Rating Day: one quarter, six decisions, and the board sees the number
A ten-minute game for CISOs, CROs and boards: six calls on your perimeter and your vendors, each moving a security rating the board will see.
Play it
Pick your seat. The quarter starts on 640, and the board meets on day ninety. Six decisions arrive — 3 on your own perimeter, 3 on your vendors, drawn at random from thirty — with 100 seconds on each, so ten minutes for the quarter at most. Run out of time and you get the outcome of doing nothing. The budget is 10 for the quarter, and the right answer usually costs something.
What is real and what is a game rule
The situations are real in kind. Exposed remote access, leaked passwords, dangling DNS records, a vendor whose rating falls overnight, a breach at your vendor’s own host, an AI tool nobody assessed: each is a common way an organisation’s outside-in risk changes, and each card says what it teaches. No company is named, and every vendor is generic.
The numbers are game rules. The 300–820 scale, the start at 640, the bands — Advanced from 740, Intermediate from 640, Basic below — the budget and every cost and rating change are set so that the right call usually costs something and doing nothing usually costs more. Picking the strongest option with 70 or more seconds left earns +10.
The game is about deciding under a clock. The incident that follows a bad quarter is a different clock, with regulators on the other end of it — play Survive the six hours next. And for the number the game is standing in for, the Rating Report gives your organisation’s own, complimentary.
A game. The scale, costs and rating changes are game rules, not measurements of any organisation, and nothing here is a security rating or professional advice.
Questions this page answers
- What is security posture management?
- Security posture management is the continuous work of finding and fixing what makes an organisation attackable from outside: exposed services, expired certificates, leaked credentials, unpatched internet-facing systems, missing email authentication and infected hosts on its addresses. Because all of it is observable from the internet, it is also what an outside-in security rating measures, and what an attacker scanning for a way in sees first.
- Why does a vendor’s security affect our own risk?
- Because the vendor holds your data or runs part of your service. A payroll provider’s exposed database exposes your employees; a cloud region outage takes your portal down; a call centre that falls for phishing can reset your customers’ passwords. Regulators increasingly treat that as the organisation’s own risk: the EU’s DORA, for example, expects financial entities to keep a register of their ICT third-party arrangements and documented exit strategies for the critical ones.
- Are annual vendor questionnaires enough?
- Not on their own. A questionnaire records what a vendor said at one point in the year, and the business often skips it when it takes weeks. The common pattern is to tier vendors by risk, monitor every vendor continuously from outside, and reserve the detailed questionnaire and contract terms — breach notification, audit rights, a minimum rating — for the critical few.
- What should the board see about cyber risk?
- A small number of measures it can compare and track over time, rather than a controls framework. An outside-in rating benchmarked against the sector, its trend over the year, and the handful of critical vendors whose failure would stop the business answer the question boards actually ask — how do we compare, and is it getting better.