Back to 360 Playbooks
Security Ratingsintermediate
What Increases or Lowers a Rating
Severity-weighted findings, attack surface, domain health, and reputation signals that move the score.
SecurityAudit360 Team
6/25/2026
5 min read
ratingsfindingsexposure
What Increases or Lowers a Rating
Who this is for: Analysts reviewing why a vendor scored high or low.
What you'll learn:
- Primary signal layers
- How severity weighting works
- Why scores change over time
Signal layers
Ratings combine intelligence from multiple indexes:
Attack surface & infrastructure
Internet-facing ports, exposed services, misconfigurations, and certificate issues. Critical/high, reachable findings reduce the score most.
Domain & email health
DNS hygiene, SPF/DKIM/DMARC gaps, weak TLS, and risky subdomain exposure.
Findings severity
Issues are tagged critical → informational. Critical and high items weigh more than low/informational noise.
Reputation (plan-dependent)
News, social, and brand signals may influence the composite view on Premium+ when technical scores and external sentiment diverge.
What moves the score quickly
| Event | Typical impact |
|---|---|
| New critical internet-facing finding | Larger drop |
| Resolved misconfiguration on re-scan | Improvement |
| Stale index / incomplete coverage | Conservative or shifting score until re-audit |
Investigate on the profile
- Unlock the vendor (unlock guide).
- Read attack surface, domain, and recon.
- Request re-audit if data looks outdated.
Related articles
Still stuck? FAQ — data updates
Last updated: 6/25/2026