Cyber risk ratings glossary
Definitions for the terms in a security rating report, plus the Indian regulatory vocabulary no global glossary carries — DAKSH, CCI, M-SOC, Data Fiduciary.
50 terms, grouped by where they appear in practice. Every definition has its own anchor, so an individual entry can be linked to directly.
The last group is the one that is hard to find anywhere else. DAKSH, the Cyber Capability Index, the Market SOC, the twelve-hour LODR clock and the DPDP vocabulary are created by Indian instruments and appear in no global ratings glossary, because the instruments that create them are Indian. They are defined here as the issuing regulator defines them.
The rating itself
The scale, the bands, and the vocabulary used to describe how a rating is produced and read.
Security rating
An objective, externally calculated measure of an organisation’s cyber security performance, expressed as a number. It is produced without the assessed organisation’s participation, which is what allows a third party to rely on it.
250–900 scale
The range a Bitsight Security Rating is expressed on. Higher indicates stronger observed security performance and a lower likelihood of breach. The scale is deliberately reminiscent of a credit score, and is read the same way.
Rating bands
Three interpretive ranges on the scale: Advanced (740–900), Intermediate (640–730) and Basic (250–630). Around 60% of rated entities sit in Advanced, 35% in Intermediate and 5% in Basic, so the bands sort the population unevenly and clearing 740 is less distinguishing than it sounds. Contractual thresholds are usually set at a band boundary rather than a precise figure, because a daily-recalculated number is hard to enforce.
Ten-point rounding
Ratings are displayed rounded down to the nearest ten, so an actual 735 is shown as 730. This is why the bands appear not to touch — nothing is ever displayed at 631–639 or 731–739 — and why any change in a displayed rating can be traced back to a change in at least one risk vector.
Effective range
The part of the 250–900 scale actually in use: 300 to 820. Bitsight reserves the top and bottom of the nominal scale for future use, so a rating in the low 800s is near the practical ceiling rather than mid-table. The average rating across the inventory is 720.
Risk vector
One measured category of externally observable signal that contributes to the rating — open ports and TLS configuration are risk vectors, as are botnet infections and mail authentication records. A rating is an aggregate; the risk vectors are where the work happens.
Outside-in measurement
Assessment built only from what is visible from the public internet. No agent, no credentials, no network access and no questionnaire — the same vantage point an attacker has.
Peer benchmark
The organisation’s position within the distribution of ratings for its own industry, usually as a percentile with the sector median and top quartile shown. More actionable than the absolute rating, because scores cluster differently by sector.
Dynamic Remediation
The ability to request an immediate rescan of a finding once it has been fixed, rather than waiting for the ordinary observation schedule, so the repair earns rating credit at the next daily update instead of days later. Currently live across five risk vectors: SSL configurations, SSL certificates, open TCP ports, server software and web application security. It shortens the gap between doing the work and seeing it — it is not a forecast of what a fix would be worth.
Asset attribution
The mapping of domains, IP ranges and hosts to the organisation they belong to. Attribution errors are the most common cause of a disputed rating: an asset wrongly assigned to you drags your score for something you do not control.
What the rating measures
The externally observable signal families. Each is measured continuously, and each is independently remediable.
Botnet infections
Evidence that a host on the organisation’s network is communicating with known command-and-control infrastructure. Among the heaviest-weighted signals, because it indicates an active compromise rather than a latent weakness.
Spam propagation
Observation of the organisation’s addresses sending unsolicited bulk mail, which generally means a host or mail service has been compromised or is misconfigured as an open relay.
Malware servers
Infrastructure attributed to the organisation observed hosting or distributing malicious files — frequently a compromised web server rather than anything deliberate.
Unsolicited communications
Traffic from the organisation’s addresses to destinations and ports with no legitimate business explanation, often the first externally visible trace of a compromised host.
Critical Vulnerability Management (CVM)
Bitsight’s assessment of externally visible critical vulnerabilities, weighted by how severe they are rather than by how long they took to patch. It replaced the earlier Patching Cadence measure in July 2026 at the same 20% weighting — the largest single weight in the rating — and the change of basis means historical comparisons across it need care. Findings carry a 90-day lifetime.
Open ports
Internet-reachable services that need not be reachable. Usually the fastest meaningful improvement available, because closing a port is a decision rather than a project.
Web application security headers
HTTP response headers that constrain what a browser will do with a page — Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options and their relatives. Cheap to add and immediately visible externally.
