EUSEC
Dashboard
Pricing Services
Rating Criteria

The methodology behind every EUSEC rating.

How we rate cyber risk.

A rating is an informed opinion built on evidence — not a guarantee, and not a penetration test. EUSEC forms that opinion from two complementary perspectives: what can be observed from the outside, and what an entity discloses from the inside. Both are expressed on a single, comparable scale, alongside a forward-looking outlook.

How a rating is formed
Outside Rating
Non-intrusive, observed. No participation required.
Inside Rating
Self-disclosed, scored on the BSI maturity model.
Outlook
Forward-looking — where the rating is heading.
AA
Combined rating
One opinion, on a scale from AAA to C, with outlook.
Exhibit 01 — The framework

Two lenses, one rating.

Confidence is not the same as security. Each lens answers a different question, and the most valuable insight lives in the space between them — where what is claimed meets what can be observed.

Lens 01 — Observed

The Outside Rating

What an entity already exposes to the public internet. Assessed entirely from the outside, with no onboarding and no cooperation from the entity. It answers: what can an attacker see today?

Lens 02 — Declared

The Inside Rating

What an entity states about its own controls, captured through a structured self-disclosure scoped to its NIS2 status and scored on the BSI maturity model. It answers: how mature does the entity say it is?

Forward-looking

The Outlook

A directional view layered onto every rating: whether posture is improving, holding or eroding over time — and, for the Inside view, whether the self-assessment is borne out by what is observed.

Exhibit 02 — The Outside Rating

What the world can already see.

The Outside Rating is assembled from observable evidence across 10 risk dimensions. Every signal is collected without intrusion and without the entity's involvement, which is why a full portfolio can be graded from day one.

Method principle — passive & lawful by design

We read only what is public or voluntarily disclosed. No exploitation, no break-in — only what a server, a record or a document already reveals on its own.

Legal Opinion — lawful in Germany & the EU
§ 202a / 202b / 303a StGB

No criminal-law violation: no data is specially protected or intercepted, no access safeguard is circumvented, and no data is altered.

GeschGehG · Dir. (EU) 2016/943

No trade-secret breach: the observed system data is general technical information the server provides voluntarily — not a protected secret.

DE & EU compliant

The method is lawful throughout Germany and meets EU compliance requirements — unlike many international providers.

EUSEC's legal opinion on the lawfulness of its methodology.

Dimension B1

Business profile & assurance

The structural context that calibrates every other signal — scale, complexity, footprint and independent certifications. Research across thousands of incidents shows that firmographic signals alone outperform chance at predicting breach likelihood, before any technical check is run.

Business model (complex vs. singular) Headcount ISO/IEC 27001 SOC 2 reporting Imprint completeness Locations & international footprint Corporate structure
Dimension B2

Data protection posture

How the entity handles personal data, judged from its public privacy disclosures and observable tracking behaviour — following EUSEC's published privacy-policy assessment method. Data sensitivity directly scales potential damage magnitude in the event of a breach.

Data protection officer Visible data-handling staff Policy change history Encryption commitments Potentially unfair terms Automated decision-making Data subject rights Tracking technologies Provider location Policy language Data sales Third-country sub-processors Controller identification Comprehensibility Readability Currency Accessibility Versioning Technical & organisational measures Processing scope & purposes App installation App information Cookies on service site
Dimension B3

Sector & entity calibration

Applied after the evidence dimensions, a rating may carry sector- and entity-specific adjustments. Different sectors face different threat models and regulatory baselines, and an entity's criticality, structural complexity or verified compensating controls can warrant an up- or downward step. These adjustments follow documented, consistently applied criteria — they refine the evidence, they never override it.

Sector threat model Regulatory baseline Criticality Structural complexity Verified compensating controls Documented & consistent
Dimension B4

Press & media coverage

Public reporting of security incidents, enforcement actions or other adverse events attributed to the entity. Coverage is weighted by source credibility, severity and recency — the score adjusts over time to reflect whether reported conditions appear resolved or ongoing.

