This post was originally published July 18, 2016 and has been updated for accuracy and comprehensiveness.
A security rating and a security score are often used interchangeably, but there are key distinctions between the two phrases.
In broad terms, a security score connotes a baseline, static result and is used by cybersecurity insurance underwriters to evaluate an organization’s potential risk. A security rating, on the other hand, offers more context into performance by providing a data-driven, objective and dynamic measurement of an organization’s security performance over time. This is important because cyber threats are continuously evolving and the cyber risk landscape is always changing.
The Oxford Dictionary definitions help to further distinguish these two:
- Score: The number of points, goals, runs, etc., achieved in a game by a team or an individual.
- Rating: A classification or ranking of someone or something based on a comparative assessment of their quality, standard, or performance.
Assessing the cybersecurity posture of trusted vendors, suppliers, and other business parties is a very complex task. With so many different elements involved to secure a network, it’s rare that a company’s security score is simply just “good,” “average,” or “bad.” A complete picture of an organization’s security is more nuanced.
The founders of Bitsight chose a security ratings scale as a performance metric for this very reason. Third- party cybersecurity risk management can require in-depth conversations with companies, and having a more precise view of a company’s security posture makes for a more valuable and transparent conversation.