Security ratings are useful for comparing externally visible supplier security posture. Their limit is context: they cannot show how a supplier connects to your organisation, how dependent you are on it, or which undocumented supplier relationships create the greatest exposure.
A rating can help answer: “What does this organisation’s externally visible security posture look like?”
Risk-based decisions require another answer: “What happens to us if this supplier is compromised or unavailable?”
That gap marks the practical limit of a security rating.
How security ratings work, and what they are good for
Security ratings use externally observable data to estimate an organisation’s security posture, typically translating technical signals into a numerical score, letter grade, or risk category.
The exact methodology varies by provider, but common inputs include internet-facing assets, vulnerabilities, DNS and certificate configuration, exposed services, malware or compromised-system signals, software and patching indicators, email and network security, and publicly observable incident information.
There is real value in that. Unlike a questionnaire, an external rating does not require a supplier to tell you how secure it believes itself to be. It can be applied consistently across hundreds or thousands of organisations and refreshed as observable conditions change, serving different capabilities such as:
- Initial screening. A rating can help identify suppliers that deserve closer examination.
- Trend monitoring. A sudden deterioration can provide a useful trigger for reassessment.
- Portfolio comparison. A common scoring framework makes it easier to compare large supplier populations.
- Executive communication. A score or grade gives boards and non-technical stakeholders a shorthand for discussing security posture.
The limitation appears when a shorthand score becomes the risk decision.
The structural limitations of security ratings
A security rating estimates externally observable posture. Its scope is bounded by the assets attributed to the supplier, the signals visible from outside, and the provider's scoring model. Customer-specific dependency, business criticality, internal controls, and indirect relationships require additional evidence.
1. Outside-in evidence only shows what is observable
External assessment works without supplier cooperation, which makes it scalable. Its field of view remains external: a scanner can observe a certificate, an exposed service, a software version or a DNS configuration.
What it generally cannot see are internal controls and operational conditions such as:
- network segmentation and internal architecture
- privileged-access controls
- incident-response and recovery capability
- compensating controls
- offline or private systems
That means outside-in assessment can provide useful evidence about observable posture, while internal assurance is still needed to understand controls, resilience, and operating context that cannot be seen from the internet.
2. Attribution can be wrong
Before a rating platform can score an organisation, it first has to decide which internet-facing assets belong to that organisation. That is an attribution problem, because cloud infrastructure changes, IP addresses move, subsidiaries are acquired and sold, hosting is shared, domains expire, infrastructure is outsourced...
A technically correct finding can still distort a rating when the underlying asset has been attributed to the wrong organisation. Attribution quality therefore matters as much as observation quality.
3. The score has no idea what the supplier does for you
This is the bigger limitation. A security rating usually evaluates the supplier as an entity and gives the same score to any client company or security team evaluating that supplier.
It does not know whether that supplier:
- hosts your production environment
- executes JavaScript inside your customer-facing application
- provides identity and authentication
- processes regulated data
- appears only in a low-impact DNS record
- supports a non-critical administrative process
- is one of ten easily replaceable providers
The supplier can carry the same score in every scenario while creating very different levels of business exposure.
4. A grade compresses complexity
A letter grade or numerical score is useful because it reduces complexity, but it also removes detail. Imagine two suppliers both receive a score of 82. Supplier A has several minor security-hygiene issues and little connection to critical systems. Supplier B has excellent general hygiene and provides authentication across your production estate.
The score gives you a common unit. Risk decisions still depend on the information that disappeared during that compression, which explains why an organisation can be breached through a supplier even if they had a perfect score.
Why two customers of the same supplier face different risk
The same supplier can create radically different risk for two customers because supplier risk depends on how each customer connects to, relies on, and could be affected by that supplier.
Imagine two organisations use the same SaaS provider. For Organisation A, it provides an optional learning portal used by a small internal team. For Organisation B, the same provider is integrated into authentication, processes sensitive employee data, and loads code into a business-critical application.
The supplier has one external security posture, one set of vulnerabilities, and potentially one security rating. The impact of compromise or outage changes with each customer relationship.
A global supplier score cannot resolve that difference. It answers “How does this supplier look?” while risk prioritisation also needs “How exposed are we through this supplier?”