Incident media mentions Regulatory & enforcement coverage Coverage recency weight Source credibility tier Post-event recovery reporting NGO & watchdog reporting
Dimension B5

Financial strength & resilience

An entity's financial standing shapes both how much it can invest in security and how well it can absorb the cost of an incident. Publicly available indicators — revenue, profitability and overall financial health — serve as a proxy for the resources available to fund and sustain security over time.

Financial health Turnover Profit Capacity to invest
Dimension B6

Corporate stability & structural change

Mergers, acquisitions, carve-outs and restructuring routinely disrupt system ownership, introduce integration gaps and stretch security teams. This dimension gauges how established and how stable the organisation is, and whether recent structural events may have opened transitional weaknesses.

Company age Recent M&A Restructuring Carve-outs Instability tendency
Dimension B7

Business model, regulation & risk exposure

Not every entity carries the same stakes. How central data is to the business, whether security is itself a core offering, and the regulatory regime an entity operates under all shape the likelihood and the magnitude of potential harm — as does any record of prior enforcement. This dimension calibrates that exposure.

Data-driven business model Security as Tier-1 offering Regulated business Past data-protection & security fines Loss magnitude
Dimension B8

Business operational resilience & response

Preventing incidents is only half the picture; resilient organisations also detect, respond to and recover from them quickly. This dimension looks for observable indicators of response readiness — the capacity to act on disclosed issues, business-continuity and disaster-recovery provisions, and engagement with the wider security community.

Reaction capability Disaster preparedness Community engagement
Dimension T1

Domain & email authentication

Whether the entity can be impersonated by email, and how rigorously its naming infrastructure is governed.

SPF DKIM DMARC Mail server / service DNS security DNSSEC WHOIS ownership Domain transfer lock Subdomain naming Subdomain enumeration Certificate Transparency (crt.sh) CAA records DNS zone transfer (AXFR) Domains in use
Dimension T2

Transport encryption

The quality and currency of the cryptography protecting data in transit, evaluated endpoint by endpoint.

HTTPS configuration HTTP fallback reachable Certificate validity TLS versions (1.0 / 1.1) Cipher suites (RC4 / 3DES) HSTS OCSP stapling Certificate chain Certificate expiry Wildcard certificates Certificate Transparency Forward secrecy
Dimension T3

Web application surface

What the public web presence reveals — from protective response headers to unintentionally exposed paths, documents and metadata.

Software versions Source code Harvestable email addresses Email address patterns Exposed sensitive documents Document metadata (FOCA / EXIF) Exposed phone numbers security.txt WordPress / wp-admin Admin paths Bug bounty programme Vulnerability disclosure policy sitemap.xml Content-Security-Policy X-Frame-Options X-Content-Type-Options Referrer-Policy Permissions-Policy HttpOnly cookies Homograph / IDN exposure WAF / CDN detection Public webmail
Dimension T4

Data exposure & breach history

Whether the entity's credentials, code or storage have leaked — and its track record as a target. Prior breach history is among the strongest individual predictors of future incidents and elevates both likelihood and expected damage in the risk model.

Total breach count (domain) Exposed data classes Prior breach history Public GitHub repositories Open S3 / Azure buckets Ransomware victim history Google dorking
Dimension T5

Social engineering surface

How much of the organisation's human attack surface is publicly enumerable and targetable. Human error is the root cause in the majority of documented breaches, making this surface a direct contributor to both likelihood and damage.

Publicly visible employees Title & department exposure Contactable individuals
Dimension T6

Reputation & infrastructure

Whether the entity's addresses, routing and brand are clean — or implicated in abuse and impersonation.

IP / domain blacklisting BGP routing (Hurricane Electric) Typosquatting & look-alikes Fake shops / brand abuse DNS history Hosting provider & ASN IP net blocks
Dimension T7

Vulnerability signals

What services disclose voluntarily — versions and banners correlated against known weaknesses, without ever probing for them.

Version-to-CVE correlation Banner grabbing / service identification Voluntarily disclosed service data HTTP response headers

Signal families shown are representative, not exhaustive. Weighting of each dimension is calibrated against the entity's business profile, threat landscape and benchmarking.

