What the Casper score is and when you typically see it
The Casper security score is a numeric indicator of your cloud infrastructure’s exposure and risk posture, produced by the security analytics platform SecurityTrails. Your score reflects elements like open ports, exposed credentials, outdated services, and other observable Internet-facing signals. If you are asking when you get your Casper score, the short answer is: you receive a score as soon as SecurityTrails has collected enough data to evaluate your assets, which usually happens within minutes to hours of onboarding or after a new scan completes. Scores update regularly as new scans run and your environment changes.
How the Casper score is generated
SecurityTrails continuously scans the Internet for exposed infrastructure, then classifies findings by severity. These findings are mapped into a weighted model that produces a numeric Casper score, typically between 0 and 100. The score is meant to represent the difficulty an attacker would face when targeting the observed assets. Higher scores indicate a smaller observed attack surface or lower-severity exposures; lower scores point to more significant issues. The engine factors in asset types, known vulnerabilities, exposed ports, and misconfigurations detected across your digital footprint.
Key inputs to the score
- Visibility into Internet-facing assets and services
- Severity weighting of exposed issues
- Timeliness and freshness of scan data
- Historical patterns and changes over time
When you get your score after onboarding or a scan
When you first connect assets or begin using SecurityTrails, the platform starts scanning. The timing of your first Casper score depends on how quickly the system can gather sufficient data across your digital assets. In practice, many users see an initial score within a few hours to the first day, assuming the target assets are reachable and the scans complete successfully. Subsequent score updates follow the cadence of scheduled scans, which can run periodically, often daily or more frequently for high-priority assets. If a scan fails or coverage is incomplete, you may see a pending status or delayed score.
Typical timeline for seeing your Casper score
Below is a practical overview of what to expect at each stage, based on typical SecurityTrails behavior and scan lifecycle patterns.
| Time or event | Expected score status | Why this matters |
|---|---|---|
| Initial asset onboarding | No score yet; scans queued | Data collection must complete first |
| First successful scan completes | Initial score typically available within hours to 1 day | Indicates first measurable risk observation |
| Subsequent scheduled scans | Score updates per scan cadence (often daily) | Keeps risk view current as environments change |
| Large infrastructure changes | New score observed after next scan that includes changes | Refreshes exposure and configuration signals |
| Scan failures or limited coverage | Score may be delayed or show stale data | Indicates need to check connectivity or asset reachability |
What to do if you don’t see a score right away
If you do not yet have a Casper score, start by confirming that your assets are reachable from the SecurityTrails scanning infrastructure. Check for common blockers such as restrictive egress or ingress firewalls, DNS resolution issues, or assets that are not routable from the public Internet. Ensure that the target assets are correctly specified in your SecurityTrails account and that scans have run recently. If scans are failing, review any logged errors and rerun or reschedule them. In some cases, limited coverage or incomplete data can delay score availability.
How to improve your Casper score over time
Because the score reflects observable signals, sustained improvements come from reducing your visible attack surface and remediating findings that affect severity. Prioritize addressing high-severity exposures, such as open management interfaces, default credentials, and outdated services with known vulnerabilities. Close unnecessary ports, enforce encryption, and remove or harden unused assets. As your environment changes, continue scanning frequently so that score updates reflect your current posture. Track score trends rather than a single point in time to understand how changes and remediation efforts move the needle.
Casper score update cadence and timing details
SecurityTrails typically runs scans on a recurring schedule, often daily for many customers, but cadence can vary based on asset criticality and subscription settings. After scans finish, the scoring engine processes findings and recalculates the numeric indicator. From a user perspective, this means your Casper score can change any time a scan completes and produces new data. If you need the freshest possible view, you can trigger scans manually or adjust schedules for critical assets. Note that score recalculation may lag slightly behind scan completion while analytics finalize, which can affect perceived timing.
When you get your score in different contexts
How and when you get your Casper score can vary slightly based on whether you are using the platform as a security analyst, a DevOps engineer, or a compliance stakeholder. Analysts may rely on continuous score tracking to spot trends; engineers often tie score checks into CI/CD or risk dashboards; compliance teams may request point-in-time snapshots for reporting. In each case, the underlying mechanics are the same: scans produce observations, the engine converts them into weighted risk signals, and the resulting numeric score reflects the current inferred difficulty of compromising observed assets. Understanding this flow helps you interpret score fluctuations and communicate them to stakeholders.
Casper score vs other risk indicators
It can help to compare the Casper score to other security metrics you might already use. Unlike vulnerability counts, which focus on missing patches, the Casper score emphasizes observable exposure and attacker effort. It differs from compliance pass/fail checks because it is risk-based and continuous rather than checklist-based and periodic. Unlike binary flags such as breached credential detection, the score provides a gradient view of your overall Internet-facing posture. These distinctions make the Casper score a useful complement to, rather than a replacement for, other risk and compliance signals in your program.
Summary: what to expect when you get your Casper score
If you are wondering when do I get my Casper score, expect your first score as soon as SecurityTrails completes sufficient scans to evaluate your assets, typically within hours to the first day. Subsequent updates follow scheduled scan cadence, often daily, and occur automatically as new data arrives. Your score will appear when the platform has adequate coverage and analytic processing has finalized. To accelerate visibility, verify asset reachability, resolve scan blockers, and address high-severity findings promptly. Track changes over time to see how hardening efforts move the needle and keep your risk posture aligned with operational realities.