Not all cyberattacks rely on novel or highly sophisticated techniques. Many exploit known vulnerabilities, insufficiently secure configurations, or compromised credentials. Yet their consequences can be significant for the organizations concerned.
At the same time, reliance on digital tools, cloud services, and SaaS solutions increases the number of assets, partners, and suppliers that need to be secured. A configuration change, a new subdomain, a tool deployed by a business team, or a recently disclosed vulnerability can alter the attack surface within hours.
Organizations can therefore no longer simply address vulnerabilities as they arise. They need to structure their governance, maintain visibility over their external attack surface, and monitor the evolution of their cyber maturity.
This is precisely the role of the cyber rating, also referred to as a cybersecurity rating. It helps CISOs, executive teams, insurers, investors, and risk managers reduce uncertainty, assess certain risk signals objectively, and better prevent attack opportunities.
What Is a Cyber Rating? Definition and Origins
Defining the cyber rating
A cyber rating, or cybersecurity rating, assesses an organization's cybersecurity posture based on information observable from the internet, including its exposed digital assets, technical configurations, and certain public risk signals.
This assessment generally results in a consolidated score that makes it possible to compare organizations, identify areas for improvement, and monitor changes in their posture over time. However, update frequency may vary depending on the solution: some provide a one-off or periodic assessment, while others offer continuous monitoring.
A cyber rating does not replace an in-depth audit, penetration test, or certification. However, it provides a complementary view of an organization's external exposure, as well as that of its subsidiaries, suppliers, or partners.
From credit rating agencies to cyber ratings
Cyber ratings are inspired by the way credit rating agencies operate. For decades, organizations such as Moody's and Standard & Poor's have assessed the financial strength of companies to inform the decisions of investors, banks, and business partners.
The objective is not limited to issuing a rating. It is to provide a shared benchmark that supports decision-making and trust among economic stakeholders.
The principle is similar for cyber ratings, which emerged in the United States before spreading to Europe. In an interconnected digital environment, an organization's security depends on its own practices, those of its third parties, and the many SaaS services it uses. Executive teams, CISOs, procurement teams, legal departments, insurers, and investors therefore need clear indicators to assess cyber risk levels.
An indicator taken seriously by public authorities
France has addressed the issue since 2021. In a report on corporate cybersecurity, Senators Sébastien Meurant and Rémi Cardon proposed the creation of a European cyber rating agency based on ANSSI frameworks.
The law of March 3, 2022, known as the "Cyberscore" law, subsequently introduced an information scheme on the security level of certain digital platforms. Its underlying philosophy aligns with cyber ratings applied to businesses: making the security posture of a digital organization more understandable in order to strengthen trust.
How Does a Cyber Rating Work?
Three complementary mechanisms
The calculation of a cyber rating generally relies on a combination of three activities:
-
Mapping internet-exposed assets: domain names, subdomains, public IP addresses, websites, and accessible services. This step helps identify the visible digital perimeter of the organization.
-
Collecting data available from open sources: service configurations, SPF, DKIM, DMARC, and TLS settings, potential presence on blacklists, indicators of compromise, or credential leaks.
-
Analyzing the collected data: an assessment engine aggregates the observed information to generate a rating and, depending on the solution, remediation recommendations.
External attack surface mapping is not only used to identify what attackers can see. It also provides valuable visibility for CISOs and CIOs into assets that may have been deployed outside standard approval processes: subdomains created for a marketing campaign, test environments, SaaS tools used by business teams, or services forgotten after a project ended.
In complex organizations, maintaining this visibility manually is difficult. Regular external assessments therefore help supplement the internal information system inventory and detect certain unrecorded assets.
What does a cyber rating actually measure?
The cyber rating market includes French and international solutions whose assessment methods, analysis scopes, and update frequencies may differ. It is therefore important not to consider the characteristics of one solution as applicable to the entire market.
