Bitsight Third-Party Risk Management vs. SAI360

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Bitsight Third-Party Risk Management
Score 7.8 out of 10
N/A
Bitsight provides comprehensive, AI-accelerated visibility into your vendors, assets, and digital footprint of every third party (and beyond) in your network, whether you work with them directly or indirectly.N/A
SAI360
Score 7.1 out of 10
N/A
SAI360 merges GRC software and Ethics & Compliance Learning to enhance risk management. Its scalable solutions have supported global organizations for 25+ years.N/A
Pricing
Bitsight Third-Party Risk ManagementSAI360
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Bitsight Third-Party Risk ManagementSAI360
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Bitsight Third-Party Risk ManagementSAI360
Considered Both Products
Bitsight Third-Party Risk Management
Chose Bitsight Third-Party Risk Management
We evalauted Security Scorecard as another option at some point, the tools have many similar features when we analyze them, basically we had a great deal with our regular security partners and finally decided for Bitsight, but to be honest we did not have a deep proof of …
Chose Bitsight Third-Party Risk Management
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are …
SAI360
Chose SAI360
Archer was very similar to SAI360 in cost and features. Has a more modern look and feel and more task functionality. The price point was very similar. Didn't choose them as our existing usage is in an On-Prem version and support from our in-house IT team was not able to be …
Chose SAI360
Also evaluated, and implemented SAP GRC Process control for Continuous Control Monitoring in SAP. Initially selected BWise for cost and flexibility.
Chose SAI360
Wasn't personally involved in the vendor selection process. I am aware that one of the main drivers for selecting BWise was cost (I believe BWise total project cost was several times lower than MetricStream's).
Features
Bitsight Third-Party Risk ManagementSAI360
Governance, Risk & Compliance
Comparison of Governance, Risk & Compliance features of Product A and Product B
Bitsight Third-Party Risk Management
-
Ratings
SAI360
7.7
Ratings
4% above category average
Common repository of GRC items00 Ratings9.00 Ratings
Risk management00 Ratings7.30 Ratings
Integration with Corporate Performance Management (CPM) systems00 Ratings7.00 Ratings
GRC policy management00 Ratings8.00 Ratings
Incident management00 Ratings7.30 Ratings
Best Alternatives
Bitsight Third-Party Risk ManagementSAI360
Small Businesses

No answers on this topic

Egnyte
Egnyte
Score 9.3 out of 10
Medium-sized Companies

No answers on this topic

Forcepoint DLP
Forcepoint DLP
Score 8.2 out of 10
Enterprises
GEP Quantum Intelligence
GEP Quantum Intelligence
Score 9.0 out of 10
Forcepoint DLP
Forcepoint DLP
Score 8.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Bitsight Third-Party Risk ManagementSAI360
Likelihood to Recommend
8.0
(0 ratings)
7.1
(0 ratings)
Likelihood to Renew
-
(0 ratings)
9.0
(0 ratings)
Usability
8.0
(0 ratings)
9.0
(0 ratings)
Support Rating
-
(0 ratings)
9.0
(0 ratings)
Implementation Rating
-
(0 ratings)
8.0
(0 ratings)
User Testimonials
Bitsight Third-Party Risk ManagementSAI360
Likelihood to Recommend
If you have a large and complex digital supply chain, this kinds of solutions, and Bitsight in particular are a must. At the starting point gives you a great leverage using the already available info for major vendors, and allows you to focus were you have already identified gaps, or for those vendors that lack of information... and probably you should be focusing on
Read full review
The usage of ROAM, as well as the integration of external programmes through API and import functions, has almost reduced duplication of work. One thing to keep in mind is that your use cases must be very clear. There are a lot of SAI solutions, and their titles don't always correspond to what they actually perform.
Read full review
Pros
  • Security hygiene tracking over time
  • Understandable risk score based on observations
  • Predictability model of potential cyber security issues based on security habits.
Read full review
  • Customized unified design platform
  • Modules that fit your organization
  • Low technology involvement with information department.
  • Built on foundational platforms some bidirectional in the ERM framework with TPRM contracts
  • Single sign-on web-based applications
Read full review
Cons
  • Since data is based on public registration IP and domain data can be stale depending on ISP/Domain registration update delays.
  • Correcting a false detection is a month-long endeavor and requires the company with the impacted score to clean up BitSight's data.
  • Customer service for incorrect data is convoluted and requires a deep understanding of domain registration to correct the data. The responsibility for correcting data is placed solely on the customer's shoulders.
Read full review
  • Internal Quality Check. I think this is the most prominent area BWise should improve on. Currently they lack internal Quality Check/Review.
  • Internal dialogue among employees. When various consultants are involved in the same project, their communication and updating each-other could be a bit stronger.
  • Inclusion of content. The application could benefit considerably from including some out-of-the-box content (e.g. COSO principles, Risk catalogs, etc.).
  • Risk Workshop functionality. This is one of the main functionalities that allows integration among different areas of an organization. However, it comes pretty much "take it or leave it"; it's almost not customizable.
  • Consultants' transparency. When an organization requests a particular design of the application or solicits changes to such design, it would be great if BWise consultants could always and more thoroughly advise on the implications of these changes, design to the organization's strategic objectives and ultimate target.
  • Product features. Application has room for improving its programming, e.g. providing internal checks when creating/answering an issue/finding (for instance, remedy implementation date cannot be before the recommendation response date or the recommendation creation date). Another example would be the possibility of automatic periodic followup (e.g. every 1 month until completion).
Read full review
Likelihood to Renew
No answers on this topic
BWIse is very flexible, and an affordable GRC tool.
Read full review
Usability
Great look and feel, intuitive in most modules, and has great features to gather the right info and process it at high speed. Good and usefull dashboards for our own, and has also proved to be very good when you are on the vendor side of the solution and need to send info to your customers
Read full review
Overall it is a very versatile system that does help to keep our processes automated and secure. We are able to streamline our day to day activities.
Read full review
Support Rating
No answers on this topic
BWise support is knowledgeable and responsive. Bug fixes and development are also timely and ongoing.
Read full review
Implementation Rating
No answers on this topic
The main issues were managing the internal conflicts and competing objectives, rather than the capability and implementation of BWise itself.
Read full review
Alternatives Considered
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are aggregate data that can provide insight into the security habits of a potential vendor and should be considered as an addition to most vendor management projects. However, they both provide metrics based on hygiene and not on data-defined risk. In concert with a platform to evaluate risk based on data and to inform the overall evaluation of a vendor, BitSight Security Ratings can be made to shine. Just understand that you may have to validate some data.
Read full review
Wasn't personally involved in the vendor selection process. I am aware that one of the main drivers for selecting BWise was cost (I believe BWise total project cost was several times lower than MetricStream's).
Read full review
Return on Investment
  • Wasted resource hours cleaning up data to correct erroneous risk score.
  • Extra time spent addressing calls from clients about erroneous risk score data.
  • Extra time validating risk score provided by BitSight Security Ratings for potential vendors to ensure valid data.
Read full review
  • The system is costly for the initial setup
  • Does help to mitigate risk and keep the vendors and internal departments from becoming non-compliant.
  • One license for all users
  • Easy to manage employee's security access
Read full review
ScreenShots