There are numerous areas of business and enterprise risk that have been measured for years in a standardized fashion — these include financial risk, market risk, operational risk, legal risk, and even IT risk.
But we’ve had to treat cyber risk in a completely different way.
The desire has been to have a consistent way to treat cyber risk — a less tangible, more dynamic risk — in the same way we treat other organizational risks.
Good news: now you can.
There are several key ways that Bitsight Security Ratings allow you to accomplish this:
- Use of security ratings to mitigate cyber risk within your organization
- Visibility into desired parts of your business
- Bi-Directional communication to measure and manage your own cyber risk, convey that risk to interested parties, and understand the risk from your supply chain
Security Ratings
Bitsight rates organizations based on externally-observable data associated with domains and IPs mapped to a rated company. The association of findings to each company is objective and follows the guidelines set out in the US Chamber of Commerce’s Principles for Fair and Accurate Security Ratings.
It’s these ratings — allowing objective, standardized measurements of security posture that can be applied to any company — that companies can use to benchmark themselves against other companies and industries in a way that wasn’t possible before security ratings were created by Bitsight in 2011.

Example of Bitsight Peer Analytics, a service that provides security and risk leaders unprecedented visibility into the relative performance of their security programs against their peers and industry sector, set achievable security performance improvement goals, effectively allocate limited resources, and efficiently prioritize security efforts.
Visibility into Divisions and Segments
However, that value isn’t limited to a single, overarching view of the entirety of your business. Most large businesses don’t operate as one big silo, but rather align their infrastructure to match product lines, geographic regions, and more.
Bitsight goes to great lengths to ensure accurate subsidiary mapping, allowing businesses to monitor their own cybersecurity (or that of their vendors’) using Bitsight’s Company Trees. The depth of visibility Bitsight provides in its reporting allows companies to manage and report cyber risk posture in great detail across any and all subsidiaries - helping them to measurably decrease risk both at the corporate and subsidiary levels.
But sometimes the desire to understand and compare risk goes beyond that top level. With Self-Published Ratings, companies can monitor and manage segments of their business whose structure only they have visibility into. For example, companies can monitor regional offices and compare to one another. Or break out ratings for specific product lines to have a consistent way to measure risks when your company serves as part of a customer’s supply chain.
Companies can also create what is known as a Primary Rating, a type of Self-Published Rating. A Primary Rating allows a company to communicate the risk of the infrastructure it believes most accurately reflects its security posture (e.g. the IPs and Domains that are used in the delivery of services and products your customers buy). Primary Ratings include a Bitsight Security Rating and grades for each of the 23 risk vectors Bitsight measures, but specifically evaluates only the activity associated with the infrastructure you’ve identified as being business-critical.
These Self-Published Ratings (which can be both for internal-use only, or to be shared with other Bitsight users) and Primary Ratings provide a level of context no one else in the Security Ratings industry can match.
Sample Bitsight Security Rating and Sample Primary Rating
Bi-Directional Communication
As security ratings become the norm, companies are realizing the value of such an objective, standardized means of measuring and discussing risk. As such, communication within these portals — both to your business partners and from — becomes even more valuable.
Companies often “tag” IPs in their organization so that activity picked up from those IPs clearly shows its purpose. If a company has a large guest network, and malware reaches out from that portion of its infrastructure, that company’s ratings details would reflect that tag, and allow companies to understand more about how their organization is structured from a security standpoint.