Exhibit 03 — The Inside Rating

Measured against what is declared.

The Inside Rating is built from a structured self-disclosure. The questions an entity is asked depend on its standing under the NIS2 Directive (EU) 2022/2555, and every answer is scored on the maturity model of the German BSI assessment framework (RUN). Higher obligations mean more criteria — never fewer.

Scoping — which criteria apply
Outside NIS2 scope 7

Baseline cyber-hygiene criteria. Applied to entities not in scope, and where status is not yet established.

Important entity 11

Adds supply-chain, cryptography and the statutory registration and reporting duties.

Essential entity 15

The full criteria set, including effectiveness review, management oversight, board training and audit readiness.

The 15 criteria & their scope
Applies Out of scope
# NIS2 article Criterion Non-NIS2 Important Very imp.
a Art. 21(2)(a) Risk management & risk analysis
b Art. 21(2)(b) Incident handling
c Art. 21(2)(c) Business continuity, backup & crisis management
d Art. 21(2)(d) Supply chain security
e Art. 21(2)(e) Secure acquisition, development & vulnerability management
f Art. 21(2)(f) Assessing the effectiveness of measures
g Art. 21(2)(g) Cyber hygiene & training / awareness
h Art. 21(2)(h) Use of cryptography & encryption
i Art. 21(2)(i) HR security, access control & asset management
j Art. 21(2)(j) Multi-factor authentication & secured communications
k Art. 3(4) / 27 Registration with the competent authority
l Art. 23 Reporting of significant incidents (24h / 72h / 1 month)
m Art. 20(1) Management approval & oversight
n Art. 20(2) Training of the management body
o Art. 31–34 Evidence & audit readiness
Criteria in scope 7 11 15

National transpositions vary — e.g. in Germany under the BSIG (sec. 30, 32, 33, 38, 39). Article references follow Directive (EU) 2022/2555.

The scoring scale — BSI maturity model (RUN)

Each applicable criterion is rated on a six-step maturity scale. A criterion may also be marked N/A where it is genuinely out of scope for the entity. The same scale is applied whether the underlying theme is a management system, an implementation control, or a statutory obligation.

5
Continuously improved
Established and continuously improved.
4
Measurable
Effectiveness is measured against defined indicators.
3
Established
Documented and implemented.
2
Managed (partial)
Initial procedure or individual elements exist.
1
Planned
Planned and budgeted, not yet started.
0
Not present
The control is not addressed.

N/A — not applicable: the criterion is genuinely out of scope for the entity and is excluded from the score rather than penalised.

Exhibit 04 — The rating scale

One scale, from AAA to C.

Outside and Inside evidence resolve into a single grade, so that any two entities can be compared on the same terms. Plus and minus modifiers signal the direction of travel within a band.

AAA
Prime

No or only negligible findings were found.

AA
Strong

Minor findings only. AA+ / AA− denote trend.

A
Solid

Some weaknesses. A+ / A− denote trend.

B
At risk

Material vulnerabilities identified.

C
Critical

Substandard controls. Immediate attention.

AAA = strongest · C = critical exposure · ± shows trend within a band.
Exhibit 05 — The outlook

Where the rating is heading.

A grade captures the present; the outlook captures the trajectory. Both lenses carry one, and each is derived differently.

Outside outlook

Is the entity working on it?

Each entity is observed repeatedly over time. The outlook reflects the direction of travel across successive snapshots: are exposed surfaces being remediated, certificates renewed, leaks closed — or is the posture quietly drifting? A history of steady improvement reads very differently from one of neglect, even at the same grade today.

Basis — historical trajectory of the observed signals.
Inside outlook

Does the self-assessment hold up?

The self-reported maturity is placed alongside the observed Outside Rating. Where the two align, the self-assessment earns confidence. Where an entity rates itself markedly higher than the evidence supports, that gap is flagged as a discrepancy and weighs on the outlook — because the comfort of a questionnaire is not the same as a secure posture.

