulnerability Pressure, Operational Impact, Exposure Surface, Weaponization, and Systemic Stress. VECTORS is intended to be more operational, more explainable, and more directly tied to external cyber telemetry — each VECTORS dimension corresponds to a specific class of public, observable feed rather than to a conceptual category that mixes several feeds together.
TVIEWS remains referenced in this document only as the previous/original model, for visitors comparing the current ICHI scoring to earlier published values. It is no longer the active scoring model.
How to read the score. ICHI is a directional signal, not a forecast precise to a single integer. The severity band (NORMAL · GUARDED · ELEVATED · HIGH · CRITICAL) is the operative read; the integer score is published as a courtesy. Treat moves within a band as noise; treat band crossings as meaningful. The six scored dimension weights are expert-prior estimates from the operator, not empirically backtested against historical events. A weight-calibration revision against named events (Shai-Hulud, CrowdStrike outage, MOVEit, xz-utils, LastPass) is planned but not yet shipped.
Top Cyber Event is explanatory. Each day ICHI surfaces a dominant observed condition — a ransomware spike, a KEV mass-exploitation wave, a supply-chain compromise, an outage cluster, a data-quality event, or remediation pressure. The Top Event card explains what is driving today's number. The Top Event does not add points to the composite. The headline integer comes from the weighted VECTORS sum plus two meta-condition uplifts (VID and Remediation Pressure) which measure things VECTORS does not capture.
Scoring policy. ICHI uses VECTORS as the headline scoring base. Limited meta-condition adjustments may be applied only for ecosystem-level conditions not directly represented as a VECTORS dimension, such as Vulnerability Intelligence Degradation or Remediation Pressure. Top Event is explanatory only and does not alter the score. Dimension signals (V, E, C, T, R, S) are not uplifted twice — if a condition already maps cleanly to a VECTORS dimension, that dimension carries the weight on its own.
Methodology revision · r63 · 2026-05-15. Renamed Patch Window Pressure to Remediation Pressure to reflect the broader operational pressure on defenders. Remediation is broader than patching alone — it includes vendor mitigations and workarounds, compensating controls, WAF / Akamai / firewall rules, disabling exposed services, configuration changes, segmentation and exposure reduction, identity-control changes, credential rotation, EDR detections and blocking, threat hunting, and incident containment. The scoring math is unchanged in r63; the existing proxies (fresh critical CVEs, KEV velocity, network-reachable bug volume, Patch Tuesday window) remain as indicators of defender action burden. The model rebuild — adding EPSS pressure, exploit references, ransomware relevance, and vendor mitigation advisories as direct inputs — is planned for a later release.
Methodology revision · model v7 · r80.0 · 2026-07-22. VECTRS becomes VECTRS+P: Phishing (P) added as the seventh scored dimension, and three further changes ship in the same event. (1) P — Phishing enters the composite at a 0.10 weight, computed from the OpenPhish Community Feed at 12-hour resolution with a 70-day backfilled baseline: unique-domain diversity carries 80% of P and positive 7-day domain momentum 20%. Phishing is a top initial-access vector and was the model's largest coverage gap. (2) T fixed and ecosystem blend activated. A defect present since r46 weighted an input (APT feed item velocity) that was never populated, silently capping T at 70; that dead sub-weight is removed and distinct named adversaries now carry the T base alone. Separately, the Adversary Ecosystem blend (75% base / 25% online criminal-ecosystem breadth from ransomlook) — computed and displayed as a gated observation since launch — is now live inside T, its baseline having shown independent movement. (3) V gains a capped patch-gap modifier (0 to +8 points): when the share of fresh high/critical CVEs lacking public fix evidence exceeds 15%, V rises linearly to +8 at a 40% gap, reflecting disclosure outrunning remediation evidence. (4) Weights re-normalized over 0.95 (the six prior weights plus P's 0.10), preserving prior relative proportions. Net transition effect measured on transition-day data: under one point of composite movement. The retired v6 model is computed alongside v7 in nightly snapshots as a shadow, so the transition is fully auditable. Naming addendum (r80.1, 2026-07-23): the seventh dimension, introduced at r80.0 as "P — Phishing," is named O — Actor Operations, restoring the model's original VECTORS acronym; the dimension's formula, weight, and inputs are unchanged, and the informational Outages dimension relinquishes the model letter. In stored snapshots and API payloads the dimension's internal key remains P (with O continuing to identify informational Outages) to preserve historical continuity. Edge Exploitation Watch is simultaneously designated a permanent drill-down view: it decomposes telemetry already scored in V and E, so scoring it would double-count.
