Free tool · Exposure checks

Rating Day: one quarter, six decisions, and the board sees the number

A ten-minute game for CISOs, CROs and boards: six calls on your perimeter and your vendors, each moving a security rating the board will see.

In short
An outside-in security rating moves with two things an organisation controls: its own internet-facing posture and the posture of the vendors it depends on. Exposed remote access, leaked credentials, unpatched edge devices and missing email authentication weigh on the first. A vendor breach, a fourth-party outage or an unassessed AI tool weighs on the second. Speed matters on both, because the evidence is visible from outside.

Play it

Pick your seat. The quarter starts on 640, and the board meets on day ninety. Six decisions arrive — 3 on your own perimeter, 3 on your vendors, drawn at random from thirty — with 100 seconds on each, so ten minutes for the quarter at most. Run out of time and you get the outcome of doing nothing. The budget is 10 for the quarter, and the right answer usually costs something.

BitScoreRating Day10 min6 decisions1 board meeting

For the people who answer to the board

Your rating is only as strong as your weakest vendor.

Ninety days to the board meeting. Six decisions across your own perimeter and forty suppliers. Every call moves your security rating — and the board sees the number.

Play as
No sign-up to play.
Music starts with the quarter — mute any time.

What is real and what is a game rule

The situations are real in kind. Exposed remote access, leaked passwords, dangling DNS records, a vendor whose rating falls overnight, a breach at your vendor’s own host, an AI tool nobody assessed: each is a common way an organisation’s outside-in risk changes, and each card says what it teaches. No company is named, and every vendor is generic.

The numbers are game rules. The 300–820 scale, the start at 640, the bands — Advanced from 740, Intermediate from 640, Basic below — the budget and every cost and rating change are set so that the right call usually costs something and doing nothing usually costs more. Picking the strongest option with 70 or more seconds left earns +10.

The game is about deciding under a clock. The incident that follows a bad quarter is a different clock, with regulators on the other end of it — play Survive the six hours next. And for the number the game is standing in for, the Rating Report gives your organisation’s own, complimentary.

A game. The scale, costs and rating changes are game rules, not measurements of any organisation, and nothing here is a security rating or professional advice.

Questions this page answers

What is security posture management?
Security posture management is the continuous work of finding and fixing what makes an organisation attackable from outside: exposed services, expired certificates, leaked credentials, unpatched internet-facing systems, missing email authentication and infected hosts on its addresses. Because all of it is observable from the internet, it is also what an outside-in security rating measures, and what an attacker scanning for a way in sees first.
Why does a vendor’s security affect our own risk?
Because the vendor holds your data or runs part of your service. A payroll provider’s exposed database exposes your employees; a cloud region outage takes your portal down; a call centre that falls for phishing can reset your customers’ passwords. Regulators increasingly treat that as the organisation’s own risk: the EU’s DORA, for example, expects financial entities to keep a register of their ICT third-party arrangements and documented exit strategies for the critical ones.
Are annual vendor questionnaires enough?
Not on their own. A questionnaire records what a vendor said at one point in the year, and the business often skips it when it takes weeks. The common pattern is to tier vendors by risk, monitor every vendor continuously from outside, and reserve the detailed questionnaire and contract terms — breach notification, audit rights, a minimum rating — for the critical few.
What should the board see about cyber risk?
A small number of measures it can compare and track over time, rather than a controls framework. An outside-in rating benchmarked against the sector, its trend over the year, and the handful of critical vendors whose failure would stop the business answer the question boards actually ask — how do we compare, and is it getting better.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of mycompany, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source →The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating →All free tools