Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

Cyber Rating

A cyber rating is a standardized measure of an organization's external cybersecurity posture, derived from observable data rather than self-reporting. Cyber ratings are used in third-party risk management to screen vendors, monitor posture over time, and prioritize remediation efforts. Black Kite's Cyber Rating expresses posture as letter grades (A through F) across 20 technical categories organized into four groups: Safeguard, Privacy, Resiliency, and Reputation. It is built on open standards including MITRE's Cyber Threat Susceptibility Assessment, Common Weakness Scoring System (CWSS), Common Weakness Risk Analysis Framework (CWRAF), and Common Vulnerability Scoring System (CVSS), making every output transparent, auditable, and defensible.

What Do the Letter Grades in a Cyber Rating Represent?

A cyber rating's overall letter grade is a weighted average across 19 graded technical categories, not a single measurement. On Black Kite's rating, categories tied to the most common attack paths get the most weight, so a weakness in one area can move the overall grade far more than a weakness in another.

Nineteen Graded Categories Feed One Overall Grade

Each category, from patch management to email security to DNS health, contributes a weighted result that rolls up into the overall rating. No single finding determines the outcome on its own.

Higher-Risk Categories Carry More Weight

Patch management, application security, and credential management sit at the top of the weighting because unpatched software and exposed credentials are the categories attackers exploit most often. If a category doesn't map to a common attack path, it simply doesn't carry the same weight.

One Category Is Tracked but Not Graded

Digital footprint, the inventory of a company's domains, subdomains, and IP ranges, is tracked but carries no weight of its own. It exists to scope everything else, not to move the grade.

  • Patch management, 10 of 100 points. The single heaviest-weighted category, tracking unresolved vulnerabilities on internet-facing systems.
  • Application security and credential management, 9 points each. Exposed application flaws and leaked or reused credentials tie for second.
  • IP reputation, 7 points. Whether a company's IP space shows up in known malicious activity.
  • DNS health, email security, SSL/TLS strength, network security, and website security, 6 points each. The mid-weight categories that make up the bulk of a typical footprint.

How Often Does a Cyber Rating Change, and Why?

A cyber rating updates whenever the underlying data changes rather than on a fixed review cycle, so a vendor's grade reflects current exposure instead of a snapshot from the last time someone asked the vendor to fill out a form. Continuous monitoring does not mean the grade moves every day. It means a change registers whenever the data behind it does. A rating built on outside-in, continuously collected data reflects a vendor's current exposure, not a snapshot from the last time someone asked the vendor to fill out a form.

A rating typically moves after:

  • A new critical vulnerability appears on an asset the vendor owns.
  • Leaked credentials tied to the company's domain surface on the dark web.
  • An underlying data source refreshes, such as a new SSL scan, DNS record change, or certificate expiration.

Why Might Two Vendors With the Same Grade Carry Different Risk?

An overall letter grade compresses roughly 19 categories into one number, so identical grades can hide very different risk profiles underneath. Black Kite®'s 2026 Wholesale & Retail Cyber Risk Report found that 54.96% of supply chain vendors in those sectors carried at least one finding rated CVSS 8 or higher somewhere in their footprint. Two vendors can each carry that exposure and still land on different overall grades, depending on which of the other categories offset it. A team that stops at the letter grade won't see which specific category is driving the number, and a team that only reads the category breakdown risks losing the at-a-glance view the grade exists to provide. Reading both together, instead of relying on either alone, is what an overall grade is built to support.

How Does a Cyber Rating Differ From an Open Standards-Based Cyber Rating?

A cyber rating is the output; an open standards-based cyber rating is the method that makes a specific output defensible. This entry covers the letter grade, the category weighting, and how a risk team reads and acts on the number. The open standards-based entry covers why that number should be trusted at all, the published frameworks like CVSS and MITRE's CTSA that back each category, and why a rating built that way holds up to an audit in a way a proprietary formula doesn't.

Where Does a Cyber Rating Fit Alongside a SIG or SOC 2 Report?

A cyber rating gives a risk team an instant, continuously updated screening signal; a SIG or SOC 2 report gives a documented, point-in-time record a compliance file still needs. A team triaging hundreds of vendors can't read a SIG questionnaire or a SOC 2 report for every one of them before deciding where to focus, but a rating sorts that queue in seconds. Neither replaces the other. A rating tells a team where to look first; a SIG or SOC 2 document tells them what a vendor formally attested to once that attention arrives. An ISO 27001 certification plays a similar documentary role, confirming a vendor passed a periodic audit rather than showing what a vendor's exposure looks like this week.

What Should a Risk Team Do When a Vendor's Rating Drops?

A dropped rating is a starting point for a conversation with the vendor, not a verdict on the relationship. The organization relying on that vendor is the one carrying the downstream exposure until the finding is resolved, so the response matters more than the grade itself.

  • Check which category moved. A drop in patch management calls for a different conversation than a drop in email security.
  • Ask for evidence, not just a plan. A vendor's remediation timeline is a promise; a rescan is proof.
  • Recheck after the vendor reports a fix, since a category that recovers on paper doesn't always recover in the underlying data.

Vendors in sectors with deep third-party dependence, manufacturing among them, tend to watch this cycle most closely, since a single unresolved finding at one supplier can stall an entire production relationship.

How Does Black Kite Apply Cyber Ratings in Practice?

Black Kite rates a vendor across the same roughly 19 categories continuously, publishing the risk management methodology behind every weight so a risk team gets the category behind the grade instead of the grade alone. Teams use the rating inside a broader vendor risk assessment workflow to decide which vendors need a closer look now and which can wait for the next cycle, with continuous monitoring replacing the gap between one review and the next.

See also: Should You Talk to Vendors About Cyber Risk?