Methodology revision · r77.13 · 2026-06-30. Outages (O) removed from the composite score. Outage events observed on vendor statuspages cannot be reliably attributed to cyber causes — most are operational (configuration error, capacity, fiber cuts) — so scoring them as cyber pressure overstated the signal. Outages is now informational only: still collected and shown on the dashboard and the Outages page, but excluded from the index. The scored model is now V E C T R S (six dimensions). The remaining weights were re-normalized over 0.85 (the sum of their prior weights), preserving their relative proportions exactly — so the change reflects only the removal of O, not a re-weighting of the others. Expect the composite to move for the same world-state, since the share Outages used to contribute is now redistributed proportionally across the six scored dimensions.
Methodology revision · r59 · 2026-05-15. Removed the Top Cyber Event composite uplift and the standalone supply-chain uplift — both double-counted signals already captured by the VECTORS dimensions, and the Top Event card is now explanatory only. Retained the VID (data-quality) and Remediation Pressure uplifts because they measure conditions outside VECTORS. Renamed the AI-Accelerated N-Day Weaponization condition to Patch Window Pressure in r59 (and then to Remediation Pressure in r63) to match what its proxies actually measure (calendar position, fresh CVE volume, KEV velocity — not AI activity itself). Promoted the severity band over the integer score in the hero UI to reduce precision overclaiming.
Methodology revision · r46 · 2026-05-13. The index moved from the six-dimension TVIEWS model to the seven-dimension VECTORS model. The old Weaponization Pressure dimension was split into C2 / Malware Infrastructure and Threat Actors — those signals had always been conceptually distinct. The old Systemic Stress dimension, which mixed cloud/CDN outages with concentration risk, was retired in favor of Supply Chain (pressure on the software trust graph) — concentration risk moved into Outages. Ransomware was promoted from a sub-signal under the old Threat dimension to its own dimension, since it is the consequence layer most operators track separately. Expect 5–15 points of movement on the composite for the same world-state vs. r45.
Seven scored dimensions, each 0–100, combined into a weighted composite: V E C T O R S (model v7). The model reclaims its original name as of r80.1: the O now denotes Actor Operations — active adversary operations, currently measured through phishing infrastructure — while the retired informational Outages dimension keeps its name but no longer holds a model letter. The model name VECTORS retains O (Outages) as a seventh, informational dimension — tracked and displayed but excluded from the score, because outage events cannot be reliably attributed to cyber causes.
| Dim | Name | Weight | What it measures | Primary signals |
|---|---|---|---|---|
| V | Vulnerability Pressure | 19% | Vulnerability pipeline: critical and high CVEs published today, KEV additions over 7 days, KEV-ransomware overlap, vendor advisory pulse across 17 vendors — plus a capped patch-gap modifier (0 to +8, v7) when public fix evidence lags disclosure. | NVD JSON 2.0, CISA KEV, 17-vendor advisory aggregate |
| E | Exploitation | 18% | The live weaponization signal — EPSS top-10 concentration above 0.9, CVEs with confirmed public exploit references, and KEV catalog burn rate. | FIRST.org EPSS, NVD reference exploit detection, CISA KEV |
| C | C2 / Malware Infrastructure | 14% | The attacker-machinery layer: active C2 footprint, C2 growth velocity over 24 hours, mass-scanning intensity at the top-port level. | abuse.ch Feodo Tracker, SANS DShield top records |
| T | Threat Actors | 13% | Who is operating — distinct named adversaries mentioned in threat-intel feeds (90-day window), blended 75/25 with live adversary-ecosystem breadth (active ransomware groups and criminal markets online, via ransomlook) as of v7. A dead reporting-velocity sub-weight (never populated; capped T at 70 since r46) was removed in v7. | 13 threat-intel feeds: Mandiant, CrowdStrike, Microsoft Threat, Talos, Kaspersky, SentinelLabs, Unit 42, Check Point, DFIR Report, ESET, BleepingComputer, DarkReading, The Record |
| O | Outages · informational · holds no model letter as of r80.1 | — | Informational only — not part of the composite (r77.13). What disruption is already visible: vendor statuspage outages, SEC 8-K Item 1.05 disclosures over 30 days, CISA infrastructure advisories, and a binary tier-1 concentration-risk indicator. | 55 vendor statuspages (3 tiers), SEC EDGAR Item 1.05, CISA ICS · Joint · OFAC |
| R | Ransomware | 14% | Ransomware operations layer — victim posts in the last 24 hours and 7 days from ransomware leak sites, plus CISA's KEV ransomware-tagged adds over 7 days. | ransomware.live, CISA KEV (ransomware-tagged) |
