QKS Logo
QKS Library Icon

QKS Library

NewsroomSPARK Plus™Sign In
QKS Logo

18.09.2025

QKS Review

QKS Review: The Incomplete Rating - How Excluding Dark Web Data Distorts Cyber Risks

Author:

Arpita Dash

backgroundImage
FolderIcon

Executive Summary:

As the Cyber Risk Rating (CRR) market faces rising pressure from sophisticated adversaries, expanding supply chain ecosystems, and regulator demands for measurable cyber resilience, organizations are moving beyond traditional hygiene-based scoring tools.
This review blog by QKS Group assesses whether CRR vendors are truly innovating to incorporate dark web intelligence or merely extending posture-driven models with incremental updates.

What Modern Cyber Risk Ratings Should Deliver:
Today’s platforms must go beyond surface scanning and compliance mapping. Critical next-gen capabilities include:

  • Native dark web and underground intelligence integration to connect posture with adversary intent.
  • Dynamic, near real-time monitoring that correlates breaches, leak sites, and active campaigns with enterprise exposure.
  • Contextualized prioritization that fuses asset criticality with underground threat visibility to guide remediation.

Key Findings:

  • Leading vendor: Recorded Future integrates dark web telemetry natively into its Intelligence Cloud, making ratings predictive by tying exposures to active threat actor behavior.
  • Capable vendors: SecurityScorecard and Bitsight provide broad scoring coverage with limited credential monitoring but treat dark web signals as secondary inputs.
  • Lagging vendors: RiskRecon and Black Kite remain posture-centric or compliance-centric, leaving end users without visibility into adversary chatter that signals imminent threats.

Cyber Risk Rating (CRR) platforms market themselves as objective measures of organizational security posture. They scan for exposed services, outdated software, weak encryption, and configuration errors, rolling these hygiene indicators into a score that procurement, insurers, and governance teams rely upon. While these posture signals have value, they overlook a dimension that often matters more: the Dark Web.

The dark web is not a single place but a network of hidden forums, encrypted marketplaces, ransomware leak sites, and communication channels where threat actors exchange stolen credentials, trade exploits, and coordinate campaigns. By systematically collecting and correlating this intelligence, risk platforms can detect whether a company’s data is already compromised, whether its assets are being discussed in underground circles, or whether specific actors are planning attacks.

For end users, this information changes the equation. A flagged expired certificate or outdated port configuration might indicate poor hygiene, but a leaked privileged credential offered on a criminal marketplace is a direct breach precursor. Incorporating underground telemetry enables risk ratings to shift from static posture snapshots to dynamic threat indicators. This means enterprises can prioritize what adversaries are actually targeting, accelerate remediation for exposures that matter, and improve vendor oversight by factoring in intent, not just hygiene.

Yet, most Cyber Risk Rating platforms still fall short. This review evaluates prominent vendors, Recorded Future, Bitsight, SecurityScorecard, RiskRecon and Black Kite to assess how they address, or ignore, the dark web dimension.

Recorded Future

Recorded Future integrates CRR into its broader Intelligence Cloud, where dark web visibility is a native component rather than an add-on. The platform collects intelligence from forums, ransomware groups, leak sites, and marketplaces, linking posture flaws to active campaigns. If a VPN service is outdated, Recorded Future doesn’t just mark it as a hygiene issue, it correlates the finding with exploit chatter or ransomware targeting. This elevates risk ratings from static compliance artifacts to predictive signals tied to adversary operations.

Recorded Future’s underground visibility is unmatched, but its overall coverage of rated organizations is narrower than some broad-market competitors. End users benefit from threat-informed ratings, yet may miss visibility into lower-tier suppliers, limiting applicability for enterprises that require universal ecosystem benchmarking.