Basis — self-assessment correlated against the observed reality.
Positive — improving Stable — holding Negative — eroding or unverified
Research basis

State of the art

The weighting of dimensions in this rating reflects the current empirical consensus across cybersecurity risk research. The findings below summarise key studies and establish why governance and organisational signals anchor the model, while technical indicators serve as calibrating inputs.

Liu & Babar · Australian Journal of Management · 2024

Four-category risk taxonomy across 12 disciplines

A systematic review of 203 empirical studies — spanning accounting, computer science, finance, information systems, law, management and six further disciplines — classifies all identified cybersecurity risk factors into four categories: management factors, firm characteristics, IT practices, and institutional factors. Firm characteristics (size, sector, data holdings) and management factors each constitute an independent risk layer that cannot be reduced to or substituted by technical metrics. The authors also find that higher IT investment significantly reduces breach risk — but only when substantively integrated; symbolic adoption without operational embedding can worsen exposure.

203 empirical studies 12 disciplines Firm characteristics as independent risk layer DOI 10.1177/03128962241293658
Verizon DBIR · 17th Annual Edition · May 2024

68 % of breaches trace to a non-malicious human element

Analysis of 10,626 confirmed breaches across 94 countries in 2023 — the largest dataset in the report's 17-year history — found that 68 % of breaches involved a non-malicious human element: an employee error, a credential handed over in a phishing attack, or a social engineering lure. This figure excludes malicious insiders, making it a conservative lower bound. The median time for a user to click a malicious link was 21 seconds; another 28 seconds to enter credentials. Stolen credentials were the initial access vector in 53 % of all web-application attacks and required a median of 292 days to identify and contain.

10,626 confirmed breaches 94 countries · 2023 data 68 % non-malicious human element 292-day credential detection window
Hu, Levi, Yahalom & Zerhouni · MIT · IEEE TDSC · 2025

Organisational attributes predict breach risk before any technical check

In the first large-scale machine-learning study of breach predictors, a model using only firm-level organisational attributes — size, sector, employee count, supply chain connectivity — already outperformed a random baseline (AUC > 50 %). This confirms that cyberattacks are not uniformly distributed: large organisations and data-intensive sectors such as healthcare face structurally higher targeting rates independent of any technical vulnerability. Adding outside-in cybersecurity ratings on top of organisational features raised the AUC meaningfully. Adding digital supply chain network features on top of both improved the out-of-sample AUC by a further 2.3 percentage points — significant given that any individual breach is a low-probability, high-impact event.

Large-scale ML study Org. features alone beat random baseline +2.3 pp AUC from supply chain features arXiv 2210.15785 · IEEE TDSC 2025
IBM / Ponemon Institute · Cost of a Data Breach Report · July 2024

Breach cost scales with firm size, sector and data sensitivity

The 19th annual IBM Cost of a Data Breach Report — covering 604 organisations across 17 industries and 16 regions, breached between March 2023 and February 2024 — found the global average breach cost reached USD 4.88 million, a 10 % year-on-year increase and the largest single-year jump since the pandemic. Healthcare recorded the highest sector average (USD 9.77 million) for the fourteenth consecutive year. Critically, breach cost is driven not by the technical nature of the vulnerability exploited, but by business disruption and post-breach response costs — both of which scale directly with firm size and the volume of data held.

604 organisations · 17 industries · 16 regions Global average USD 4.88 M (+10 %) Healthcare: USD 9.77 M sector average Cost driven by disruption, not exploit type
NetDiligence · Cyber Claims Study · 15th Annual Edition

2 % of claims by volume account for 51 % of total insured cost

NetDiligence's analysis of insurance claims data reveals a pronounced asymmetry in the cyber-loss distribution. Small and medium-sized enterprises (revenue below USD 2 billion) account for approximately 98 % of all claims by volume but only 49 % of total insured cost. The remaining 2 % of claims — all from large enterprises — account for roughly 51 % of total cost, or approximately USD 2.4 billion. The average large-enterprise cyber incident now costs USD 10.3 million per claim. This bimodal distribution confirms that firm size is the dominant scalar for expected damage magnitude, independently of the technical characteristics of any individual incident.

