On the surface, the Bitsight Rating and associated Risk Vectors look self-explanatory. However, taking them at face value doesn't tell the full cybersecurity story of your organization or your vendors. As with any complex dataset, interpreting the presented information takes a bit of domain knowledge and some leaps of intuition. The investigative skill involved can feel like arcana, almost like reading tea leaves.
Risk vs. Exposure
The Bitsight Rating provides a single, objective rating that's normalized across all organizations, taking into account footprint and size. More than just an arbitrary number, Bitsight's Rating is correlated to both likelihood of a security incident and to becoming a victim of ransomware.
Stepping back for a moment, the Rating was designed as a complement to other ratings systems such as:
- Consumer credit, including Equifax, Experian, TransUnion, and Schufa
- Capital markets and credit ratings, including Moody's, Fitch, S&P Global, and JCR
- Consumer goods, including Consumer Reports, Michelin, Zagat, TripAdvisor, and Yelp
As such, the Rating assesses an organization's performance over time, correlated to the probability of a negative outcome in the future.
To put this in perspective, if you miss a car payment for June, but make up for it in July—paying what's owed for both June and July—you may be caught up but your credit rating will drop and take a while to recover. You've shown that you either have a cash flow or a payment discipline problem, albeit slight in this case. If you miss additional payments for the car or other loans, or take on excessive potential debt by applying for multiple credit cards—even if you don't run them up—your rating continues to drop because you're a credit risk.
And that's the operative term—the Bitsight Rating is a measure of risk, of which vulnerabilities are just one factor. This subtlety is often lost on security operations, who monitor and manage immediate liability—mainly exploitable flaws in systems and software, including open ports, out-of-date or unpatched operating systems and applications, and malware. These are point-in-time issues, or exposure, and restricted to technology; risk is a measure of cybersecurity governance, policy, practices, and procedures, of which exposure is but one consideration.
For example, a Conficker infection is not an immediate threat. It's fifteen years old and none of the Windows vulnerabilities it exploits should be unpatched at this point in time. As a result, Conficker is no longer an exposure concern. However, all modern endpoint detection and response (EDR, aka host firewalls or anti-malware) tools should be able to detect and neutralize it, so the presence of Conficker tells us that the organization has poor defenses. If the infection persists for longer than a day, it tells us they have gaps in their detection and response practices and may lack log management or a SIEM.
Risk Vectors are more than vulnerabilities and open ports
Digging deeper into the rating model, Bitsight captures 25 Risk Vectors and their underlying findings. Most contribute to the overall Rating, although some are simply informational—they don't tell us anything about the organization's practices but are helpful in informing the organization about external threats—and others are being evaluated for eventual inclusion in the Rating.
Each of the Risk Vectors has associated findings, and each finding has a grade of GOOD, FAIR, NEUTRAL, WARN, or BAD, based on severity, which percolate up to a cumulative grade of A–F.
Summary of the Bitsight Findings, Grades, Risk Vectors, Rating, and Organization Tree