What security ratings do well
Security ratings earned their place for a real reason. If you need a quick, comparable read on the cyber hygiene of a company you have no right to audit — a prospective vendor, an acquisition target, a portfolio company — an outside-in rating gives you one in seconds. It scans what is observable from the internet: exposed and misconfigured services, TLS and certificate hygiene, patching cadence on public assets, leaked credentials, and signals of compromise like botnet participation.
For triaging a large vendor portfolio, that is valuable. A rating tells you where to look first, flags the worst hygiene without a questionnaire, and updates continuously without anyone filling in a form. As a screening and monitoring signal, it does a job nothing else does as cheaply.
The black-box problem
The trouble starts when a rating is treated as a verdict rather than a signal. Many ratings are proprietary black boxes: the methodology is undisclosed, the weighting between factors is opaque, and the evidence behind the grade is partial, attributed by imperfect internet mapping, and often out of date. Companies routinely find assets attributed to them that they do not own, or findings that were remediated weeks ago still dragging the score down.
When the score drops and no one can point to the specific, current finding that caused it, three bad things happen. You cannot dispute it with confidence, you cannot remediate it efficiently, and you cannot tell whether the movement is real or an artefact of the rating vendor's data. A number you cannot trace is a number you cannot act on.
What outside-in ratings structurally cannot see
Even a perfectly accurate outside-in rating is blind to most of what determines real risk. It cannot see your internal segmentation, your identity controls, your detection and response capability, or the compensating controls that neutralise a finding it flags. It cannot see business context — whether an exposed service fronts a crown-jewel system or a marketing microsite.
So an outside-in grade is, at best, a measure of external hygiene, not of security. A company can have excellent internet hygiene and weak internal controls, or messy external hygiene and strong defence in depth. Treating the external grade as the whole picture inverts the actual risk in both cases.
What transparent scoring changes
Transparent scoring flips the default from 'trust the number' to 'show the working'. Every input that feeds the score is visible. The weighting is explained rather than hidden. Each contributing finding carries its provenance — where it came from, how fresh it is, and whether it reflects live telemetry, a sample, or simulated data — so no one confuses a stale artefact for a current fact. And the line from an individual finding to its effect on the score is auditable end to end.
The practical difference is that a disputed score becomes a fixable one. If you can see that the number moved because of a specific internet-facing service with a known-exploited vulnerability, you can decide to remediate it, add a compensating control and record it, or challenge the finding with evidence. Transparency does not lower the bar — it makes the bar visible, which is what makes the score defensible to an auditor, a regulator or your own board.
Use ratings as an input, not an oracle
The mature posture is neither to worship security ratings nor to dismiss them. Use them as one input among several. Insist on transparency — a score you cannot trace to evidence is not a control, it is a rumour. And combine the outside-in view with inside-out evidence: your own asset inventory, control state, exposure analysis and exploitability signals, all carrying their provenance.
An outside-in rating tells you how you look from the internet. Inside-out, transparent scoring tells you what is actually true about your controls and exposure. Together, with visible evidence behind every number, they give you a posture you can both trust and defend — which is more than any single black-box grade can offer.