NEW BLOG
Cisco ThousandEyes Comes to Cisco Cloud Control

Industry

Beyond the Scorecard – Why Automated Security Ratings Don’t Tell the Whole Story

By Ryan Hogan
| | 6 min read

Summary

Automated security ratings often fail to capture the depth of internal controls and the specific operational requirements of sophisticated platforms like Cisco ThousandEyes. This article explores the limitations of "outside-in" scanning and explains why context-aware assessments are essential for a true understanding of security posture.


In the modern era of Third-Party Risk Management (TPRM), security professionals are increasingly presented with automated security rating services. These platforms promise a simple, "outside-in" view of an organization’s security posture, often represented as a single numerical score. While these tools can provide a high-level pulse check, they often fail to capture the nuanced, dynamic reality of complex, global technology enterprises like Cisco and the Cisco ThousandEyes business unit.

When we see reports from automated services, it is important to understand that these scores are not a substitute for a comprehensive security audit. Here is what these automated assessments may not show.

1. The "Outside-in" Visibility Gap

Automated rating services rely primarily on public-facing data—scanning open ports, analyzing DNS configurations, and monitoring for leaked credentials on the dark web. While this provides a snapshot of the perimeter, it is fundamentally an "outside-in" view.

It fails to account for:

  • Compensating Controls: A service that appears "exposed" from the outside may be shielded by rigorous internal identity and access management controls (IAM), multi-factor authentication (MFA), or zero-trust network access (ZTNA) policies that an external scanner may not detect.

  • Internal Security Architecture: Security is not just about what is public; it is about the depth of defense-in-depth strategies, internal segmentation and the maturity of an organization’s Security Operations Center (SOC).

2. Scanners and ThousandEyes

ThousandEyes is a digital experience assurance platform that measures network and application performance across Internet paths, cloud providers and SaaS applications. By its very nature, the infrastructure that powers ThousandEyes must be highly visible and distributed to provide accurate network performance data.

Automated scanners often struggle to differentiate between:

  • Intentional Exposure: Services that are intentionally public facing to perform their business function.

  • Vulnerabilities: Confirmed security issues.

When a scanner flags a public endpoint as a "risk," it may lack the business context to recognize that the endpoint is a managed and monitored component of our measurement network rather than a misconfigured server.

3. The Methodology Problem: Static Snapshots vs. Dynamic Security

Security is a continuous, evolving process. Automated rating services often provide a static snapshot based on a specific moment in time. However, a large enterprise’s attack surface changes by the minute.

Furthermore, each provider applies its own scoring methodology, and the factors behind a given score are not always disclosed. When a score drops, it is frequently difficult for the organization to trace the root cause to a specific, actionable vulnerability. This leads to "alert fatigue" rather than meaningful security improvements. As Cisco’s security team investigates the findings raised by these services, the assessment methodology do not consistently reflect the complexity of our multi-layered security posture, as they lack the necessary context.

4. The Need for Context-Aware Assessment

For security professionals, the goal is to reduce risk, not just to manage a score. Relying on automated ratings can lead to a "checkbox" mentality that ignores real, high-impact threats.

Instead of relying solely on automated scores, we encourage our customers and partners to look at:

  • Validated Assurance: Reviewing our SOC 2 Type II report, ISO 27001 certifications, and other third-party attestations that provide an independently assessed view of the controls in scope for those audits.

  • Transparency: Reviewing the Security Brief prepared by our security team which discusses specific architecture and risk management practices.

  • Risk-Based Analysis: Focusing on the controls that help protect data and business logic, rather than external indicators discussed above.

  • Ongoing vulnerability management: As risks and vulnerabilities are identified by our internal and external testing, we review and remediate confirmed vulnerabilities based on their risk.

Conclusion

While automated security ratings can serve as a starting point for understanding a vendor’s security posture, they are not a definitive measure of an organization's security health. At Cisco and ThousandEyes, security is a key focus for our business. We utilize internal review processes, conduct ongoing monitoring, and maintain a commitment to transparency with our customers. We encourage our customers to look beyond the scorecard and review the security resources available through the Cisco Trust Portal to better understand the security measures we have in place.

related blogs

Upgrade your browser to view our website properly.

Please download the latest version of Chrome, Firefox or Microsoft Edge.

More detail

Subscribe to the ThousandEyes Blog

Stay connected with blog updates and outage reports delivered while they're still fresh.