| S | Supply Chain | 13% | Pressure on the software trust graph: classification level from /api/supply-chain (CRITICAL/MAJOR/ELEVATED/NOMINAL), plus advisory volume across five ecosystem feeds. The S dimension stands on its own in the composite — there is no separate supply-chain uplift on top (removed in r59 because it double-counted the S signal). |
GitHub Advisory DB, OSV.dev, PyPI Security, npm Security, Sigstore/SLSA, CISA Cybersecurity Advisories |
| O | Actor Operations · new in v7 · phishing-driven | 10% | Active adversary operations, currently measured through phishing: unique phishing domains in the OpenPhish rolling window (80% of the dimension) plus positive 7-day domain momentum (20%). The dimension is defined by operational activity rather than a single vector, so future operational signals (credential-harvesting or infostealer campaign volume) can join it through normal methodology events without a model rename. Domain diversity is the signal — the window's URL count saturates at its ceiling and carries none. Sampled every 12 hours; scored atop a 70-day backfilled baseline. Raw phishing URLs are never stored or displayed. | OpenPhish Community Feed (12h samples via the public_feed mirror) |
Each dimension is scored 0–100 using logarithmic (ln) and square-root (rt) transforms to prevent single signals from dominating. The composite is a fixed weighted sum, plus two meta-condition uplifts that measure things VECTORS does not capture:
Logarithmic scaling compresses extreme values: a day with 1,000 C2 servers doesn't score 10× a day with 100. Square-root scaling is used where moderate growth is more meaningful than extreme concentration.
Note on precision and calibration. ICHI is a directional signal, not a forecast precise to a single point. The integer score is published as a courtesy; the severity band is the operative read. The seven dimension weights are expert-prior estimates from the operator, not empirically backtested against historical events. Treat moves within a band (e.g. 42 → 47, both GUARDED) as noise; treat band crossings as meaningful. Future revisions may publish a backtested weight calibration against named events (Shai-Hulud, CrowdStrike outage, MOVEit, xz-utils, LastPass); until then, the weights should be read as a defensible starting point, not a settled measurement.
| 0–24 · NORMAL | Background threat activity within normal parameters. Standard operations tempo is appropriate. | Standard monitoring. Routine patch cadence. |
| 25–49 · GUARDED | Above-baseline signals in one or more dimensions. Increased attacker activity, vulnerability pressure, or infrastructure stress. | Increase awareness. Review new advisories. Confirm KEV patch status. |
| 50–69 · ELEVATED | Significant threat convergence across multiple dimensions — active exploitation, infrastructure stress, and adversary tooling coinciding. | Prioritize KEV coverage. Review external exposure. Increase third-party monitoring. |
| 70–84 · HIGH | High-severity signals across multiple dimensions. Active campaign pressure correlates with this band. | Activate heightened cyber posture. Executive reporting. Validate IR readiness. |
| 85–100 · CRITICAL | Systemic cyber stress. Historically rare; correlates with active campaigns, major infrastructure events, or mass exploitation. | Emergency response posture. Executive notification. Consider isolation of highest-risk systems. |
Each day ICHI identifies the dominant observed condition — a supply-chain compromise, a KEV mass-exploitation wave, a ransomware leak-site spike, a cluster of Tier-1 vendor outages, a Vulnerability Intelligence Degradation event, or Remediation Pressure. This is the "Top Cyber Event" surfaced on the dashboard. The Top Event does not add points to the composite score. It is an explanatory narrative layer that points at which VECTORS dimension(s) the dominant condition is showing up in, so readers can audit how the day's score relates to the day's news.
Why no uplift. Earlier revisions (r48–r58) added an additive uplift to the composite when a Top Event was active — CRITICAL +20, MAJOR +13, ELEVATED +6. In r59 the uplift was removed because the underlying signal was already being counted in the VECTORS dimensions (a ransomware spike raises the R dimension; an outage cluster raises O; etc.), and adding a separate uplift double-counted the same event. The Top Event card still selects today's dominant condition and explains it in full narrative form, but the headline integer comes only from the weighted VECTORS sum plus the two meta-condition uplifts described below (VID and Remediation Pressure), which measure conditions VECTORS does not capture. The running archive of daily Top Events remains available at /events.html.
