Skip to main content

Cybersecurity Risk Assessment Methodology

How Does Mastercard Assess Cybersecurity Risk?

Nora Tumanyan avatar
Written by Nora Tumanyan
Updated over 3 weeks ago

Q: What is Mastercard’s cybersecurity rating and why does it matter?
Mastercard provides a cybersecurity risk rating that reflects an organization’s external cyber hygiene and the likelihood of real-world incidents like data breaches or ransomware attacks.

Q: What does the score represent?
The score is an A–F grade (based on a 0–10 numeric scale).

  • A = Excellent hygiene, lowest breach rates

  • F = High risk, up to 35x more likely to experience breaches

Q: How is it used?
It helps organizations evaluate partners and vendors, prioritize remediation, and manage third-party risk.

Q: What is the score based on?
It’s based on cybersecurity issues observed across external systems, weighted by how important the systems are and how severe the issues are.

Q: Is the scoring model based on real-world data?
Yes. The model reflects real security incidents, including 6,999 breach events and 817 ransomware cases, across a monitored population of 150,000+ organizations.

Did this answer your question?