What Is a Security Rating?

Also called: Cyber risk rating, Security ratings, Cybersecurity rating

Related problems: A customer or insurer quoted our security score and we don't know where it came from; Too many vendors to assess with questionnaires alone; Need a quick outside view of a supplier's security before signing; Board wants a simple way to compare our security against peers

A security rating is a score that a ratings provider assigns to an organization based on an outside-in analysis of its cybersecurity. The provider collects data that can be observed from the internet and other external sources, such as exposed systems, unpatched software, email and DNS settings, and evidence of leaked credentials, then turns it into a number or letter grade. Organizations use ratings to screen vendors, benchmark themselves and track change over time, much as a credit score summarizes financial risk.

At a glance

  • A security rating is an outside-in score: the rated organization doesn’t need to participate for a rating to exist.
  • Ratings are based on externally observable data, such as internet-facing systems, configuration, certificates and breach data.
  • Each provider uses its own data, scale and methodology, so scores aren’t directly comparable across providers.
  • Common uses are vendor risk screening, cyber insurance underwriting, board reporting and acquisition due diligence.
  • A rating can’t see internal controls, so it complements, rather than replaces, questionnaires and audits.

What problem it solves

Organizations depend on dozens or hundreds of suppliers, and each one is a potential path to their data or operations. Sending a long security questionnaire to every vendor is slow, the answers are self-reported, and they go stale as soon as they are filed. Security leaders also struggle to give boards a simple sense of whether the company is getting better or worse, or how it compares with peers.

Security ratings offer a fast, continuous and independent view. A third-party risk management (TPRM) team can screen a whole vendor list in hours, spot suppliers with obvious problems and focus deeper reviews there. Monitoring alerts teams when a vendor’s score drops. The same data shows an organization what outsiders, including attackers, customers and insurers, can see about its own exposure.

How it works

Asset mapping. The provider works out which domains, IP address ranges and cloud services belong to an organization, using registration records, DNS and other public data. Mistakes here are a common source of inaccurate scores.

Data collection. It scans and gathers signals such as open ports and exposed services, outdated software versions, certificate and email authentication settings, website security headers, leaked credentials, breach history and, depending on the provider, signs of infected machines communicating from the organization’s addresses.

Scoring. Findings are weighted and combined into a score, usually with category sub-scores. Methodology, weighting and scale differ by provider, and many say their scores correlate with breach likelihood; ask for the evidence behind such claims.

Monitoring and collaboration. Subscribers watch scores for their own company and their vendors over time and get alerts on significant changes. Many platforms let subscribers share findings with a vendor so it can fix issues or dispute them.

When it matters for buyers

  • When a customer or insurer cites your score. A low rating can slow a sale or affect cyber insurance terms, so know what is being said about you.
  • When building a vendor risk program. Ratings help tier vendors and decide who gets a full assessment. See our governance, risk and compliance overview.
  • When reporting to the board. A trend line is easier to discuss than a list of technical findings, provided its limits are explained.
  • During mergers and acquisitions. A rating gives a quick external view of a target before deeper diligence.
  • When cleaning up your external footprint. Rating findings can feed your vulnerability management and attack surface management work.

Questions to ask vendors

  • What data sources do you use, and how often is each one refreshed?
  • How do you decide which assets belong to an organization, and how are errors corrected?
  • How is the score calculated, and what evidence links it to breach risk?
  • How can our vendors see, dispute and fix findings, and is there a cost to them?
  • How many of our vendors are already in your coverage?
  • Can findings be exported to our GRC, ticketing or vulnerability tools?
  • How is the service priced: by number of monitored companies, users or features?

How it differs from a security questionnaire

A security questionnaire asks an organization to describe its own controls, such as backups, access management, training and incident response, and relies on honest, current answers backed by evidence where requested. A security rating is collected from the outside without the organization’s input and only sees what is externally observable. Questionnaires can cover internal controls a rating can’t see; ratings are faster, continuous and independent of the vendor’s self-reporting. Most vendor risk programs use both, along with audit reports, and vendor management processes decide what happens when either one raises concerns.

Frequently Asked Questions

How do ratings providers get data about us?
Mostly from what can be observed from outside your network without your involvement: internet scans of your public systems, DNS and email settings, certificates, leaked credential and breach data, and signs of malware communicating from your addresses. Each provider uses its own sources and methods, which is why scores for the same company can differ between providers.
Is a security rating accurate?
It is a useful but partial view. It can't see internal controls such as backups, training or how well endpoints are monitored, and it can be wrong about which systems belong to you, for example shared hosting or a former subsidiary's addresses. Treat it as one input alongside questionnaires, audits and evidence from the vendor.
Can we dispute or improve our rating?
Most providers let the rated organization claim its profile, correct which assets belong to it and dispute findings, often without paying. Fixing real issues, such as exposed services, missing patches or weak email authentication, usually improves the score over time. Check each provider's correction process.
Who uses security ratings?
Commonly third-party risk teams screening vendors, cyber insurers assessing applicants, security leaders benchmarking themselves for the board, and companies doing due diligence before an acquisition. Some customers set a minimum rating in supplier requirements.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.