Can you measure your cyber risk?
Companies measure performance in key business functions such as customer service, human resources and corporate strategy and now Optus and BitSight are working together to enable you to measure cyber security performance.
The BitSight Security Rating Platform generates objective, data-driven, outside-in ratings using evidence of security outcomes from networks around the world. No information is required from the rated entity.
Organisations are using security ratings to:
- Benchmark security performance – to understand relative cyber security performance and communicate strategic objectives across the enterprise
- Manage risk posed by third parties – to effectively monitor and identify issues within the information supply chain
- Underwriting cyber insurance – to better understand the security performance of applicants and insureds
Features
BitSight Security Ratings are calculated using a proprietary algorithm that analyses and classifies externally observable data and generated based on three classes of data – security events (evidence of cyber attacks), diligence data (evidence of steps taken to prevent an attack) and user behaviour (evidence of harmful activities undertaken by network users).
Security ratings, historical trends, event and diligence details, industry and peer comparisons are updated daily and are accessible through the BitSight platform and via the API.
The diagram below depicts how Security Ratings are calculated and shared in the BitSight Platform. Security Ratings range from 250 to 900, the higher the rating, the more effective the company is in implementing good security practices.

Cyber Security Ratings Factsheet
How you can simplify your approach to cyber risk management.