TLS/SSL configuration
The certificate, protocol version and cipher suite offered by each internet-facing service. Expired certificates, deprecated protocol versions and weak ciphers are all measured, and all accumulate quietly as an estate ages.
DNSSEC
Cryptographic signing of DNS records so a resolver can verify a response has not been tampered with. Its absence is measurable, which is why it appears in a rating despite being invisible to most internal reviews.
SPF (Sender Policy Framework)
A DNS record declaring which servers may send mail for a domain. An absent or permissive record makes the domain cheaper to spoof.
DKIM (DomainKeys Identified Mail)
A cryptographic signature on outbound mail that lets a recipient verify the message genuinely came from the domain and was not altered in transit.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
A DNS policy that tells receiving mail servers what to do when a message fails SPF or DKIM, and where to send reports about it. It became rating-impacting in Bitsight’s July 2026 algorithm update, carrying a 1% weight reallocated from compromised systems — small, but a cheap point for any domain that has already done SPF and DKIM.
External attack surface management (EASM)
Continuous discovery and inventory of everything an organisation exposes to the internet. It answers the question that precedes every other one: what do we actually have out there?
Third-party and supply-chain terms
The vocabulary of vendor risk programmes, where most of the practical work with ratings happens.
Third-Party Risk Management (TPRM)
The discipline of identifying, assessing and monitoring the risk an organisation inherits from its suppliers, vendors and partners. In a ratings context, applying continuous outside-in measurement to the vendor estate rather than to your own.
Security Posture Management (SPM)
The same continuous outside-in measurement pointed at your own organisation — with benchmarking, board reporting and control-framework mapping attached.
Vendor tiering
Sorting suppliers into groups by the consequence of their failure, then setting a different monitoring threshold and a different response per group. Monitoring two hundred vendors identically produces two hundred alerts and no action.
Fourth-party (and nth-party) risk
Risk inherited from your vendors’ own vendors, and onward down the chain. It matters because concentration is usually invisible one hop out: several suppliers may depend on a single upstream provider.
Concentration risk
Exposure arising when many critical dependencies resolve to the same underlying provider, region or platform. A supplier list that looks diversified can be highly concentrated once fourth parties are mapped.
Continuous monitoring
Assessment that recalculates as conditions change, rather than at a review interval. The distinction that matters is not frequency but latency: how long a supplier’s posture can deteriorate before anyone is told.
Questionnaire-based assessment
Assurance obtained by asking a vendor to describe its own controls. It captures intent and design, is self-reported, and is accurate for the day it was completed — which is why it complements external measurement rather than substituting for it.
Exit readiness
The ability to terminate a supplier relationship and move the service elsewhere without unacceptable disruption. Increasingly expected by regulators as a documented, tested capability rather than a contractual clause.
Time to remediate
How long a finding stays open from first observation to fix. Measured directly by the rating, and often a better indicator of programme health than the count of open findings.
Dark web intelligence
Monitoring of underground forums and marketplaces for material relating to an organisation or its suppliers — leaked credentials, access being offered for sale, or discussion preceding an attack.
The Indian regulatory vocabulary
Terms an Indian board meets in a supervisory letter and will not find in any global glossary, because the instruments that create them are Indian. Every entry below is stated as the issuing regulator states it, and each links onward to the page that carries the clause.
Regulated Entity (RE)
The addressee of an Indian financial-sector instrument — the entity the circular binds, as that circular defines it. Worth its own entry because the same three letters mean different populations in different places: an RE under SEBI’s CSCRF is a SEBI registrant, an RE under the RBI’s 2026 Directions is whichever entity class that particular Direction names, and an RE under the IFSCA Guidelines is a GIFT City licensee. Reading one instrument’s definition into another is the most common way an obligation gets applied to the wrong firm.
DAKSH
The Reserve Bank of India’s supervisory platform, and the channel on which a regulated entity files a cyber incident report — within six hours of detection, not of confirmation. It is where the filing goes, not a separate obligation: the duty comes from the RBI Direction that binds the entity class, and DAKSH is the mechanism. Filing on DAKSH does not discharge CERT-In, which is a parallel six hours.
The six-hour clock
CERT-In’s reporting deadline under its Directions of 28 April 2022, issued under section 70B(6) of the Information Technology Act, 2000. It binds every entity in India, regulated or not, and it runs from noticing the incident or being brought to notice of it — so a vendor, a researcher or a regulator telling you starts it exactly as your own alerting does. An investigation still in progress does not pause it.
The LODR twelve-hour clock
A listed entity’s disclosure to its stock exchanges under regulation 30(6) of the SEBI LODR Regulations: twelve hours for an event emanating from within the entity, twenty-four for one arising outside it. Ransomware, a data breach and an IT outage all originate within the entity, so a cyber incident falls in the twelve-hour limb. Twenty-four is the figure most commonly repeated, and quoting it puts the disclosure twelve hours late.
CSCRF
SEBI’s Cybersecurity and Cyber Resilience Framework, issued 20 August 2024, which replaced the earlier circulars for each SEBI-regulated population with one graded framework. Obligations scale by the category an entity falls into rather than applying uniformly, and the framework has been amended five times since issue.
CSCRF category re-fixing
SEBI’s rule that an entity’s CSCRF category is fixed at the start of each financial year on the previous year’s data and held for the whole year. A category is therefore a state, not a property: a firm can be correctly categorised today and correctly categorised differently in April. The corollary catches people out — because the thresholds themselves were revised three times between August 2024 and August 2025, a firm can be sitting in the right category and still working to a superseded threshold table.
Cyber Capability Index (CCI)
The CSCRF’s maturity measure, scored against defined parameters rather than against an incident count. Who does the scoring is the part that matters: Market Infrastructure Institutions must have their CCI assessed by a third party every six months, while Qualified REs self-assess once a year. A third-party assessment and a self-report carry different evidential weight and are not interchangeable in front of a supervisor.
Market SOC (M-SOC)
The shared Security Operations Centre operated by BSE and NSE, which CSCRF mandates for Small-size and Self-certification REs — the populations for which running an in-house SOC is not proportionate. Narrow carve-outs exist below a hundred clients, and they are exemptions from the SOC obligation alone, never from CSCRF itself.
MIIs, KRAs and QRTAs
Market Infrastructure Institutions — stock exchanges, clearing corporations and depositories — together with KYC Registration Agencies and Qualified Registrars and Transfer Agents. Grouped here because CSCRF treats them as the population that carries the framework in full, and because both of the compliance extensions that moved the deadline to 31 August 2025 expressly carved all three out. Their original deadline never moved, which is why a timeline drawn for the general population is wrong for them.
Scale-Based Regulation layers
The RBI’s four-layer classification of NBFCs — Base, Middle, Upper and Top — which governs how heavily an NBFC is regulated. It carries into cyber security: the 2026 NBFC Directions are graded by chapter against these layers, and a Base Layer NBFC below ₹500 crore sits under a chapter carrying no six-hour DAKSH clause at all. That is a narrower obligation, not an exemption — CERT-In’s six hours still binds it.
IFSC displacement
The rule that an International Financial Services Centre licence displaces the mainland regulator. A GIFT City banking unit reports a cyber incident to IFSCA, not to the RBI, even for business the RBI supervises onshore — and a GIFT City broker to IFSCA rather than SEBI. One thing survives the displacement in every case: CERT-In binds the entity regardless, because its Directions are made under the IT Act rather than under any financial-sector statute.
Data Fiduciary
Under the Digital Personal Data Protection Act, 2023, any person who alone or with others determines the purpose and means of processing digital personal data — the Indian analogue of a controller. The status is orthogonal to financial-sector regulation: it attaches from what an entity does with personal data, not from who licences it, so a firm can be a Data Fiduciary and an RBI regulated entity at once and owe both sets of duties in full.
Significant Data Fiduciary
A Data Fiduciary designated as such by the Central Government on notified criteria including the volume and sensitivity of the personal data processed. Designation is an act of government, not a threshold a firm crosses on its own reading. It adds a Data Protection Impact Assessment and an audit every twelve months, a duty to verify that technical measures including algorithmic software do not risk Data Principals’ rights, and a localisation requirement for government-specified personal data and its traffic data.
Data Principal
The individual the personal data relates to — the Indian analogue of a data subject. For a child, the term takes in the parent or lawful guardian. The word matters operationally because the DPDP breach duty runs to Data Principals directly and without any threshold for size or severity: every affected individual is intimated, not only those above some materiality line.
Consent Manager
A DPDP-specific intermediary through which a Data Principal can give, manage, review and withdraw consent, via an interoperable platform, with the Data Protection Board as its registrar. There is no equivalent in GDPR, which is why no global glossary carries it. Registration opens on 13 November 2026, a year after the Rules were notified and six months before the security and breach duties commence.
Data Protection Board of India
The adjudicating body created by the DPDP Act, which receives breach reports and determines non-compliance and penalties. Its machinery took effect when the Rules were notified on 13 November 2025, well ahead of the obligations it will adjudicate: the breach duty in Rule 7 and section 8 of the Act do not commence until 13 May 2027. It is an adjudicator, not a supervisor — it has no inspection or examination function of the kind the RBI and SEBI exercise.
Protected system and NCIIPC
A system declared a protected system by notification under section 70 of the IT Act, with the National Critical Information Infrastructure Protection Centre designated under section 70A as the nodal agency for it. Protected-system status is a notified fact, never an inference from an entity’s sector or size, and where a system is declared, the specific reporting terms come from the declaration itself rather than from any general circular.
Where these terms are used
For how the scale is calculated and what it cannot tell you, see what is a cyber security rating. For how to read a particular number, see what is a good Bitsight score. For the order to fix findings in, see how to improve your Bitsight security rating.
For the Indian terms, the instruments themselves are set out on India's cyber security regulations, and three of the definitions above are computed rather than described: the incident reporting clock works out which of the six-hour, twelve-hour and DAKSH deadlines you owe, the CSCRF category tool applies the re-fixing rule to your own figures, and which regulation applies resolves IFSC displacement. Dark web intelligence pointed at your own estate rather than your suppliers' is worked through in the credential exposure check.
Risk vector names, the rating bands, the band distribution, the effective range and the rounding rule follow Bitsight Technologies, Inc., read from its published rating methodology in August 2026. Definitions are BitScore's, written for a governance audience rather than lifted from vendor documentation; where a term has a narrower technical meaning in a standard, the standard governs. Bitsight's July 2026 algorithm update made three changes reflected above: Critical Vulnerability Management superseded Patching Cadence with a changed methodology, DMARC became rating-impacting, and SPF and DKIM now return N/A rather than a penalty for organisations holding no domains.
The Indian regulatory terms follow the issuing regulators' own notifications rather than any secondary summary: CERT-In's Directions of 28 April 2022 under section 70B(6) of the Information Technology Act, 2000; the RBI's Cybersecurity, Technology Risk, Resilience and Assurance Framework Directions, 2026, which are seven parallel instruments and not one; SEBI's CSCRF of 20 August 2024 as amended five times to August 2025, together with regulation 30(6) of the LODR Regulations; the IFSCA Guidelines on Cyber Security and Cyber Resilience of 10 March 2025; and the Digital Personal Data Protection Act, 2023 with the DPDP Rules, 2025 notified as G.S.R. 846(E) on 13 November 2025. Every circular reference and date is held in the register behind the regulation register, which records when each was last re-read at source.
Questions this page answers
- What is a risk vector?
- A risk vector is one grouped category of externally observable finding that feeds a security rating — botnet infections, open ports, TLS/SSL configuration, DMARC records and so on. Findings are grouped into vectors, each vector is weighted, and the weighted result is the rating. Vectors are graded on a percentile of all rated companies rather than out of a hundred, so a grade describes standing against the population rather than an absolute score.
- What do the rating bands mean?
- Advanced begins at 740, Intermediate at 640, and Basic sits below that, on a nominal 250–900 scale of which roughly 300–820 is currently in use. Ratings round down in ten-point increments, which is why the bands do not touch. The bands are read alongside the trend and the sector position, not on their own.
- What is the difference between SPM and TPRM?
- Security Posture Management is the continuous measurement and improvement of your own externally visible estate. Third-Party Risk Management is the same measurement applied to the organisations you depend on. The data and the platform are largely common; the programme, the owner and the decisions they support are not, and buying one expecting the other is the most frequent mismatch in this category.
- What Indian regulatory terms does a vendor-risk programme need?
- A handful created by Indian instruments and used nowhere else: CSCRF and its Cyber Capability Index, the Market SOC available to smaller SEBI regulated entities, DAKSH as the RBI’s supervisory platform, and the DPDP vocabulary of Data Fiduciary and Data Principal. Each is defined here, because a programme written in global vendor language will not map cleanly onto what an Indian supervisor asks for.