>> All posts

Ratings estimate risk. Attackers exploit paths.

Security ratings earned their place: a quick outside-in snapshot, a letter or score you can compare across a book. Brokers recognize the logos. Boards like the simplicity. The category — think BitSight / Security Scorecard–style grading — answers a real hunger for "something external."

The problem is what that something often is: an estimate assembled from perimeter datapoints. Useful as a conversation starter. Dangerous if you mistake it for proof of how an attacker gets in — or for what will drive the next claim.

Datapoints aren't intrusion paths

Ratings engines are good at noticing things that are visible and countable. Certificate issues. Similar hygiene signals. Configuration tells that are easy to automate. Some of those deserve a ticket. Many of them are not material to a breach.

An expired SSL certificate is the clearest example. It's detectable. It's scorable. It rarely explains ransomware in the living room. If your underwriting attention is spent on that class of finding, you're ranking noise while a reachable VPN with weak authentication sits quietly on the same perimeter.

Attackers don't optimize for your scorecard. They optimize for a path that works.

Estimate vs verify

ApproachQuestion it answersFailure mode
Ratings-style estimate"How does this perimeter look on soft signals?"High volume of immaterial findings; false confidence or false alarm
Verified assessment"Where could someone break in — and is that path real?"Narrower by design; requires actual testing discipline

BreachRisk is built for the second column: discover what an attacker would see, verify what's exploitable, and score breach risk from that — not from a collage of non-material perimeter trivia. That's also how you engineer for an industry-low false-positive posture without claiming miracles: you stop treating every detectable datapoint as underwriting-grade risk.

Why insurers should care

If you use ratings as a screen, fine — know what you're screening for. If you use them as a substitute for knowing whether the applicant is breakable from the outside, you're back to a proxy — just a shinier one than the questionnaire.

Kill the Questionnaire only works when the replacement is stricter than the form, not merely faster. Speed without signal is how you bind hope. Speed with verified paths is how you underwrite.

How to read a finding like an underwriter

Ask three questions of any outside-in output:

  1. Is this a break-in path — authentication, remote access, exploitable edge software — or housekeeping?
  2. Has it been verified, or only inferred from a datapoint?
  3. Would I explain this finding in a claims review without embarrassment?

If the answer to (3) is "we declined them over an expired cert," you already know the category problem.

Ratings estimate. Attackers exploit. Underwrite the second.

The bottom line

Letter grades aren't the enemy. Mistaking estimation for proof is. Keep ratings in their lane if you use them. Put verified intrusion paths at the center of bind decisions — and you'll find you need far less questionnaire theater to feel honest about the risk.

That's the contrast we built BreachRisk around, and the reason Cyber Questionnaire Validator can take weight off the form. Book a demo or see the insurer overview at Cyber insurers.

See your cyber risk, proven.