Fundamentals

What is a good Bitsight score?

740 and above is the Advanced band — but the useful answer depends on who is asking. How the bands work, what counts as good to an insurer, a customer and a board, and why percentile beats the absolute number.

In short
A Bitsight rating of 740 or above sits in the Advanced band, usually treated as good — though roughly 60% of rated entities are already there, marking the majority rather than the front. Sector percentile, trajectory and the vectors dragging on the score say more. A 700 climbing sixty points in a year beats an 800 sliding.

The bands, and what they actually assert

A Bitsight rating is expressed on a 250–900 scale and falls into one of three bands.

BandRangeInterpretationShare of entities
Advanced740–900Strong security performance, lower risk60% of rated entities
Intermediate640–730Fair security performance, moderate risk35% of rated entities
Basic250–630Poor security performance, higher risk5% of rated entities
Bitsight rating bands on the 250–900 scale, with the share of rated entities in each as published by Bitsight.

Two mechanical points, because both change how a number should be read. Ratings round down in ten-point increments, so an actual 735 displays as 730 and nothing is ever rated 631 to 639 — the apparent gaps between bands are an artefact of that, not missing territory. And while the nominal scale runs 250 to 900, Bitsight reserves both ends “for future use”: the currently achievable range is 300 to 820. An 810 is therefore close to the practical ceiling rather than a comfortable distance from it.

The bands describe observed external performance, not the quality of a security team or the sophistication of an internal control environment. A rating is calculated from signals an attacker could also see — open ports, certificate and header configuration, mail authentication records, evidence of compromised hosts — with no agent, no credentials and nothing self-reported. That is precisely what makes it usable as evidence by a third party, and precisely what limits what it can tell you.

“Good” depends on who is asking

The question almost never arrives in the abstract. It arrives inside one of three conversations, and each of them means something different by it.

To an insurer

Underwriters use ratings as a risk signal because the correlation to outcomes has been studied rather than asserted. The published relationship is comparative: Bitsight states that Intermediate entities are, on average, 1.5–2× more likely to be breached than Advanced entities, that Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities, and that entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above. The independent work behind it is principally Marsh McLennan's Cyber Risk Analytics Center analysis of October 2022. In this conversation, good means far enough up the scale that your expected loss assumption improves, and stable enough that the assumption holds for the policy period.

To a customer or prospect running due diligence

Here good is whatever their own policy says it is. Organisations that tier their suppliers set a floor per tier — a common shape is that vendors touching critical operations must hold a specified minimum, with lower tiers held to a lower bar. The floor is usually a band boundary rather than a precise number, because a threshold that moves with every daily recalculation is unenforceable in a contract.

To your own board or regulator

In governance conversations the absolute figure is the least interesting part. What a board needs is a measurement that is independent, dated, repeatable and comparable quarter-on-quarter — so that oversight can be evidenced rather than asserted. A rating that is merely adequate but demonstrably improving, with named owners against named findings, answers that question better than a high score nobody can account for.

Percentile beats the absolute number

Ratings are not evenly distributed across industries. Sectors with heavy regulatory pressure and mature security functions cluster higher; sectors with sprawling, long-lived internet estates cluster lower. An identical score can therefore be top-quartile in one industry and below median in another.

This is why a peer benchmark is more actionable than the raw figure. The questions worth asking are:

  • Where does this rating place us in our industry distribution — top quartile, median, or below?
  • Which specific risk vectors run behind the peer median, and by how much?
  • What is the median and top-quartile score in our sector, so we know what closing the gap requires?
  • How do our critical vendors distribute against the same benchmark?

A rating read without that context invites the wrong conclusion in both directions: complacency at 780 in a sector where 820 is median, and unwarranted alarm at 690 in one where it is comfortably above.

Trajectory is a stronger signal than position

Because ratings recalculate continuously, the shape of the line carries information the current value does not. A sustained decline usually means something structural: an expanding estate nobody is decommissioning, a certificate or patching process that has quietly stopped being owned, or an acquisition whose infrastructure has been absorbed but not remediated.

A sustained rise means the opposite — findings are being closed faster than new ones appear. That is the property boards and insurers actually care about, because it predicts where the organisation will be next quarter rather than describing where it was last one.

What a good score does not mean

A high rating is evidence of externally observable hygiene. It is not, and does not claim to be:

  • Proof that you have not been breached. An intrusion that leaves no externally visible artefact will not move the rating.
  • A measure of internal controls. Identity, segmentation, privileged access, backup integrity and detection capability are not externally visible and are not measured.
  • A substitute for testing. A rating identifies configuration and exposure weaknesses; it does not attempt exploitation, so it cannot tell you what an attacker would achieve once inside.
  • Static. A rating quoted in a slide is accurate for the day it was pulled. Any contractual or reporting use needs to reference the live figure, not a snapshot.

The practical reading is that a good rating raises the cost of attacking you opportunistically and gives third parties a defensible basis for trusting you. It does not close the question of whether you are secure, and any programme that treats it as though it does will optimise for the measurement rather than the outcome.

What it takes to move a band

Band movement comes from remediating the specific findings that depress the score, in priority order rather than in the order they were discovered. The findings that typically carry the most weight are unnecessary open ports, unremediated critical vulnerabilities — Critical Vulnerability Management alone carries a 20% weight, and since July 2026 grades on severity rather than on time-to-patch — TLS/SSL misconfiguration, missing security headers, and incomplete DNSSEC, SPF, DKIM and DMARC records. DMARC became rating-impacting in that same July 2026 update, at a 1% weight. The remediation guide covers the ordering and how quickly the score responds to each.

Rating bands, the 250–900 scale, the 300 to 820 effective range, the ten-point rounding rule, the band distribution and the breach multiples are all as published by Bitsight Technologies, Inc. and read from its rating methodology documentation, August 2026. The independent correlation work is Marsh McLennan Cyber Risk Analytics Center research of October 2022; Bitsight additionally cites Marsh McLennan, Moody's and Gallagher Re and others on its outcomes page. BitScore Cybertech LLP is an authorised Bitsight partner.

Questions this page answers

Is 740 a good Bitsight score?
740 is the floor of the Advanced band, and roughly 60% of all rated entities are already above it, so it marks the majority rather than the front. Against an average of 720, clearing 740 puts a firm twenty points past the middle of the field — worth knowing before presenting it to a board as an achievement.
What is the average Bitsight rating?
720, which sits twenty points below the Advanced threshold of 740. The distribution is lopsided: roughly 60% of rated entities are in the Advanced band, 35% in Intermediate and 5% in Basic. That shape is why a percentile against your own sector carries more information than the absolute number does.
Why does our rating show 730 when we calculated 735?
Ratings are rounded down in ten-point increments, so an actual 735 displays as 730. The same rule means nothing is ever rated between 631 and 639 — the apparent gaps between the bands are an artefact of the rounding rather than missing territory.
What is the highest rating actually achievable?
The nominal scale runs 250 to 900, but Bitsight reserves both ends for future use, so the currently achievable range is 300 to 820. An 810 is therefore close to the practical ceiling rather than a comfortable distance below the top of the published scale.
Is a high rating better than a rising one?
Not necessarily. A 700 that has climbed sixty points in a year is a stronger signal than an 800 that has been sliding: the trend describes whether a security programme is operating, where the absolute number describes a moment. A single reading cannot distinguish steady competence from one good year.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