Back to 360 Playbooks
Security Ratingsintermediate

What Increases or Lowers a Rating

Severity-weighted findings, attack surface, domain health, and reputation signals that move the score.

SecurityAudit360 Team
6/25/2026
5 min read
ratingsfindingsexposure

What Increases or Lowers a Rating

Who this is for: Analysts reviewing why a vendor scored high or low.

What you'll learn:

  • Primary signal layers
  • How severity weighting works
  • Why scores change over time

Signal layers

Ratings combine intelligence from multiple indexes:

Attack surface & infrastructure

Internet-facing ports, exposed services, misconfigurations, and certificate issues. Critical/high, reachable findings reduce the score most.

Domain & email health

DNS hygiene, SPF/DKIM/DMARC gaps, weak TLS, and risky subdomain exposure.

Findings severity

Issues are tagged critical → informational. Critical and high items weigh more than low/informational noise.

Reputation (plan-dependent)

News, social, and brand signals may influence the composite view on Premium+ when technical scores and external sentiment diverge.

What moves the score quickly

Event Typical impact
New critical internet-facing finding Larger drop
Resolved misconfiguration on re-scan Improvement
Stale index / incomplete coverage Conservative or shifting score until re-audit

Investigate on the profile

  1. Unlock the vendor (unlock guide).
  2. Read attack surface, domain, and recon.
  3. Request re-audit if data looks outdated.

Related articles

Still stuck? FAQ — data updates

Last updated: 6/25/2026