Cyber posture rating

Understand how MineOS rates a vendor’s cyber posture, what each risk category means, and how to use the rating in vendor reviews.

A vendor's cyber posture rating gives you an outside-in view of how well it protects itself against security threats. MineOS adds the rating to vendors in your inventory automatically, so you can spot weak vendors early, prioritize security reviews, and have better-informed conversations with business owners about which vendors to keep.

What the rating includes

The rating is broken down into four risk categories:

CategoryWhat it covers
ApplicationSecurity of the vendor's public-facing web applications and services
NetworkExposure of the vendor's network, such as open ports and vulnerable services
ITThe state of the vendor's IT infrastructure, such as outdated software or misconfigurations
Human factorRisks related to people, such as exposed credentials or susceptibility to phishing

Each vendor receives an overall rating, from Excellent to Poor.

Where to find it

Open a vendor from your inventory. The cyber posture rating appears on the Details tab. [confirm: section, e.g. TPRM] Click a category to expand it and see how its rating was calculated.

The rating is generated automatically and can't be edited. It's available for vendors that have a public website.

Use the rating in vendor reviews

If the rating isConsider
StrongProceeding with your standard review, and focusing on contractual and privacy safeguards
WeakRunning a full security assessment, asking the vendor for evidence such as a SOC 2 report or ISO 27001 certificate, and flagging the risk in your risk registry
Weak in one categoryFocusing your security questions on that area, for example asking about patching when IT risk is high

Cyber posture is one input, not a final verdict. An outside-in rating can't see internal controls, so combine it with the vendor's documents and assessment answers before deciding.

Where else the rating is used

  • Business impact analysis: compare vendors' cyber posture against how many employees use them and how sensitive their data is. See Analyze business impact across your data sources.
  • Risk suggestions: a weak cyber posture can lead MineOS to suggest risks in the vendor's assessments. See Flagging risks in assessments.
  • Assessments: a template question can show the vendor's current rating, so reviewers see it alongside the vendor's answers. [confirm: rating can be pulled into assessment questions]

Related articles


Did this page help you?