A security rating is a score that a ratings provider assigns to an organization based on an outside-in analysis of its cybersecurity. The provider collects data that can be observed from the internet and other external sources, such as exposed systems, unpatched software, email and DNS settings, and evidence of leaked credentials, then turns it into a number or letter grade. Organizations use ratings to screen vendors, benchmark themselves and track change over time, much as a credit score summarizes financial risk.
At a glance
- A security rating is an outside-in score: the rated organization doesn’t need to participate for a rating to exist.
- Ratings are based on externally observable data, such as internet-facing systems, configuration, certificates and breach data.
- Each provider uses its own data, scale and methodology, so scores aren’t directly comparable across providers.
- Common uses are vendor risk screening, cyber insurance underwriting, board reporting and acquisition due diligence.
- A rating can’t see internal controls, so it complements, rather than replaces, questionnaires and audits.
What problem it solves
Organizations depend on dozens or hundreds of suppliers, and each one is a potential path to their data or operations. Sending a long security questionnaire to every vendor is slow, the answers are self-reported, and they go stale as soon as they are filed. Security leaders also struggle to give boards a simple sense of whether the company is getting better or worse, or how it compares with peers.
Security ratings offer a fast, continuous and independent view. A third-party risk management (TPRM) team can screen a whole vendor list in hours, spot suppliers with obvious problems and focus deeper reviews there. Monitoring alerts teams when a vendor’s score drops. The same data shows an organization what outsiders, including attackers, customers and insurers, can see about its own exposure.
How it works
Asset mapping. The provider works out which domains, IP address ranges and cloud services belong to an organization, using registration records, DNS and other public data. Mistakes here are a common source of inaccurate scores.
Data collection. It scans and gathers signals such as open ports and exposed services, outdated software versions, certificate and email authentication settings, website security headers, leaked credentials, breach history and, depending on the provider, signs of infected machines communicating from the organization’s addresses.
Scoring. Findings are weighted and combined into a score, usually with category sub-scores. Methodology, weighting and scale differ by provider, and many say their scores correlate with breach likelihood; ask for the evidence behind such claims.
Monitoring and collaboration. Subscribers watch scores for their own company and their vendors over time and get alerts on significant changes. Many platforms let subscribers share findings with a vendor so it can fix issues or dispute them.
When it matters for buyers
- When a customer or insurer cites your score. A low rating can slow a sale or affect cyber insurance terms, so know what is being said about you.
- When building a vendor risk program. Ratings help tier vendors and decide who gets a full assessment. See our governance, risk and compliance overview.
- When reporting to the board. A trend line is easier to discuss than a list of technical findings, provided its limits are explained.
- During mergers and acquisitions. A rating gives a quick external view of a target before deeper diligence.
- When cleaning up your external footprint. Rating findings can feed your vulnerability management and attack surface management work.
Questions to ask vendors
- What data sources do you use, and how often is each one refreshed?
- How do you decide which assets belong to an organization, and how are errors corrected?
- How is the score calculated, and what evidence links it to breach risk?
- How can our vendors see, dispute and fix findings, and is there a cost to them?
- How many of our vendors are already in your coverage?
- Can findings be exported to our GRC, ticketing or vulnerability tools?
- How is the service priced: by number of monitored companies, users or features?
How it differs from a security questionnaire
A security questionnaire asks an organization to describe its own controls, such as backups, access management, training and incident response, and relies on honest, current answers backed by evidence where requested. A security rating is collected from the outside without the organization’s input and only sees what is externally observable. Questionnaires can cover internal controls a rating can’t see; ratings are faster, continuous and independent of the vendor’s self-reporting. Most vendor risk programs use both, along with audit reports, and vendor management processes decide what happens when either one raises concerns.
