Pros and Cons of Hiring a Security Rating Agency

Oct 19, 2017

By Jennifer Thompson

See all of Our JDSupra Posts by Clicking the Badge Below

View Patrick Law Group, LLC

One can hardly check out any news outlet today without reading or hearing about a security breach.  Experts frequently advocate performing internal assessments to identify security weaknesses.  Commentators tout the importance of assessing the security of the entities with which you do business.  Investors, partners and markets shy away from companies that are not proactive enough with respect to security. Given the multitude of variables involved and security measures available, how can a company convey the effectiveness of its own security program in a meaningful manner? Further, given how fact and business-specific that security is, how can one company compare its own security measures to those taken by another company?  Many companies turn to independent ratings agencies for an objective evaluation and systematized rating.

Security rating agencies are becoming instrumental in helping companies evaluate security risks and potential transactions.  Investors in start-ups will use such ratings to evaluate risks and identify future investment needs of the entity.  Security ratings are a critical part of due diligence review in mergers, acquisitions and joint ventures.  Procurement departments routinely require vendors to obtain ratings before entering into agreements.  Some companies may even request that a rating agency evaluate its own operations to identify weak points and opportunities for improvement.

In compiling the ratings, the rating agencies compile public and private data points, feed them into the agency’s proprietary algorithm and generate a “score.”  Scores can be used to measure one entity’s security efforts against others.  Of course, the rating is only as reliable as the entity providing it, so is it worth it to expend the money on these services?  Similarly, once a score is obtained, can it harm your business?  Will others deem your score too low?  Will the publication of your score actually hamper prospects operations?  Or worse, will having a low score published ultimately make you a more attractive target to would-be hackers?

Fortunately, some forty-odd companies and the US Chamber of Commerce identified the need for suggesting a standardized methodology for the security rating agencies.  In June 2017, these companies and the US Chamber of Commerce issued the Principles for Fair and Accurate Security Ratings (the “Principles”).

The Principles seek to establish guidelines for fair and accurate reporting of security ratings and promote standards for the appropriate use and disclosure of the scores.  The Principles suggest that all security rating agencies should:

  • provide transparency of the methodologies and data used to create the rating;
  • provide a mechanism by which entities that are rated can dispute, correct and/or appeal any rating published by the ratings agencies;
  • provide advance notice of any changes to ratings methodologies so that rated companies are clear on how the procedural changes may affect their scores;
  • remain independent of the entities they rate; and
  • maintain confidentiality of all sensitive information (including information shared during disputes, non-public ratings and other private information).

Hopefully, the Principles will result in greater consistency among rating agencies, increased reliability in the scores and more efficiency in the ratings process itself.  All of these Principles ideally will lead to candid discussions among business partners as to how entities can improve their security and, more importantly, suffer fewer breaches.

Of course, every company must assess whether to have itself rated and how to utilize and share any scores it obtains from the various rating agencies.  But assuming the agency retained to provide the security rating is in compliance with the Principles, at least buyers of these services can be reasonably certain they are receiving a truly objective measure with full opportunity to appeal or clarify any questions with respect to the score.

So, if your entity uses a security rating agency, make sure it is one that is operating in compliance with the Principles for Fair and Accurate Security Ratings espoused by the Chamber of Commerce.


Good, Bad or Ugly? Implementation of Ethical Standards In the Age of AI

By Dawn Ingley See all of Our JDSupra Posts by Clicking the Badge Below With the explosion of artificial intelligence (AI) implementations, several technology organizations have established AI ethics teams to ensure that their respective and myriad uses across...

IoT Device Companies: The FTC is Monitoring Your COPPA Data Deletion Duties and More

By Jennifer Thompson See all of Our JDSupra Posts by Clicking the Badge Below Recent Federal Trade Commission (FTC) activities with respect to the Children’s Online Privacy Protection Act (COPPA) demonstrate a continued interest in, and increased scrutiny of,...

Predictive Algorithms in Sentencing: Are We Automating Bias?

By Linda Henry See all of Our JDSupra Posts by Clicking the Badge Below Although algorithms are often presumed to be objective and unbiased, recent investigations into algorithms used in the criminal justice system to predict recidivism have produced compelling...

My Car Made Me Do It: Tales from a Telematics Trial

By Dawn Ingley See all of Our JDSupra Posts by Clicking the Badge Below Recently, my automobile insurance company gauged my interest in saving up to 20% on insurance premiums.  The catch?  For three months, I would be required to install a plug-in monitor that...

When Data Scraping and the Computer Fraud and Abuse Act Collide

By Linda Henry See all of Our JDSupra Posts by Clicking the Badge Below As the volume of data available on the internet continues to increase at an extraordinary pace, it is no surprise that many companies are eager to harvest publicly available data for their own use...

Is Your Bug Bounty Program Uber Risky?

By Jennifer Thompson See all of Our JDSupra Posts by Clicking the Badge Below In October 2016, Uber discovered that the personal contact information of some 57 million Uber customers and drivers, as well as the driver’s license numbers of over 600,000 United States...

IoT Device Companies: COPPA Lessons Learned from VTech’s FTC Settlement

By Jennifer Thompson See all of Our JDSupra Posts by Clicking the Badge Below In “IoT Device Companies:  Add COPPA to Your "To Do" Lists,” I summarized the Federal Trade Commission (FTC)’s June, 2017 guidance that IoT companies selling devices used by children will be...

Beware of the Man-in-the-Middle: Lessons from the FTC’s Lenovo Settlement

By Linda Henry See all of Our JDSupra Posts by Clicking the Badge Below The Federal Trade Commission’s recent approval of a final settlement with Lenovo (United States) Inc., one of the world’s largest computer manufacturers, offers a reminder that when it comes to...

#TheFTCisWatchingYou: Influencers, Hashtags and Disclosures 2017 Year End Review

Influencer marketing, hashtags and proper disclosures were the hot button topic for the Federal Trade Commission (the “FTC”) in 2017, so let’s take a look at just how the FTC has influenced Social Media Influencer Marketing in 2017. First, following up on the more...

Part III of III | FTC Provides Guidance on Reasonable Data Security Practices

By Linda Henry See all of Our JDSupra Posts by Clicking the Badge Below This is the third in a series of three articles on the FTC’s Stick with Security blog. Part I and Part II of this series can be found here and here. Over the past 15 years, the Federal Trade...