Bitsight's Ratings Algorithm Update for 2026 Makes Risk Vectors More Impactful
Article excerpt
Highlighted: the sentence this signal was extracted from
Bitsight's annual Ratings Algorithm Update (RAU) has been in effect as of July 16, 2026 . In preparation, RAU 2026 Preview was made available in April 2026. As in the past, RAU 2026 is an effort to account for the continuous evolution of the threat landscape the Bitsight security ratings seek to quantify. This year's update is focused on modernizing the rating by improving how it is composed from various risk vectors (RVs). In particular, this entails the following: In addition to Sender Policy Framework (SPF) and Domain Keys Identified Mail (DKIM), Domain-based Message Authentication, Reporting, and Conformance (DMARC) constitutes a pillar of modern e-mail security. Specifically, DMARC requires that the domains used for delivering messages (SPF's Mail From or DKIM's d= tag) align with the visible domain in the "From" field of the email, and dictates how receiving servers should handle messages that fail authentication. Details of Bitsight's evaluation of DMARC are available here, with guidance on how to set up a DMARC policy discussed here. Starting in RAU 2026, DMARC accounts for 1% of the Bitsight rating, bringing its impact in line with those of SPF and DKIM. On a related note, Compromised Systems now accounts for 26% of the ratings, instead of the 27% before RAU 2026. For the evaluation of E-Mail Security, an absence of appropriately configured security elements...
Keep reading with a free account
The rest of this article, and every signal for BitSight, is in your free account.
