What is a cyber security rating?
A cyber security rating is an objective, externally calculated measure of security performance. How the 250–900 scale works, what the risk vectors are, and what the score can and cannot tell you.
Most security assessment is self-reported. Someone fills in a questionnaire, someone else files it, and both parties treat the result as evidence. A security rating inverts that: it measures what an outside observer can actually see, continuously, whether or not the organisation cooperates.
How a rating is calculated
The calculation runs entirely on external signals. There is no agent to deploy, no network access to grant, no credentials to share, and no questionnaire to complete. The platform identifies the internet-facing assets belonging to an organisation, observes their behaviour and configuration, and scores what it finds.
Bitsight scans in excess of 4 billion routable addresses daily and tracks over 250 million hostnames across more than 40 million organisations, processing roughly 400 billion security events per day. Findings are grouped into 25 risk vectors and weighted, with more than twelve months of history retained so the score reflects a trend rather than a single day.
The four families of signal
- Compromised systems.Botnet infections, malware servers, spam propagation and unsolicited communications — evidence that machines on your network are already under someone else's control. These carry the heaviest weight, because they are not a theoretical weakness but an active compromise.
- Diligence. Patching cadence, open ports, TLS/SSL configuration, web application security headers, DNSSEC, and DKIM/SPF records. This is the housekeeping category: individually minor, collectively the clearest signal of whether a security programme is actually operating.
- User behaviour.Signals such as file sharing and exposed credentials associated with the organisation's domains.
- Public disclosures. Publicly reported breaches and security incidents attributed to the organisation.
What the 250–900 scale means
| Band | Range | Interpretation |
|---|---|---|
| Advanced | 740–900 | Strong security performance, lower risk |
| Intermediate | 640–730 | Fair security performance, moderate risk |
| Basic | 250–630 | Poor security performance, higher risk |
The absolute number matters less than two things beside it: your trend over twelve months, and your position against sector peers. A 690 that has climbed from 610 describes a functioning programme. A 690 that has slid from 760 describes one that has stopped being maintained. Both look identical on the day you read the score.
Why the credit score comparison holds — and where it breaks
The analogy is useful. Like a credit score, a security rating is calculated about you rather than by you, updates continuously, is used by third parties to make decisions, and reduces a complicated reality to a number that non-specialists can act on.
Where it breaks: a credit bureau sees essentially complete data on your borrowing, whereas a security rating sees only your external surface. It cannot observe your internal segmentation, your privileged access controls, your backup regime, or the quality of your security team. A strong rating means your externally visible hygiene is good. It does not certify that you cannot be breached, and no honest vendor claims otherwise.
Does the number actually predict anything?
This is the question worth pressing any ratings vendor on, because a score that correlates with nothing is theatre.
For Bitsight ratings, independent research by Marsh McLennan's Cyber Risk Analytics Center and AIR Worldwide has examined the relationship between rating and subsequent breach incidence, and found organisations with higher ratings materially less likely to suffer a data breach — roughly half as likely. Further work by Moody's Analytics, IHS Markit and Gallagher Re has examined the correlation to financial risk. The underlying evidence is published rather than asserted, which is the standard any rating should be held to.
Who is already looking at your rating
- Cyber insurers, in underwriting and pricing. Roughly half the cyber insurance market uses Bitsight data.
- Prospective enterprise customers, during vendor due diligence — often before they tell you they are evaluating you.
- Existing customers running continuous third-party monitoring, who will be alerted if your posture degrades.
- Boards and regulators, as independent evidence of oversight rather than management assertion.
- Acquirers, during technical due diligence.
The consequence is simple: the rating exists whether or not you have looked at it, and other people are acting on it. Not knowing your score does not make it neutral — it makes you the only party in the conversation without the information.
Where to go next
- How to improve your Bitsight security rating — which findings actually move the number, and in what order.
- How the ratings platforms compare — Bitsight, SecurityScorecard, RiskRecon and UpGuard.
- What Indian boards must now evidence — the regulatory context for continuous measurement.