+49 6151 6290246

Published: August 6, 2026

What is a security rating?

This text was generated using artificial intelligence (AI).

A security rating translates a company’s IT security posture into a single, comparable metric. The rating is derived from an external perspective: it analyzes what attackers can see and access via the Internet. This article explains how KPI-based ratings are created, how companies use them, what their limitations are, and how they differ from audits and penetration tests.

The terms Cyber Risk Rating, Cybersecurity Rating and IT Security Assessment are commonly used. In each case, this refers to a data-driven classification of cyber risk; the scope and assessment model may vary depending on the provider.

Key Points at a Glance

Definition: What a Security Rating Indicates

A security rating is a data-driven assessment of an organization’s IT security, summarized as a numerical value or a grade. Similar to a credit report in the financial sector, it answers a simple question: From an outsider’s perspective, how well is a company positioned to defend against cyberattacks?.

The assessment is based exclusively on information accessible via the Internet. This includes domains, IP addresses, accessible services, certificates, and email configurations. A rating therefore requires neither software agents on the systems nor access to internal networks. The auditing company and the company being evaluated do not even need to be in contact with each other.

It is precisely this feature that makes ratings scalable. While an audit requires weeks of preparation, an external assessment can be conducted for hundreds of suppliers simultaneously. LocateRisk delivers such an analysis within 48 hours, without any installation and without interfering with ongoing systems.

Important to note: A rating measures the visible attack surface and its state of maintenance. It does not measure the quality of internal processes. A good rating is a strong indication of effective security management, but it is not proof.

How a KPI-Based Security Rating Is Developed

The first step is to identify the attack surface. Starting with a domain, the analysis identifies associated subdomains, IP addresses, servers, and services. This procedure is consistent with the approach of the External Attack Surface Management (EASM). Only once it is clear which systems belong to an organization can their status be assessed.

In the second step, the analysis examines measurable security indicators, including:

These individual findings are consolidated into key metrics, weighted by risk, and aggregated into a total value. This results in a score that can be compared across time periods and between companies.

Transparency is part of the methodology: It is clearly visible from the outside which software a system uses and how it is configured. Without access to the system, it is not always possible to determine with certainty whether the specific version installed is actually vulnerable. Reputable providers label such findings as recommendations for further investigation.

The dynamic nature of the threat landscape necessitates ongoing monitoring. According to the BSI Situation Report 2025, an average of 119 new vulnerabilities were identified each day during the reporting period from July 2024 to June 2025. A rating that is updated monthly or continuously reflects such changes. A one-time assessment cannot achieve this.

The timeliness of a rating depends on how quickly new vulnerability reports are incorporated. LocateRisk uses Preemptive Intelligence, in order to cross-reference reports from multiple sources against the attack surface even before a final NVD assessment is available. This allows the technical classification process to begin earlier; however, such a report remains a preliminary finding and does not automatically constitute a confirmed vulnerability.

Why Companies Use Security Ratings

Security ratings have become established in four areas of application.

Supplier Evaluation: Cyberattacks often target companies through service providers and suppliers. Organizations that manage dozens or hundreds of partners cannot audit each one individually. Ratings provide a continuously updated overview of the security levels of all partners and highlight where further action is needed. Our page on this topic explains how to implement this from an organizational perspective: Vendor Risk Management. For companies subject to NIS-2, there is also the fact that the Supply Chain Security is expressly included among the mandatory measures.

Cyber Insurance: Before issuing a cyber insurance policy, insurers assess the state of an organization’s IT security, typically through questionnaires and minimum requirements. A current rating helps you realistically assess your own situation before applying and address any visible vulnerabilities in advance. This reduces the risk of follow-up questions during the application process and disputes over coverage in the event of a claim.

Benchmarking: A score becomes more meaningful when it has a point of reference. Comparing it to competitors or the industry average shows whether your own security level is above or below the norm and provides justification for budget decisions.

Executive Board Reporting: Senior management and the executive board need a metric that is easy to understand without technical prior knowledge and can be tracked over quarters. A rating does exactly that: It highlights progress and setbacks and documents the effectiveness of security investments. This is becoming increasingly important because NIS-2 requires senior management to approve risk management measures and monitor their implementation.

Limitations of Security Ratings

A rating measures what is visible from the outside. This results in clear boundaries that reputable providers openly state.

First, the internal situation remains hidden. Whether backups are working, networks are segmented, employees can recognize phishing attempts, or an emergency plan exists cannot be assessed from an external perspective. A very good rating may coincide with weak internal processes, and the reverse is also true.

