Security ratings are quantified, continuously updated measures of an organisation's cybersecurity posture, produced from data observable without that organisation's cooperation. A single security rating is the credit-score analogy of security: an outside party forms a view from evidence it can gather independently, and that view updates as the evidence changes.
They are also called cyber security ratings, cybersecurity ratings or security scores — the same measurement under different labels, and the wording varies more by vendor than by method.
RiskXchange scores on a 0–900 scale, presented as an A–F grade. The number is what moves and what you track over time; the letter is the summary a board or a vendor conversation actually uses. They are the same measurement, not two ratings.
The signals behind it are the ones an attacker would also see: externally exposed infrastructure — domains, subdomains, IP ranges, open services and their versions — TLS and certificate configuration, email authentication such as SPF, DKIM and DMARC, DNS hygiene, patching latency on internet-facing software, exposed or misconfigured services, leaked credentials appearing in breach corpora, and reputational signals like appearance in botnet or malware telemetry.
What a rating cannot see is the inside: encryption at rest, network segmentation, privileged access management, staff training, backup and recovery testing. That is the honest limit of the method, and it is why RiskXchange combines the outside-in score with the vendor's own evidence — questionnaires, certifications, policies — rather than treating the rating as the whole answer. The gap between what a vendor claims and what is externally observable is frequently the most useful finding. For how the major platforms compare, see our platform comparison.