Your free Cyber Risk Rating Report
See your organisation's 250–900 cyber security rating, how it compares with your industry average, and your likelihood of a ransomware or data-breach incident. Complimentary, as little as 45 minutes for publicly listed entities, up to 48 hours for all others.
- /01Your current Bitsight Security Rating (250–900)
- /02Likelihood of ransomware and data-breach incidents
- /03Your rating against your industry average
- /04Cyber security performance over the last twelve months
- /05Threat insights tied to observable security gaps
Almost every organisation we speak to is already being rated. Insurers price against it, prospective enterprise customers check it during procurement, and regulators increasingly expect a board to know it. The rating exists whether or not you have ever looked at it, because it is calculated from what an outside observer can see. The report simply lets you read your own file.
Yes, you can check your score for free
There is no licence, no trial window and no card. The report is complimentary and one-time, and it is the same Bitsight output a customer sees rather than a reduced version of it. What a licence buys is not the number but the continuity: watching it daily as your estate changes, and watching your vendors' numbers alongside it.
The one thing worth being clear about is that the rating already exists. It is calculated from what an outside observer can see, so requesting the report does not create a rating for your organisation — it gives you sight of the one your insurer, your regulator and your prospective customers can already read.
What is actually in the report
It is a complete report, not a teaser that withholds the number until you buy something. Six things arrive together, and the report is built on the data independently verified to correlate most strongly with the likelihood of an incident:
- Your current Security Rating, 250–900. One number, calculated daily from external signals, on the same scale used by nearly 40% of the Global Fortune 500.
- Your likelihood of a ransomware incident. Expressed as a multiple against companies rated 750 and above, so the figure is comparative rather than a probability plucked from nowhere.
- Your likelihood of a data-breach incident. The same comparative treatment, against the same reference population.
- Your rating against your industry average. With your percentile placement and the distribution your industry actually forms. This is the part boards react to, because 650 in isolation means nothing and 650 against an industry average of 740 means something very specific.
- Performance over the last twelve months. The rating's trajectory, with its highest and lowest points and the dates they occurred — which distinguishes a programme that is working from one that had a good year.
- Threat insights tied to observable security gaps. What is visible from outside, connected to the exposure it creates.
It is also a document written to be shown to other people. Aligning a security team, setting a target and evidencing progress to a board or an audit committee are the uses it gets put to most often, which is why it leads with comparison and trajectory rather than with a finding list.
How it is produced
The rating is calculated entirely from externally observable, attacker-visible signals across your internet-facing footprint. The platform identifies the assets belonging to your organisation, observes their configuration and behaviour continuously, and scores what it finds across risk vectors including botnet infections, spam propagation, malware servers, Critical Vulnerability Management, open ports, TLS/SSL configuration, web application headers, DNSSEC and DKIM/SPF records.
Because no internal telemetry is involved, there is nothing to deploy and nothing to approve. That is also why the turnaround is measured in hours: for publicly listed entities the internet-facing footprint is usually already well attributed, so a report can arrive in as little as 45 minutes. Everyone else receives theirs within 48 hours, the extra time going into attributing assets correctly rather than into any onboarding step on your side.
What the bands mean
| Band | Range | Interpretation |
|---|---|---|
| Advanced | 740–900 | Strong security performance, lower risk |
| Intermediate | 640–730 | Fair security performance, moderate risk |
| Basic | 250–630 | Poor security performance, higher risk |
To read a specific number against these bands and the grades beneath them, use what a Bitsight score means.
The relationship between band and breach likelihood is published rather than asserted, and it is comparative: Bitsight states that Intermediate entities are on average 1.5–2× more likely to be breached than Advanced ones, and that entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than those rated 700 or above. The principal independent study behind it is Marsh McLennan’s Cyber Risk Analytics Center analysis of October 2022. That external validation is why the number carries weight with an insurer or a board in a way an internal maturity score does not.
Why a rating can disagree with a self-serve scan
A company may designate particular subsidiaries, business units or locations as representative of its digital footprint and exclude the rest — guest wireless networks, security test environments and infrastructure used for customer hosting are the usual exclusions, on the argument that they do not describe the organisation's own security posture. The result is called a Primary Rating. Bitsight does not validate those exclusions, nor the predictive quality of a rating produced from them.
This is worth knowing before comparing numbers. A free instant scan run by any vendor against a domain is looking at whatever it can attribute from outside; a Primary Rating is looking at a curated estate. Two different numbers for the same company are usually two different estates rather than two different opinions.
