What does the 300–850 cybersecurity risk score represent?
The Xcigence cyber risk score places an organization on a fixed 300-to-850 scale, where 300 indicates the highest cyber risk and 850 the lowest. The score expresses compromise likelihood and residual exposure based on observable security evidence — not on self-reported questionnaire answers.
The range is bounded deliberately. A fixed floor and ceiling make scores comparable across organizations, across industries, and across time: a vendor at 690 today and 740 next quarter has measurably reduced exposure, and two suppliers at 620 and 810 can be ranked without further interpretation.
The scale is also intentionally familiar. Executives, underwriters, and procurement teams already reason fluently about a 300–850 range, which removes the translation step that usually stands between technical security findings and a business decision.
How is the 300–850 score calculated?
Evidence is collected continuously across the external attack surface, enriched with threat and exploit intelligence, and then weighted rather than counted. A vulnerability that is actively exploited in the wild on an internet-facing production service carries far more weight than a low-severity finding on an isolated asset.
Weighted findings pass through calibration and the proprietary Artemis™ risk analytics engine, which converts them into a stable position on the scale. Calibration is what keeps the score comparable: without it, a large organization with more assets would always appear riskier than a small one simply by virtue of surface area.
The underlying algorithms remain proprietary, but the methodology is explainable by design. Every score retains the specific findings that produced it, so the movement between two scores can always be attributed to identifiable evidence.
What do the risk bands mean?
The scale is divided into five bands — Critical Exposure, Elevated Risk, Moderate Risk, Strong Posture, and Industry-Leading — so that a number can be converted immediately into a decision posture. Bands are what make the score usable in policy: an organization can require Strong Posture or better from any vendor handling regulated data, or trigger review whenever a supplier drops into Elevated Risk.
Bands are read alongside industry thresholds rather than in isolation. Highly regulated sectors — finance and banking, healthcare and life sciences, government and public services — carry target thresholds in the 830–850 range, while manufacturing and energy typically target 800 and above.
The consequence is that the same score can be acceptable in one context and insufficient in another, which is why Xcigence always presents the score with the sector threshold it is being measured against.
How do organizations use the score?
Internally, the score gives security leaders a single measure to report upward and to track remediation against — it answers the board question "is our risk going up or down?" with evidence rather than narrative. Because it updates continuously, it also shows whether a security investment actually moved exposure.
Externally, the score functions as a shared reference point. Insurers use it in underwriting and portfolio monitoring, investors and acquirers use it in due diligence, procurement teams use it to set vendor onboarding thresholds, and auditors and regulators use it as independent, evidence-backed input.
In every case the value comes from independence: because the assessment requires no agents, no questionnaires, and no cooperation from the assessed party, the same methodology applies to your own organization, your vendors, their downstream providers, and companies you are evaluating.