Our Hackability Score puts organisations on a single scale from an Internet survey alone, which makes comparison across industries and regions possible. It reads four things an outsider can see: identity and access management, security architecture, asset hardening and patch management. We built it by scanning more than 5,000 companies across geographies and verticals. In that data, from 2018, banks came out among the three best-protected industries. The score reads only what is visible from the Internet. It says nothing about endpoint security and nothing about whether anyone inside those banks would click a link, and we have not re-run it since.
How
Internet-wide scanning across four directly measurable areas, scored per organisation and aggregated by industry and region.
What it does not support
It reads only what is visible from the Internet. It says nothing about endpoint security and nothing about social-engineering resilience, and it has not been re-run since 2018.
The Hackability of organizations can be measured and comparedBanks scored above other industries, but not evenly across the sub-scores: the areas an auditor looks at were ahead, and the areas an auditor does not were behind. Regulation moved attention, not security.
How
Compared the shape of the Hackability sub-score distribution for banks against other industries, testing two competing explanations: security evolution under attack pressure, versus compliance-directed effort.
Banking regulation has an effect on Hackability