The Xcigence Score

300–850 Cybersecurity Risk Score

A bounded, evidence-based scale from 300 to 850 — where 300 is the highest cyber risk and 850 the lowest. Continuously reassessed, industry-calibrated, and traceable back to the findings that produced it.

Xcigence is an AI-powered cyber risk intelligence and risk-scoring platform that uses patented technology to quantify cybersecurity risk across organizations, users, assets, vendors and supply chains. That measurement is expressed as a single 300–850 cyber risk score — bounded, industry-calibrated, continuously reassessed, and traceable back to the findings that produced it.

300
← Higher Risk
Xcigence Cyber Risk Score
850
Lower Risk →
300 – 579
Critical Exposure
580 – 669
Elevated Risk
670 – 739
Moderate Risk
740 – 799
Strong Posture
800 – 850
Industry-Leading

The Xcigence Cyber Risk Scale

Five bands across a bounded range, so a number converts directly into a decision.

300
← Higher Risk
Xcigence Cyber Risk Score
850
Lower Risk →
300 – 579
Critical Exposure
580 – 669
Elevated Risk
670 – 739
Moderate Risk
740 – 799
Strong Posture
800 – 850
Industry-Leading
300 – 579

Critical Exposure

Multiple exploitable exposures on the external attack surface. Compromise likelihood is high and remediation is urgent.

580 – 669

Elevated Risk

Material weaknesses present across several assessed domains. Risk is concentrated enough to affect underwriting and vendor decisions.

670 – 739

Moderate Risk

Core controls are in place, with recurring gaps in configuration, patch cadence, or exposed services.

740 – 799

Strong Posture

Consistent control coverage with limited residual exposure. Typically acceptable for most commercial engagements.

800 – 850

Industry-Leading

Minimal external exposure and mature, continuously validated controls. Meets thresholds for highly regulated sectors.

How the Score Is Produced

Raw telemetry is ingested, enriched, weighted, and calibrated before it becomes a position on the scale.

Data Collection
Threat Intel
Vulnerability
Risk Modeling
Calibration
Artemis™ Engine
Score

Understanding the 300–850 score

What the range represents, how it is calculated, and how organizations put it to work.

What does the 300–850 cybersecurity risk score represent?

The Xcigence cyber risk score places an organization on a fixed 300-to-850 scale, where 300 indicates the highest cyber risk and 850 the lowest. The score expresses compromise likelihood and residual exposure based on observable security evidence — not on self-reported questionnaire answers.

The range is bounded deliberately. A fixed floor and ceiling make scores comparable across organizations, across industries, and across time: a vendor at 690 today and 740 next quarter has measurably reduced exposure, and two suppliers at 620 and 810 can be ranked without further interpretation.

The scale is also intentionally familiar. Executives, underwriters, and procurement teams already reason fluently about a 300–850 range, which removes the translation step that usually stands between technical security findings and a business decision.

How is the 300–850 score calculated?

Evidence is collected continuously across the external attack surface, enriched with threat and exploit intelligence, and then weighted rather than counted. A vulnerability that is actively exploited in the wild on an internet-facing production service carries far more weight than a low-severity finding on an isolated asset.

Weighted findings pass through calibration and the proprietary Artemis™ risk analytics engine, which converts them into a stable position on the scale. Calibration is what keeps the score comparable: without it, a large organization with more assets would always appear riskier than a small one simply by virtue of surface area.

The underlying algorithms remain proprietary, but the methodology is explainable by design. Every score retains the specific findings that produced it, so the movement between two scores can always be attributed to identifiable evidence.

What do the risk bands mean?

The scale is divided into five bands — Critical Exposure, Elevated Risk, Moderate Risk, Strong Posture, and Industry-Leading — so that a number can be converted immediately into a decision posture. Bands are what make the score usable in policy: an organization can require Strong Posture or better from any vendor handling regulated data, or trigger review whenever a supplier drops into Elevated Risk.

Bands are read alongside industry thresholds rather than in isolation. Highly regulated sectors — finance and banking, healthcare and life sciences, government and public services — carry target thresholds in the 830–850 range, while manufacturing and energy typically target 800 and above.

The consequence is that the same score can be acceptable in one context and insufficient in another, which is why Xcigence always presents the score with the sector threshold it is being measured against.

How do organizations use the score?

Internally, the score gives security leaders a single measure to report upward and to track remediation against — it answers the board question "is our risk going up or down?" with evidence rather than narrative. Because it updates continuously, it also shows whether a security investment actually moved exposure.

Externally, the score functions as a shared reference point. Insurers use it in underwriting and portfolio monitoring, investors and acquirers use it in due diligence, procurement teams use it to set vendor onboarding thresholds, and auditors and regulators use it as independent, evidence-backed input.

In every case the value comes from independence: because the assessment requires no agents, no questionnaires, and no cooperation from the assessed party, the same methodology applies to your own organization, your vendors, their downstream providers, and companies you are evaluating.

Score Inputs

Every score is derived from continuous analysis of the external attack surface — no agents, no questionnaires, and no cooperation required from the assessed party.

Web applications & internet-facing services
Networks & exposed infrastructure
Domains & subdomains
Cloud environments (AWS, Azure, GCP)
Email security posture
Social media impersonation & brand exposure
Dark web & underground intelligence
Publicly disclosed vulnerabilities

Industry Thresholds

A score of 800 may be strong for a retail supplier and insufficient for a critical banking vendor. Scores are always read against sector-specific thresholds.

700740780850Finance &BankingHealthcare &Life SciencesGovt & PublicServicesManufacturing& Energy

Where the Score Is Used

One measurement, read by every party that needs a defensible view of cyber exposure.

Enterprise cyber risk management
Board and executive reporting
Third-party and vendor risk management
Cyber insurance underwriting support
Vendor due diligence and onboarding
Regulatory and governance oversight
Investment and acquisition due diligence

Find out where you land on the 300–850 scale

Request an assessment and receive your score, your risk band, the evidence behind it, and how you compare against your sector threshold.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.