{"id":9292,"date":"2026-08-06T10:03:34","date_gmt":"2026-08-06T10:03:34","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9292"},"modified":"2026-08-06T11:22:08","modified_gmt":"2026-08-06T11:22:08","slug":"what-is-a-security-rating","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/","title":{"rendered":"What is a security rating?"},"content":{"rendered":"<h1 class=\"wp-block-heading\">What is a security rating?<\/h1><span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n<p>A security rating translates a company\u2019s IT security posture into a single, comparable metric. The rating is derived from an external perspective: it analyzes what attackers can see and access via the Internet. This article explains how KPI-based ratings are created, how companies use them, what their limitations are, and how they differ from audits and penetration tests.<\/p><p>Security ratings are also known as <strong>Cybersecurity Ratings<\/strong> or <strong>Cyber Risk Ratings<\/strong> is called. In German, there are also <strong>IT Security Assessment<\/strong> and <strong>Cyber Risk Assessment<\/strong> common. A \"security score\" often refers only to the numerical or alphabetic value derived from it. The scope, data source, and scoring model may vary depending on the provider.<\/p>\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>A security rating measures a company's externally visible IT security and summarizes it in a comparable metric.<\/li><li>The assessment is conducted without agents and without access to internal systems, based solely on publicly available information.<\/li><li>Typical areas of application include supplier evaluation, cyber insurance, benchmarking, and reporting to management and the board of directors.<\/li><li>A rating is not a substitute for either an audit or a penetration test. It complements both by providing a continuous, scalable external perspective.<\/li><li>Regulatory frameworks such as NIS-2 and DORA require the monitoring of service provider risks. Ratings provide a reliable data foundation for this purpose.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">Definition: What a Security Rating Indicates<\/h2>\n<p>A security rating is a data-driven assessment of an organization\u2019s IT security, summarized as a numerical value or a grade. Similar to a credit report in the financial sector, it answers a simple question: From an outsider\u2019s perspective, how well is a company positioned to defend against cyberattacks?.<\/p>\n<p>The assessment is based exclusively on information accessible via the Internet. This includes domains, IP addresses, accessible services, certificates, and email configurations. A rating therefore requires neither software agents on the systems nor access to internal networks. The auditing company and the company being evaluated do not even need to be in contact with each other.<\/p>\n<p>It is precisely this feature that makes ratings scalable. While an audit requires weeks of preparation, an external assessment can be conducted for hundreds of suppliers simultaneously. LocateRisk delivers such an analysis within 48 hours, without any installation and without interfering with ongoing systems.<\/p>\n<p>Important to note: A rating measures the visible attack surface and its state of maintenance. It does not measure the quality of internal processes. A good rating is a strong indication of effective security management, but it is not proof.<\/p>\n<h2 class=\"wp-block-heading\">How a KPI-Based Security Rating Is Developed<\/h2>\n<p>The first step is to identify the attack surface. Starting with a domain, the analysis identifies associated subdomains, IP addresses, servers, and services. This procedure is consistent with the approach of the <a href=\"\/en\/know\/what-is-easm\/\">External Attack Surface Management (EASM)<\/a>. Only once it is clear which systems belong to an organization can their status be assessed.<\/p>\n<p>In the second step, the analysis examines measurable security indicators, including:<\/p>\n<ul class=\"wp-block-list\"><li>Encryption: Protocol versions, certificate validity periods, weak cipher suites<\/li><li>Accessible Services: Open Ports, Exposed Administrative Access Points, Databases on the Network<\/li><li>Email Security: Configuring SPF, DKIM, and DMARC<\/li><li>Software Version: Systems Identifiable from the Outside and Their Version Information<\/li><li>Security: DNS Configuration, Obsolete or Forgotten Subdomains<\/li><\/ul>\n<p>These individual findings are consolidated into key metrics, weighted by risk, and aggregated into a total value. This results in a score that can be compared across time periods and between companies.<\/p>\n<p>Transparency is part of the methodology: It is clearly visible from the outside which software a system uses and how it is configured. Without access to the system, it is not always possible to determine with certainty whether the specific version installed is actually vulnerable. Reputable providers label such findings as recommendations for further investigation.