SMEs: 98 % of claim volume · 49 % of cost Large enterprise: 2 % volume · 51 % cost Large-enterprise average: USD 10.3 M per claim Size dominates damage magnitude
Bitsight / Verisk (AIR Worldwide) · Marsh McLennan · Independent validation

Technical security ratings correlate with breach — but span a narrow absolute range

Independent validation by Verisk (AIR Worldwide) across 27,458 organisations found that those with a Bitsight Security Rating of 700 or above had a breach probability below 1 %, while those below 500 faced a probability of approximately 3 %. A separate Marsh McLennan analysis identified 14 specific Bitsight analytics — including patching cadence and exposed service configuration — as statistically correlated with cyber incidents. Patching cadence within a 90-day observation window was shown to be as well-correlated with breach outcomes as a 300-day window, confirming it as the strongest single actionable technical predictor. Importantly, these technical signals function as calibrators that sharpen the organisational baseline — they do not replace it.

27,458 organisations analysed (Verisk) Rating ≥700: breach prob. <1 % Rating <500: breach prob. ≈3 % 14 analytics correlated (Marsh McLennan) Patching cadence: strongest technical signal
Market practice · Insurance underwriting · 2024 – 2026

Revenue and sector class are the primary underwriting variables; technical posture is a secondary modifier

Across the cyber insurance market, revenue is the primary pricing variable in most standard underwriting models, with industry sector as the second determinant. Technical security posture — including security controls documentation, EDR deployment, and patching discipline — functions as a modifier, not the baseline. Carriers such as Coalition and At-Bay that perform active pre-bind scanning represent a minority practice; most market participants price from firmographic inputs alone. Businesses with identical revenue and employee counts receive quotes that differ by up to 40 % based solely on how their security posture is documented and evidenced — confirming that control quality affects premium, but sits downstream of size and sector in the pricing hierarchy. Aon's 2025 Global Cyber Risk Report found that verified cyber preparedness reduces claim payments by up to 77 % in the US — illustrating the scale of the gap between standard underwriting proxies and measurable risk reduction.

Revenue: primary underwriting variable Sector class: second determinant Technical posture: modifier, not baseline Up to 40 % premium variance from control documentation Preparedness reduces claims by up to 77 % (Aon 2025)
References
  1. Liu, C., & Babar, M. A. (2024). Corporate cybersecurity risk and data breaches: A systematic review of empirical research. Australian Journal of Management, 51(1), 62–92. doi.org/10.1177/03128962241293658
  2. Verizon. (2024). 2024 Data Breach Investigations Report (17th ed.). Verizon Business. Based on 10,626 confirmed breaches, November 2022 – October 2023, 94 countries.
  3. IBM & Ponemon Institute. (2024). Cost of a Data Breach Report 2024 (19th ed.). IBM. Based on 604 organisations, 17 industries, 16 regions; breaches March 2023 – February 2024. ibm.com/reports/data-breach
  4. Hu, K., Levi, R., Yahalom, R., & Zerhouni, E. G. (2025). Supply chain characteristics as predictors of cyber risk: A machine-learning assessment. IEEE Transactions on Dependable and Secure Computing, 1–10. Preprint: arXiv:2210.15785 (MIT, October 2022; revised November 2023). arxiv.org/abs/2210.15785
  5. NetDiligence. (2024). Cyber Claims Study (15th Annual Edition). NetDiligence. Claims data covering US, Canada and UK insurers.
  6. Bitsight & Verisk (AIR Worldwide). Independent validation study: breach probability correlation across 27,458 organisations over a two-year observation window. Reported via Bitsight Knowledge Base. help.bitsighttech.com
  7. Marsh McLennan Cyber Risk Analytics Center. (2022). Independent analysis of Bitsight security rating and risk vector correlation with cybersecurity incidents. 14 analytics identified as statistically correlated with breach frequency and severity.
  8. Aon. (2025). Global Cyber Risk Report 2025. Aon plc. Cyber preparedness reduces claim payments by up to 77 % in the United States. aon.com/cyber-solutions


Scalable. Trusted.

See the criteria applied — 10 ratings, free.

No credit card. No account required. Zero obligation.
Results delivered straight to your inbox.