See.Tech

Cyber risk scoring

Turn External Cyber Exposure into a Risk Score You Can Act On

The See.Tech external risk score is a single number from 0 to 100 that summarises how exposed an organisation is to the public internet. A higher score is better: 100 represents no material external exposure found, and a low score indicates significant exposure.

The score exists so that a technical assessment can be discussed by people who will never read a CVSS vector, without discarding the detail underneath it.

Risk Classification, illustrative example
84 / 100 Medium
Breached accounts 96
Dark web exposure 88
Email security 41
IP and domain reputation 79
SSL / TLS 52
Vulnerabilities 33
Healthy Needs attention Act now

The example above is illustrative, not a real customer result. It shows the shape of a typical first assessment: strong in some categories, weak in others, with an overall score that would be misleading without the breakdown beneath it.

What contributes

The categories behind the score.

The overall score is a weighted view of category scores. Each category is scored independently, so a single weak area is visible rather than being averaged away.

CategoryWhat raises the scoreWhat lowers it
VulnerabilitiesNo known vulnerabilities on internet-facing softwareReachable services with known vulnerabilities, weighted by CVSS severity
Breached accountsNo credentials for the domain in breach corporaCredentials exposed, weighted by how many and how recent
Dark web exposureNo references to the organisation on monitored sourcesCompany data or credentials appearing on leak sites and forums
Email securitySPF, DKIM and DMARC correctly configured and enforcingMissing DKIM, permissive SPF, or DMARC set to none
SSL / TLSModern protocols, strong ciphers, valid certificatesLegacy TLS versions, weak ciphers, expired or expiring certificates
IP and domain reputationClean reputation across threat intelligence sourcesListed infrastructure, or lookalike domains registered against the brand

Reading the score

The same number, two audiences.

For executives

A position, and a direction of travel

The score answers "are we more or less exposed than last quarter?" in one number. Its value is comparability over time and against an anonymised peer cohort in the same industry and region, not the absolute figure.

For technical teams

An ordered work queue

The category breakdown shows where the score is being lost, and the findings under each category are ranked by severity. The lowest category is usually where remediation buys the most improvement.

How it moves

Remediation, then rescan

The score changes when the underlying exposure changes and a rescan observes it. Rescans can be scheduled weekly or monthly, and change detection flags material changes between them with a timestamp and severity.

What it is not

Not a guarantee, and not a substitute

A high score means little material exposure was observable from outside. It says nothing about internal controls, endpoint security, insider risk or whether a vulnerability is genuinely exploitable in your configuration.

Questions

Cyber risk scoring, answered.

What is a cyber risk score?

A cyber risk score summarises an organisation's security exposure as a single figure so that it can be tracked over time and communicated to people who do not read technical findings. The See.Tech external risk score runs from 0 to 100 and reflects exposure observable from the public internet.

Is a higher or lower score better?

Higher is better. A score of 100 means no material external exposure was found. A low score means significant exposure was observed across one or more categories.

What does a score of 84 mean?

It means the overall external position is reasonable but at least one category is materially weak. The overall figure is always read alongside the category breakdown, because a single critical category can sit beneath a comfortable-looking total.

How often does the score change?

It changes when a rescan observes a change in the underlying exposure. Rescans can be scheduled weekly or monthly, and environmental change detection flags material changes between scheduled scans with a timestamp and a severity.

Can we compare our score to other organisations?

Yes. Industry benchmarking compares the score against an anonymised peer cohort by industry and region, presented as a percentile band alongside your own figure.

Does the score prove we are secure?

No. It reflects what is observable from outside. Internal controls, endpoint security, insider risk and the real exploitability of a given finding are outside its scope, and it should be read as one input rather than a verdict.

Start here

Assess your domain.

A See.Tech assessment starts from a domain name. Nothing is installed, no credentials change hands, and the first findings come back in hours.

Ready to see the threats before they strike?

Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.