Improve your Bitsight Security Rating

You can improve your rating by remediating findings that have a negative impact on your rating during calculation. Negatively-impacting findings are graded BAD, WARN, or FAIR, including all findings in the Compromised Systems and User Behavior risk categories and the Critical Vulnerability Management (CVM) risk vector.

Identify findings to remediate

The Bitsight platform offers many rich features which can be used to focus remediation efforts as detailed in the table below.

Findings Table

Findings are the culmination of observed internet traffic and configurations. They’re recorded in the Bitsight platform as events and records.

Findings ➔ Findings Table
 

Risk Remediation Plan

A Risk Remediation Plan is a prioritized list of findings you can fix to improve certain risk vector grades. This plan is designed to help you identify and remediate high-impact findings to reach an “A” grade.

Action Plans ➔ Risk Remediation
 

Forecasting

The Forecasting page is an analytics tool that observes patterns and projects possible future ratings by extracting information from existing data sets.

Action Plans ➔ Forecasting
 

Subsidiary Improvement

Subsidiary Improvement provides a guideline for remediation that maximizes the potential impact on the parent rating if findings within its subsidiaries were remediated.

Action Plans ➔ Subsidiary Improvement
 

Remediation Strategy Panel

The Remediation Strategy panel highlights findings that have had the highest impact on your rating over the last 60 days. Use this to determine which risk vectors have the largest possible improvement if remediated.

Organization ➔ Company Details
 

Once a finding is remediated, request a user-initiated findings rescan to update it in the platform. See What To Do After Remediation.

Maintain your rating

To maintain your rating, ensure that remediated assets continue to implement security best practices.

For example, you should consistently:

  • Ensure security measures are in place to prevent security incidents
  • Renew SSL Certificates before expiration
  • Use secure network protocols for sensitive data transmission
  • Avoid using deprecated encryption cipher suites
  • Upgrade or patch software with known or recently-discovered vulnerabilities
  • Keep end user devices up-to-date (i.e. operating system, web browser)

Frequently asked questions

How does Bitsight calculate a Security Rating?

Bitsight calculates ratings daily with a proprietary algorithm that examines two classes of externally observable data: security events and configuration. It assesses security effectiveness across four risk categories: Compromised Systems, Diligence, User Behavior, and Public Disclosures. The algorithm then aggregates the weighted letter grades for each risk vector and normalizes the result for the company.

Learn more here.

How do I request a rescan for a finding?

In the SPM app, go to Findings ➔ Findings Table and use any of these methods:

  • Hover over a finding and select Rescan.
  • Open the finding details sheet and select Options ➔ Request Rescan.
  • Check off up to 250 eligible findings, select Rescan at the top of the table, review the request, and select Submit.
  • Invite a company to the Client and Vendor Access Program and ask them to request a rescan for their own organization.

After you submit a request, the Rescan Status column shows progress. You can request up to 1,000 rescans per day, and up to 250 findings at a time.

Learn more here.

Why do Bitsight Ratings fluctuate?

Bitsight Ratings update daily as new observations arrive and as older events decay or reach the end of their lifetime. The displayed rating rounds down in 10-point increments, so small changes in the underlying rating can move the displayed rating without changing any individual risk vector grade.

Learn more here.

Why did my risk vector letter grades change without affecting my overall rating?
Risk Vector Letter Grades are correlated to how well a company is performing relative to all companies in the Bitsight inventory. The letter grade can change and this does not necessarily indicate an overall rating change should have occurred.
 
Publish Date or Recent Edits
  • October 28, 2024: Renamed Rating Improvement to Forecasting; Updated navigation for Findings Table, Forecasting, & Remediation Strategy panel.
  • February 7, 2023: Published.
Was this article helpful?
0 out of 2 found this helpful

Comments

0 comments

Please sign in to leave a comment.