In the case of Security Rating®, the analysis covers several types of public data in order to provide the most comprehensive possible view of the external attack surface. The solution assigns an overall score from 0 to 1,000 and a rating from A to E for each of its seven assessment domains.
| Category | Assessment domain | What is assessed |
|---|---|---|
| Control measures | Attack surface | Mapping of exposed assets: subdomains, open ports, and accessible services |
| Email security | SPF, DKIM, DMARC configuration and email server exposure | |
| Web TLS/SSL | Certificate quality and validity, supported protocols, and risky configurations | |
| Security controls | Presence and configuration of essential protection mechanisms | |
| Performance measures | Vulnerabilities | Known CVEs detected on exposed assets and their severity level |
| Patch performance | Remediation speed based on vulnerability criticality | |
| CTI indicators | Presence on blacklists, compromised IP addresses or domains, data leaks, or credential leaks |
This two-tier approach makes it possible to tailor information to different audiences. Executive teams can monitor the overall score, its evolution, and positioning against the sector. Technical teams can use the details of the assessment domains and the associated recommendations.
What cyber ratings do not measure
Cyber ratings have a scope that must be understood to use them properly. Since they rely on public data, they cannot account for all of an organization's internal security measures: EDR deployment, backup configuration, privilege management, employee awareness, incident response process robustness, or detailed multi-factor authentication configuration.
They therefore do not replace in-depth audits, security questionnaires, or penetration tests. They complement them.
As part of a supplier cyber risk management or Third-Party Risk Management (TPRM) approach, cyber ratings provide regular external monitoring. Questionnaires provide declarative and documentary information, while audits explore the most critical issues in greater depth. Comparing what a supplier declares with information observable from the internet is a more robust approach than relying on a single source of information.
Why Cyber Ratings Have Become a Governance Tool
A clear indicator for executive teams
Cybersecurity is often difficult to present to senior management or an executive committee. Technical indicators, vulnerability volumes, and operational dashboards do not always make it easy to clearly communicate changes in the organization's security posture.
A cyber rating does not, on its own, summarize an organization's overall security level. However, it can provide a clear, comparable, and understandable governance indicator for non-technical audiences.
For a CISO, this indicator can be used to:
- monitor changes in the external attack surface over time;
- highlight improvements or deterioration in the cyber posture;
- compare the organization with companies of a similar size or within the same sector;
- prioritize remediation actions;
- support reporting to the executive committee, board of directors, or insurers;
- substantiate investment needs and the results of action plans.
This approach is relevant for SMEs and mid-sized companies as well as large groups, public organizations, and listed companies. Challenges and asset volumes may differ, but the need for a reliable, understandable, and continuously monitored indicator remains the same.
As Julien Steunou, Chief Product Officer at Board of Cyber, explains:
"Cyber ratings are an important decision-making tool in risk management. For a business leader, having a clear assessment and presentation of cyber performance makes it possible to identify straightforward actions."
Addressing regulatory requirements
Organizations face a growing number of regulations intended to strengthen their digital resilience and their ability to manage third-party risks:
- NIS 2, which strengthens cybersecurity requirements for certain relevant sectors and entities;
- DORA, relating to the digital operational resilience of financial entities and the management of their ICT service providers;
- ISO/IEC 27001:2022, the leading standard for information security management systems;
- AI Act, the European regulation on artificial intelligence;
- Cyber Resilience Act, which establishes cybersecurity requirements for certain products with digital elements;
- GDPR, concerning the protection of personal data.
These texts do not impose the same approach or the same obligations. However, they share a common requirement: organizations must be able to demonstrate active management of their risks, including those involving service providers, suppliers, and subcontractors.
Cyber ratings can contribute to this process by providing factual information about the external attack surface, identifying signals that may weaken security, and documenting changes in posture over time. They do not make an organization compliant on their own, but they can provide useful evidence as part of a compliance programme. To explore this topic further, see our use case on improving compliance.
A driver of trust and competitiveness
Cyber maturity is now taken into account in an increasing number of business decisions: purchasing or renewing cyber insurance, awarding contracts, becoming an approved supplier for a client, assessing a vendor, or valuing a company prior to an acquisition.
