How to read your Cyber Risk Rating Report
A panel-by-panel guide to a Bitsight Cyber Risk Rating Report: the band, the percentile, the twelve-month trend, the 750+ multiples and the Primary Rating note.
The executive Cyber Risk Rating Report runs to two pages, and most of it is comparison rather than finding. That is the reason to read it in a particular order: the number alone is the least informative thing on it. This guide takes the panels in the order that answers the questions a board asks, using the executive specimen published on this site as the layout.
Structure only. The specimen is Bitsight's output and carries Bitsight's notice restricting its reproduction, so no figure from it appears here — open the PDF alongside this page to see the panels described.
The rating and its band
The headline is one number on Bitsight's 250 to 900 scale, with the band it falls in. The effective range today is 300 to 820, because Bitsight reserves the outer ends for future use, and the average across everything it rates is 720. Ratings are rounded down in ten-point increments, so an actual 735 is displayed as 730.
| Band | Range | Bitsight's reading |
|---|---|---|
| Advanced | 740–900 | Strong security performance, lower risk |
| Intermediate | 640–730 | Fair security performance, moderate risk |
| Basic | 250–630 | Poor security performance, higher risk |
Read the band as a starting point, not a verdict. Because the average sits inside the Intermediate band, clearing 740 puts an organisation in the majority rather than ahead of the field — what counts as a good score sets out why.
Where you sit among your peers
The peer panel does the work the number cannot. It states how many companies are in your industry comparison, where you fall among them as a percentile, and the industry average beside your own rating. Beneath it, a distribution shows what share of the industry sits in each part of the range, with your position marked.
This is the panel boards react to, because a rating in isolation has no scale. The same number reads as a strong position in one industry and a lagging one in another, and the percentile is what says which. Two cautions: the industry grouping is Bitsight's own, so check the label names the sector you would name; and a small comparison group moves a percentile further than a large one.
The twelve months
The trend graph covers the last twelve months and includes every rating-change event, publicly disclosed incidents among them, and the report states the highest and lowest points with the dates they occurred. Those two dates are the useful part.
- A recent low asks what happened around that date — a change in the estate, an incident, a vendor or an acquisition — before it asks what to fix.
- A high that is a year old and a rating that has drifted down since is a programme losing ground slowly, which a single snapshot would not show.
- A flat line is not automatically good. It can mean a stable estate or one nobody is changing.
Ransomware and incident multiples
Two panels, one for ransomware and one for security incidents, each state how much more exposed the company is than companies rated 750 and above. They are multiples of that group's likelihood, not probabilities: Bitsight bases them on its published correlation work, which is linked from the report itself — ransomware and security incidents.
A multiple of one would be parity with the 750-plus group, and a larger multiple means more exposed than it. What they cannot do is predict what will happen to a particular organisation. They sort populations by likelihood, which is what makes them useful in an insurance conversation and unsafe as a forecast.
Publicly disclosed incidents
The second page lists publicly disclosed security incidents in the last eighteen months — confirmed events of unauthorised access, often involving data loss, graded on factors that include the number of records exposed. Bitsight draws on news reporting and on regulatory reports obtained through Freedom of Information requests or local equivalents, and this vector affects the rating only when an incident is confirmed.
An empty list therefore means no confirmed, publicly disclosed incident in the window. It says nothing about incidents that were never disclosed.
Which estate was scored
A report that uses a Primary Rating says so in the additional information. A company may designate particular subsidiaries, business units or locations as representative of its digital footprint and exclude the rest — guest wireless, security test environments and networks used for customer hosting are the usual exclusions. Bitsight does not validate those exclusions, nor the predictive quality of a rating built from them.
Check this line before comparing your number with anyone else's. Two different figures for the same company are usually two different estates rather than two opinions; the report page explains why a rating can disagree with a self-serve scan.
Questions to take into the walkthrough
Bitsight's request page also lists threat insights tied to observable security gaps; the executive specimen published here does not include that panel, and it carries no findings list. What follows the report is a conversation, and these are the questions that make it worth the hour:
- Is every asset attributed to us ours, and is anything of ours missing?
- Is this a Primary Rating, and who decided what it excludes?
- What happened on the date of the lowest point?
- Which two or three findings account for most of the distance to the industry average?
- How long would those take to clear, and how quickly would the rating respond?
Related reading
- How to improve your Bitsight security rating — the order to work the findings in once you have them.
- Attribution across Indian group structures — why the first walkthrough question is usually the most valuable.
Questions this page answers
- What does "more vulnerable than companies rated 750+" mean in the report?
- It is a comparison, not a probability. Bitsight states ransomware and security-incident likelihood as a multiple of the likelihood for companies rated 750 and above, and links its published correlation datasheets from the report itself. A multiple of one would be parity with that group, and a larger multiple means more exposed than it. The figure sorts populations by likelihood and does not predict the outcome for any single organisation.
- Why does the report show a percentile when it already has a rating?
- A rating has no scale on its own. The percentile and the industry average place it against the companies in Bitsight’s comparison group for the industry, so the same number reads as strong in one sector and lagging in another. The average across everything Bitsight rates is 720, which sits inside the Intermediate band, so the band alone says little about standing.
- What is a Primary Rating?
- A Primary Rating is the rating of a company that has designated particular subsidiaries, business units or locations as representative of its digital footprint and excluded the rest, typically guest wireless, security test environments and customer-hosting networks. Bitsight does not validate those exclusions or the predictive quality of the result. A report built on one says so in its additional information.
- Does the executive report list what to fix?
- The executive specimen published on this site is a comparison and trend document and carries no findings list. Bitsight’s request page also lists threat insights tied to observable security gaps, which the specimen does not show. Working through the findings is the purpose of the analyst walkthrough that follows the report, and of continuous monitoring after it.