Logo icône Board of Cyber Cyber rating - Security Rating®

Automated cyber assessment: continuously evaluate and manage the cyber performance of your organisation and ecosystem

Security Rating

The external attack surface of organizations changes every day. Vulnerabilities emerge, configurations drift, threats grow more sophisticated. And yet, the majority of organizations only have a point-in-time view of their cyber exposure — one that quickly becomes obsolete in the face of today's threat landscape. One question is essential for every CISO, CIO, CEO, or risk management officer:

What assets of my organization are exposed on the Internet, which vulnerabilities can be exploited, and what about my suppliers and subsidiaries?

Security Rating® enables you to:

  • Obtain a clear cyber score (0–1,000) and a per-domain rating (A to E) to manage your posture and communicate with your leadership
  • Present your security KPIs to the executive committee in minutes through dashboards and summary reports readable by non-experts, with no manual reformatting
  • Continuously assess your cyber performance and that of your ecosystem — 100% automated, non-intrusive, and updated daily
  • Identify your priority vulnerabilities across 7 analysis domains covering both control and performance measures
  • Accelerate remediation for technical teams with concrete, actionable recommendations prioritized by criticality level
  • Benchmark your posture against organizations in your sector using built-in industry benchmarks
  • Manage the cyber risk of your portfolio, subsidiaries, or suppliers from a consolidated multi-organization dashboard

Why cyber ratings have become essential for organisations and their ecosystems

The external attack surface of organisations has never been wider. Exposed infrastructure, cloud services, email systems, misconfigured TLS/SSL certificates, unpatched vulnerabilities… every digital asset visible on the internet is a potential target. And the threat no longer comes solely from an organisation’s own assets: a poorly secured third party (supplier, service provider, subsidiary) can become the gateway for a devastating cyberattack.

Faced with this reality, traditional approaches show their limits:

Point-in-time audits only provide a static snapshot that quickly becomes obsolete

Penetration tests are intrusive, costly, and do not cover the entire external attack surface

Manual questionnaires sent to suppliers are time-consuming, subjective, and difficult to consolidate

The lack of a clear score and reporting intelligible to leadership makes any strategic cybersecurity management highly complex



Security Rating® was designed to address all of these challenges simultaneously: an automated, non-intrusive, continuous assessment that produces an objective and actionable score for your organization and your entire ecosystem.

Security Rating®: continuously assess, manage and improve your cyber performance

Security Rating® is a 100% automated, non-intrusive SaaS solution that identifies, classifies and analyses assets exposed publicly on the internet. It generates an objective cyber maturity score, updated daily, which is translated into practical recommendations for each area of analysis.

This is the same approach used by your cyber adversaries to map your attack surface before exploiting it, or by your business partners and investors to assess your cyber maturity before engaging with you. A rating agency, an investment fund or a major client is probably already doing this continuously on your organisation, without your knowledge. Security Rating® allows you to see exactly what they see and to improve accordingly.

An overall cyber score to help you manage your security posture in real time

Security Rating® assigns each organisation an overall score of 0 to 1,000, summarising its cyber maturity, as well as a grade from A to E for each of the seven areas of analysis. This dual-level approach enables communication tailored to each audience: senior management, the executive committee, technical teams and partners.

  • Overall score 0–1,000, updated daily
  • A–E rating per domain to immediately identify weaknesses
  • Complete history of rating changes day by day
  • Sector benchmark: comparison with the sector’s minimum, maximum and average ratings
  • Downloadable summary and detailed reports
  • Multilingual to support complex and international organisations
11 analysis axes for comprehensive coverage

Security Rating® analyses all of an organisation’s external exposure vectors, grouped into two main categories:

Control measures: what is exposed and how it is protected

  • Attack surface: mapping of assets exposed on the internet (subdomains, open ports, accessible services)
  • Email: configuration of SPF, DKIM and DMARC records, and exposure of email servers
  • Web TLS/SSL: quality and validity of certificates, supported protocols, risky configurations
  • Security controls: presence and configuration of essential protection mechanisms

Performance metrics: how the organisation responds to threats

  • Vulnerabilities: known CVEs detected on exposed assets, with severity level
  • Update performance: patching frequency for each criticality level (e.g. < 5 days for critical vulnerabilities)
  • CTI (Cyber Threat Intelligence) indicators: presence on blacklists, compromised IPs or domains detected, data or credential leaks linked to the organisation

****Focus: Cyber Threat Intelligence (CTI) – why is it a key indicator?

Cyber Threat Intelligence (CTI) refers to the analysis of data relating to active threats targeting an organisation: the presence of IP addresses or domains on global blacklists, compromised credentials circulating on the dark web, and infrastructure associated with known malicious campaigns. Unlike other areas of analysis that assess what is configured, CTI indicators reveal what has already happened or what is currently happening. It is often the earliest warning sign of an ongoing breach, and one of the least monitored by organisations that do not have a dedicated CTI programme. These indicators are powered by ANOZR WAY, a specialist in human cyber risk management and personal protection. Their expertise covers, in particular, the exposure of employees and executives, as well as the detection of compromised personal and professional data on the dark web. Security Rating® integrates these indicators natively, without the need for an additional subscription to threat intelligence feeds.

Tableau de bord multi-organisations pour piloter votre écosystème

Security Rating® includes a multi-organisation view to centralise the management of cyber risk across your entire ecosystem: subsidiaries, critical suppliers, partners and associated companies.

  • Consolidated view of the ratings for all your monitored organisations
  • Comparison of scores to quickly identify the most exposed entities
  • History and tracking of rating changes over time
  • Exportable reports by entity for audits and governance
Executive and technical reports
  • Executive report — summary, global score, key risks, strategic priorities
  • Detailed technical report — observables, criticality, recommendations, and remediation plan
  • Exportable reports for NIS2, DORA, and ISO 27001 compliance audits
Multilingual platform

Available in French, English, German, Italian, and Spanish — designed for international organizations.

Security Rating® vs one-off audit: what’s the difference?

Traditional cybersecurity audits, penetration tests, configuration audits and manual questionnaires have inherent limitations when it comes to addressing the reality of today’s threats: they are costly, time-consuming, require the target’s cooperation, and their results become obsolete almost immediately.

Criteria Security Rating® Traditional Point-in-Time Audit
Assessment method ✅ 100% automated, non-intrusive ❌ Audit requiring custom tooling setup
Analysis frequency ✅ Continuous, daily updates ❌ Point-in-time (once a year on average)
Readable synthetic score ✅ Score 0–1,000 + A to E rating ❌ Technical report often unreadable by leadership
Coverage ✅ 7 domains, control & performance measures ⚠️ Varies by provider
CTI indicators (threat intel) ✅ Natively included ❌ Often absent or available as a paid add-on
Industry benchmark ✅ Min / avg / max sector comparison ❌ Not available
Multi-organization view ✅ Consolidated dashboard (subsidiaries, suppliers) ❌ Single-entity view only
Automated executive report ✅ Ready-to-use summary report ❌ Time-consuming manual writing
Assessment without target cooperation ✅ Possible (public data) ❌ Requires access and cooperation
Immediate availability ✅ Score available within a few hours ❌ Delivery takes several weeks

Security Rating® offers a fundamentally different approach:

  • Immediate assessment: no delays or coordination with the target; the score is available in under an hour
  • Continuous monitoring: vulnerabilities change every day, and so does the score
  • Comparison: a single score allows organisations to be compared objectively
  • Clarity for management: the 0–1,000 score and A to E rating are understandable to everyone, not just experts
  • Scalability: an organisation can assess dozens of third parties simultaneously, without any extra effort

How does Security Rating® work?

Security Rating® is a fully hosted SaaS solution. No installation is required on the client side. As the analysis relies exclusively on publicly available data on the internet, it is by nature non-intrusive and does not require access to the information systems of the organisation being assessed. Informing the third party of the process remains good practice and is often the starting point for productive collaboration on securing the ecosystem.

1

Enter the main domain name of the organization to be assessed on the Board of Cyber platform

2

Security Rating® automatically collects and analyzes publicly available data on the Internet related to that domain (exposed assets, configurations, vulnerabilities, CTI…)

3

A global score from 0–1,000 and an A to E rating per domain are generated, available within a few hours for an initial assessment

4

The platform updates the score daily to reflect the real-time evolution of the cyber posture

5

Access prioritized recommendations, summary and detailed reports, and the multi-organization dashboard from your workspace

How do our customers use Security Rating®?

Mid-size companies, SMEs, insurance brokers, private equity funds, local authorities, notaries, lawyers... Board of Cyber supports a wide range of organizations based on their needs.

"We have a perfect understanding of our external exposure surface across all the group's offices. Thanks to the score, we are able to communicate about our maturity level."

Frédéric SOULIER, Deputy CIO and CISO, CMS Francis Lefebvre Avocats

Client 1
Client 2
Client 3

Security Rating® Use Cases

Private Equity Funds: Assess the Cyber Risk of Your Portfolio

Cybersecurity has become a decisive factor in investment decisions. A cyber incident can significantly devalue a holding, expose the fund to liability, and jeopardize an acquisition. Security Rating® enables investment teams to integrate cyber risk into their due diligence and portfolio monitoring processes, without relying on the cooperation of target companies.

  • Rapid cyber risk assessment of an acquisition target before closing, without access to the internal network
  • Continuous monitoring of the cyber posture of all holdings from a consolidated dashboard
  • Identification of the most exposed portfolio entities to prioritize post-acquisition actions
  • Exportable report for investment committees and due diligence processes

Large Enterprises: Manage the Cyber Risk of Your Subsidiaries and Suppliers

For large organizations, the attack surface is no longer limited to their own perimeter: every critical supplier, every subsidiary, every service provider is a potential extension of their cyber risk. Security Rating® enables organizations to structure and automate the management of this risk at scale.