If you want to run something yourself first, two of our free tools scan from outside in the same way — an email spoofing check reading SPF, DMARC and DKIM, and an SSL estate check across your subdomains. Neither is a rating, and neither sees what the report sees. They answer one question each, in a few seconds, without you asking anyone for anything.
Who tends to request one
- CISOs and CROs who can describe their controls in detail but cannot evidence how they compare to sector peers today, between annual assessments.
- Heads of third-party risk who want to see the instrument applied to their own organisation before pointing it at two hundred vendors.
- CFOs and boards preparing for a cyber insurance renewal, a regulatory examination, or an enterprise customer's security review — all three of which now ask for external evidence rather than a self-assessment.
What happens afterwards
A BitScore analyst offers to walk through the findings and explain what is driving the score. That conversation is usually worth an hour, because the gap between “here are forty findings” and “here are the six that move your number this quarter” is where the value sits. There is no obligation attached to it.
From there the two natural paths are Security Posture Management, if the goal is to maintain and improve your own rating continuously rather than measure it once, and Third-Party Risk Management, if the more urgent blind spot is your vendor ecosystem. Packaging and how a quote is determined are set out on the pricing page.
See what you'll get, before you ask for it.
Specimen reports · No form
SPECIMEN / EXECUTIVECyber Risk Rating ReportThe board-level snapshot: your Bitsight Security Rating on the 250–900 scale, how much more exposed you are to ransomware and security incidents than companies rated 750+, percentile placement against your industry, and the 12-month trend.View specimen (2-page PDF) →
SPECIMEN / BENCHMARKNIFTY 50 Peer BenchmarkThe same rating read against the NIFTY 50 as a peer group: where you fall in the distribution, the median and top-quartile scores to close on, and which risk vectors run behind or ahead of the index.View specimen (4-page PDF) →Genuine Bitsight output, run against a demo entity. No client data.
Questions people actually ask about RPT.
/01What does the Cyber Risk Rating Report cost?
Nothing. The baseline Cyber Risk Rating Report is complimentary and one-time. It carries no obligation to buy anything afterwards, and it is a complete report rather than a teaser — your current rating, your likelihood of ransomware and data-breach incidents, your rating against your industry average, your performance over the last twelve months and threat insights tied to observable security gaps are all included.
/02Can we check our Bitsight score for free?
Yes. BitScore delivers a complimentary, one-time Cyber Risk Rating Report carrying your organisation’s current Bitsight Security Rating on the 250 to 900 scale, with no licence, no trial period and no obligation. Nothing is installed and no access is granted, because the rating is calculated from signals an outside observer can already see. What a licence buys is not the number but the continuity — watching it daily, and watching your vendors.
/03What is a Primary Rating, and will ours be one?
A Primary Rating is what a company gets once it has curated which parts of its digital footprint the rating covers — excluding, typically, guest wireless networks, security test environments or infrastructure used for customer hosting, on the basis that these do not describe its own security posture. Bitsight does not validate those exclusions or the predictive quality of the result. It matters here because it is the usual explanation for a rating disagreeing with a self-serve external scan: the two are not looking at the same estate.
/04How long does the report take to arrive?
Publicly listed entities typically receive their report in as little as 45 minutes, because their internet-facing footprint is already well attributed. All other organisations receive theirs within 48 hours. There is no onboarding or deployment step to wait on, since the rating uses only external signals.
/05Do we need to install anything or grant system access?
No. There is no agent to deploy, no network access to grant, no credentials to share, and no questionnaire to complete. The rating is calculated entirely from externally observable, attacker-visible signals across your internet-facing footprint.
/06Can we see a specimen report before requesting ours?
Yes. Two specimen reports are published on the BitScore site — an executive Cyber Risk Rating Report and a NIFTY 50 peer benchmark. Both are real Bitsight output run against a demonstration entity rather than mock-ups, so they show the actual deliverable and its actual level of detail.
/07What happens after we receive the report?
Nothing automatic. A BitScore analyst will offer to walk through the findings and explain what is driving the score, which is usually worth an hour. Organisations that want the rating maintained continuously rather than measured once move to Security Posture Management; those whose concern is their vendor ecosystem move to Third-Party Risk Management.
Start with the number, not the contract.
Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.
- FundamentalsWhat is a cyber security rating?What a rating is, the four families of signal it is built from, and the genuine limits of a number produced without your participation.
- RemediationHow to improve your Bitsight security ratingThe findings that actually move the score, the order to fix them in, and how quickly the rating responds.
- ComparisonCyber security rating vendors in India: how to choose oneWhat a ratings vendor is and is not, who is available in India, and the six criteria that separate them for an Indian buyer.