Vulnerability Intelligence Degradation (VID) measures whether public vulnerability data is complete, timely, and actionable. ICHI raises the score when CVEs are missing enrichment, KEV records change materially, ransomware-use indicators flip, or exploitation signals appear before public vulnerability context is complete. The intuition: defenders depend on timely public data — CVSS scores to triage, CWE classifications to scope, CPE configurations to identify affected stacks, and KEV indicators to prioritize patching. When that pipeline is degraded, organizations make patch decisions on incomplete information. The index reflects that uncertainty as a real risk, even when the underlying vulnerabilities are not new.
| VID level | Uplift | Triggers |
| NORMAL | +0 | Baseline. Enrichment current, no material KEV deltas, no ransomware-use flips. |
| ELEVATED | +2 | ≥30% of recent CVEs lack CVSS; or ≥40% in NVD "Awaiting Analysis"; or net new KEV adds since yesterday; or any KEV ransomware-use flip; or any KEV-listed CVE still missing NVD enrichment. |
| HIGH | +4 | ≥50% of recent CVEs lack CVSS; or ≥60% awaiting analysis; or 5+ net new KEV adds in 24h; or 3+ ransomware-use flips; or 3+ KEV-listed CVEs still un-enriched. |
| SEVERE | +6 | ≥70% of recent CVEs lack CVSS; or ≥80% awaiting analysis. Indicates the public enrichment pipeline is effectively stalled across the trailing week. |
The five trigger conditions ICHI watches: (1) NVD enrichment gap — recent CVEs missing CVSS, CPE, or CWE data; (2) NVD backlog — meaningful fraction of CVEs in "Awaiting Analysis" status past normal turnaround; (3) CISA KEV delta — new entries added since yesterday's snapshot; (4) KEV ransomware flip — knownRansomwareCampaignUse changes from "Unknown" to "Known"; (5) exploit-before-enrichment — exploitation/EPSS/vendor warnings present for CVEs whose NVD enrichment is still incomplete. The VID uplift stacks additively only with approved meta-condition uplifts (currently Remediation Pressure), capped at composite 99. Levels and signals are recomputed daily by a scheduled function (vid-builder.js) that snapshots NVD enrichment state and the KEV catalog into Netlify Blobs; the dashboard reads the snapshot on demand.
Remediation Pressure measures the urgency placed on defenders to act based on current external cyber conditions. It includes patching, but is broader than patching alone. The signal reflects fresh critical vulnerabilities, known exploitation, KEV velocity, exploit availability, ransomware relevance, exposure risk, and conditions where compensating controls or emergency mitigations may be required.
What counts as remediation. Remediation in this context is the full set of defender actions taken in response to external cyber conditions — not just applying vendor patches. ICHI treats the following as remediation work that consumes operator capacity:
What this condition measures today. Four calendar and CVE proxies are used as initial indicators of defender action burden: (a) Patch Tuesday proximity, (b) fresh critical-severity CVE volume, (c) fresh network-reachable bug volume, (d) KEV weaponization velocity. These are good proxies because each one expands the set of remediation decisions defenders must make this week — but they are not the full signal. The scoring math has not yet been rebuilt to incorporate EPSS pressure, exploit-availability references, ransomware relevance, emergency vendor advisories, and explicit network-exposure data. Adding those inputs is planned for a later release. Until that rebuild, the current proxies stand in for the broader signal.
What this condition does not measure. It does not detect AI-assisted exploit research, AI-generated exploit code, or attacker tooling. The condition was previously labeled "AI-Accelerated N-Day Weaponization" (renamed to Patch Window Pressure in r59, then to Remediation Pressure in r63) — the current naming is meant to describe the operator-side consequence (defender action burden), not the attacker-side capability that contributes to it.
| Level | Uplift | Raw score | Operational guidance |
| LOW | +0 | 0 | Standard remediation cadence. Monitor advisories. |
| MODERATE | +2 | 1–2 | Prioritize internet-facing critical CVEs and review available mitigations. |
| SEVERE | +4 | 3–4 | Accelerate remediation for KEV, exploited, ransomware-linked, or network-reachable vulnerabilities. Validate compensating controls, WAF / firewall rules, and exposure reduction. |
| CRITICAL | +6 | ≥5 | Emergency remediation posture. Patch or mitigate immediately, reduce exposure, apply blocking controls, hunt for exploitation, and brief leadership. |
Note: in r63, the surfaced labels in the dashboard (Today's Snapshot card) still read as elevated / high / severe for consistency with prior releases. The operational-guidance bands above (LOW / MODERATE / SEVERE / CRITICAL) describe the same four states with action-oriented framing. A future release will align the surfaced labels.
