Data Breach Index (DBI)
The Data Breach Index is a Black Kite index that provides a historical performance score based on a company's past data breach events. It measures breach severity using the volume of records compromised and the recency of each incident, giving organizations a clear signal of a vendor's breach track record alongside forward-looking technical ratings.
What Actually Feeds Into a Vendor's DBI Score?
DBI complements Black Kite's other cyber ratings within the same portfolio view. Where the Ransomware Susceptibility Index (RSI™) predicts how likely a vendor is to be hit next, DBI documents what’s already happened: confirmed breaches, leaked credentials, and other incidents visible from outside, weighted by severity and how recently they occurred. A vendor with a clean RSI can still carry a troubling DBI if its breach history hasn't caught up with its current defenses, and the reverse is just as possible.
DBI combines five types of incidents visible from outside the company: data breaches, leaked credentials, stealer logs, hacktivist forum mentions, and IP reputation issues. Each one is weighted by severity and recency, with more recent and more severe findings pushing the score higher on a 0.0 to 1.0 scale. A vendor whose last breach was several years ago and small will carry a DBI near zero, while one that exposed millions of records last quarter will score much higher, even though both technically carry a breach in their history.
That distinction matters for a risk team deciding where to focus attention first. A vendor whose only incident happened years ago and stayed small carries a materially different third-party risk than one that exposed customer records last quarter, even though a simple checklist that just asks whether this vendor has ever been breached would treat them identically.
The Score Is Built for Prioritization
A due diligence team screening a new vendor, or a risk team deciding which existing vendors deserve a closer look this quarter, can use DBI to separate a distant, contained incident from a recent, severe one and weight each accordingly.
In practice, the numbers tend to cluster low. Black Kite Research Group™ found, across the manufacturing and distribution sector, an average DBI of roughly 0.09 for trucking and freight companies, compared with roughly 0.18 for manufacturers, a gap that tracks with how often each group shows up in breach disclosures. Neither figure is high on its own. The comparison is what's useful, since it shows which vendor population carries more documented breach history than the other.
How Is DBI Different From RSI and Data Breach Risk?
DBI, RSI, and Data Breach Risk sound related and answer three separate questions about a vendor:
- DBI is a historical record of what this vendor has already disclosed, and how severe those incidents were.
- RSI is predictive, estimating how likely this vendor is to be hit by ransomware next, based on its current externally visible exposure.
- Data breach risk is a financial modeling input, one of the three FAIR scenarios inside Financial Impact Rating, estimating in dollar terms what a future breach at this vendor would cost the company relying on it.
A vendor can score well on one and poorly on another. Past severity, future likelihood, and future financial exposure are three separate calculations, even when a single incident could eventually feed data into all three.
Why Doesn't a Low DBI Always Mean a Vendor Is Low Risk?
A low DBI means no breach, leak, or related incident has surfaced publicly in recent months, or older findings have fully decayed. Disclosure and occurrence are two different things, and a severe breach can still have happened without ever surfacing in the data.
Black Kite's Third-Party Breach Report 2026 found that across roughly 200,000 monitored organizations, the average cyber grade is a 90.27, an A, while the average RSI sits at 0.378, just under the report's own high-risk threshold. A strong letter grade and a clean breach history can sit right next to meaningful, undisclosed exposure.
Disclosure itself is uneven. A data breach only becomes public when it meets a legal notification trigger, or when a vendor chooses to say something before it has to. A vendor's DBI reflects what's been disclosed and confirmed, a real signal, and a partial one, since the complete history of every incident that's actually occurred isn't always public.
How Does DBI Fit Into a Broader Vendor Risk Assessment?
DBI works best paired with forward-looking indicators. A vendor's cyber rating and RSI describe current exposure and near-term likelihood, and vendor risk tiering uses signals like these together to decide which vendors need closer, more frequent review. Feeding a documented breach history into that same view gives a risk team the full picture, the history alongside the forecast.
That combination also supports cyber risk quantification, where financial impact analysis models what a future incident could cost. A vendor’s breach history is one signal among several, and it earns its place precisely because it’s the one signal the forward-looking indicators can’t reconstruct on their own.
See also: A Guide to Fix Your Cyber Rating, Here's the Black Kite Strategy Report