<\/p>\n<p>The dynamic nature of the threat landscape necessitates ongoing monitoring. According to the BSI Situation Report 2025, an average of 119 new vulnerabilities were identified each day during the reporting period from July 2024 to June 2025. A rating that is updated monthly or continuously reflects such changes. A one-time assessment cannot achieve this.<\/p><p>The timeliness of a rating depends on how quickly new vulnerability reports are incorporated. LocateRisk uses <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a>, in order to cross-reference reports from multiple sources against the attack surface even before a final NVD assessment is available. This allows the technical classification process to begin earlier; however, such a report remains a preliminary finding and does not automatically constitute a confirmed vulnerability.<\/p>\n<h2 class=\"wp-block-heading\">Why Companies Use Security Ratings<\/h2>\n<p>Security ratings have become established in four areas of application.<\/p>\n<p><strong>Supplier Evaluation:<\/strong> Cyberattacks often target companies through service providers and suppliers. Organizations that manage dozens or hundreds of partners cannot audit each one individually. Ratings provide a continuously updated overview of the security levels of all partners and highlight where further action is needed. Our page on this topic explains how to implement this from an organizational perspective: <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a>. For companies subject to NIS-2, there is also the fact that the <a href=\"\/en\/know\/nis2-supply-chain-security\/\">Supply Chain Security<\/a> is expressly included among the mandatory measures.<\/p>\n<p><strong>Cyber Insurance:<\/strong> Before issuing a cyber insurance policy, insurers assess the state of an organization\u2019s IT security, typically through questionnaires and minimum requirements. A current rating helps you realistically assess your own situation before applying and address any visible vulnerabilities in advance. This reduces the risk of follow-up questions during the application process and disputes over coverage in the event of a claim.<\/p>\n<p><strong>Benchmarking:<\/strong> A score becomes more meaningful when it has a point of reference. Comparing it to competitors or the industry average shows whether your own security level is above or below the norm and provides justification for budget decisions.<\/p>\n<p><strong>Executive Board Reporting:<\/strong> Senior management and the executive board need a metric that is easy to understand without technical prior knowledge and can be tracked over quarters. A rating does exactly that: It highlights progress and setbacks and documents the effectiveness of security investments. This is becoming increasingly important because NIS-2 requires senior management to approve risk management measures and monitor their implementation.<\/p>\n<h2 class=\"wp-block-heading\">Limitations of Security Ratings<\/h2>\n<p>A rating measures what is visible from the outside. This results in clear boundaries that reputable providers openly state.<\/p>\n<p>First, the internal situation remains hidden. Whether backups are working, networks are segmented, employees can recognize phishing attempts, or an emergency plan exists cannot be assessed from an external perspective. A very good rating may coincide with weak internal processes, and the reverse is also true.<\/p>\n<p>Second, version detection has its limitations. It is possible to determine from the outside which software a system is using. However, without system access, it is not always possible to definitively determine whether the specific version installed is vulnerable\u2014for example, when vendors backport security fixes to older versions. Such findings are audit notes, not confirmed vulnerabilities.<\/p>\n<p>Third, the accuracy of the results depends on correct classification. If a third-party system is incorrectly attributed to the company, this distorts the score. Good providers validate the scope of the analysis together with the client and correct any misclassifications.<\/p>\n<p>Fourth, a rating is no substitute for an in-depth assessment. It indicates where risks are likely to exist, but not whether they can actually be exploited. To determine that, a penetration test is needed; to evaluate processes, an audit is required. The strength of the rating lies in its breadth, speed, and repeatability, not in the depth of individual findings.<\/p>\n<h2 class=\"wp-block-heading\">Comparison of Security Ratings, Audits, and Penetration Tests<\/h2>\n<p>Ratings, audits, and penetration tests address different questions and are not mutually exclusive. An audit assesses whether security processes are defined and followed. A penetration test examines specific targets to determine whether attacks can be carried out successfully from a technical standpoint. A rating monitors the entire attack surface continuously and without any effort on the part of the organization being assessed. The following table categorizes the three methods.