  • Automated assessment of the cyber posture of all your critical suppliers
  • Consolidated third-party risk view to feed your TPRM program
  • Benchmarking of subsidiaries against each other to identify the weakest links in your group
  • Integration into Trust HQ® for a unified governance + third-party risk view

SMEs / Mid-size Companies: Turn Your Cyber Rating into a Concrete First Step Toward Managing Your Cyber Risk

For SMEs and mid-size companies, cybersecurity is often seen as a complex, costly topic reserved for large organizations. Security Rating® changes that perception: within a few hours, with no installation and no prior technical expertise, you get a clear and objective view of your cyber exposure — whether your IT is managed in-house or outsourced to a provider.

  • Rapid initial assessment of your cyber exposure, with no installation or technical expertise required — accessible even with an outsourced IT environment
  • Precise and continuous knowledge of your cyber risk level, trackable over time
  • Identification of remediation priorities with concrete, domain-specific recommendations to share with your IT provider
  • A third-party verifiable cyber score to present to clients, partners, insurers, or contracting authorities requiring NIS2 / DORA compliance
  • Access to an industry benchmark to position your performance relative to competitors and peers

Banks & Insurance: Assess the Cyber Risk of Your Counterparties

Financial institutions are increasingly integrating cyber risk into their credit and underwriting risk assessment models. Security Rating® provides objective, up-to-date and comparable data to enrich these models without intrusive audits.

  • Cyber risk assessment of borrowers, policyholders, or counterparties based on public data
  • Integration into credit scoring and lending decision processes
  • Continuous cyber risk monitoring of the client portfolio
  • Exportable report for regulatory documentation (DORA, Basel III/IV…)

Local Authorities & Public Services: Protect Data and Service Continuity

Local authorities and public organizations are increasingly targeted by cyber attackers, with direct consequences on the continuity of services to citizens. Security Rating® enables public entities to understand their level of exposure and prioritize their security actions, even with limited internal resources.

  • Rapid, non-intrusive assessment of the authority's cyber posture
  • Identification of exposed assets and priority vulnerabilities
  • Benchmark against other authorities of comparable size
  • Summary report communicable to elected officials and supervisory bodies

Frequently asked questions about cyber ratings and Security Rating®

What is a cyber score?

A cyber score is an objective rating assigned to an organization to quantify its external cybersecurity level. It is calculated from the automated analysis of digital assets exposed on the Internet: service configurations, TLS/SSL certificates, email, known vulnerabilities, indicators of compromise... This score distills a complex reality into a single indicator readable by everyone — leadership, CISOs, partners, insurers, and investors.

How is the Security Rating® score calculated?

Security Rating® automatically and non-intrusively analyzes all publicly exposed digital assets on the Internet for a given domain. The analysis covers 7 domains: attack surface, email, Web TLS/SSL, security controls, vulnerabilities, patching performance, and CTI indicators. A global score from 0 to 1,000 is assigned, along with an A to E rating for each domain. The score is updated daily to reflect the real-time evolution of the cyber posture.

Is the Security Rating® assessment truly non-intrusive?

Yes. Security Rating® relies exclusively on publicly available data on the Internet — no access to the internal network, no agent installation, no interaction required with the assessed organization. This approach makes it possible to evaluate any organization, even without its cooperation, which is particularly valuable for due diligence processes, supplier assessments, and portfolio monitoring.

What is the difference between Security Rating® and a penetration test (pentest)?

A penetration test is an attack simulation carried out by experts, requiring system access, coordination with the target, and several weeks of work. Its result is a snapshot at a single point in time. Security Rating® is a continuous, automated, and non-intrusive assessment that permanently analyzes the organization's external exposure. The two approaches are complementary: Security Rating® provides a real-time view of the attack surface, while the pentest dives deep into internal systems.

Does Security Rating® help meet NIS2 and DORA requirements?

Yes. NIS2 and DORA require organizations to demonstrate active risk management, including third-party risk. Security Rating® provides an objective and continuous assessment of the cyber posture, exportable reports usable during audits, and traceability of improvement over time. For organizations subject to DORA, monitoring the cyber risk of critical third-party providers is an explicit obligation that Security Rating® helps structure.

Can multiple organizations be rated simultaneously with Security Rating®?

Yes, this is one of the core use cases of Security Rating®. The multi-organization dashboard enables simultaneous monitoring of the cyber rating of an entire portfolio, supplier chain, or group of subsidiaries. Each entity has its own score and recommendations, visible from a consolidated view that enables comparisons and action prioritization.

Can Security Rating® be integrated with other risk management tools?

Security Rating® integrates naturally with Trust HQ®, Board of Cyber's cyber governance and TPRM platform. The cyber scores of your suppliers assessed by Security Rating® can directly feed your TPRM program and governance dashboards in Trust HQ®. This integration delivers a unified view: objective third-party risk (Security Rating®) + governance and action plans (Trust HQ®).