Security Rating

A score summarizing an organization's security posture from externally observable signals. Useful as a comparative indicator, though it does not replace continuous discovery and validation of exposure.

What the score is

A security rating is a score that summarizes, in a number or a letter, an organization's externally observable security posture. Certificates, email configuration, exposed services, presence in public leaks, network reputation.

All of it is collected without the rated company's cooperation, and that property is what gives the score its utility: it exists for all your suppliers, today, without asking anyone for anything.

What it is good for

Triage. With three hundred suppliers and capacity for deep diligence on twenty, the score says where to start.

And trend. The most valuable reading of a rating sits in the direction rather than in the absolute value it shows now: a supplier that dropped two grades in four months is going through something, and that is the moment to ask.

What it does not support

Capital decisions. The score is not money, not a probability, and has no unit that enters a spreadsheet. Asking what it costs to do nothing and getting back "B minus" moves no budget. That is what risk quantification is for, returning financial value with written assumptions.

Absolute risk judgement. A high score describes good external hygiene, which differs from good internal security. A company with an excellent score and no network segmentation is still a company with no network segmentation, because that is not observable from outside.

Where provider differences come from

Two scores for the same company can diverge considerably, and the cause is rarely collection quality.

It is attribution. Deciding which assets belong to that organization is the hard part, and each provider solves it differently. Counting one domain more or less moves the score, and the rated customer usually disagrees at exactly that point.

This is why the first question to ask a rating provider is not about scoring methodology. It is how they decide what is yours, and what happens when you disagree.

Where it fits

A rating summarizes; an inventory lists. The two answer different questions, and confusing them produces the common error of treating the score as if it were the surface.

A third-party risk management program uses the rating to order attention and uses the detailed survey to decide. Using only the score is buying a summary and never reading the text.

Veja isso na sua superfície

Análise preliminar gratuita