Bitsight

Bitsight, the pioneer of CRR, is widely used by insurers and regulators. It extends beyond hygiene by incorporating credential leak detection and statistical models to correlate exposure with breach probability. However, its underground monitoring is largely limited to compromised credentials, with minimal visibility into exploit chatter, malware campaigns, or ransomware targeting. Dark web signals influence scoring, but they are treated as an adjunct to the core external scanning model. This creates a partial connection to adversary activity, but the platform’s predictive value remains bounded by its hygiene-heavy weighting.

Bitsight remains the most established risk rating brand, but with dark web intelligence peripheral, end users miss timely context about whether attackers are actively preparing campaigns. They receive risk correlations built on statistical probability rather than direct adversary intent, which can leave them underprepared for imminent threats.

SecurityScorecard

SecurityScorecard is one of the most recognized Cyber Risk Rating vendors, with ratings on millions of organizations. It integrates credential monitoring through third-party breach data, alerting when corporate accounts appear in dumps. This feature provides some visibility into compromised user data but does not extend to adversary forums or ransomware ecosystems. As a result, underground telemetry remains secondary to surface hygiene factors such as SSL configurations, patch cycles, or DNS records. The weighting ensures that most downgrades in score stem from observable technical missteps rather than adversary activity.

SecurityScorecard’s breadth of scoring is unmatched, but the absence of native dark web integration means end users miss visibility into whether observed vulnerabilities are actively exploited. Instead of separating high-priority exposures from background noise, they are left with posture-driven ratings that may underrepresent imminent threats.

RiskRecon

RiskRecon sets itself apart by contextualizing external observations. A vulnerable server hosting a business-critical application is scored differently from one hosting a trivial service. This business relevance is a step beyond hygiene, allowing organizations to focus on assets that matter. However, the model does not incorporate underground activity. A critical system may be flagged appropriately, but whether it is already listed in an exploit kit or discussed on a ransomware forum is invisible to the score. This creates a disconnect between asset prioritization and threat targeting.

RiskRecon helps enterprises align remediation with business impact, but end users lose insight into whether their most valuable assets are being targeted or traded underground. This prevents them from combining asset criticality with adversary activity to build a true picture of risk.

Black Kite

Black Kite approaches CRR through compliance and quantification. Its scoring framework maps posture to standards and includes a model for ransomware susceptibility. While this provides value for governance reporting, the dark web dimension is limited. Credential leaks are captured, but deeper monitoring of threat actor communities, marketplaces, or exploit kits is not a native strength. This results in ratings that align well with regulatory expectations but underrepresent dynamic threat conditions.

Black Kite delivers strong compliance fit, but end users gain audit-ready ratings at the cost of underground awareness. They may satisfy governance frameworks while missing real-time exposure flagged by adversaries, limiting the ratings’ usefulness for proactive defense.

Final Verdict

Dark web intelligence is the missing layer in most Cyber Risk Rating platforms. Recorded Future stands apart, embedding dark web signals as a primary driver of ratings and shifting from posture visibility to threat visibility. SecurityScorecard and Bitsight capture credential leaks but keep underground data peripheral. RiskRecon introduces asset context but ignores adversary chatter. Black Kite aligns closely with compliance, leaving them blind to dynamic threat conditions.

The divide is clear: most CRR vendors inform on where organizations are weak, but only Recorded Future informs on how adversaries plan to exploit those weaknesses. Until competitors elevate underground intelligence to the same level as hygiene metrics, CRR will remain incomplete, reducing its predictive value and leaving enterprises exposed to risks that manifest first in the hidden corners of the web.

Disclaimer:

This blog is based on independent research and publicly available information. The insights presented reflect the views of QKS Group and are for informational purposes only. While we strive for accuracy, we do not guarantee completeness or absolute correctness. Vendors are welcome to provide clarifications or updates. If any vendor listed in this analysis wishes to provide additional context or clarification, we welcome a briefing call and will consider incorporating relevant updates. This analysis is not intended to disparage any vendor but to provide an informed, balanced perspective. We encourage open and constructive dialogue to foster transparency and a deeper understanding of the industry.

Author: Arpita Dash, Analyst - Security Analytics and Automation at QKS Group

Vendors: