The third-party cyber risk platform that grades your vendors the way an attacker would - then tells you what it will cost if they fail.
Boston, Massachusetts. Founded 2016 as NormShield. A company that built its reputation by looking at the internet the way a burglar looks at a street: for the unlocked doors.
Most companies spend fortunes hardening their own defenses, and then hand a set of keys to a payroll processor, a cloud host, or a law firm they have never audited. Black Kite was built on the observation that breaches rarely start at the front door. They start with a vendor. The Boston company rates the cyber health of those vendors continuously, from the outside, using only what an attacker could already see.
That outside-in stance is the heart of the pitch. Traditional third-party risk management runs on questionnaires - long spreadsheets a vendor fills out once a year and, often, half-heartedly. Black Kite skips the survey. It scans a company's internet-facing footprint, correlates the findings against recognized standards, and produces a rating without ever touching the target's network. The vendor can then validate the results, but the starting point is evidence rather than self-attestation.
The company is not shy about where the idea came from. Co-founder and chief technology officer Candan Bolukbas spent part of his career working with NATO, helping member nations spot weaknesses in the third-party networks that threatened their national security. He realized the framework he was testing against nation-states had an obvious commercial life. In 2016 he and co-founder Mohamoud Jibrell turned that insight into a product, first under the name NormShield.
Black Kite's platform pulls three jobs into one place. It assesses a vendor's external security posture and assigns a letter-grade technical rating. It monitors that posture continuously, because an attacker does not wait for the annual review. And it helps teams respond - flagging which vendors are exposed to a specific emerging vulnerability so the queue sorts itself by urgency rather than alphabetical order.
Two features do most of the differentiating. The first is the Ransomware Susceptibility Index, a predictive score that estimates how likely a company is to end up on a ransomware crew's target list. The second is Open FAIR financial modeling, which converts a vendor's exposure into a probable dollar loss. A letter grade is easy for an executive to wave away. A number with a currency symbol in front of it tends to stay in the room.
RSI is a single number between 0.0 and 1.0. Unlike a purely technical score, it blends what an attacker can exploit - misconfigurations, exposed remote ports, leaked credentials, botnet chatter - with intrinsic factors like industry, geography, and company size. The result is less "how healthy is this network" and more "how attractive and reachable is this target."
Standards-based third-party cyber risk management - external assessment, continuous monitoring, and response across the entire vendor ecosystem.
A 0.0-1.0 predictive score blending technical indicators with industry, size, and geography to estimate ransomware likelihood.
A letter-grade view of a company's internet-facing attack surface, built from open-source, non-intrusive data only.
Translates vendor cyber exposure into a probable financial loss, moving the conversation to the boardroom.
Automatically maps external findings to a dozen-plus frameworks - NIST, ISO 27001, PCI-DSS, GDPR, HIPAA and more.
Timely tags flag which vendors are affected by a specific emerging vulnerability or active campaign, so response can be prioritized.
Security ratings is not an empty field. Black Kite shares the market with BitSight, SecurityScorecard, RiskRecon and UpGuard, all of which grade external cyber posture. Black Kite's differentiation is less about the raw scan and more about interpretation: a ransomware-specific prediction, a financial-loss estimate, and automated mapping to compliance standards - packaged for third-party risk teams rather than security engineers alone.
| Approach | Questionnaire tools | Black Kite |
|---|---|---|
| Data source | Vendor self-report | Outside-in, open-source intelligence |
| Cadence | Annual snapshot | Continuous monitoring |
| Ransomware view | Rarely modeled | Predictive RSI score |
| Executive output | Pass / fail grade | Open FAIR dollar impact |
Black Kite has raised more than $33 million. The headline round was a $22 million Series B in October 2021, led by Volition Capital, with participation from existing investors. The company said the capital would go toward marketing, customer success, channels, and strategic partnerships - the machinery of turning a strong product into a category leader.
Candan Bolukbas and Mohamoud Jibrell begin building security ratings from a hacker's perspective.
The company introduces its predictive RSI score for ransomware likelihood.
NormShield becomes Black Kite in January and relocates from Vienna, VA to Boston, MA.
Volition Capital leads a round to expand the platform and go-to-market.
RSI computation updated to reflect emerging risk indicators alongside yearly ransomware research.
The company frames its mission broadly - "to improve the health and safety of the entire planet's cyber ecosystem" - and its vision around a world where cyber risk no longer slows business down. Internally it leans on five stated values: People First, Act with Integrity, Innovate with Purpose, Foster Inclusivity, and Strive for Excellence, Not Perfection. Leadership points to a combined 200-plus years of cybersecurity experience across the team.
It rates and continuously monitors the cyber risk posed by an organization's third-party vendors and supply chain - using non-intrusive external assessments, ransomware scoring, compliance mapping, and financial-impact modeling.
No. It was founded in 2016 as NormShield and rebranded to Black Kite in January 2021, when it also moved its headquarters to Boston.
RSI is a score between 0.0 and 1.0 estimating how likely a company is to be targeted by ransomware, based on technical indicators and intrinsic factors like industry and size.
It assesses vendors from the outside using open-source intelligence - no survey required and no access to the vendor's network - then translates findings into ratings and financial impact.
Its main competitors in the security ratings and third-party cyber risk space are BitSight, SecurityScorecard, RiskRecon, and UpGuard.