Automated Cyber Rating: Security Rating

Continuously assess and manage the cyber performance of your organisation and its ecosystem.

Organisations' external attack surface evolves every day. Vulnerabilities emerge, configurations drift and threats become more sophisticated. Yet most organisations have only a point-in-time view of their cyber exposure, which quickly becomes outdated in the face of today's threat landscape. This raises a critical question for every CISO, CIO, CEO or risk management leader:

Which of my organisation's assets are exposed to the Internet, which vulnerabilities are exploitable, and what is the cyber posture of my suppliers and subsidiaries?

Security Rating® enables you to:

  • Obtain a clear cyber score (0–1,000) and a per-domain rating (A to E) to manage your posture and communicate with your leadership
  • Present your security KPIs to the executive committee in minutes through dashboards and summary reports readable by non-experts, with no manual reformatting
  • Continuously assess your cyber performance and that of your ecosystem — 100% automated, non-intrusive, and updated daily
  • Identify your priority vulnerabilities across 7 analysis domains covering both control and performance measures
  • Accelerate remediation for technical teams with concrete, actionable recommendations prioritized by criticality level
  • Benchmark your posture against organizations in your sector using built-in industry benchmarks
  • Manage the cyber risk of your portfolio, subsidiaries, or suppliers from a consolidated multi-organization dashboard

Why cyber ratings have become essential for organisations and their ecosystems

The external attack surface of organisations has never been wider. Exposed infrastructure, cloud services, email systems, misconfigured TLS/SSL certificates, unpatched vulnerabilities… every digital asset visible on the internet is a potential target. And the threat no longer comes solely from an organisation’s own assets: a poorly secured third party (supplier, service provider, subsidiary) can become the gateway for a devastating cyberattack.

IN LIGHT OF THIS, TRADITIONAL APPROACHES ARE SHOWING THEIR LIMITATIONS:

A one-off audit provides only a snapshot that quickly becomes outdated.

Penetration tests are intrusive, costly and do not cover the entire external attack surface

Manual questionnaires sent to suppliers are time-consuming, subjective and difficult to collate.

The lack of clear metrics and reporting that management can understand makes it difficult to manage cybersecurity strategically.

Security Rating® was designed to address all of these challenges simultaneously: an automated, non-intrusive, continuous assessment that produces an objective and actionable score for your organization and your entire ecosystem.

Security Rating®: continuously assess, manage and improve your cyber performance

Security Rating® is a 100% automated, non-intrusive SaaS solution that identifies, classifies and analyses assets exposed publicly on the internet. It generates an objective cyber maturity score, updated daily, which is translated into practical recommendations for each area of analysis.

This is the same approach used by your cyber adversaries to map your attack surface before exploiting it, or by your business partners and investors to assess your cyber maturity before engaging with you. A rating agency, an investment fund or a major client is probably already doing this continuously on your organisation, without your knowledge. Security Rating® allows you to see exactly what they see and to improve accordingly.

An overall cyber score to help you manage your security posture in real time

Security Rating® assigns each organisation an overall score of 0 to 1,000, summarising its cyber maturity, as well as a grade from A to E for each of the seven areas of analysis. This dual-level approach enables communication tailored to each audience: senior management, the executive committee, technical teams and partners.

  • Overall score 0–1,000, updated daily
  • A–E rating per domain to immediately identify weaknesses
  • Complete history of rating changes day by day
  • Sector benchmark: comparison with the sector’s minimum, maximum and average ratings
  • Downloadable summary and detailed reports
  • Multilingual to support complex and international organisations
11 analysis axes for comprehensive coverage

Security Rating® analyses all of an organisation’s external exposure vectors, grouped into two main categories:

Control measures: what is exposed and how it is protected

  • Attack surface: mapping of assets exposed on the internet (subdomains, open ports, accessible services)
  • Email: configuration of SPF, DKIM and DMARC records, and exposure of email servers
  • Web TLS/SSL: quality and validity of certificates, supported protocols, risky configurations
  • Security controls: presence and configuration of essential protection mechanisms

Performance metrics: how the organisation responds to threats

  • Vulnerabilities: known CVEs detected on exposed assets, with severity level
  • Update performance: patching frequency for each criticality level (e.g. < 5 days for critical vulnerabilities)
  • CTI (Cyber Threat Intelligence) indicators: presence on blacklists, compromised IPs or domains detected, data or credential leaks linked to the organisation

****Focus: Cyber Threat Intelligence (CTI) – why is it a key indicator?

Cyber Threat Intelligence (CTI) refers to the analysis of data relating to active threats targeting an organisation: the presence of IP addresses or domains on global blacklists, compromised credentials circulating on the dark web, and infrastructure associated with known malicious campaigns. Unlike other areas of analysis that assess what is configured, CTI indicators reveal what has already happened or what is currently happening. It is often the earliest warning sign of an ongoing breach, and one of the least monitored by organisations that do not have a dedicated CTI programme. These indicators are powered by ANOZR WAY, a specialist in human cyber risk management and personal protection. Their expertise covers, in particular, the exposure of employees and executives, as well as the detection of compromised personal and professional data on the dark web. Security Rating® integrates these indicators natively, without the need for an additional subscription to threat intelligence feeds.

