How does SecurityScorecard calculate my score?

SecurityScorecard takes into account all the external-facing discoverable assets of an organisation, the issues associated with those assets, and the severity of the threats found in order to determine a score for each organisation. Their scoring algorithm is based on a statistical framework that takes into account the 1,500,000+ rated companies on the SecurityScorecard platform.

SecurityScorecard’s scoring model is a continuous measure of the typical number of findings for an organisation versus their size.

The score is developed based on the number of standard deviations an organisation has compared to the average number of findings for organisations of a similar size. This enables fair comparisons and brings increased accuracy, transparency, and fairness to the security rating process.

Machine Learning Tuned Risk Factors

SecurityScorecard uses machine learning to tune the scoring impact of our 10 risk factor groups.

This data-driven approach enables them to not only optimise the correlation between our grades and the relative likelihood of a breach but it also provides users more insightful scores.

We’ve found that companies with an F rating are 7.7 times more likely to be breached compared to an A. Read this report on their website to learn more.

Monthly Scoring Updates

The breadth and depth of their ratings product is continuously enhanced with monthly scoring updates.

These scoring updates don’t just allow SecurityScorecard to readjust the baseline that companies are scored against to makes scoring more accurate. They also allow the addition of new signals, retirement of old signals, and adjust the weight of issues and factors.

This monthly cadence enables SecurityScorecard to keep up with the continuously changing threat landscape and provide an increasingly accurate picture of an organisation’s cybersecurity posture.