Bitsight provides comprehensive, AI-accelerated visibility into your vendors, assets, and digital footprint of every third party (and beyond) in your network, whether you work with them directly or indirectly.
N/A
SAI360
Score 7.1 out of 10
N/A
SAI360 merges GRC software and Ethics & Compliance Learning to enhance risk management. Its scalable solutions have supported global organizations for 25+ years.
N/A
Pricing
Bitsight Third-Party Risk Management
SAI360
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Bitsight Third-Party Risk Management
SAI360
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Bitsight Third-Party Risk Management
SAI360
Considered Both Products
Bitsight Third-Party Risk Management
Verified User
Anonymous
Chose Bitsight Third-Party Risk Management
We evalauted Security Scorecard as another option at some point, the tools have many similar features when we analyze them, basically we had a great deal with our regular security partners and finally decided for Bitsight, but to be honest we did not have a deep proof of …
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are …
Archer was very similar to SAI360 in cost and features. Has a more modern look and feel and more task functionality. The price point was very similar. Didn't choose them as our existing usage is in an On-Prem version and support from our in-house IT team was not able to be …
Wasn't personally involved in the vendor selection process. I am aware that one of the main drivers for selecting BWise was cost (I believe BWise total project cost was several times lower than MetricStream's).
If you have a large and complex digital supply chain, this kinds of solutions, and Bitsight in particular are a must. At the starting point gives you a great leverage using the already available info for major vendors, and allows you to focus were you have already identified gaps, or for those vendors that lack of information... and probably you should be focusing on
The usage of ROAM, as well as the integration of external programmes through API and import functions, has almost reduced duplication of work. One thing to keep in mind is that your use cases must be very clear. There are a lot of SAI solutions, and their titles don't always correspond to what they actually perform.
Since data is based on public registration IP and domain data can be stale depending on ISP/Domain registration update delays.
Correcting a false detection is a month-long endeavor and requires the company with the impacted score to clean up BitSight's data.
Customer service for incorrect data is convoluted and requires a deep understanding of domain registration to correct the data. The responsibility for correcting data is placed solely on the customer's shoulders.
Internal Quality Check. I think this is the most prominent area BWise should improve on. Currently they lack internal Quality Check/Review.
Internal dialogue among employees. When various consultants are involved in the same project, their communication and updating each-other could be a bit stronger.
Inclusion of content. The application could benefit considerably from including some out-of-the-box content (e.g. COSO principles, Risk catalogs, etc.).
Risk Workshop functionality. This is one of the main functionalities that allows integration among different areas of an organization. However, it comes pretty much "take it or leave it"; it's almost not customizable.
Consultants' transparency. When an organization requests a particular design of the application or solicits changes to such design, it would be great if BWise consultants could always and more thoroughly advise on the implications of these changes, design to the organization's strategic objectives and ultimate target.
Product features. Application has room for improving its programming, e.g. providing internal checks when creating/answering an issue/finding (for instance, remedy implementation date cannot be before the recommendation response date or the recommendation creation date). Another example would be the possibility of automatic periodic followup (e.g. every 1 month until completion).
Great look and feel, intuitive in most modules, and has great features to gather the right info and process it at high speed. Good and usefull dashboards for our own, and has also proved to be very good when you are on the vendor side of the solution and need to send info to your customers
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are aggregate data that can provide insight into the security habits of a potential vendor and should be considered as an addition to most vendor management projects. However, they both provide metrics based on hygiene and not on data-defined risk. In concert with a platform to evaluate risk based on data and to inform the overall evaluation of a vendor, BitSight Security Ratings can be made to shine. Just understand that you may have to validate some data.
Wasn't personally involved in the vendor selection process. I am aware that one of the main drivers for selecting BWise was cost (I believe BWise total project cost was several times lower than MetricStream's).