LEET Security's reference service

LEET Rating: Understand and Improve Your Cybersecurity Posture

The LEET Seal is a label that shows the level of cybersecurity of a rated service.

LEET Seal, the cybersecurity rating label for ICT services
  1. LEET Self-Assessment Performed directly by the supplier, without evidence verification
  2. LEET Assessment Our auditors review and evaluate the supporting documentation
  3. This service LEET Rating Rigorous audit process, subject to monitoring mechanisms

The LEET Seal gives a "score" to the security measures integrated by the supplier in the construction and operation of the service, unlike other mechanisms that only certify the implementation of management procedures -such as the ISO/IEC 27001 certification– or certifying product characteristics -Certification Common Criteria-, but in no case establish a quantitative assessment nor do they allow organizations to show the security level in a given service regarding the information or data being handled.

In practical terms it is similar to what happens with hotels: They all require an opening license but not all offer the same number of stars. Likewise, an ICT service must also be provided by an authorized company and possibly have an ISO/IEC 27001 certification, but it is the LEET Seal that indicates not only the number of stars, but also separately values their rooms, the restaurant and auxiliary facilities. Higher ratings indicate a lower likelihood of security incidents and, more importantly, a greater ability of the supplier to restore normal service quickly in the event of a disruption.

The entire methodology, evaluation criteria and the registry of services are public, so it provides total transparency when it comes to assess and compare different services when selecting your ICT suppliers.

The rating system managed by LEET Security became the first implementation of the recommendation of the EU Cybersecurity Strategy, to create ICT security labeling systems.

The rating

Rating granted in three dimensions

This rating is awarded in three dimensions: Confidentiality, Integrity and Availability, and the LEET Seal shows the assessment obtained by the rated service in each of them based on the security and continuity measures implemented, expressed by three letters, from A+ (corresponding to the highest level) to D (the most basic one).

How to read the LEET Seal: rating in Confidentiality, Integrity and Availability, from A+ to D
For customers and suppliers

Security and confidence when selecting an ICT supplier

LEET Security's objective is to facilitate the processes of contracting ICT services by simplifying the evaluation of their security.

LEET Security covers the lack of an objective system that standardizes the criteria and minimizes inequalities in the selection process of companies that compete in the ICT services market, avoiding adverse selection.

Through its seal, the LEET Security agency labels the different ICT services offered by suppliers based on an exhaustive and rigorous evaluation of the security measures they incorporate, the reliability of the supplier and the resilience mechanisms applied.

From the customer's perspective

  • How to compare two similar services?
  • Will the contracted services I seek have the level of security I need?
  • What happens if the supplier suffers an incident?

Benefits for customers

  • Improved operabilityStreamlines selection processes
  • Cost improvementOptimisation of own resources
  • Improving your imageWith authorities, regulators, customers and shareholders
  • Improve your managementFacilitates risk management in your business
The LEET Seal connects ICT service customers and suppliers

From the supplier perspective

  • How can I guarantee confidence in my services?
  • How to differentiate myself from the competition based on my investments in security?
  • How can I segment my offer?

Benefits for suppliers

  • CompetitivenessFacilitates access to customers and differentiation from competition
  • Cost improvementReduction of resources in accreditation to your customers
  • Improving your imageProactive image to customers
  • Improve your managementShorter audit time and better access to cyber-policies
Why LEET

Advantages

  • Promotes transparency

    All users can know the rating levels of a service and have a complaint mechanism in case of non-compliance of the necessary conditions.

  • Limits the usual conflict of interest in trusted third parties

    The security system, based on supervised self-assessment, reduces the possibility of conflict of interest and sets the responsibility on the side of the supplier of services.

  • Simplifies the understanding of the level of security

    An expert is not required to assess whether the service to be contracted is the appropriate one for the risk profile pursued.

  • Reduces implementation costs

    The supervised self-assessment model allows suppliers to enroll without having to face large adaptation costs.

  • Streamlines the audit process

    By leveraging widely used standards and a regulatory control rating, ICT service suppliers can avoid repetitive testing of the same controls, following the “audit once, use multiple times” principle.

Download 'Cybersecurity capabilities Datasheet'
Trust

Recognition

Developed since 2010 and continuously evolving, LEET Security’s rating system is recognized by the European Agency for Network and Information Security and is registered as a trusted instrument with the National Institute of Cybersecurity (INCIBE).

ENISA, European Union Agency for Cybersecurity INCIBE, Spanish National Cybersecurity Institute

The rating methodology complies with UNE 71381:2016 Information Technology. Cloud computing. Labelling Systems

Understand and Improve Your Cybersecurity Posture