Methodology
How the Resilience Rating works
No black box. We publish exactly what we measure, how it is weighted, and what moves your score — so you always know how to improve it.
The TrustQuant Resilience Rating is a single 0–100 score derived from verified, agentlessly-collected evidence about your infrastructure. It replaces subjective, self-attested questionnaires with continuous configuration audits across six factor groups. Higher is stronger.
Strong, well-evidenced posture. Best-positioned for premium insurance and lending terms.
Solid posture with minor, well-understood gaps to close.
Notable exposure. Prioritised remediation will move the score quickly.
Critical gaps that materially raise financial and operational risk.
What we measure
Six factor groups, published weightings
The rating is the weighted sum of these groups. The weights are fixed and public — so you always know where to focus.
Access & Identity Controls
What we check: MFA on privileged accounts, least-privilege enforcement, credential rotation, dormant-account detection.
Why it matters: Credential compromise is the fastest path to payment fraud and ransomware — the highest-impact, highest-likelihood failure mode for SMEs.
Host & Server Hardening
What we check: SSH configuration, OS and kernel patch currency, exposed/open ports, unnecessary services.
Why it matters: Unpatched, over-exposed hosts are the exploited entry points behind most opportunistic breaches.
Backup & Recovery Discipline
What we check: Off-site backup coverage, restore-test recency, retention policy, recovery-time posture.
Why it matters: Untested backups turn a containable incident into a business-interruption event — and can invalidate a cyber-insurance claim.
Cloud Configuration & Exposure
What we check: Public storage buckets, security-group rules, encryption settings, configuration drift.
Why it matters: A single public-facing bucket or open security group can expose sensitive customer data and trigger UK GDPR liability.
Data Protection & Encryption
What we check: Encryption at rest and in transit, key management, TLS posture on public endpoints.
Why it matters: Encryption gaps directly affect regulatory exposure and the cost of a notifiable breach.
Operational & Cost Hygiene
What we check: Resource tagging, over-provisioning, orphaned volumes, idle hosts (FinOps signals).
Why it matters: Waste here is the funding source for remediation — good hygiene pays for the upgrades that raise every other factor.
The maths, in the open
The maths, in the open
Your rating is a weighted aggregation of the six factor scores, each normalised to 0–100. Every factor score is itself a priority-weighted roll-up of individual control findings. Because the weights are published and the inputs are verified telemetry, the result is fully auditable — you can trace any point of movement back to a specific control.
Overall rating
Resilience Rating = Σ ( weight_i × FactorScore_i )Per factor
FactorScore_i = Σ ( priority_j × control_finding_j ) / max_iZero incubation latency
Your score moves the moment you do
Legacy platforms make you wait — often up to 90 days — before new risks or fixes affect your live rating, then queue updates behind daily batches. That hides active exposure. TrustQuant re-scores in real time: fix a control and your rating reflects it on the next pass, not next quarter.
No hidden exposure
New risks surface immediately instead of incubating out of sight.
Instant remediation credit
Prove a fix the moment it lands — no waiting to be re-rated.
Always-current Trust Passport
What lenders, insurers and buyers see reflects your posture now.
Comparison reflects incubation and batch-update behaviours documented in public customer reviews of legacy ratings platforms (Gartner Peer Insights and G2, accessed July 2026).
How we govern the score
Transparent by design
Evidence, not attestation
Every point is backed by collected telemetry — never a checkbox someone ticked about themselves.
Transparent weightings
The factor weights above are published. You always know why a change moved your score.
Continuously recalibrated
The model is refined as threats evolve, with weightings reviewed on a scheduled cycle — not silently changed.
Cadence matched to your plan
Monthly, weekly or continuous re-scoring depending on tier, so remediation is reflected promptly.
The TrustQuant Resilience Rating is a designed, evidence-based model intended to help SMEs measure and improve their posture. It is not a credit score issued by a credit reference agency, and insurance or lending outcomes always rest with the relevant underwriter or lender.
See your rating against these factors
Connect agentlessly and get a factor-by-factor breakdown in under 10 minutes.