Fundamentals

How to read your Cyber Risk Rating Report

A panel-by-panel guide to a Bitsight Cyber Risk Rating Report: the band, the percentile, the twelve-month trend, the 750+ multiples and the Primary Rating note.

In short
A Bitsight Cyber Risk Rating Report reads best in six steps: the rating and its band, the percentile against the industry average, the twelve-month trend with its highest and lowest dates, the ransomware and incident multiples against companies rated 750 and above, publicly disclosed incidents in eighteen months, and the Primary Rating note naming the estate scored. Read percentile and trend before the number.

The executive Cyber Risk Rating Report runs to two pages, and most of it is comparison rather than finding. That is the reason to read it in a particular order: the number alone is the least informative thing on it. This guide takes the panels in the order that answers the questions a board asks, using the executive specimen published on this site as the layout.

Structure only. The specimen is Bitsight's output and carries Bitsight's notice restricting its reproduction, so no figure from it appears here — open the PDF alongside this page to see the panels described.

The rating and its band

The headline is one number on Bitsight's 250 to 900 scale, with the band it falls in. The effective range today is 300 to 820, because Bitsight reserves the outer ends for future use, and the average across everything it rates is 720. Ratings are rounded down in ten-point increments, so an actual 735 is displayed as 730.

BandRangeBitsight's reading
Advanced740–900Strong security performance, lower risk
Intermediate640–730Fair security performance, moderate risk
Basic250–630Poor security performance, higher risk
The three bands as Bitsight prints them. The gaps between them are the rounding rule, not missing values.

Read the band as a starting point, not a verdict. Because the average sits inside the Intermediate band, clearing 740 puts an organisation in the majority rather than ahead of the field — what counts as a good score sets out why.

Where you sit among your peers

The peer panel does the work the number cannot. It states how many companies are in your industry comparison, where you fall among them as a percentile, and the industry average beside your own rating. Beneath it, a distribution shows what share of the industry sits in each part of the range, with your position marked.

This is the panel boards react to, because a rating in isolation has no scale. The same number reads as a strong position in one industry and a lagging one in another, and the percentile is what says which. Two cautions: the industry grouping is Bitsight's own, so check the label names the sector you would name; and a small comparison group moves a percentile further than a large one.

The twelve months

The trend graph covers the last twelve months and includes every rating-change event, publicly disclosed incidents among them, and the report states the highest and lowest points with the dates they occurred. Those two dates are the useful part.

  • A recent low asks what happened around that date — a change in the estate, an incident, a vendor or an acquisition — before it asks what to fix.
  • A high that is a year old and a rating that has drifted down since is a programme losing ground slowly, which a single snapshot would not show.
  • A flat line is not automatically good. It can mean a stable estate or one nobody is changing.

Ransomware and incident multiples

Two panels, one for ransomware and one for security incidents, each state how much more exposed the company is than companies rated 750 and above. They are multiples of that group's likelihood, not probabilities: Bitsight bases them on its published correlation work, which is linked from the report itself — ransomware and security incidents.

A multiple of one would be parity with the 750-plus group, and a larger multiple means more exposed than it. What they cannot do is predict what will happen to a particular organisation. They sort populations by likelihood, which is what makes them useful in an insurance conversation and unsafe as a forecast.

Publicly disclosed incidents

The second page lists publicly disclosed security incidents in the last eighteen months — confirmed events of unauthorised access, often involving data loss, graded on factors that include the number of records exposed. Bitsight draws on news reporting and on regulatory reports obtained through Freedom of Information requests or local equivalents, and this vector affects the rating only when an incident is confirmed.

An empty list therefore means no confirmed, publicly disclosed incident in the window. It says nothing about incidents that were never disclosed.

Which estate was scored

A report that uses a Primary Rating says so in the additional information. A company may designate particular subsidiaries, business units or locations as representative of its digital footprint and exclude the rest — guest wireless, security test environments and networks used for customer hosting are the usual exclusions. Bitsight does not validate those exclusions, nor the predictive quality of a rating built from them.

Check this line before comparing your number with anyone else's. Two different figures for the same company are usually two different estates rather than two opinions; the report page explains why a rating can disagree with a self-serve scan.

Questions to take into the walkthrough

Bitsight's request page also lists threat insights tied to observable security gaps; the executive specimen published here does not include that panel, and it carries no findings list. What follows the report is a conversation, and these are the questions that make it worth the hour:

  • Is every asset attributed to us ours, and is anything of ours missing?
  • Is this a Primary Rating, and who decided what it excludes?
  • What happened on the date of the lowest point?
  • Which two or three findings account for most of the distance to the industry average?
  • How long would those take to clear, and how quickly would the rating respond?

Related reading

Questions this page answers

What does "more vulnerable than companies rated 750+" mean in the report?
It is a comparison, not a probability. Bitsight states ransomware and security-incident likelihood as a multiple of the likelihood for companies rated 750 and above, and links its published correlation datasheets from the report itself. A multiple of one would be parity with that group, and a larger multiple means more exposed than it. The figure sorts populations by likelihood and does not predict the outcome for any single organisation.
Why does the report show a percentile when it already has a rating?
A rating has no scale on its own. The percentile and the industry average place it against the companies in Bitsight’s comparison group for the industry, so the same number reads as strong in one sector and lagging in another. The average across everything Bitsight rates is 720, which sits inside the Intermediate band, so the band alone says little about standing.
What is a Primary Rating?
A Primary Rating is the rating of a company that has designated particular subsidiaries, business units or locations as representative of its digital footprint and excluded the rest, typically guest wireless, security test environments and customer-hosting networks. Bitsight does not validate those exclusions or the predictive quality of the result. A report built on one says so in its additional information.
Does the executive report list what to fix?
The executive specimen published on this site is a comparison and trend document and carries no findings list. Bitsight’s request page also lists threat insights tied to observable security gaps, which the specimen does not show. Working through the findings is the purpose of the analyst walkthrough that follows the report, and of continuous monitoring after it.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

The complimentary Cyber Risk Rating Report →

Request my rating →Read any rating against the bands