Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

Security Ratings

Security ratings are standardized, continuously updated measures of an organization's cybersecurity posture, derived from externally observable data. Black Kite differentiates its approach by building ratings exclusively on open standards — MITRE frameworks, Common Vulnerability Scoring System (CVSS), Common Weakness Scoring System (CWSS), and Factor Analysis of Information Risk (FAIR) — making outputs transparent and defensible rather than based on proprietary, black-box scoring methodologies.

Where Did the Security Ratings Category Come From?

Security ratings emerged as an alternative to slow, manual vendor questionnaires, letting a buyer get a read on a vendor's posture without waiting for that vendor to respond to anything. A handful of specialized providers built businesses around collecting externally observable signals and compiling them into a single comparable grade.

  • Exposed ports and services, visible to anyone scanning a company's public-facing infrastructure.
  • Certificate hygiene, including expired or misconfigured SSL/TLS certificates.
  • Patch cadence, inferred from how quickly known vulnerabilities get resolved on public systems.
  • Breach and exposure history, pulled from public disclosures and dark web signals.

That speed is still the category's core value. A SIG questionnaire or a SOC 2 report takes a vendor days or weeks to produce. A rating exists the moment enough external data has been continuously monitored, whether the vendor participates or not.

How Has the Terminology Around Security Ratings Evolved?

The category started out calling itself "security ratings" or "security scores," and much of the market has since moved away from that language because it became associated with black-box grades nobody could explain.

Black Kite's Own History Reflects This Shift

Black Kite entered the market inside that category, when it operated as NormShield, and its older blog archive still carries the Security Ratings Services framing. The current positioning drops "security rating" for language like risk intelligence and standards-based ratings, a deliberate distancing from a term that came to signal an opaque number rather than a defensible one.

  • Legacy framing: security rating, security score, Security Rating Services (SRS).
  • Current framing: cyber rating, open standards-based cyber rating, cyber risk intelligence.

The shift shows up in how the industry talks about the category today, not just in Black Kite's own materials. A rating that can't show its work reads as a liability in a board meeting or a regulatory exam, which is pushing providers across the space toward methodology transparency as a selling point rather than an afterthought.

How Are Security Ratings Actually Used Across Different Buyers?

Vendor screening is the most common use, but it isn't the only one. The same underlying product shows up in several distinct buying contexts, each with a different tolerance for the category's known weaknesses.

  • Vendor screening and monitoring. A third-party risk team's primary use, sorting a large vendor population by relative risk before deeper due diligence.
  • Cyber insurance underwriting. An underwriter uses a rating to gauge an applicant's exposure without conducting its own technical assessment of every policyholder.
  • M&A due diligence. A rating gives an acquiring company a fast read on a target's security posture before deal terms are finalized.
  • Board and executive reporting. A single grade is easier to present to a board than a raw list of technical findings, for better or worse.

The insurance use case in particular depends on ratings staying current. Insurance underwriters evaluating that kind of moving-target risk lean on continuously updated ratings rather than a once-a-year audit. Black Kite's 2026 Ransomware Report counted 146 active ransomware groups by June 2026, up from 127 at the close of its reporting period, with 61 new groups entering during that period alone, a pace an annual underwriting review can't track on its own.

What Are the Common Criticisms of Security Ratings as a Category?

The most persistent criticism is that two providers rating the same company can produce meaningfully different grades, since each uses its own data sources and its own weighting.

Different Providers Produce Different Grades

A vendor can show a strong grade from one provider and a weak one from another without anything about the vendor actually changing, which makes a rating hard to defend as an objective fact rather than one provider's opinion.

A Proprietary Methodology Can't Be Interrogated

A vendor disputing a poor grade needs to know which specific finding drove it, and a methodology that won't show its inputs leaves that vendor arguing with a number instead of fixing a problem. This is the exact gap that pushed the terminology shift described above, and it's still the standard a buyer should hold any rating provider to, regardless of which one they use.

How Do Security Ratings Differ From Security Scores?

The two terms are often used interchangeably in casual conversation, but the distinction between them is significant enough to warrant its own explanation. The two terms are often used interchangeably, but Black Kite draws a real line between them. A score is typically a proprietary, black-box output whose methodology isn't published. A rating, in Black Kite's definition, is built on open, auditable standards a vendor can check.  See security ratings vs. security scores for the full breakdown of where that line actually falls.

How Does This Category Differ From Black Kite's Cyber Rating?

"Security ratings" describes the market category. A cyber rating is Black Kite's own specific output within it. Consistent with moving away from the legacy framing described above, Black Kite doesn't market its own grade as a "security rating." It's built on named, published standards rather than a proprietary formula, which is the distinction the open standards-based cyber rating entry covers in full.

How Does Black Kite Address the Problems That Shaped This Category?

A rating a vendor can't interrogate isn't useful to anyone, which is why Black Kite built its risk management methodology around named, checkable standards instead of a proprietary formula. Every category behind the grade maps to a published framework, so a vendor disputing a finding has something concrete to check rather than a number to argue with. That standard runs through the third-party risk management programs built on top of it, not just the grade itself.

See also: The End of CRR: Why TPCRM Is the Future of Third-Party Risk