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Criterion<\/th><th>Security Rating<\/th><th>Audit (e.g., ISO 27001)<\/th><th>Penetration Test<\/th><\/tr><\/thead><tbody><tr><td>Perspective<\/td><td>Exterior view of the attack surface<\/td><td>An Inside Look at Processes and Documentation<\/td><td>Simulated attack on specified targets<\/td><\/tr><tr><td>Participation of the Auditee<\/td><td>None required<\/td><td>high (interviews, evidence)<\/td><td>Intermediate (Goal Definition, Approvals)<\/td><\/tr><tr><td>Frequency<\/td><td>continuously or monthly<\/td><td>typically on a multi-year basis, with an annual review<\/td><td>usually annually or as needed<\/td><\/tr><tr><td>Result<\/td><td>Score and KPIs with Findings List<\/td><td>Certificate, Nonconformity Report<\/td><td>Report with Documented Vulnerabilities<\/td><\/tr><tr><td>Applicability to Third Parties<\/td><td>Can be done simultaneously for many suppliers<\/td><td>barely<\/td><td>barely<\/td><\/tr><tr><td>Depth of meaning<\/td><td>Width over Depth<\/td><td>Process Readiness<\/td><td>Technical depth of individual objectives<\/td><\/tr><\/tbody><\/table><\/figure>\n<p>In practice, this combination has proven effective: The rating provides a continuous overview and sets priorities. Audits and penetration tests come into play where a more in-depth analysis is required. Especially when evaluating a large number of third parties, the rating is often the only method that can be applied cost-effectively across the entire portfolio.<\/p>\n<h2 class=\"wp-block-heading\">Regulatory Framework: NIS-2 and DORA<\/h2>\n<p>Two sets of European regulations make the monitoring of service provider risks mandatory (as of August 2026).<\/p>\n<p><strong>NIS-2:<\/strong> According to the BSI, the German NIS 2 Implementation Act entered into force on December 6, 2025. According to estimates from the legislative process, approximately 29,500 companies and organizations are subject to the new obligations under the BSI Act. These include risk management measures, reporting requirements, and, explicitly, supply chain security. Our <a href=\"\/en\/know\/nis2-directive-overview\/\">Overview of the NIS 2 Directive<\/a>.<\/p>\n<p><strong>DORA:<\/strong> Regulation (EU) 2022\/2554, known as DORA for short, has been in effect for the financial sector since January 17, 2025. According to BaFin, it requires banks, insurers, and other financial institutions to implement structured management of ICT risks, including risks arising from contracts with ICT service providers. For more details, see our article on <a href=\"\/en\/know\/dora-ict-third-party-risk\/\">Third-Party ICT Risk Under DORA<\/a>.<\/p>\n<p>In both cases, the following applies: A security rating alone does not fulfill these obligations. Contracts, exit strategies, and internal processes remain necessary. However, ratings provide the continuous, objective data foundation that makes it feasible to implement the required monitoring of service providers, even for large portfolios.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is a security rating the same as a vulnerability scan?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. A vulnerability scan lists individual technical findings for a system. A security rating goes two steps further: It identifies systems that are accessible from the outside and then aggregates the findings into weighted metrics and an overall score. This enables comparability over time and across organizations.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How quickly is a security rating available?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">With LocateRisk, initial analysis results are available within 48 hours. All that\u2019s needed is the company\u2019s main domain. No installation or involvement of the IT department is required, as the assessment is conducted exclusively from an external perspective.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Can a security rating replace a penetration test?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. A penetration test conducts an in-depth assessment to determine whether specific vulnerabilities can be exploited, and in the process also uncovers logical flaws in applications. A rating provides a broad overview: It continuously monitors the entire attack surface and prioritizes where an in-depth assessment is worthwhile. When used in combination, the two methods complement each other.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Are companies allowed to evaluate their suppliers without their consent?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Ratings are based exclusively on information that is already available on the Internet. They do not bypass access controls or alter any systems. Nevertheless, many companies actively inform their suppliers about the ratings, as transparency makes it easier to jointly address any issues and strengthens the business relationship.