Tableau de bord multi-organisations pour piloter votre écosystème

Security Rating® includes a multi-organisation view to centralise the management of cyber risk across your entire ecosystem: subsidiaries, critical suppliers, partners and associated companies.

  • Consolidated view of the ratings for all your monitored organisations
  • Comparison of scores to quickly identify the most exposed entities
  • History and tracking of rating changes over time
  • Exportable reports by entity for audits and governance
Executive and technical reports
  • Executive report — summary, global score, key risks, strategic priorities
  • Detailed technical report — observables, criticality, recommendations, and remediation plan
  • Exportable reports for NIS2, DORA, and ISO 27001 compliance audits
Multilingual platform

Available in French, English, German, Italian, and Spanish — designed for international organizations.

Security Rating® vs one-off audit: what’s the difference?

Traditional cybersecurity audits, penetration tests, configuration audits and manual questionnaires have inherent limitations when it comes to addressing the reality of today’s threats: they are costly, time-consuming, require the target’s cooperation, and their results become obsolete almost immediately.

Criteria Security Rating® Traditional Point-in-Time Audit
Assessment method ✅ 100% automated, non-intrusive ❌ Audit requiring custom tooling setup
Analysis frequency ✅ Continuous, daily updates ❌ Point-in-time (once a year on average)
Readable synthetic score ✅ Score 0–1,000 + A to E rating ❌ Technical report often unreadable by leadership
Coverage ✅ 7 domains, control & performance measures ⚠️ Varies by provider
CTI indicators (threat intel) ✅ Natively included ❌ Often absent or available as a paid add-on
Industry benchmark ✅ Min / avg / max sector comparison ❌ Not available
Multi-organization view ✅ Consolidated dashboard (subsidiaries, suppliers) ❌ Single-entity view only
Automated executive report ✅ Ready-to-use summary report ❌ Time-consuming manual writing
Assessment without target cooperation ✅ Possible (public data) ❌ Requires access and cooperation
Immediate availability ✅ Score available within a few hours ❌ Delivery takes several weeks

Security Rating® offers a fundamentally different approach:

  • Immediate assessment: no delays or coordination with the target; the score is available in under an hour
  • Continuous monitoring: vulnerabilities change every day, and so does the score
  • Comparison: a single score allows organisations to be compared objectively
  • Clarity for management: the 0–1,000 score and A to E rating are understandable to everyone, not just experts
  • Scalability: an organisation can assess dozens of third parties simultaneously, without any extra effort

HOW DOES SECURITY RATING® WORK?

Security Rating® is a fully hosted SaaS solution. No installation is required on the client side. As the analysis relies exclusively on publicly available data on the internet, it is by nature non-intrusive and does not require access to the information systems of the organisation being assessed. Informing the third party of the process remains good practice and is often the starting point for productive collaboration on securing the ecosystem.

Please enter the primary domain name of the organisation to be assessed on the Board of Cyber platform

Security Rating® automatically collects and analyses publicly available data on the internet relating to this domain (exposed assets, configurations, vulnerabilities, CTI, etc.)

An overall score of 0–1,000 and a rating from A to E for each area are generated and made available within a few hours for an initial assessment

How do our customers use Security Rating®?

Mid-size companies, SMEs, insurance brokers, private equity funds, local authorities, notaries, lawyers... Board of Cyber supports a wide range of organizations based on their needs.

"We have a perfect understanding of our external exposure surface across all the group's offices. Thanks to the score, we are able to communicate about our maturity level."

Frédéric SOULIER, Deputy CIO and CISO, CMS Francis Lefebvre Avocats

Client 1
Client 2
Client 3

Security Rating® use cases

Private Equity Funds: Assess the cyber risk of your portfolio

Cybersecurity has become a decisive criterion in investment decisions. A cyber incident can significantly reduce the value of a portfolio company, expose the fund to liability and jeopardise an acquisition. Security Rating® enables investment teams to incorporate cyber risk into their due-diligence and portfolio-monitoring processes, without relying on the target's cooperation.
  • Rapid assessment of an acquisition target's cyber risk before closing, without access to its internal network
  • Continuous monitoring of the cyber posture of all portfolio companies through a consolidated dashboard
  • Identification of the most exposed portfolio companies to prioritise post-acquisition actions
  • Exportable reports for investment committees and due diligence

Large Enterprises: Manage the cyber risk of your subsidiaries and suppliers

For large organisations, the attack surface no longer stops at their own perimeter: every critical supplier, subsidiary and service provider can extend their cyber risk exposure. Security Rating® helps structure and automate the management of this risk at scale.
  • Automated assessment of the cyber posture of all critical suppliers
  • Consolidated view of third-party risk to support your TPRM programme
  • Benchmarking of subsidiaries to identify the weakest links across the group
  • Integration with Trust HQ® for a unified view of governance and third-party risk

