New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

Ransomware Susceptibility Index® (RSI™)

The Ransomware Susceptibility Index® is Black Kite's proprietary predictive index for the likelihood of a specific organization being successfully hit by a ransomware attack. It correlates technical control findings, dark web intelligence, ransomware entry method modeling, company size, industry, and country of operation. RSI outputs range from 0 to 1, with higher values indicating greater susceptibility.

The Ransomware Susceptibility Index® (RSI™) is a Black Kite rating from 0.0 to 1.0 that measures how likely a company is to experience a ransomware attack. It compares an organization's observable digital footprint against patterns drawn from thousands of confirmed ransomware victims, giving risk teams a forward-looking signal on every vendor.

That signal matters most across a vendor ecosystem. Black Kite's 2026 Ransomware Report found that trusted vendor platforms became the year's primary ransomware attack path, which means the ransomware question facing most risk teams isn't whether their own defenses hold. It's which of their vendors is closest to being encrypted.

What Does the Ransomware Susceptibility Index Measure?

It measures likelihood, not damage. RSI answers one question about a company, which is how closely its externally observable footprint resembles the footprint of organizations that ransomware operators have already compromised.

The separation at the top of the scale is stark. The 2026 Ransomware Report found that companies carrying an RSI above 0.8 were 291 times more likely to be attacked than companies below 0.2. In absolute terms, 41% of companies above 0.8 were hit during the reporting period, against 0.14% of companies below 0.2. A rating in the top band isn't a caution. It's close to a forecast.

That framing separates RSI from most vendor risk data. A vulnerability count tells you what's wrong. A compliance rating tells you what a vendor claims to have in place. RSI tells you how reachable that vendor looks to a ransomware operator right now, using the same signals the operator would use when choosing targets.

How Is an RSI Rating Calculated?

It's calculated by matching a company's external digital footprint against the technical characteristics observed in real ransomware victims. The model reflects the evolving tactics, techniques, and procedures of active ransomware groups, and it draws on data from thousands of confirmed victims each year rather than on a theoretical scoring framework.

RSI tracks common ransomware indicators, including:

  • Vulnerabilities with remote code execution
  • Open critical ports
  • Phishing or fraudulent domains
  • Leaked credentials and stealer logs
  • Endpoint security and email security posture
  • Company size, industry, and geolocation

Everything is collected non-intrusively from outside the target. No agent is installed, no scan touches the vendor's systems, and no permission is required. That's what allows a rating to exist across an entire vendor population rather than only the vendors who agreed to participate.

Can RSI Predict a Ransomware Attack Before It Happens?

In most cases it can, and the warning shows up as movement rather than as a single number. The 2026 Ransomware Report found that 93.5% of ransomware victims showed a meaningful RSI increase before their breach was disclosed, and 85.9% showed a month-over-month rise of 10% or more.

That pattern is what makes the rating operationally useful rather than merely descriptive. A vendor sitting at a stable 0.6 is a different problem from a vendor that has climbed from 0.4 to 0.6 in two months. The second one is trending toward an incident, and the window to act is open now.

Catching that movement requires a cyber risk monitoring platform rather than a periodic assessment. An annual review captures one point on a curve and tells you nothing about its direction.

How Is Ransomware Susceptibility Different From a Security Rating?

A security rating summarizes overall posture. RSI predicts a specific outcome. The two answer different questions, and substituting one for the other is how teams end up surprised.

Overall cyber ratings aggregate many categories into a general picture of how well a company defends itself. That picture is useful for tiering and for tracking direction over time. It isn't built to tell you which vendor is most likely to be encrypted next quarter, because the weaknesses that drag down a general rating aren't always the weaknesses ransomware operators use.

Black Kite publishes open standards-based cyber ratings rather than proprietary security scores, so a vendor can see the findings behind a rating and act on them. A number a vendor can't interrogate is a number they'll argue with instead of remediating.

What Does a High RSI Rating on a Vendor Mean for You?

It means your exposure is elevated, even though the risk sits on someone else's network. A vendor with high ransomware susceptibility is a vendor whose operations may stop without warning, and if your business depends on that vendor, your operations stop with them.

The downstream consequences fall into three categories. Operational disruption comes first and moves fastest, because a vendor under encryption can't ship, process, authenticate, or support anything. Data exposure follows, since modern ransomware operations exfiltrate before they encrypt, and the data they take includes yours. Regulatory liability comes last and lasts longest, because the obligation to notify your customers doesn't transfer to the vendor that lost their records.

Blue Yonder made the operational cost concrete. When the supply chain software provider was hit, grocery retailers across two continents lost planning and fulfillment capability for days. None of them had a security failure. They had a dependency.

A breached vendor also isn't a safer vendor. The 2026 report found that 43.5% of ransomware victims still carried critical patch vulnerabilities when rescanned after the incident, 30.8% still carried known exploited vulnerabilities, and stealer log exposure ran 175% higher than before. Average RSI across victims rose after the attack rather than falling. Treating a post-incident vendor as remediated is a decision the data does not support.

How Do Risk Teams Act on an RSI Rating?

They use it to decide where to spend attention, and as the opening argument in a vendor conversation. A predictive rating is only worth having if it changes what somebody does this week.

Move High-RSI Vendors Into a Higher Oversight Tier

A vendor above 0.8 warrants scrutiny that doesn't wait for the renewal cycle. Tier movement should follow the rating and its trend, not the contract calendar.

Open the Vendor Conversation With Evidence

Telling a vendor their posture is weak invites a debate. Showing them that their external footprint matches the pattern of companies that were successfully attacked, with the specific exposures listed, gives them something concrete to fix. That's the difference between a questionnaire and ransomware threat intelligence a vendor can act on.

Plan for the Vendor Being Offline

For a critical dependency carrying high susceptibility, the useful question isn't only how to reduce the rating. It's how the business runs for two weeks if that vendor goes dark. Black Kite's Ransomware Susceptibility Index® is built to support both conversations.

Where Does RSI Sit Alongside the Adversary Susceptibility Index?

RSI covers susceptibility to ransomware as a class of attack. The Adversary Susceptibility Index™ covers susceptibility to named threat actors, including the groups behind those ransomware operations.

The two work as a pair. RSI answers how likely a vendor is to be hit. ASI answers which adversaries are most likely to do it, and whether their known techniques line up with that vendor's specific weaknesses. A vendor with elevated ransomware susceptibility becomes considerably more urgent when a threat actor known to target their sector is currently active. Read together, they turn a list of exposed vendors into a prioritized queue.

See also: Blue Yonder Ransomware and Supply Chain Lessons