Methodology · Enterprise

A rating you can argue with
is a rating worth having.

A score nobody can interrogate is just a number with a colour. This is the whole model: how findings become module scores, how modules become a company rating, and exactly what moves it.

A8.5–10
B7.0–8.4
C5.5–6.9
D4.0–5.4
F0–3.9
Principles

Three rules the model follows

Everything below follows from these. Where a design decision was a trade-off, it went in favour of being defensible.

Deterministic

Same inputs, same score

The rubric is weighted and versioned. Two companies with identical observable posture receive identical scores, and a rescan that finds nothing new does not move the number.

Evidence-based

Every point traceable

A score is an aggregate of findings, and every finding carries the observation that produced it. You can always walk from the grade back to the raw evidence.

Outside-in

Only what is observable

Scores are built from what can be seen from the public internet. Nothing is inferred from a questionnaire, and nothing depends on the company under assessment cooperating.

The scale

From finding to grade

Six module scores, one weighted rating, one letter band.

0–100 per moduleEach of the six modules is scored independently, so a strong perimeter cannot hide a weak brand posture.
Weighted aggregateModule scores combine into one company rating using published weights rather than an average.
Letter gradeThe rating maps to a letter band for reporting, so a board sees a grade and an engineer sees the number.
Severity-drivenA single critical finding moves a score further than a long tail of low-severity ones, count alone does not drive the result.
Movement

What actually moves a score

Scores should move when posture changes and stay still when it does not.

Score dropsA new critical or high finding, a newly published CVE affecting a detected technology, a newly registered lookalike domain, or fresh credential exposure.
Score risesA finding is remediated and the next scan confirms it cleared, most domain findings clear automatically once the record changes.
Score holdsA rescan that finds nothing new. Scores do not drift with time or decay for inactivity.
Score is correctedA finding is triaged as a false positive or accepted risk, with the rationale recorded in the audit trail.

What the score is built from

  • Findings observed from the public internet, across six modules
  • Severity, with exploitability weighted via CVSS, EPSS and KEV
  • Evidence recorded for every finding
  • Analyst verification on brand-protection indicators
  • Triage decisions you have recorded

What it is deliberately not built from

  • Self-reported questionnaire answers
  • Raw vulnerability counts
  • Company size, sector or revenue
  • Anything requiring access to your environment
  • Time decay, a score does not drift on its own
Company rating with the six module scores that produced it

The rating, with the six module scores underneath that produced it

Questions

Common questions

Is the score comparable between companies?

Yes, that is the point of a deterministic rubric. The same observation is scored the same way for every company, which is what makes a vendor portfolio meaningful rather than a collection of unrelated opinions.

Can a company improve its score without improving security?

Not meaningfully. Scores move on findings, and findings are observations rather than assertions: there is no questionnaire to answer favourably. The fastest legitimate improvements tend to be domain and header findings, which are genuine fixes that happen to be quick.

What if you flag something that is not a real risk for us?

Triage it. Findings governance covers false-positive marking and accepted-risk decisions with a recorded rationale, and the score reflects those decisions rather than the finding silently reappearing on the next scan.

Do you publish raw vulnerability counts?

No, deliberately. A raw count rewards noise and punishes a large estate. Findings are prioritised and evidence-backed, and the score is driven by severity and exploitability rather than volume.

How often is a score recalculated?

Continuously, with on-demand rescans when you want to confirm a fix. The rating reflects the estate as observed, not as reviewed last quarter.

Run the model against your own company

The quickest way to test a scoring model is on a company whose posture you already know.

Free for your own organisation. Assessed by domain, no access required.