What Risk Insights Actually Does
Before we start, let's level set on what “risk” means. You likely know the classic equation Risk=Threat×Vulnerability×Asset Value. But here, we are talking about signal and findings clustering to identify high-centrality nodes of security events. That information can surely translate into your internal equations about threat and asset value. But Datadog does not inherently know how you assign asset value or what you determine the impact of exploitation is. Now that we understand what risk is measuring, let’s move on to what this feature does.
Many security teams still triage one signal at a time: an anomalous API call here, a misconfigured S3 bucket there. Or maybe you’re leveraging Bits AI Security Analyst to relieve some of that triage burden. Either way, both of these routes are generally not counting the number of times an entity or asset shows up in signals, linking those to findings elsewhere in the platform, or maintaining a rolling baseline of what signal criticalities are firing. So that means you may be blind to the entities in your environment that are becoming those high-centrality nodes of security events.
Datadog's Risk Insights, which is built into Cloud SIEM, fixes that. It consolidates SIEM signals, Cloud Security misconfigurations, and identity risks into one profile per entity, then scores that entity so you can make better decisions with better security context.
How to Set It Up and Use It
Risk Insights requires you to have Cloud SIEM configured against at least one of AWS, GCP, Azure, or GitHub. If you've also configured Cloud Security Management, the entity panel pulls in posture findings, too. That’s it! If you have done these steps, Risk Insights is live. Head to the Risk Insights explorer page to get a list of every entity with a non-zero risk score.

“What’s classified as an ‘entity’?” you might ask. Great question, a whole lot! User emails, compute instances, storage buckets, IAM users, service accounts- the list goes on.

Clicking into an entity opens a view that gives you a thorough breakdown of:
- Why does this entity have this risk score?
- Over what time frame has this entity accumulated this risk score?
- Related logs events
- Related IP addresses
- A pivot to the Investigator graph analysis tool (this one is very useful, and I would recommend you explore it!)
Scoring itself is transparent and tunable. By default, Critical signals add 100 points, High adds 50, Medium adds 5, and Low/Info add nothing. Posture Management findings also do not add any points by default. You should feel empowered to adjust these.
Each signal's contribution decays to zero after 14 days, so scores reflect recent behavior, not historical baggage. Entities cross the Critical risk threshold at 100 total points, High at 50–99, Medium at 25–49, Low at 10–24. You
All of this is made operational when you set up notification rules. RapDev highly recommends leaning into this. You can get notified when an asset or identity crosses a risk threshold maybe only when crossing into the High or Critical Risk categories at first which is a valuable inclusion in your security monitoring toolkit. Remember, this is all about finding those high-centrality nodes of security events to direct your operations. The best way to detect them quickly is to set up automatic notifications.

Why This Matters for Your Team
The point of Risk Insights is to move a step beyond just alerts to understand where in your environment security issues are clustering. The value isn't the score itself; it's that Risk Insights collapses parallel investigations into one. An IAM user with a medium-severity signal, a stale permission, and a misconfigured trust policy looks like three disconnected findings in most SIEMs. Here it's one entity, one score, one notification that can draw your attention to potentially underlying suspicious activity.
If you want a team of security experts on your side, in your Datadog instance, working with you on these challenges, look no further. RapDev is the home of top-notch Datadog and security engineering. As a six-time Datadog North American Partner of the Year, we know good Datadog security operations. Contact us today about our Managed SOC offering!