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What role does data protection play in security ratings?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Since the analysis evaluates publicly available technical information, it generates virtually no personal data. LocateRisk processes all analysis data in compliance with the GDPR and hosts the platform in certified German data centers. For companies with strict compliance requirements, this is a key selection criterion.<\/p><\/div><\/div><\/div><\/div>\n\n<h2 class=\"wp-block-heading\">Conclusion: The Fastest Way to Your Own Key Metric<\/h2>\n<p>A security rating quickly shows how your company appears from an attacker\u2019s perspective and provides a metric you can use to manage IT security and demonstrate it to management, insurers, and customers. The easiest way to get started is to take a look at your own organization: LocateRisk will generate a <a href=\"\/en\/landing\/free-rating\/\">Free Security Rating<\/a> Your externally visible attack surface, without any installation, and within 48 hours. This lets you see what attackers see before they do.<\/p>","protected":false},"excerpt":{"rendered":"<p>Security ratings measure IT security from an external perspective and make it comparable. How KPI-based ratings are developed, what they\u2019re used for, and what their limitations are.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[818],"class_list":["post-9292","wissen","type-wissen","status-publish","hentry","wissen_thema-easm-angriffsflaeche"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Rating: Definition, Nutzen, Grenzen \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Security Rating erkl\u00e4rt: Definition, KPI-basierte Messung von au\u00dfen, Einsatz f\u00fcr Lieferanten, Versicherung und Reporting sowie Grenzen und Vergleich.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Rating: Definition, Nutzen, Grenzen \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Security Rating erkl\u00e4rt: Definition, KPI-basierte Messung von au\u00dfen, Einsatz f\u00fcr Lieferanten, Versicherung und Reporting sowie Grenzen und Vergleich.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T11:22:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-ein-security-rating\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-ein-security-rating\\\/\",\"name\":\"Security Rating: Definition, Nutzen, Grenzen \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:34+00:00\",\"dateModified\":\"2026-08-06T11:22:08+00:00\",\"description\":\"Security Rating erkl\u00e4rt: Definition, KPI-basierte Messung von au\u00dfen, Einsatz f\u00fcr Lieferanten, Versicherung und Reporting sowie Grenzen und Vergleich.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-ein-security-rating\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-ein-security-rating\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/was-ist-ein-security-rating\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Was ist ein Security Rating?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Rating: Definition, Benefits, Limitations \u2013 LocateRisk","description":"Security Rating Explained: Definition, KPI-Based External Assessment, Applications for Suppliers, Insurance, and Reporting, as well as Limitations and Comparisons.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/","og_locale":"en_US","og_type":"article","og_title":"Security Rating: Definition, Nutzen, Grenzen \u2013 LocateRisk","og_description":"Security Rating erkl\u00e4rt: Definition, KPI-basierte Messung von au\u00dfen, Einsatz f\u00fcr Lieferanten, Versicherung und Reporting sowie Grenzen und Vergleich.","og_url":"http:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T11:22:08+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-ein-security-rating\/","url":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-ein-security-rating\/","name":"Security Rating: Definition, Benefits, Limitations \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:34+00:00","dateModified":"2026-08-06T11:22:08+00:00","description":"Security Rating Explained: Definition, KPI-Based External Assessment, Applications for Suppliers, Insurance, and Reporting, as well as Limitations and Comparisons.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-ein-security-rating\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/was-ist-ein-security-rating\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/was-ist-ein-security-rating\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Was ist ein Security Rating?"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":6,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9292\/revisions"}],"predecessor-version":[{"id":9336,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9292\/revisions\/9336"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9292"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}