Each year, we revisit our risk rating system to ensure it best reflects the needs of security practitioners safeguarding their organizations and supply chains. For our recentupdate, we’ve made two closely related changes: we’ve recategorized some of our existing findings to make an organization’s risk profile more understandable and recalibrated our scoring algorithm to more clearly illustrate the impact of specific risks.
This article provides an overview of these two exciting changes and offers an in-depth look at each risk category we factor into our proprietary cyber risk rating algorithm. We’ll explore how we’ve refined these categories to better align with industry standards and how they contribute to a more accurate assessment of an organization’s security posture.
Identify and reduce attack surface risks faster with UpGuard Breach Risk >
UpGuard has two major categories of risk detection: those detected by security questionnaires and those detected from continuous internet-wide scanning. The categorization of risks in questionnaires depends on the taxonomy used by the questionnaire, though UpGuard’s industry-leading questionnaire library also includes a Multi-Framework Questionnaire that normalizes security domains across several frameworks. Answering the Multi-Framework Questionnaire provides the evidence needed to map to SIG, ISO, or NIST standards.
For risks on the external attack surface detected by our internet scanner, we have created our own taxonomy—based on third-party standards when applicable—designed to make the available information maximally actionable. Previously, we grouped findings into five specific categories, but we recently reorganized some of these findings to create five additional categories.
We’ve updated our risk categorization and created five additional risk categories for three primary reasons:
After reorganizing our risk categories, we expanded from five to ten distinct categories. These now encompass website security, encryption, IP reputation, brand and reputation, email, DNS, network, data leakage, attack surface, and vulnerability management.

We've refined our risk categories into ten distinct areas to provide a more precise and actionable assessment of an organization’s security posture. Each category addresses a specific aspect critical to cybersecurity, making it easier for organizations to identify, prioritize, and mitigate risks. Here’s an in-depth look at each category:
By reorganizing our risk categories, we also needed to change our scoring algorithm. Previously, we allotted each category a maximum impact on an organization’s risk rating. This relatively high ceiling worked because we only divided risks into a few categories.
However, after expanding our categories, this method no longer made sense, as the ceilings sometimes obscured rare, high-impact risks like actively exploited vulnerabilities only applicable to a few hosts. We did not want to hide the impact of these findings nor give the impression that their absence necessarily represented a strong security posture.
Our solution was to calculate overall and category scores separately so that a finding in any category can appropriately impact an organization’s overall score, regardless of the category’s size. At the same time, this also allowed category scores to more accurately reflect the strength of controls present across an organization’s security domains. In re-scoring organizations with this new method, most companies experienced a minor drop in score, as we were now fully counting the small number of risks that had exceeded the category ceiling in every organization’s overall score.
This update widely improves the usability of UpGuard’s existing scanning and lays the foundation for continued expansion of risk detection. Our threat analyst team adds new vulnerabilities as they discover them and continually researches methods of data leak detection, both of which are now more visible in dedicated, coherent categories.
From refining our scoring algorithm to continually recalibrating our risk categories, UpGuard is committed to providing security teams with the tools and insights needed to defend their organizations and supply chains.
UpGuard Breach Risk empowers organizations to identify and reduce attack surface risks faster with daily scanning, clear risk prioritization, and streamlined remediation workflows. Our scanning engine scans over 80 million organizations and 800 billion records daily to provide security teams with our industry-leading Security Ratings.
As we look to the future and continue to refine our cyber risk ratings as new threats and vulnerabilities emerge, we encourage your feedback. What additional security domains would you like us to include in our 2025 update?