Your HackRisk Score, explained.
Your HackRisk Score is a real-time measure of your organisation's cybersecurity risk, shown as a percentage and graded A* to F.
It aggregates dark web monitoring, external reconnaissance and vulnerability scanning into a single, actionable number.
A score built from real threat data.
Findings from each of these intelligence streams feed into a single score, so one view covers everything an attacker can see. Only the services you have switched on count towards it, and your weakest area carries the most weight — so the fastest way to move your score is to fix whatever is worst, not whatever is easiest.
The result is a risk percentage from 0 to 100 – the lower the better – translated into a letter grade, the same idea that makes credit scores and energy ratings immediately understandable. The grade runs the other way to the percentage: A* is the best grade and sits at the lowest risk.
What does your grade mean?
Your external posture is strong. No critical exposures detected, credentials are clean and your attack surface is well managed.
Few or minimal vulnerabilities identified. They should still be addressed, but none require urgent remediation.
Minor issues are present but no critical exposures. Routine remediation and monitoring will bring this down.
Several exposures exist that should be addressed. Attackers probing your perimeter may find something exploitable.
Significant exposure that leaves your systems vulnerable to a threat actor. These findings want attention soon.
Serious weaknesses across your external surface. Remediation should be planned and started rather than queued.
Severe exposure identified. Credentials may already be compromised. Immediate remediation is advised.
What affects your score?
Exposed credentials
Email addresses and passwords discovered in stealer logs, breach dumps, and dark web marketplaces. Even old credentials create risk if passwords are reused.
Open ports & services
Unnecessarily exposed services increase your attack surface. Legacy protocols, admin interfaces and unpatched services all count against you.
Known vulnerabilities
CVEs matched against your external infrastructure. Critical and high-severity vulnerabilities with public exploits have significant score impact.
Dark web mentions
References to your domain, brand, or executive names on dark web forums, paste sites, and threat actor channels.
SSL certificate health
Expired, self-signed, or misconfigured SSL certificates signal poor security hygiene and can enable man-in-the-middle attacks.
Subdomain exposure
Forgotten staging environments, legacy APIs, and subdomains you no longer maintain extend your attack surface beyond your primary domain.
Training completion
How much of their assigned security awareness training your people have finished, and how well they scored on it. Higher completion lowers your risk.
Phishing simulation results
How your team responds to simulated phishing. Opening the email counts against you, clicking the link counts for more, and entering credentials counts for most.
How to move from F to A*.
- 01
Check your dark web exposure
Start with credential exposure. If your staff email addresses appear in breach data, prompt password resets and enforce MFA immediately.
- 02
Patch and close open ports
Review your HackRisk recon scan results and close any services that don't need to be publicly accessible. Apply critical patches as a priority.
- 03
Audit your SSL certificates
Ensure all domains and subdomains have valid, trusted certificates. Enable HSTS and redirect HTTP to HTTPS everywhere.
- 04
Enumerate your attack surface
Use HackRisk's subdomain and asset discovery to identify forgotten infrastructure. Decommission or secure anything you don't actively maintain.
- 05
Monitor continuously
Your score reflects your current posture. New breaches, newly discovered subdomains, and new CVEs can change your score overnight. Stay on top of it.
Get your free score.
Find out where your business stands. Your first HackRisk Score is free - no credit card required.
Get your free score