What is a cyber security rating?
An objective measure of security performance, calculated from outside. The four families of signal behind it, and what a rating cannot tell you.
Most security assessment is self-reported. Someone fills in a questionnaire, someone else files it, and both parties treat the result as evidence. A security rating inverts that: it measures what an outside observer can actually see, continuously, whether or not the organisation cooperates.
How a rating is calculated
The calculation runs entirely on external signals. There is no agent to deploy, no network access to grant, no credentials to share, and no questionnaire to complete. The platform identifies the internet-facing assets belonging to an organisation, observes their behaviour and configuration, and scores what it finds.
Bitsight scans 4 billion+ routable IPv4 and IPv6 addresses daily and tracks 250 million+ hostnames across 325 million+ organisations, processing 400 billion security events per day. Findings are grouped into 25 risk vectors and weighted, with more than twelve months of history retained so the score reflects a trend rather than a single day.
The four families of signal
- Compromised systems. Botnet infections, malware servers, spam propagation and unsolicited communications — evidence that machines on your network are already under someone else's control. These carry the heaviest weight, because they are not a theoretical weakness but an active compromise.
- Diligence. Critical Vulnerability Management, open ports, TLS/SSL configuration, web application security headers, DNSSEC, and SPF, DKIM and DMARC records. This is the housekeeping category: individually minor, collectively the clearest signal of whether a security programme is actually operating. DMARC joined it in July 2026, when Bitsight's annual algorithm update made the record rating-impacting at a 1% weight; Critical Vulnerability Management carries 20%, the largest single weighting in the diligence family.
- User behaviour. Signals such as file sharing and exposed credentials associated with the organisation's domains.
- Public disclosures. Publicly reported breaches and security incidents attributed to the organisation.
Where a rating sits on the scale
Bitsight publishes ratings on a nominal 250 to 900 scale, in three bands — Basic, Intermediate and Advanced — against an average of 720. The detail underneath is more awkward than the headline. Both ends of the nominal scale are reserved for future use, so the achievable range is 300 to 820. Ratings round down in ten-point steps, so no published rating ends in 1 to 9 and the bands do not touch. And Advanced holds the majority of the rated inventory rather than the front of it.
The Bitsight score reader takes any rating and returns the band, the share of entities above it, the letter grades underneath and the risk categories that move it. This page is about what a rating is; that one is about what a particular number says.
Why the credit score comparison holds — and where it breaks
The analogy is useful. Like a credit score, a security rating is calculated about you rather than by you, updates continuously, is used by third parties to make decisions, and reduces a complicated reality to a number that non-specialists can act on.
Where it breaks: a credit bureau sees essentially complete data on your borrowing, whereas a security rating sees only your external surface. It cannot observe your internal segmentation, your privileged access controls, your backup regime, or the quality of your security team. A strong rating means your externally visible hygiene is good. It does not certify that you cannot be breached, and no honest vendor claims otherwise.
Does the number actually predict anything?
This is the question worth pressing any ratings vendor on, because a score that correlates with nothing is theatre.
Bitsight publishes the relationship band by band, and it is comparative rather than absolute: Intermediate entities are, on average, 1.5–2× more likely to be breached than Advanced entities, and Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities. At the extremes, entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above. Note the shape of those claims — the rating sorts populations by likelihood; it does not promise anything about an individual organisation.
The independent work behind it is research by Marsh McLennan, Moody's and Gallagher Re, together with work by Verisk Extreme Event Solutions and S&P Global, which Bitsight still cites under their former names, AIR Worldwide and IHS Markit. The most substantial is Marsh McLennan's Cyber Risk Analytics Center analysis of October 2022, which compared the security performance of thousands of organisations that experienced incidents against those that did not and identified fourteen Bitsight analytics as statistically significant.
Who is already looking at your rating
- Cyber insurers, in underwriting and pricing. Roughly half the cyber insurance market uses Bitsight data.
- Prospective enterprise customers, during vendor due diligence — often before they tell you they are evaluating you.
- Existing customers running continuous third-party monitoring, who will be alerted if your posture degrades.
- Boards and regulators, as independent evidence of oversight rather than management assertion.
- Acquirers, during technical due diligence.
The consequence is simple: the rating exists whether or not you have looked at it, and other people are acting on it. Not knowing your score does not make it neutral — it makes you the only party in the conversation without the information.
Where to go next
- How to improve your Bitsight security rating — which findings actually move the number, and in what order.
- How the ratings platforms compare — Bitsight, SecurityScorecard, RiskRecon and UpGuard, and the head-to-heads on each.
- What Indian boards must now evidence — the regulatory context for continuous measurement.
Questions this page answers
- What is a cyber security rating?
- A cyber security rating measures what an outside observer can see of an organisation’s internet-facing estate, continuously, whether or not the organisation cooperates. Most security assessment is self-reported — someone completes a questionnaire and both parties treat the result as evidence. A rating inverts that: there is no agent to deploy, no network access to grant, no credentials to share and no questionnaire to complete.
- Is a cyber security rating the same as a cyber risk rating?
- In practice the two names describe the same instrument, and vendors use them interchangeably. Both mean a score calculated from externally observable evidence about an organisation’s internet-facing estate, recalculated continuously, expressed on a fixed scale. Neither name implies a different methodology. What does differ between vendors is the scale, the refresh cadence and whether anyone outside the vendor has tested the score against real breach outcomes.
- Can a rating be produced without our permission?
- Yes, and that is the point of the instrument rather than a flaw in it. A rating is calculated only from signals an outside observer can already see, so no consent, contract or cooperation is required to produce one. Insurers, regulators, prospective customers and existing clients can therefore hold a view of an organisation’s security performance that the organisation has never been shown — and usually do, before any conversation starts.
- What does a rating actually measure?
- Four families of externally observable signal. Compromised systems — botnet infections, malware servers, spam propagation — which carry the heaviest weight because they evidence an active compromise rather than a theoretical weakness. Diligence, the housekeeping category covering Critical Vulnerability Management, open ports, TLS/SSL configuration, security headers, DNSSEC and SPF, DKIM and DMARC. User behaviour, such as exposed credentials associated with the organisation’s domains. And public disclosures of breaches attributed to it.
- What does a strong rating not tell you?
- A strong rating means externally visible hygiene is good. It does not certify that internal controls are effective, and it cannot see anything that is not internet-facing. Treating it as a certification of the whole security programme is the most common way the number gets misused — in procurement clauses and in board packs alike.