Second, version detection has its limitations. It is possible to determine from the outside which software a system is using. However, without system access, it is not always possible to definitively determine whether the specific version installed is vulnerable—for example, when vendors backport security fixes to older versions. Such findings are audit notes, not confirmed vulnerabilities.

Third, the accuracy of the results depends on correct classification. If a third-party system is incorrectly attributed to the company, this distorts the score. Good providers validate the scope of the analysis together with the client and correct any misclassifications.

Fourth, a rating is no substitute for an in-depth assessment. It indicates where risks are likely to exist, but not whether they can actually be exploited. To determine that, a penetration test is needed; to evaluate processes, an audit is required. The strength of the rating lies in its breadth, speed, and repeatability, not in the depth of individual findings.

Comparison of Security Ratings, Audits, and Penetration Tests

Ratings, audits, and penetration tests address different questions and are not mutually exclusive. An audit assesses whether security processes are defined and followed. A penetration test examines specific targets to determine whether attacks can be carried out successfully from a technical standpoint. A rating monitors the entire attack surface continuously and without any effort on the part of the organization being assessed. The following table categorizes the three methods.

CriterionSecurity RatingAudit (e.g., ISO 27001)Penetration Test
PerspectiveExterior view of the attack surfaceAn Inside Look at Processes and DocumentationSimulated attack on specified targets
Participation of the AuditeeNone requiredhigh (interviews, evidence)Intermediate (Goal Definition, Approvals)
Frequencycontinuously or monthlytypically on a multi-year basis, with an annual reviewusually annually or as needed
ResultScore and KPIs with Findings ListCertificate, Nonconformity ReportReport with Documented Vulnerabilities
Applicability to Third PartiesCan be done simultaneously for many suppliersbarelybarely
Depth of meaningWidth over DepthProcess ReadinessTechnical depth of individual objectives

In practice, this combination has proven effective: The rating provides a continuous overview and sets priorities. Audits and penetration tests come into play where a more in-depth analysis is required. Especially when evaluating a large number of third parties, the rating is often the only method that can be applied cost-effectively across the entire portfolio.

Regulatory Framework: NIS-2 and DORA

Two sets of European regulations make the monitoring of service provider risks mandatory (as of August 2026).

NIS-2: According to the BSI, the German NIS 2 Implementation Act entered into force on December 6, 2025. According to estimates from the legislative process, approximately 29,500 companies and organizations are subject to the new obligations under the BSI Act. These include risk management measures, reporting requirements, and, explicitly, supply chain security. Our Overview of the NIS 2 Directive.

DORA: Regulation (EU) 2022/2554, known as DORA for short, has been in effect for the financial sector since January 17, 2025. According to BaFin, it requires banks, insurers, and other financial institutions to implement structured management of ICT risks, including risks arising from contracts with ICT service providers. For more details, see our article on Third-Party ICT Risk Under DORA.

In both cases, the following applies: A security rating alone does not fulfill these obligations. Contracts, exit strategies, and internal processes remain necessary. However, ratings provide the continuous, objective data foundation that makes it feasible to implement the required monitoring of service providers, even for large portfolios.

Frequently asked questions


No. A vulnerability scan lists individual technical findings for a system. A security rating goes two steps further: It identifies systems that are accessible from the outside and then aggregates the findings into weighted metrics and an overall score. This enables comparability over time and across organizations.


With LocateRisk, initial analysis results are available within 48 hours. All that’s needed is the company’s main domain. No installation or involvement of the IT department is required, as the assessment is conducted exclusively from an external perspective.


No. A penetration test conducts an in-depth assessment to determine whether specific vulnerabilities can be exploited, and in the process also uncovers logical flaws in applications. A rating provides a broad overview: It continuously monitors the entire attack surface and prioritizes where an in-depth assessment is worthwhile. When used in combination, the two methods complement each other.


Ratings are based exclusively on information that is already available on the Internet. They do not bypass access controls or alter any systems. Nevertheless, many companies actively inform their suppliers about the ratings, as transparency makes it easier to jointly address any issues and strengthens the business relationship.


Since the analysis evaluates publicly available technical information, it generates virtually no personal data. LocateRisk processes all analysis data in compliance with the GDPR and hosts the platform in certified German data centers. For companies with strict compliance requirements, this is a key selection criterion.

Conclusion: The Fastest Way to Your Own Key Metric

A security rating quickly shows how your company appears from an attacker’s perspective and provides a metric you can use to manage IT security and demonstrate it to management, insurers, and customers. The easiest way to get started is to take a look at your own organization: LocateRisk will generate a Free Security Rating Your externally visible attack surface, without any installation, and within 48 hours. This lets you see what attackers see before they do.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish