Security Ratings are still a relatively new phenomenon. As a result, many security and risk professionals are still familiarizing themselves with how ratings work, the data used to compute ratings, and how ratings are put into action. We expect this education to continue: consumer credit scores are always changing and after many years, people are still constantly coming up to speed with the multitude of factors that affect their score.
While security and risk professionals familiarize themselves with the emergence of security ratings, it is vital to recognize information that is misleading - or meaningless. Below are some common myths about security ratings that everyone should be aware of.
#1 Ratings claiming to have X% more data
Security Ratings are a big data application that assess a company’s security performance from the outside-in. Rating firms need to leverage as many data sources as possible in order to be accurate. Moreover, the data consumed by rating firms needs to be vetted for accuracy before being added into the calculation of a security rating.
When a firm claims to leverage a larger percentage of data than other rating services, ask yourself:
- How could they know this? No business is disclosing the exact amount of data they collect.
- The more important questions to ask are; where is the data coming from? How proven are these data sources? Is the data relevant to the security hygiene of my company?
- What does relative data volume even mean if the rating isn’t actionable, especially when it comes to managing third party vendors?
#2 Creating Data In-House Is Better Than Acquiring It Elsewhere
Some rating firms claim that they have “proprietary” data collection methods, and that their ratings are inherently more accurate since the bulk of the underlying data is gathered internally. Businesses should be wary of ratings that are comprised almost entirely of internally generated data.