Knowledge Center

Cyber risk, explained properly.

In-depth reference articles on cyber risk scoring, quantification, insurance underwriting and third-party risk — written by the team that builds the scoring engine, with sources cited throughout.

Xcigence is an AI-powered cyber risk intelligence and risk-scoring platform that uses patented technology to quantify cybersecurity risk across organizations, users, assets, vendors and supply chains. Xcigence translates cyber-risk evidence into standardized risk scores and financial exposure intelligence for enterprises, financial institutions, insurers and investors.

Scoring

What Is a Cybersecurity Risk Score?

A cybersecurity risk score turns observable security evidence into a standardized number decision-makers can compare, price, and act on. Here is what goes into one and what makes it defensible.

9 min read
Scoring

Understanding the 300–850 Cyber Risk Score

The five bands of the Xcigence 300–850 scale, what each one signals to insurers and procurement teams, and how to read score movement over time.

8 min read
Scoring

Cybersecurity Risk Score vs Credit Score

The credit score analogy explains cyber scoring faster than anything else — and it breaks in three specific places worth understanding before you rely on either number.

8 min read
Scoring

Cyber Risk Score vs Security Rating: The Difference That Matters

Security ratings measure hygiene. Risk scores measure likelihood and consequence. Confusing the two is a common and expensive category error.

7 min read
Quantification

What Is Cyber Risk Quantification?

Cyber risk quantification expresses exposure in currency and probability instead of red-amber-green. Here is how it works and why boards now expect it.

9 min read
Quantification

How to Calculate the Financial Impact of a Cyber Breach

A practical cost model: the seven loss categories that make up breach impact, how to source credible numbers for each, and where estimates go wrong.

10 min read
Quantification

The FAIR Model Explained for Risk and Security Leaders

Factor Analysis of Information Risk decomposes risk into loss event frequency and loss magnitude. A plain-language walkthrough of the taxonomy and its limits.

9 min read
Insurance

How Cyber Risk Scores Are Changing Cyber Insurance Underwriting

Underwriters are replacing self-attested questionnaires with continuously measured evidence. What that changes for pre-bind triage, pricing and in-force monitoring.

9 min read
Insurance

How Insurers Actually Price Cyber Insurance Policies

From exposure base and loss costs to control credits and aggregation limits — the mechanics behind a cyber premium, and where your score enters the math.

9 min read
Third-Party Risk

How to Build a Third-Party Cyber Risk Program

A six-stage blueprint: inventory, tiering, assessment depth, contractual controls, continuous monitoring and offboarding — with what to automate at each stage.

10 min read
Third-Party Risk

The Limits of Vendor Security Questionnaires

Questionnaires are self-attested, point-in-time, and unverified. They still matter — but only for the questions external evidence genuinely cannot answer.

8 min read
Third-Party Risk

Fourth-Party and Supply Chain Cyber Risk Explained

Your vendors have vendors. Concentration risk in shared cloud, identity and file-transfer providers is now the dominant mode of systemic cyber failure.

9 min read
Comparisons

Xcigence vs Traditional Security Ratings

Traditional security ratings grade external hygiene. Xcigence scores risk — likelihood and financial consequence — on a 300–850 scale under a patented method. A factual, sourced comparison.

10 min read
Comparisons

Cyber Risk Scoring vs Vulnerability Assessment

A vulnerability assessment enumerates technical weaknesses. A risk score expresses business exposure. They answer different questions and neither substitutes for the other.

9 min read
Comparisons

Cyber Risk Scoring vs Penetration Testing

Penetration testing proves depth on a point in time. Risk scoring provides breadth over continuous time. Where each one is authoritative — and where each one is blind.

9 min read
Comparisons

Cyber Risk Quantification vs Cybersecurity Ratings

Ratings answer "how good is their hygiene?". Quantification answers "how much money is at stake?". Boards, insurers and regulators are converging on the second question.

9 min read
Maturity

What Is a Cybersecurity Maturity Score?

A cybersecurity maturity score measures how repeatable, governed and effective an organization's security capabilities are — not how exposed it is today. What goes into one, the 0–5 levels, and why evidence confidence matters.

9 min read
Maturity

Cybersecurity Maturity vs Cyber Risk Score

Maturity asks how capable your program is. Risk asks how much exposure you carry right now. An organization can be high on one and low on the other — and the four combinations each call for a different response.

8 min read
Maturity

NIST CSF 2.0 Tiers vs Cybersecurity Maturity Levels

NIST is explicit that CSF Tiers are not maturity levels. What the four Tiers actually describe, how they relate to C2M2 and CMMC, and how a normalized 0–5 maturity model keeps each framework in its own terms.

9 min read

Put the theory to work

See how a standardized 300–850 cyber risk score changes vendor decisions, underwriting and board reporting at your organization.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.