SMEs / Mid-sized Companies: Make your cyber rating a practical first step towards managing cyber risk

For an SME or mid-sized company, cybersecurity is often seen as a complex, costly topic reserved for large organisations. Security Rating® changes that perception: within a few hours, with no installation and no prior technical expertise required, you gain a clear, objective view of your cyber exposure, whether your information system is managed in-house or outsourced to a service provider.
  • A rapid initial assessment of your cyber exposure, with no installation or technical expertise required, including for outsourced IT environments
  • Accurate, continuous visibility of your cyber-risk level, enabling monitoring over time
  • Identification of remediation priorities, with practical recommendations by area that can be shared with your IT provider
  • An independent, verifiable cyber score to share with clients, partners, insurers or contracting authorities requiring NIS2 / DORA compliance
  • Access to sector benchmarking to position your performance against competitors and peers

Banks and insurers: Assess the cyber risk of your counterparties

Financial institutions are increasingly incorporating cyber risk into their credit-risk and underwriting assessment models. Security Rating® provides objective, up-to-date and comparable data to enhance these models without conducting intrusive audits.
  • Assessment of the cyber risk of borrowers, policyholders or counterparties using public data
  • Integration into scoring and credit-approval processes
  • Continuous monitoring of cyber risk across the client portfolio
  • Exportable reports for regulatory documentation purposes, including DORA and Basel III/IV

Local authorities and public services: Protect data and service continuity

Local authorities and public-sector bodies are increasingly targeted by cybercriminals, with direct consequences for the continuity of citizen services. Security Rating® enables public organisations to understand their exposure and prioritise security actions, even with limited internal resources.
  • Rapid, non-intrusive assessment of the organisation's cyber posture
  • Identification of exposed assets and priority vulnerabilities
  • Benchmarking against local authorities of a comparable size
  • A summary report that can be shared with elected officials and supervisory authorities
Frequently asked questions about cyber ratings and Security Rating®
What is a cyber score?
A cyber score is an objective rating assigned to an organisation to quantify its external cybersecurity posture. It is calculated through the automated analysis of digital assets exposed to the Internet: service configurations, TLS/SSL certificates, email security, known vulnerabilities and indicators of compromise. The score turns a complex reality into an indicator that is easy for everyone to understand - executives, CISOs, partners, insurers and investors.
How is the Security Rating® score calculated?
Security Rating® automatically and non-intrusively analyses all digital assets publicly exposed on the Internet for a given domain. The assessment covers seven areas: attack surface, email security, web TLS/SSL, security controls, vulnerabilities, patching performance and CTI indicators. An overall score from 0 to 1,000 is assigned, along with an A to E rating for each area. The score is updated daily to reflect the actual evolution of the organisation's cyber posture.
Is the Security Rating® assessment truly non-intrusive?
Yes. Security Rating® relies exclusively on publicly accessible data on the Internet - no access to the internal network, no agent installation and no interaction required with the assessed organisation. This approach makes it possible to assess any organisation, including without its cooperation, which is particularly valuable for due diligence, supplier assessments and portfolio monitoring.
What is the difference between Security Rating® and a penetration test?
A penetration test is an attack simulation conducted by experts. It requires access to the system, coordination with the target organisation and several weeks of work. Its result is a snapshot at a given point in time. Security Rating® is a continuous, automated and non-intrusive assessment that constantly analyses an organisation's external exposure. The two approaches are complementary: Security Rating® provides a real-time view of the attack surface, while a penetration test examines internal systems in depth.
Does Security Rating® help meet NIS2 and DORA requirements?
Yes. NIS2 and DORA require organisations to demonstrate active risk management, including third-party risk. Security Rating® provides an objective and continuous assessment of cyber posture, exportable reports for audit purposes, and traceability of improvements over time. For organisations subject to DORA, monitoring the cyber risk of critical third-party service providers is an explicit requirement that Security Rating® can help structure.
Can several organisations be assessed simultaneously with Security Rating®?
Yes, this is one of Security Rating®'s core use cases. The multi-organisation dashboard makes it possible to monitor the cyber ratings of an entire portfolio, supply chain or group of subsidiaries simultaneously. Each entity has its own score and recommendations, available from a consolidated view that supports comparison and action prioritisation.
Can Security Rating® be integrated with other risk-management tools?
Security Rating® integrates naturally with Trust HQ®, Board of Cyber's cyber governance and TPRM platform. Cyber scores for suppliers assessed by Security Rating® can therefore directly feed into your TPRM programme and governance dashboards in Trust HQ®. This integration provides a unified view: objective third-party risk insights from Security Rating® combined with governance and action plans in Trust HQ®.