Generate the Daily Ratings Change Report

This report provides a detailed summary of a company’s daily security rating performance. The Daily Ratings Change Report is generated for a specific date and reflects changes effective as of that date, offering a snapshot of changes from one day to the next.

The report visualizes the company’s security rating over time, highlights major rating fluctuations, and explains the root causes of observed changes: whether from risk vector movements, security incidents, or asset modifications. It specifically lists new findings and remediated issues, giving stakeholders a complete view of daily rating changes.

Instructions

From the SPM Reports page:

  1. Access the Reports Section 
    Navigate to the Reports page in the Bitsight platform. 
  2. Locate the Rating Change Report Card 
    Find the Ratings Change option. 
  3. Select Create 
    Hover over the report card and click Create to start a new report. 
  4. Choose a Company 
    Use the available filters or search bar to select a company. 
  5. Select a Date (Optional)
    A date up to 30 days in the past can be selected for this report. If no date is elected, the report will be run for the most recent rating date.
  6. Generate and Review 
    Click View to generate the report. Once it is created, you can edit, save, schedule, Quick Share, or download the document as a PDF.

From the Company Detail page:

  1. Go to the Company Detail page in the SPM. 
  2. Locate the Ratings History card. 
  3. Go to the (...) Menu. 
  4. Download Daily Rating Change Report.

Tips for Reading the Daily Rating Change Report

Security Rating Overview

At the top of the report, you’ll find the company’s current Bitsight Security Rating and the effective date (e.g., 600, Basic, effective 22 Oct 2025). The visualization chart below shows rating changes over time, including highest and lowest values within the past 12 months.

Rating Changes

This section summarizes whether the company’s rating increased, decreased, or remained stable on the effective date.
If a change occurred, it is broken down into:

  • Due to Risk Vectors: Specific factors such as Web Application Security or Compromised Systems (for example) that directly impacted the rating.
  • Due to Other Causes: Broader factors such as breaches, general security incidents, or infrastructure changes (e.g., IP expirations or additions).

Findings

The Findings section lists new or no-longer-impacting issues discovered on the report date.

Each entry includes:

  • Risk Vector
  • Finding Identifier
  • Grade and Severity
  • Details about the issue, such as insecure protocols, weak keys, or misconfigurations.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.