Our cyber-rating methodology
At Scovery, we calculate the cyber scores of more than 3 million companies worldwide every month. To do so, we collect checkpoint data concerning assets available on the Internet (IP addresses, domain names, etc.) and then link these assets to companies. The data is aggregated, weighted and normalized to produce a score between 100 and 900 and a grade from F to A (see below).
Here are the first insights drawn from our score database.
Sector analysis
One of our first analyses compared different business sectors. We simply calculated the average score of the companies in each sector. A company may belong to several sectors, such as Payment Services and Software. In that case, it is included in the average for each sector to which it belongs.
Our first observation is that sector averages are relatively close, ranging from 766 to 787. This is unsurprising because many factors other than business sector influence a company’s cybersecurity level. In the extreme case where sector had no influence, the law of large numbers suggests that sector scores would fluctuate around the global average of 772.
Nevertheless, we observe meaningful differences between sector averages, and these differences are consistent with what one might intuitively expect. Financial-sector companies are among the highest rated, whereas industrial and advertising companies are among the least secure.
Geographic analysis
We conducted a similar analysis across European Union countries. Here, each company is associated with a single country.
Country averages are more widely dispersed than business-sector averages: the range is 57 points, compared with 21 points across sectors. This is consistent with the intuitive expectation that companies in different countries have noticeably different cybersecurity levels.
Northern European countries occupy the upper end of the spectrum, while Southern European countries have a less advanced cybersecurity posture on average.
Interpreting the results
We found substantial differences between the business sectors and countries studied. These differences warrant further investigation to identify the many underlying causes.
Scovery’s cyber-rating methodology
Our rating algorithm consists of several main stages:
1. For each company, we count the number of its assets (IP addresses, domain names, etc.) that test positive at each of our checkpoints.
2. These asset counts are then normalized for two purposes:
a. To account for the effect of company size, defined as its number of assets;
b. To make scores from different checkpoints comparable.
3. The results from each checkpoint are aggregated into a single score for each company. Each checkpoint is assigned a weight representing its severity in terms of cyber risk.
4. The scores are normalized again to account globally for the influence of company size.
5. The results are then adjusted to fit within a range of 100 to 900. This transformation introduces a comparison between companies, making their scores interdependent. It reflects the idea that the more vulnerable a company is relative to its peers, the more likely it is to suffer a cybersecurity incident.
6. Finally, the resulting company scores are converted into grades from F to A.
Visit Scovery to discover your company’s score!