Your risk score

Your HackRisk Score, explained.

Your HackRisk Score is a real-time measure of your organisation's cybersecurity risk, shown as a percentage and graded A* to F.

It aggregates dark web monitoring, external reconnaissance and vulnerability scanning into a single, actionable number.

How it's calculated

A score built from real threat data.

Findings from each of these intelligence streams feed into a single score, so one view covers everything an attacker can see. Only the services you have switched on count towards it, and your weakest area carries the most weight — so the fastest way to move your score is to fix whatever is worst, not whatever is easiest.

The result is a risk percentage from 0 to 100 – the lower the better – translated into a letter grade, the same idea that makes credit scores and energy ratings immediately understandable. The grade runs the other way to the percentage: A* is the best grade and sits at the lowest risk.

Dark web monitoring
Recon & attack surface
Vulnerability scanning
SSL & config health
Grade system

What does your grade mean?

A*
Low risk
Score: 0–9%

Your external posture is strong. No critical exposures detected, credentials are clean and your attack surface is well managed.

A
Low risk
Score: 10–24%

Few or minimal vulnerabilities identified. They should still be addressed, but none require urgent remediation.

B
Medium risk
Score: 25–36%

Minor issues are present but no critical exposures. Routine remediation and monitoring will bring this down.

C
Medium risk
Score: 37–49%

Several exposures exist that should be addressed. Attackers probing your perimeter may find something exploitable.

D
High risk
Score: 50–62%

Significant exposure that leaves your systems vulnerable to a threat actor. These findings want attention soon.

E
High risk
Score: 63–74%

Serious weaknesses across your external surface. Remediation should be planned and started rather than queued.

F
Critical risk
Score: 75%+

Severe exposure identified. Credentials may already be compromised. Immediate remediation is advised.

Score factors

What affects your score?

Exposed credentials

Email addresses and passwords discovered in stealer logs, breach dumps, and dark web marketplaces. Even old credentials create risk if passwords are reused.

Open ports & services

Unnecessarily exposed services increase your attack surface. Legacy protocols, admin interfaces and unpatched services all count against you.

Known vulnerabilities

CVEs matched against your external infrastructure. Critical and high-severity vulnerabilities with public exploits have significant score impact.

Dark web mentions

References to your domain, brand, or executive names on dark web forums, paste sites, and threat actor channels.

SSL certificate health

Expired, self-signed, or misconfigured SSL certificates signal poor security hygiene and can enable man-in-the-middle attacks.

Subdomain exposure

Forgotten staging environments, legacy APIs, and subdomains you no longer maintain extend your attack surface beyond your primary domain.

Training completion

How much of their assigned security awareness training your people have finished, and how well they scored on it. Higher completion lowers your risk.

Phishing simulation results

How your team responds to simulated phishing. Opening the email counts against you, clicking the link counts for more, and entering credentials counts for most.

Improve your score

How to move from F to A*.

  1. 01

    Check your dark web exposure

    Start with credential exposure. If your staff email addresses appear in breach data, prompt password resets and enforce MFA immediately.

  2. 02

    Patch and close open ports

    Review your HackRisk recon scan results and close any services that don't need to be publicly accessible. Apply critical patches as a priority.

  3. 03

    Audit your SSL certificates

    Ensure all domains and subdomains have valid, trusted certificates. Enable HSTS and redirect HTTP to HTTPS everywhere.

  4. 04

    Enumerate your attack surface

    Use HackRisk's subdomain and asset discovery to identify forgotten infrastructure. Decommission or secure anything you don't actively maintain.

  5. 05

    Monitor continuously

    Your score reflects your current posture. New breaches, newly discovered subdomains, and new CVEs can change your score overnight. Stay on top of it.

Get your free score.

Find out where your business stands. Your first HackRisk Score is free - no credit card required.

Get your free score