An organization whose cyber posture shows signs of weakness may find its relationships with customers, partners, or insurers becoming more complex. Conversely, a posture that is monitored and improved over time can foster trust and demonstrate the organization's ability to address identified risks.
Cyber ratings are therefore not only a risk management tool. They can also become a source of reassurance and differentiation within an organization's ecosystem.
Cyber Rating Use Cases: Who Uses It and Why?
Managing your own cyber performance
The primary use case is to assess the organization's and its subsidiaries' external cyber posture. This approach applies to SMEs and mid-sized companies as well as large groups, including CAC 40 companies: all need a clear view of their exposure and the ability to monitor changes in their cyber maturity.
The score provides the CISO with a time-based indicator, sector benchmarking, and a reporting tool that is easy for management to understand, without manual reformatting.
Cyber ratings therefore turn technical information into a governance indicator that is understandable to everyone, while providing operational teams with the information required to address identified weaknesses.
Assessing and monitoring suppliers
In procurement and supplier risk management, cyber ratings are an important TPRM lever. They make it possible to assess a large number of third parties, identify those requiring further investigation, and trigger alerts when their external posture deteriorates.
Questionnaires, audits, monitoring activities, and contractual clauses remain essential. However, a company is itself a supplier to dozens or even hundreds of other organizations. It may therefore, sooner or later, be subject to a cyber assessment request from a client, partner, or insurer.
Taking a proactive approach makes it possible to anticipate these requests, address weaknesses before they become blockers, and better prepare discussions with customers and contracting entities. Cyber ratings thus help structure an ongoing dialogue with suppliers, complementing other supplier cyber risk assessment methods.
Cyber insurance: raising awareness and supporting policyholders
In the insurance sector, cyber ratings can be used as a tool for awareness and continuous improvement among policyholders. They help identify certain external risks and guide organizations toward concrete remediation actions.
At AXA France, for example, cyber ratings are used to help companies better understand their exposure level and improve throughout the life of their policy. Read Thierry Piton's feedback from AXA France.
Private equity and M&A: cyber due diligence
Investment funds can integrate cyber ratings into their due diligence processes. Because they are based on public data, these assessments can be conducted without access to the target's internal network. They provide an initial level of visibility into its external attack surface, visible vulnerabilities, and apparent cyber maturity.
This analysis can inform the assessment of an acquisition target or portfolio company. Insufficient cyber performance may reveal remediation costs, operational risks, or additional investment needs that could affect the terms of the transaction.
After an acquisition, cyber ratings also facilitate consolidated portfolio monitoring and the identification of entities requiring priority security actions. This approach aligns with the practices described in our article on supplier due diligence.
The testimony of Samuel Bafourd, CIO of the Seven2 investment fund, also illustrates the value of a consolidated view of the external exposure of portfolio companies to monitor their cyber maturity.
Regulated sectors and public administrations
In regulated sectors and public administrations, cyber ratings can support partner assessments, the identification of external weaknesses, and the prioritization of security actions.
Financial institutions can use them to assess the cyber risk of their counterparties objectively and support the management of ICT service providers. Local authorities and public bodies can use them to better prioritize their actions, particularly when human and financial resources are limited.
Seven Common Misconceptions About Cyber Ratings
"It is intrusive"
No. External cyber ratings rely on publicly accessible data and do not require access to the assessed organization's information system. However, it is essential to choose a solution that is transparent about its analysis scope and enables the organization to validate the assets attributed to it.
"It is burdensome"
An automated cyber rating generally requires no installation, agent deployment, or technical configuration from the assessed organization. On the contrary, it should enable teams to spend more time remediating identified risks.
"The results are not reliable"
Any automated mapping may produce attribution errors, for example when an asset is confused with that of a similarly named organization or a former service provider. This risk must be addressed through validation of the assessed scope and correction mechanisms that are accessible to the organization concerned.
"It is impossible to scale"
Manual questionnaires and audits are difficult to deploy across several hundred suppliers. This is precisely one of the benefits of cyber ratings: providing a consistent initial assessment of a large third-party portfolio and focusing human investigations on the most sensitive organizations.