Raw score components (each independent, additive — these are the unchanged proxies retained from the prior Patch Window Pressure formulation): (a) Patch Tuesday proximity — within 7 days after the 2nd Tuesday of the month: +1; (b) Fresh critical-severity CVEs (CVSS ≥ 9.0, published in trailing 7 days): ≥5 → +1; ≥10 → +2; (c) Fresh network-reachable bugs (CVSS vector contains AV:N, trailing 7 days): ≥3 → +1; ≥6 → +2; (d) KEV weaponization velocity (trailing 30-day median lag between NVD publication and KEV addition): ≤14d → +1; ≤7d → +2. The condition is recomputed daily by ainday-builder.js (internal name retained for route stability). Editorial override: set AINDAY_FORCE=elevated|high|severe|clear as a Netlify env var to pin the level when external conditions warrant a specific public classification. Forced levels are flagged in the Today's Snapshot fact as "(editorial)" for transparency.
As of model v7 (r80.0), this signal contributes to the score as a capped modifier inside Vulnerability Pressure: a coverage gap (100 − coverage) at or below 15% adds nothing; above that, V rises linearly to a maximum of +8 points at a 40% gap. It is deliberately a bounded modifier rather than a standalone input because coverage partly reflects NVD reference-linking speed, not only true remediation state — the cap limits how much that proxy noise can move the composite. The panel below continues to document the raw signal.
Patch-Reference Coverage tracks the share of fresh high/critical CVEs that include public evidence of a vendor fix, advisory, mitigation, or security update. A falling coverage rate may indicate that vulnerability publication is outrunning remediation evidence, but this signal is experimental and not yet included in the ICHI score.
What it measures. Each day ICHI pulls the trailing 30 days of HIGH and CRITICAL CVEs from the NVD CVE 2.0 API and counts how many carry at least one reference tagged or identifiable as a vendor patch, vendor advisory, release note, mitigation, security update, or commit-style fix. The coverage ratio is that count divided by the total. The panel shows the trailing-30-day high/critical count, the count carrying remediation evidence, the coverage percentage, and 7-day and 30-day trend once baseline history accumulates.
What it does NOT measure, and why. ICHI does not currently measure true discovery-to-enterprise-deployment time, which is not publicly observable. NVD references are not reliably timestamped, and CISA KEV remediation windows reflect policy deadlines rather than observed remediation behavior. ICHI therefore tracks patch-reference coverage — the share of fresh high/critical vulnerabilities carrying public evidence of a vendor fix, advisory, mitigation, or security update — as an experimental, advisory-only indicator. This is a presence proxy, not a patch-lag or time-to-patch measurement. The absence of a reference in an NVD record does not mean no patch exists — a vendor may have shipped a fix that is simply not yet linked in the record. Coverage is informative only in aggregate and over time, not for any individual CVE.
Why it exists and where it may go. The motivation is the shift, visible in 2026, from finding vulnerabilities being the bottleneck to verifying, disclosing, and remediating them being the bottleneck — as AI-assisted discovery began outpacing the ecosystem's capacity to patch. A widening gap between disclosure volume and public remediation evidence is the observable shadow of that shift. ICHI collects this metric now to build a baseline (stored daily, retained 180 days) so that a future release can decide, with real history in hand, whether it deserves to feed Remediation Pressure as one input. Until then it is shown for visibility only and has no effect on the composite score. Computed daily by patch-coverage-builder.js; served from /api/patch-coverage.
The Edge Exploitation Watch tracks exploitation pressure against internet-facing edge devices — VPNs, firewalls, gateways, routers, load balancers, and security appliances. These systems are privileged, exposed, and often slower to patch, making them priority targets for state actors and ransomware groups.