ThingsRecon calls this relationship-specific risk, measured by Digital Proximity to core systems. A supplier can maintain strong security hygiene and still sit inside a high-impact dependency.
Security ratings vs Digital Proximity: posture vs criticality
Security ratings describe supplier posture at entity level. Digital Proximity measures the depth and significance of the observable relationship between a supplier and a specific organisation.
The distinction is straightforward. A security rating asks “How secure does this supplier appear to be?” Digital Proximity asks “How closely is this supplier connected to systems that matter to us?”
Digital Proximity uses observable technical relationships such as DNS, JavaScript, APIs, certificates and infrastructure connections to measure the depth and nature of that relationship.
A script executing inside a customer-facing application represents a different kind of dependency from a DNS TXT record. An API supporting a production workflow represents a different potential blast radius from an isolated marketing integration.
Digital Proximity adds customer-specific relationship context alongside security posture.
Looking at both gives a more useful prioritisation view:
- A supplier with weak security posture but low proximity may need remediation without being one of your most consequential dependencies.
- A supplier with strong security posture but high proximity may still warrant close monitoring because disruption or compromise could have significant impact.
- A supplier with both weak posture and high proximity should usually receive greater attention because both likelihood signals and business exposure are elevated.
The same principle applies to vulnerability prioritisation, where Digital Proximity can sit alongside CVSS severity.
Security ratings vs EASM: scoring your perimeter vs discovering it
Security ratings score externally observable posture associated with a known organisation. External Attack Surface Management (EASM) continuously discovers and monitors the internet-facing assets and exposures that form an organisation's external attack surface.
A rating platform evaluates the externally visible security signals associated with the footprint it attributes to a company. EASM starts one step earlier with discovery: “What else exists?”
This can include:
- forgotten domains
- unmanaged subdomains
- cloud environments
- APIs
- certificates
- development systems
- mobile infrastructure
- exposed services
- assets introduced through acquisitions
- shadow infrastructure
Ratings begin with an entity and evaluate its observable posture. EASM begins with discovery and builds the perimeter that needs assessment.
Each capability answers a different operational question. Ratings support comparative posture analysis; discovery supports finding internet-facing infrastructure that inventories have missed.
Security ratings vs TPRM platforms: where they overlap
Security ratings and TPRM platforms both support third-party risk decisions and typically begin with suppliers already known to the organisation.
Traditional TPRM platforms are built around governance workflows such as supplier inventories, onboarding, questionnaires, due diligence, document collection, inherent-risk assessments, review cycles, remediation and audit trails. Security ratings can complement that process by bringing externally observed security posture into the assessment.
TPRM contributes workflow and declared evidence; ratings contribute external posture signals. Used together, they give teams a broader supplier assessment.
A shared blind spot remains: both commonly begin with the supplier population already known to the organisation. This includes:
- unknown suppliers
- infrastructure providers
- subprocessors
- externally connected SaaS
- fourth parties
- shared dependencies
When a dependency is absent from the vendor inventory, there may be no questionnaire, assessment, contract, or rating attached to it. Supply chain intelligence changes the starting point by discovering observable suppliers and dependencies before the assessment workflow begins.
Security ratings vs EASM vs TPRM vs Supply Chain Intelligence: comparison table
Choosing between these capabilities starts with the question the team needs to answer.
What should security ratings still be used for?
Security ratings work best as screening, benchmarking, and monitoring signals within a broader supplier-risk process, as they are one signal in the risk picture.
Security teams need prioritisation, procurement teams need common language, and boards need summaries. The risk appears when a convenient measurement becomes the definition of supplier risk.
A security rating can describe observable supplier posture. Relationship-level questions still require evidence about connectivity, dependent systems, potential blast radius, shared providers, fourth parties and business impact.
Strong supplier-risk programmes combine multiple forms of evidence: posture, discovery, assurance, business criticality and relationship context.
ThingsRecon contributes relationship context by continuously discovering the digital connections around an organisation and measuring their significance with Digital Proximity. Security posture remains important; proximity shows how much that posture matters to a specific customer.
A supplier can look secure and still represent one of the largest risks in your ecosystem.





