Your risk score

Your HackRisk Score, explained.

Your HackRisk Score is a real-time measure of your organisation's cybersecurity risk, shown as a percentage and graded A* to F.

It aggregates dark web monitoring, external reconnaissance and vulnerability scanning into a single, actionable number.

How it's calculated

A score built from real threat data.

Findings from each of these intelligence streams feed into a single score, so one view covers everything an attacker can see. Only the services you have switched on count towards it, and your weakest area carries the most weight, so the fastest way to move your score is to fix whatever is worst rather than whatever is easiest.

The result is a risk percentage from 0 to 100, where lower is better, translated into a letter grade, the same idea that makes credit scores and energy ratings immediately understandable. The grade runs the other way to the percentage: A* is the best grade and sits at the lowest risk.

Dark web monitoring
Recon & attack surface
Vulnerability scanning
SSL & config health
Grade system

What does your grade mean?

A HackRisk grade is the letter, from A* down to F, that sits beside your risk percentage and says how serious your exposure is. The percentage runs the opposite way to a school mark, because it measures risk rather than achievement: a low number is the good one. A* covers 0 to 9 per cent and A covers 10 to 24 per cent, and both count as low risk. B and C span 25 to 49 per cent and count as medium risk, where nothing critical has turned up but real issues exist. D and E, from 50 to 74 per cent, are high risk. Anything at 75 per cent or above is an F and counts as critical, which often means credentials are already circulating. The grade is there so you can see where you stand before reading a single finding.

A*
Low risk
Score: 0–9%

Your external posture is strong. No critical exposures detected, credentials are clean and your attack surface is well managed.

A
Low risk
Score: 10–24%

Few or minimal vulnerabilities identified. They should still be addressed, but none require urgent remediation.

B
Medium risk
Score: 25–36%

Minor issues are present but no critical exposures. Routine remediation and monitoring will bring this down.

C
Medium risk
Score: 37–49%

Several exposures exist that should be addressed. Attackers probing your perimeter may find something exploitable.

D
High risk
Score: 50–62%

Significant exposure that leaves your systems vulnerable to a threat actor. These findings want attention soon.

E
High risk
Score: 63–74%

Serious weaknesses across your external surface. Remediation should be planned and started rather than queued.

F
Critical risk
Score: 75%+

Severe exposure identified. Credentials may already be compromised. Immediate remediation is advised.

Score factors

What affects your score?

Eight signals feed a HackRisk Score, and they split into what an attacker can see and how your people behave. The external six are credentials exposed in breach data and stealer logs, open ports and services, known CVEs matched against your infrastructure, mentions of your domain or your executives on dark web forums, the health of your SSL certificates, and subdomains you may have forgotten you own. The human two are how much security awareness training your staff have finished and how they handle a simulated phishing email. That last one is weighted by what someone actually did: opening the email counts against you, clicking the link counts for more, and entering credentials counts for most. Only the services you have switched on are counted, and your weakest area carries the most weight. Old credentials still count against you, because people reuse passwords.

Exposed credentials

Email addresses and passwords discovered in stealer logs, breach dumps, and dark web marketplaces. Even old credentials create risk if passwords are reused.

Open ports & services

Unnecessarily exposed services increase your attack surface. Legacy protocols, admin interfaces and unpatched services all count against you.

Known vulnerabilities

CVEs matched against your external infrastructure. Critical and high-severity vulnerabilities with public exploits have significant score impact.

Dark web mentions

References to your domain, brand, or executive names on dark web forums, paste sites, and threat actor channels.

SSL certificate health

Expired, self-signed, or misconfigured SSL certificates signal poor security hygiene and can enable man-in-the-middle attacks.

Subdomain exposure

Forgotten staging environments, legacy APIs, and subdomains you no longer maintain extend your attack surface beyond your primary domain.

Training completion

How much of their assigned security awareness training your people have finished, and how well they scored on it. Higher completion lowers your risk.

Phishing simulation results

How your team responds to simulated phishing. Opening the email counts against you, clicking the link counts for more, and entering credentials counts for most.

Improve your score

How to move from F to A*.

Improving a HackRisk Score means working through the findings worst first, because the weakest area carries the most weight. Start with credential exposure: if staff addresses appear in breach data, force password resets and turn on multi-factor authentication. Then read your recon scan and close any service that has no reason to be reachable from the internet, applying critical patches ahead of anything else. Check next that every domain and subdomain has a valid, trusted certificate and that HTTP redirects to HTTPS. After that, use subdomain and asset discovery to surface infrastructure you had forgotten, then decommission or secure it. Then keep watching, because your score describes today. A new breach dump, a subdomain someone spins up, or a freshly published CVE can move it overnight. The order matters more than the pace: each step clears the exposure the next one would otherwise trip over.

  1. 01

    Check your dark web exposure

    Start with credential exposure. If your staff email addresses appear in breach data, prompt password resets and enforce MFA immediately.

  2. 02

    Patch and close open ports

    Review your HackRisk recon scan results and close any services that don't need to be publicly accessible. Apply critical patches as a priority.

  3. 03

    Audit your SSL certificates

    Ensure all domains and subdomains have valid, trusted certificates. Enable HSTS and redirect HTTP to HTTPS everywhere.

  4. 04

    Enumerate your attack surface

    Use HackRisk's subdomain and asset discovery to identify forgotten infrastructure. Decommission or secure anything you don't actively maintain.

  5. 05

    Monitor continuously

    Your score reflects your current posture. New breaches, newly discovered subdomains, and new CVEs can change your score overnight. Stay on top of it.

Get your free score.

Find out where your business stands. Your first HackRisk Score is free - no credit card required.

Get your free score