As a recent Forrester report highlighted, there are many cybersecurity ratings available. Security ratings have a valuable place in your overall cyber risk mitigation strategy, for many reasons.
Not all security ratings are equal though.
One criteria that was omitted from the report is whether ratings have been independently verified. To date, Bitsight remains the only rating that has been independently verified to correlate to either the increased likelihood of breach or company performance
What Does Independent Verification Mean?
In short, it means that a third party has done a statistical study to determine if the rating accurately correlates to what it says it is going to. Cyber security ratings were designed to indicate whether a company is at increased risk of cyber security breach.
Like credit ratings, security ratings are not designed to be predictive, but to indicate likelihood of a negative event. They externally examined the effectiveness of cyber risk mitigation efforts, tools and hygiene to indicate the probable overall risk of breach a company faces due to their observable cybersecurity posture.
Why Does It Matter
Frankly, unless it’s been proven to be correlative, a rating is just a number.
A ratings service needs to be proven to be measuring the right data and that its model is correlated to a greater or lesser risk of cybersecurity breach. Security ratings are strategic business tools that are used to make important decisions within the organization. They are used to measure the effectiveness of security controls put in place, decide which vendors present too great of a security risk to work with, communicate to the board of directors about cyber risk mitigation, and make investment and prioritization decisions.
In a world where breaches like SolarWinds and Hafnium have become an accepted fact of life, do you want to use a rating that has not been independently verified to make those business decisions?
The risks of doing so are non-trivial. Since ratings are used to inform strategy, you want to ensure you’re using the ratings that provide the most accurate information possible. Since ratings services are often used to verify vendor risk assessments, they need to be up to date and comprehensive. Because they’re used to verify the effectiveness of your cyber security risk mitigation efforts, they need to measure the right things to give you the peace of mind that you’ve taken the right steps to reduce your risk.