What a Bitsight score of 600 means
Read any Bitsight rating against the published scale — the band, how the rated inventory is distributed, what the letter grades underneath mean, and which risk categories actually move the number.
What this rating says
A rating of 600 is Basic, the lowest of the three categories and around 5% of the rated inventory. It sits 120 points below the published average and 40 below the bottom of the Intermediate band. The useful reading is not the label but the distance: four rating steps, each of which has to be traceable to a risk vector, and nearly three-quarters of the weight available in configuration work that is visible from outside.
| Reading | Value |
|---|---|
| Category | Basic |
| Band range | 250 – 630 |
| True rating behind it | 600 – 609, since ratings are rounded down in tens |
| Share of rated entities in this band | 5% |
| Share in a stronger band | 95% |
| Against the average of 720 | 120 points below |
| To the next band | 40 points to Intermediate |
| Relative breach likelihood | Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities. |
600 is Basic, and 120 points below the published average of 720. Roughly 95% of rated entities sit in a stronger band.
Entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above. Ratings run from 300 to 820 in practice, always in steps of ten — so there is no rating of 605, and a figure ending in 1 to 9 did not come from a Bitsight report.
Read your own rating
The reader below opens on 600. Enter your own figure to see the band, the distance to the next one, and which risk categories carry the weight.
600 is Basic, and 120 points below the published average of 720. Roughly 95% of rated entities sit in a stronger band.
A published rating is the floor of a ten-point interval, not a point. A rating shown as 600 means the true rating is somewhere between 600 and 609.
| Category | Range | Share of entities | Relative breach likelihood |
|---|---|---|---|
| Advanced | 740 – 900 | 60% | The lowest breach likelihood of the three bands. |
| Intermediate | 640 – 730 | 35% | Intermediate entities are, on average, 1.5–2× more likely to be breached than Advanced entities. |
| BasicYour band | 250 – 630 | 5% | Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities. |
Entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above.
40 points to Intermediate. That is 4 rating steps, and every step has to be traceable to a risk vector — the rounding is set so it cannot come from aggregate drift.
What actually moves it
| Risk category | Weight | What sits in it |
|---|---|---|
| Diligence | 71.5% | Externally observable configuration — TLS and certificates, email authentication, open ports, software currency, vulnerability remediation practice. |
| Compromised Systems | 26% | Evidence of machines on your network behaving as though under external control — command-and-control traffic, malware distribution, participation in DDoS, spam. |
| User Behavior | 2.5% | File sharing and exposed credentials attributable to people on your network. |
| Public Disclosures | Conditional | Disclosed breaches. Weighted only if they occur, so it carries no standing share. |
Nearly three-quarters of the rating is Diligence — configuration anyone outside can observe. That is the part you can move without touching your internal estate, and it is why most of a first remediation pass is certificates, TLS and email authentication rather than anything architectural.
Reading the vector grades underneath
| Grade | What it means |
|---|---|
| A | In the top 10% of companies. |
| B | In the top 30% of companies. |
| C | In the top 60% of companies. |
| D | In the bottom 40% of companies. |
| F | In the bottom 20% of companies. |
| N/A | No correlation with performance — an informational vector, a vector with no findings, or one still inside its evaluation period. |
A C is the middle of the field, not seventy per cent right, and a D is the bottom four-tenths. Individual findings underneath a vector carry a separate GOOD / FAIR / WARN / BAD scale — the two vocabularies do not map onto each other.
Indicative. This reads the published scale; it does not look up any organisation’s rating. Figures verified against Bitsight’s own knowledge base.
Take this away as a rating brief
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
For the rounding rule in full, the distribution across all three bands, and what the number cannot tell you, see the full rating reader. For the judgement question rather than the lookup, see what counts as a good Bitsight score.
This page reads the published rating scale and does not look up any organisation’s rating. Every figure was read from Bitsight’s own knowledge base rather than from secondary reporting. Every instrument cited here was verified against the issuing regulator's own notification on .
Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What does a Bitsight score of 600 mean?
- It is a Basic rating — the lowest of the three categories, covering ratings of 630 and below and around 5% of the rated inventory. Bitsight characterises the band as poor security performance and higher risk, and puts Basic entities on average 2 to 3 times more likely to suffer a publicly disclosed breach than Intermediate ones. It sits 120 points below the published average of 720, and 40 points below the bottom of the Intermediate band.
- Why is there no Bitsight rating of 635?
- Because ratings are rounded down in ten-point increments, so every published rating is a multiple of ten. A true rating of 635 is published as 630. Bitsight sets the rounding this way so that any movement in a rating can be traced back to at least one risk vector rather than to aggregate noise. The practical consequence is that a published rating is the floor of a ten-point interval: a rating shown as 740 means the true figure is somewhere between 740 and 749. Any source quoting a band as “640 to 739” is describing numbers that cannot occur.
- What is the range of Bitsight security ratings?
- The nominal scale runs from 250 to 900, but the upper and lower edges are reserved for future use and are unoccupied. The effective range — where ratings actually fall — is 300 to 820. Quoting 250 to 900 as the working scale overstates the spread at both ends, which matters when a rating is being read as a percentage of some maximum. It is not a percentage of anything.
- What is the average Bitsight score?
- 720, which sits in the Intermediate band. This is worth holding alongside the distribution: 60% of rated entities are Advanced at 740 or above, 35% are Intermediate, and 5% are Basic. Advanced is therefore the majority of the inventory rather than the front of it, and clearing 740 says less about relative standing than the label suggests.
- What do the Bitsight letter grades mean?
- They are percentile ranks against every rated company, not marks out of a hundred. A is the top 10%, B the top 30%, C the top 60%, D the bottom 40% and F the bottom 20%. N/A carries no performance signal at all — it appears on informational vectors, on vectors with no findings, and on vectors still inside an evaluation period. Individual findings underneath a vector are graded on a separate GOOD, FAIR, WARN, BAD scale, and the two vocabularies do not map onto each other.
- What has the biggest effect on a Bitsight rating?
- Diligence, which carries 71.5% of the weight — externally observable configuration such as TLS and certificates, email authentication, open ports, software currency and vulnerability remediation practice. Compromised Systems carries 26%, User Behavior 2.5%, and Public Disclosures is weighted only if a breach occurs, so it has no standing share. Because Diligence dominates and is made of things anyone outside can observe, most of a first remediation pass is configuration work rather than anything architectural.