Inside a DDactic Scan Report: The OPI Scorecard

June 5, 2026 | 10 min read | Platform

A DDactic scan report opens with the OPI scorecard -- a single-page summary that answers the question the CISO actually cares about: how exposed are we, and to what? The scorecard is not a traffic light or a generic risk heat map. It is a structured breakdown of the assessment across six measurement categories, each with a sub-score, the top finding, and the remediation action that would produce the largest score improvement.

The scorecard is designed to be readable in two minutes by someone who did not run the scan. It answers: what is the overall score (0-100), what are the three highest-impact gaps, and what are the specific actions that close them. Everything else in the report -- the full findings list, the evidence, the vendor commands -- supports those three answers.

Scorecard Structure

The scorecard has six rows, one per assessment category: API endpoint coverage, rate limit calibration, TLS and connection hardening, authentication endpoint protection, subdomain exposure, and configuration verification. Each row shows the category sub-score (0-100), the number of findings in that category by severity (P1/P2/P3/P4), and a one-line description of the highest-severity finding in the category. The category sub-scores are weighted and combined into the overall OPI score shown at the top.

Below the six-row table, the scorecard shows three "quick wins" -- the three findings whose remediation would produce the largest OPI score improvement per hour of implementation effort. These are selected by the scan engine based on the estimated implementation time for each remediation (a Cloudflare rate limit rule takes minutes to configure; a TLS renegotiation change requires a service restart and careful testing) against the OPI points the remediation recovers.

Reading the Sub-Scores

A sub-score of 100 means all checks in that category passed: every API endpoint has a calibrated rate limit, or all TLS renegotiation settings are correct. A sub-score of 0 means the category was entirely unaddressed. In practice, scores cluster in the 40-80 range per category, with the lowest sub-scores in rate limit calibration (because many organizations have rate limits that exist but are miscalibrated) and subdomain exposure (because forgotten subdomains consistently appear in assessments).

Sub-score interpretation

A sub-score of 70 in API endpoint coverage means 70% of the weighted endpoint risk is covered by an active, calibrated rate limit. The remaining 30% represents endpoints where either no rate limit exists or the existing limit is set above the measured saturation threshold.

Evidence Links

Every finding in the scorecard links to the evidence section of the full report, which contains the measurement data: the request sequence used to probe the endpoint, the observed response codes and latencies, and the saturation threshold measurement. The evidence section allows an engineer to reproduce the finding manually and verify that a remediation has been effective. This is the design principle behind DDactic's report structure: every claim is traceable to a measurement, and every measurement is reproducible.

Using the Scorecard for Board Reporting

The OPI scorecard translates directly into board-level reporting. The overall OPI score (e.g., 58/100) provides a single metric for tracking improvement over time. The category breakdown shows which domains of risk are addressed and which are not. The sector benchmark comparison -- showing the organization's score against the anonymized median for its industry -- provides context that executives can evaluate without deep technical knowledge. The three quick wins provide the board with concrete evidence that a remediation roadmap exists and is actionable.

Get Your OPI Scorecard

A DDactic scan delivers your full OPI scorecard and findings report. Start with a free scan of your primary API surface.

Run a Free Scan
OPI ScorecardDDactic ReportSecurity AssessmentCISODDoS Resilience