FAQ (Third-Party Risk)

Recorded Future’s Third-Party Intelligence module provides third-party risk teams with comprehensive third-party risk data and analysis. Potential risks associated with third parties include:

These potential risks, along with dozens of other factors, are incorporated into the calculation of a real-time risk score, which is valuable for a quick assessment of the risk associated with third parties.

What is the Third-Party Intelligence module used for?

Recorded Future’s Third-Party Intelligence offering provides cyber risk scores and deep access to the comprehensive data behind them as a fully integrated part of its universal security intelligence platform.

The Recorded Future Third-Party Intelligence module is designed for third-party risk teams that are concerned with risks resulting from partners, vendors, customers, and contractors with which they do business.

Recorded Future’s Third-Party Intelligence module enables organizations to improve their risk management by understanding environmental risk factors affecting their partners and suppliers. Risk management professionals use risk scores to efficiently screen and monitor third parties, and collaborate with security professionals to investigate and remediate specific risks as needed with transparency to the underlying evidence.

This module is not intended to serve as a one-stop compliance litmus test or to provide a final authoritative “credit score.” Rather, Third-Party Intelligence is intended to arm customers with cyber risk insights available externally using Recorded Future’s Security Intelligence Platform to have informed conversations with current and potential business partners.

Who do we score?

Recorded Future currently scores 150,000 of the largest companies in the world. We are constantly evaluating our coverage and will expand over time.

The Third-Party Intelligence module also currently scores only publicly traded and private companies, not geographic and political entities or non-commercial organizations.

What does each criticality level mean?

Each criticality level carries the following implications derived from the risk rule when triggered:

  • High (65–99): Recorded Future has observed indicators of high-severity threats and elevated cyber risk.
  • Moderate (25–64): Recorded Future has observed, over time, indicators of moderate threats and cyber risk.
  • Informational (5–24): Important for general situational awareness.

How can I view my risk score?

Customers of the Third-Party Intelligence module can view their risk score on the relevant Intelligence Card™, which lists the “triggered risk rules” and associated data that compose the risk score. Recorded Future clients can view the full list of the risk rules here.

Since Recorded Future’s risk scores update automatically, once an organization remediates the root cause behind a triggered risk rule, it will be incorporated into the risk score according to automatic age-out criteria and timeliness factors associated with each risk rule.

I’m not a Recorded Future customer. Can I view my risk score?

Scored organizations that are not currently Recorded Future customers can request a limited review of their Third-Party Intelligence risk score here. These reports do not provide the specific score but do show the “triggered risk rules” that determine the overall score for a company and a brief explanation of why they matter.

Generally, we limit these complimentary requests for a company’s risk exposure to once per quarter.

How can I provide feedback on my risk scores?

You can provide feedback on Third-Party Intelligence risk scores here.

How is Recorded Future’s Third-Party Intelligence module different from security rating services?

Recorded Future is an intelligence provider, arming third-party risk teams with relevant information about risks to their third parties. Unlike other services, a Recorded Future third-party risk score is not an assessment or judgement of an organization's overall security posture and behavior. It is a measure of observable risk, backed by detailed evidence that can be used for productive remediation conversations.

Recorded Future uses a broad range of sources across the open web, dark web, and technical sources. Other services may collect their data from different sources or may not consider items like attention on the dark web or leaked credentials in calculating their score. Additionally, Recorded Future incorporates proprietary research from our industry-leading Insikt Group unique to Recorded Future.

How is the risk score calculated? Where does the data come from?

Third-Party risk scoring aggregates information from Recorded Future’s industry-leading data set that includes sources from the open, deep, and dark web, along with technical and proprietary sources. Recorded Future relies exclusively on external data, and does not engage in active scanning of organizations.

Fairness, accuracy, and transparency

To ensure fairness and accuracy in Recorded Future’s Third-Party Intelligence module, Recorded Future is committed to the following principles: