Reference

Cyber risk ratings glossary

Plain definitions for the terms that appear in a security rating report: the 250–900 scale, every risk vector, and the third-party programme vocabulary.

In short
A cyber security rating is built from externally observable signals grouped into risk vectors, expressed on a 250–900 scale of which 300–820 is currently in use, and read in bands: Advanced from 740, Intermediate from 640, Basic below. The terms below define every component of that sentence, plus the vocabulary of vendor-risk programmes.

33 terms, grouped by where they appear in practice. Every definition has its own anchor, so an individual entry can be linked to directly.

The rating itself

The scale, the bands, and the vocabulary used to describe how a rating is produced and read.

Security rating

An objective, externally calculated measure of an organisation’s cyber security performance, expressed as a number. It is produced without the assessed organisation’s participation, which is what allows a third party to rely on it.

250–900 scale

The range a Bitsight Security Rating is expressed on. Higher indicates stronger observed security performance and a lower likelihood of breach. The scale is deliberately reminiscent of a credit score, and is read the same way.

Rating bands

Three interpretive ranges on the scale: Advanced (740–900), Intermediate (640–730) and Basic (250–630). Around 60% of rated entities sit in Advanced, 35% in Intermediate and 5% in Basic, so the bands sort the population unevenly and clearing 740 is less distinguishing than it sounds. Contractual thresholds are usually set at a band boundary rather than a precise figure, because a daily-recalculated number is hard to enforce.

Ten-point rounding

Ratings are displayed rounded down to the nearest ten, so an actual 735 is shown as 730. This is why the bands appear not to touch — nothing is ever displayed at 631–639 or 731–739 — and why any change in a displayed rating can be traced back to a change in at least one risk vector.

Effective range

The part of the 250–900 scale actually in use: 300 to 820. Bitsight reserves the top and bottom of the nominal scale for future use, so a rating in the low 800s is near the practical ceiling rather than mid-table. The average rating across the inventory is 720.

Risk vector

One measured category of externally observable signal that contributes to the rating — open ports and TLS configuration are risk vectors, as are botnet infections and mail authentication records. A rating is an aggregate; the risk vectors are where the work happens.

Outside-in measurement

Assessment built only from what is visible from the public internet. No agent, no credentials, no network access and no questionnaire — the same vantage point an attacker has.

Peer benchmark

The organisation’s position within the distribution of ratings for its own industry, usually as a percentile with the sector median and top quartile shown. More actionable than the absolute rating, because scores cluster differently by sector.

Dynamic Remediation

The ability to request an immediate rescan of a finding once it has been fixed, rather than waiting for the ordinary observation schedule, so the repair earns rating credit at the next daily update instead of days later. Currently live across five risk vectors: SSL configurations, SSL certificates, open TCP ports, server software and web application security. It shortens the gap between doing the work and seeing it — it is not a forecast of what a fix would be worth.

Asset attribution

The mapping of domains, IP ranges and hosts to the organisation they belong to. Attribution errors are the most common cause of a disputed rating: an asset wrongly assigned to you drags your score for something you do not control.

What the rating measures

The externally observable signal families. Each is measured continuously, and each is independently remediable.

Botnet infections

Evidence that a host on the organisation’s network is communicating with known command-and-control infrastructure. Among the heaviest-weighted signals, because it indicates an active compromise rather than a latent weakness.

Spam propagation

Observation of the organisation’s addresses sending unsolicited bulk mail, which generally means a host or mail service has been compromised or is misconfigured as an open relay.

Malware servers

Infrastructure attributed to the organisation observed hosting or distributing malicious files — frequently a compromised web server rather than anything deliberate.

Unsolicited communications

Traffic from the organisation’s addresses to destinations and ports with no legitimate business explanation, often the first externally visible trace of a compromised host.

Critical Vulnerability Management (CVM)

Bitsight’s assessment of externally visible critical vulnerabilities, weighted by how severe they are rather than by how long they took to patch. It replaced the earlier Patching Cadence measure in July 2026 at the same 20% weighting — the largest single weight in the rating — and the change of basis means historical comparisons across it need care. Findings carry a 90-day lifetime.

Open ports

Internet-reachable services that need not be reachable. Usually the fastest meaningful improvement available, because closing a port is a decision rather than a project.

Web application security headers

HTTP response headers that constrain what a browser will do with a page — Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options and their relatives. Cheap to add and immediately visible externally.

TLS/SSL configuration

The certificate, protocol version and cipher suite offered by each internet-facing service. Expired certificates, deprecated protocol versions and weak ciphers are all measured, and all accumulate quietly as an estate ages.

DNSSEC

Cryptographic signing of DNS records so a resolver can verify a response has not been tampered with. Its absence is measurable, which is why it appears in a rating despite being invisible to most internal reviews.

SPF (Sender Policy Framework)

A DNS record declaring which servers may send mail for a domain. An absent or permissive record makes the domain cheaper to spoof.

DKIM (DomainKeys Identified Mail)

A cryptographic signature on outbound mail that lets a recipient verify the message genuinely came from the domain and was not altered in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

A DNS policy that tells receiving mail servers what to do when a message fails SPF or DKIM, and where to send reports about it. It became rating-impacting in Bitsight’s July 2026 algorithm update, carrying a 1% weight reallocated from compromised systems — small, but a cheap point for any domain that has already done SPF and DKIM.

External attack surface management (EASM)

Continuous discovery and inventory of everything an organisation exposes to the internet. It answers the question that precedes every other one: what do we actually have out there?

Third-party and supply-chain terms

The vocabulary of vendor risk programmes, where most of the practical work with ratings happens.

Third-Party Risk Management (TPRM)

The discipline of identifying, assessing and monitoring the risk an organisation inherits from its suppliers, vendors and partners. In a ratings context, applying continuous outside-in measurement to the vendor estate rather than to your own.

Security Posture Management (SPM)

The same continuous outside-in measurement pointed at your own organisation — with benchmarking, board reporting and control-framework mapping attached.

Vendor tiering

Sorting suppliers into groups by the consequence of their failure, then setting a different monitoring threshold and a different response per group. Monitoring two hundred vendors identically produces two hundred alerts and no action.

Fourth-party (and nth-party) risk

Risk inherited from your vendors’ own vendors, and onward down the chain. It matters because concentration is usually invisible one hop out: several suppliers may depend on a single upstream provider.

Concentration risk

Exposure arising when many critical dependencies resolve to the same underlying provider, region or platform. A supplier list that looks diversified can be highly concentrated once fourth parties are mapped.

Continuous monitoring

Assessment that recalculates as conditions change, rather than at a review interval. The distinction that matters is not frequency but latency: how long a supplier’s posture can deteriorate before anyone is told.

Questionnaire-based assessment

Assurance obtained by asking a vendor to describe its own controls. It captures intent and design, is self-reported, and is accurate for the day it was completed — which is why it complements external measurement rather than substituting for it.

Exit readiness

The ability to terminate a supplier relationship and move the service elsewhere without unacceptable disruption. Increasingly expected by regulators as a documented, tested capability rather than a contractual clause.

Time to remediate

How long a finding stays open from first observation to fix. Measured directly by the rating, and often a better indicator of programme health than the count of open findings.

Dark web intelligence

Monitoring of underground forums and marketplaces for material relating to an organisation or its suppliers — leaked credentials, access being offered for sale, or discussion preceding an attack.

Where these terms are used

For how the scale is calculated and what it cannot tell you, see what is a cyber security rating. For how to read a particular number, see what is a good Bitsight score. For the order to fix findings in, see how to improve your Bitsight security rating.

Risk vector names, the rating bands, the band distribution, the effective range and the rounding rule follow Bitsight Technologies, Inc., read from its published rating methodology in August 2026. Definitions are BitScore's, written for a governance audience rather than lifted from vendor documentation; where a term has a narrower technical meaning in a standard, the standard governs. Bitsight's July 2026 algorithm update made three changes reflected above: Critical Vulnerability Management superseded Patching Cadence with a changed methodology, DMARC became rating-impacting, and SPF and DKIM now return N/A rather than a penalty for organisations holding no domains.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