Platform · Security ratings

Ratings that move when reality moves.

Continuously-monitored security ratings backed by combined-signal analysis — outside-in scans plus the vendor's own evidence, on the same score. Not a stale snapshot from a single source.

What are security ratings?

Security ratings are quantified, continuously updated measures of an organisation's cybersecurity posture, produced from data observable without that organisation's cooperation. A single security rating is the credit-score analogy of security: an outside party forms a view from evidence it can gather independently, and that view updates as the evidence changes.

They are also called cyber security ratings, cybersecurity ratings or security scores — the same measurement under different labels, and the wording varies more by vendor than by method.

RiskXchange scores on a 0–900 scale, presented as an A–F grade. The number is what moves and what you track over time; the letter is the summary a board or a vendor conversation actually uses. They are the same measurement, not two ratings.

The signals behind it are the ones an attacker would also see: externally exposed infrastructure — domains, subdomains, IP ranges, open services and their versions — TLS and certificate configuration, email authentication such as SPF, DKIM and DMARC, DNS hygiene, patching latency on internet-facing software, exposed or misconfigured services, leaked credentials appearing in breach corpora, and reputational signals like appearance in botnet or malware telemetry.

What a rating cannot see is the inside: encryption at rest, network segmentation, privileged access management, staff training, backup and recovery testing. That is the honest limit of the method, and it is why RiskXchange combines the outside-in score with the vendor's own evidence — questionnaires, certifications, policies — rather than treating the rating as the whole answer. The gap between what a vendor claims and what is externally observable is frequently the most useful finding. For how the major platforms compare, see our platform comparison.

The numbers your team already knows.

Most security ratings are single-signal — outside-in scans only — and most of them sit between refreshes for weeks at a time. A score that moves the day after the breach is a score that didn't help.

7-30 days
Typical rating refresh latency at competing platforms
Industry estimate
11 days
Average time to act on a vendor breach signal
Industry average
Daily / weekly
Refresh cadence for customer / vendor scans on RX

REX scores it. ARIA contextualises it. TARA acts on the drop.

The rating is the head of the funnel. REX produces the score from continuous external scanning. ARIA layers in the vendor's own evidence. TARA decides what a drop should actually trigger.

REX avatar
REX
Risk & Breach Intelligence

A rating that's continuously, not occasionally, calibrated. REX's Outside-In Scanner refreshes daily for customers and weekly for vendors — and the Continuous Monitoring sub-agent watches the time-series for material changes around the clock.

What you get
  • Outside-in scoring across 5M+ companies
  • Continuous Monitoring detects material drops in real time
  • BreachWatch correlates dark-web findings into the score
ARIA avatar
ARIA
Assessment & Risk Intelligence

A rating, joined to the vendor's own evidence. ARIA pairs REX's external score with the vendor's questionnaires, certs and trust centre — so the rating reflects both what we can see and what's been attested.

What you get
  • Combined-signal analysis on every vendor
  • Document evidence linked to the score that summarises it
  • Response Validator flags ratings/attestation mismatches
TARA avatar
TARA
Tiering & Remediation

A drop that triggers the right action automatically. When a rating moves materially, TARA decides what it means — for that vendor's tier, against the regulatory frameworks in scope, and what the SLA-bound remediation should be.

What you get
  • Smart Tiering — score drops weighted by inherent risk
  • SLA-driven remediation kicked off automatically
  • DORA, NIS2, ISO 27001 gap analysis on every vendor

From single-signal score to combined-signal posture.

The number stops being a thing you check on a dashboard and starts being something the agents act on while you sleep.

Drops detected, not discovered

Continuous Monitoring catches material rating changes in real time, not at the next refresh window.

The score is the front of the evidence

Click any rating and you get the underlying signals — scan data, breach findings, attested evidence — joined together.

Mismatches surface automatically

When a vendor scores well externally but the questionnaire suggests otherwise, ARIA flags it before you investigate.

Action follows the drop, not the meeting

A material rating change opens a TARA-led remediation track without waiting for someone to spot it on a dashboard.

The combined-signal model is the difference. We stopped arguing about whose rating was 'right' — we started looking at the score and the evidence together.

MK
CISO
FTSE 250 financial services

What teams ask about security ratings.

How the score is built, what it can and cannot tell you, and what to do when a vendor disputes theirs.

How is the security rating calculated?
From continuously collected outside-in signals, weighted by severity and by how directly each indicates exploitable risk rather than untidiness. An expired certificate on a marketing subdomain and an unpatched internet-facing VPN appliance are not the same finding, and a rating that treats them alike is not useful. Findings are attributed to the organisation through its verified digital footprint, aggregated into the 0–900 score and expressed as an A–F grade. Because collection is continuous, the score moves when posture moves rather than when an assessment is scheduled.
What are cyber security ratings?
The same thing as security ratings — an objective, continuously updated score of an organisation's externally observable security posture, derived without that organisation's cooperation. “Cyber security ratings”, “security ratings” and “security scores” are used interchangeably across the market. What matters is not the label but what sits behind it: which signals are collected, how findings are attributed to the right organisation, how severity is weighted, and how often the score is refreshed.
Can a security rating be wrong?
It can be incomplete, and the most common cause is attribution: assets assigned to the wrong organisation, or a subsidiary's estate scored against the parent. Disputes are usually about footprint rather than about whether a finding is real, which is why the footprint should be reviewable and correctable. Beyond that, a rating is a measure of externally observable posture and nothing more — a well-run organisation with a small external surface and a poorly-run one can look closer together than they are. Treat a low score as a strong signal and a high score as a weaker one.
How do security ratings differ from a questionnaire?
They answer different questions and fail in opposite directions. A rating is objective, continuous and needs no cooperation, but sees only the outside. A questionnaire reaches internal controls, governance and process, but is self-reported, point-in-time and only as good as the care taken answering it. Used together the interesting thing is the disagreement: a vendor asserting a mature vulnerability management programme while running months-old unpatched software on the perimeter has told you something no single source would have.
What should we do when a vendor disputes their rating?
Treat it as useful rather than adversarial — a dispute is usually the fastest route to an accurate footprint. Start with attribution: ask which assets they consider theirs, and correct the map where they are right. Then separate the two remaining cases: a finding they say is remediated, which re-scanning resolves, and a finding they say is accepted risk, which is a legitimate position that belongs recorded against the vendor rather than argued away. The one answer to push back on is that a finding does not matter because the asset is not important — exposure is exposure, and attackers pick targets by reachability, not by your asset register.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.