What it measures. Each day ICHI filters CISA KEV entries and trailing-30-day high/critical NVD CVEs against a curated, conservative list of edge-device vendors (Fortinet, Ivanti, Citrix/NetScaler, SonicWall, Palo Alto, F5, Juniper, Check Point, and others) and device-category keywords (VPN, firewall, gateway, load balancer, security appliance). It reports a current level (Normal / Guarded / Elevated / High / Critical) driven by the count and recency of edge entries, the product categories driving it, the evidence tier reached, and a confidence indicator. The match list favors precision over recall so the figure is defensible and auditable.
Evidence tiers. Three tiers are distinguished. Vulnerability-only (high/critical CVEs on edge products) and exploit-confirmed (edge entries in CISA KEV) are measured directly from public feeds. Implant / persistence-confirmed — reporting that adversaries have placed implants on edge devices — is not machine-measurable from a structured feed; it lives in narrative threat-intelligence reporting (Mandiant, Google TAG, CISA/NSA advisories). The computed level is driven only by the two measurable tiers. The implant tier is surfaced only as an editorial flag when a major report warrants it, and is labeled as such; ICHI never auto-claims implant detection.
Why it is not scored — permanently (decided r80.0). Edge-device vulnerabilities already contribute to the composite through Vulnerability Pressure and Exploitation: a Fortinet KEV entry raises both today. This watch isolates the edge-specific share of telemetry that is already scored, so adding it to the composite would double-count the same KEV signal — and its baseline confirmed it tracks overall exploitation pressure rather than moving independently. As of the model v7 methodology event it is designated a permanent drill-down view: kept for visibility into a critical device class, with no effect on the score, by design rather than by pending decision. Computed daily by edge-watch-builder.js; served from /api/edge-watch.
Phishing Watch is ICHI's first phishing-class signal. It observes aggregate volume in the OpenPhish Community Feed — a continuously refreshed rolling window of live, independently verified phishing URLs, updated roughly every twelve hours.
What it measures. Each day ICHI records the number of URLs in the window, the number of unique base domains hosting them, and the distribution of top-level domains. Because the community feed is a fixed-size rolling window, the raw URL count saturates at the window ceiling; the meaningful signals are the day-over-day and 7-day movement of unique domains and shifts in the TLD mix, which reflect the breadth and churn of active phishing infrastructure. Raw phishing URLs are aggregated and immediately discarded — they are never stored, displayed, or republished by ICHI.
Scored as of model v7 (r80.0, 2026-07-22). Phishing graduated from observation to the seventh scored dimension exactly as this section previously described the path: it accumulated a 70-day baseline (12-hour resolution, reconstructed from feed history and continued live), demonstrated movement independent of the six existing dimensions, and entered the model through a public methodology event with renormalization notes (see the model v7 revision above). P is weighted at 0.10 of the composite: unique-domain diversity carries 80% of the dimension and positive 7-day domain momentum 20%. Computed daily by phishing-watch-builder.js; served from /api/phishing. Source data © OpenPhish, used with attribution.
Kill-Chain Pressure re-projects ICHI's existing signals onto the stages of a generic attack sequence, answering a question the dimension grid doesn't: where along the attack chain is internet-wide pressure currently concentrated?
What it is — and is not. Each stage's heat derives entirely from signals already collected and documented above: Recon from DShield mass-scanning volume; Initial Access from phishing-infrastructure breadth and fresh KEV additions; Exploitation from EPSS-critical and confirmed-exploit counts; Command & Control from active and newly-registered C2; Impact from ransomware leak-site victim flow. The same logarithmic saturation math and severity bands as the composite are used, so a HIGH here means the same thing a HIGH means anywhere on the page. This is a re-projection of observed pressure, not attack-path prediction: it does not model any specific environment, does not infer unobserved vulnerability chains, and contributes nothing to the score. Inferred or "novel" path modeling — connecting vulnerabilities into hypothesized chains — is a separate research direction that would ship, if ever, only as clearly-labeled hypothesis after methodology review.
The Internet Cyber Health Index is not investment advice. It is not breach attribution. It is not a prediction engine. It is not a substitute for enterprise-specific risk assessment. It is based on public, commercial, and observed cyber-risk indicators. It is designed as a composite signal of digital ecosystem stress.
ICHI is a directional cyber-risk signal, not a deterministic forecast.
The index is maintained by Joe Bernik, a cybersecurity executive who built this as a personal outside-in daily briefing tool. The methodology is open: all sources are public, the weight derivation is published here, and the scoring code runs entirely in the browser and Netlify edge functions.