Bitsight is committed to creating trustworthy, data-driven, and actionable measurements of organizational cybersecurity performance. As part of this commitment, Bitsight periodically makes improvements to our ratings algorithm. These updates often include new observation capabilities, enhancements to reflect the rapidly changing threat landscape, and adjustments to further increase accuracy and correlation with outcomes. We also make some changes based on direct feedback from rated entities.
We follow a detailed process whenever we update our ratings algorithm, and all changes are rigorously governed by our Policy Review Board to ensure that they adhere to our principles and policies. Additionally, it is important to note that we always provide a preview of the changes to our users (and what the likely impact on their rating will be), well before they affect live ratings.
Our latest Rating Algorithm Update is live, so let's take a look at what changed and why.
Ratings Methodology Adjustments
|
Bitsight Risk Vector/Mapping |
Updates |
Results |
|
Findings Related to RDP graded as ‘BAD’ |
Better reflects the risk of operating these services, especially in regards to Ransomware |
|
|
Limited the rating impact of individual findings |
Ensures that the rating impact of a single Open Port record is more appropriate for smaller organizations |
|
|
Desktop and Mobile Software |
Implemented Dynamic N/A Grades |
Ensures fair grading in cases of low record visibility—important for work-from-home environments |
|
Employee Counts |
Improved algorithms for estimating organizational employee counts |
Ensures accurate employee counts and updates over time |
|
Breach Re-calibration |
Recalibrated breach methodology |
Improves grading scheme and approach for assessing breach impacts that is more consistent with other vectors |
|
Headline Rating |
Revised weighting of Compromised System Findings and SSL configurations |
Improves ransomware risk assessment in today’s work-from-home environments |
|
Increased Robustness of Security Rating Calculation |
Improves transparency into changes in the Security Rating |