Methodology
Version CW-1.0 · Daily public observatory
What Cyber Weather Index is
The Cyber Weather Index (0–100) is a composite measure of publicly observable cybersecurity activity from authoritative feeds. It is updated daily after ingestion, not in real time.
It is not a probability of attack, breach, or organisational risk. It describes observable signal pressure from public data.
Severity bands
- 0–19 CALM — Limited observable pressure across monitored public signals.
- 20–39 QUIET — Some notable vulnerabilities or malicious activity are present, but overall pressure is low.
- 40–59 ACTIVE — Observable cybersecurity activity is present across one or more monitored signals.
- 60–74 ELEVATED — Cybersecurity pressure is above normal across one or more signal categories.
- 75–89 SEVERE — Multiple significant observable cyber signals are active.
- 90–100 EXTREME — Exceptional levels of observable vulnerability or malicious activity pressure.
Categories and weights
- Exploitation — weight 0.3
- Vulnerability Pressure — weight 0.25
- Ransomware — weight 0.2
- Malware — weight 0.15
- Identity Attacks — weight 0
- Cloud Activity — weight 0.1
- Supply Chain — weight 0
- Breach Activity — weight 0
Data sources
- cisa-kev — feeds exploitation, ransomware
- nvd — feeds vulnerability pressure
- epss — feeds vulnerability pressure
- urlhaus — feeds malware
- msrc — feeds cloud activity, vulnerability pressure
Collection schedule
Sources are collected once daily around 4:00 AM Australia/Sydney via an automated pipeline. Freshness allows a grace period after the scheduled run before marking data stale.
Geographic methodology
The global map shows observable signals associated with infrastructure or source-reported geography where defensible country-level data exists — primarily malware infrastructure from URLhaus host/IP inference.
Vulnerability, exploitation, EPSS, and most vendor advisories do not provide victim or attacker geography. The map does not display geographic data for those categories unless an individual event record includes defensible location metadata.
Geography never implies attacker origin, victim location, or attack attribution unless a source explicitly establishes that (currently not used for attribution on this site).
Coverage by category
- Exploitation — strong: CISA Known Exploited Vulnerabilities catalogue
- Vulnerability Pressure — strong: NVD, EPSS, and vendor advisories
- Malware — strong: URLhaus malware infrastructure observations
- Ransomware — limited: Derived from KEV ransomware flags and URLhaus tags; no dedicated ransomware feed
- Cloud Activity — developing: Microsoft security updates and cloud-related advisories
- Identity Attacks — limited: No dedicated public feed in CW-1.0
- Supply Chain — limited: No dedicated public feed in CW-1.0
- Breach Activity — limited: No dedicated public feed in CW-1.0
Confidence
Data confidence reflects completeness and freshness of monitored sources — not statistical certainty that attacks will occur. Lower confidence is explained when sources are stale, degraded, or never collected.
Recency and deduplication
Recent activity contributes more than older activity. Multiple reports of the same underlying CVE or URL are deduplicated through deterministic event identity before scoring.
Limitations
This observatory cannot see private incidents, all global cyber activity, or future attacks. Ransomware coverage is limited to indirect public signals. Cloud activity coverage is developing. Identity, supply chain, and breach categories lack dedicated feeds in CW-1.0.