Roast Score Methodology
No black box: see exactly why your score is what it is and how to boost it fast.
"Not a Pentest" Notice: This guide is for hardening your own systems. No attack tools.
Score categories (weighting)
30% Exposure & Network
Public endpoints, egress policy, unnecessary ports.
25% Secrets & Credentials
Hardcoded secrets, missing rotation, privilege drift.
20% Identity & Access
RBAC/ABAC, JIT access, token TTL.
15% Monitoring & Detection
Audit logs, SIEM hooks, alert noise.
10% Resilience & Recovery
Backups, rollback, IR readiness.
Quick wins (fast score boost)
1
Rotate secrets immediately
Fastest lever for +10–15 points.
2
Lock egress to allowlists
Stops data exfiltration risk.
3
Enforce mTLS internally
Stops lateral movement in the cluster.
4
Audit logs + SIEM
Instant detect capability.