"The rating quickly becomes outdated"
A one-off assessment does indeed provide a snapshot at a given point in time. Solutions that update their analysis regularly make it possible to better monitor changes in the external attack surface. At Board of Cyber, Security Rating® updates scores daily.
"It is not useful for my business"
Cyber ratings are not intended only for large groups. SMEs, mid-sized companies, local authorities, listed companies, insurers, investment funds, and public administrations may all need to understand their own external exposure or that of their partners.
Any organization can be targeted by an attacker and, in turn, become a risk link in its customers' supply chain. Proactively assessing its posture makes it possible to better anticipate partner requests and address detected weaknesses before they are exploited.
"It is too expensive or I do not have the budget"
The cost of an assessment must be considered in relation to the time required to carry out manual controls, the difficulty of monitoring multiple suppliers, and the potential cost of a cyber incident. Cyber ratings help automate part of the external controls and prioritize actions to be taken.
They do not eliminate the need for necessary security investments, but they help direct them toward the most visible and highest-priority risks.
Security Rating®: Board of Cyber's Approach to Cyber Ratings
Board of Cyber already supports more than 500 private and public organizations in assessing and improving their cyber posture.
Security Rating® provides a continuous, automated, and non-intrusive assessment of the external attack surface. The solution helps organizations identify exposed assets, monitor their score, detect certain risk signals, and prioritize remediation recommendations.
It can be used to assess an organization's own posture, as well as that of its subsidiaries, suppliers, partners, or portfolio companies. Dashboards, technical reports, and executive summaries facilitate information sharing across different governance levels. Sector benchmarking also makes it possible to position an organization against comparable players.
For broader supplier cyber risk management programmes, Security Rating® results can be complemented by Trust HQ®, Board of Cyber's cyber governance and third-party risk management platform. In particular, it makes it possible to structure audit campaigns, collect evidence, manage questionnaires, and monitor action plans.
Organizations wishing to extend assessment beyond their external attack surface can also rely on Rating +, which combines Security Rating®, AD Rating®, and 365 Rating® to provide a consolidated view of cyber exposure related to infrastructure, identity, and collaborative environments.
To discover the assessment of three partners or suppliers, it is possible to rate three suppliers free of charge.
Conclusion: From Rating to Trust
Cyber ratings do not guarantee the absence of incidents and do not replace audits, penetration tests, or compliance programmes. However, they provide a structured and actionable view of an organization's external exposure.
When properly integrated into a risk management approach, they help organizations reduce uncertainty, monitor changes in their attack surface, prioritize their actions, and establish a more fact-based dialogue with suppliers, partners, insurers, and investors.
The value of a rating therefore lies not only in the score obtained. It lies in the organization's ability to understand the observed risks, remediate identified weaknesses, and demonstrate sustained improvements in its cyber maturity.
FAQ
How is a cyber rating calculated?
A cyber rating is calculated using data observable from the internet. The assessment generally includes mapping exposed assets, analyzing technical configurations, detecting known vulnerabilities, and identifying certain indicators of compromise. Methods, criteria, and update frequencies vary between solutions. Security Rating® assigns a score from 0 to 1,000 and a rating from A to E across seven assessment domains.
Does a cyber rating replace a security audit or penetration test?
No. Cyber ratings complement audits and penetration tests but do not replace them. They analyze the external attack surface using public data, without accessing the information system. An audit or penetration test enables a more in-depth examination of systems, applications, processes, and internal defense mechanisms.
Why integrate cyber ratings into a TPRM approach?
Cyber ratings provide an external, factual, and comparable data point for supplier assessments. They help monitor a large portfolio of third parties, identify organizations requiring further audits, and detect certain posture degradations. They should be combined with questionnaires, audits, contractual clauses, and remediation plans.
Does a good cyber rating guarantee the absence of a cyberattack?
No. A good rating indicates that certain external risk signals are under control, but it does not measure all internal defenses or the human factor. It therefore cannot guarantee the absence of an incident. However, it helps reduce certain attack opportunities by identifying and remediating exposures visible from the internet.