BitSight Security Ratings vs. UpGuard Vendor Risk

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
BitSight Security Ratings
Score 7.6 out of 10
N/A
BitSight in Cambridge, Massachusetts offers an Internet security platform.N/A
UpGuard Vendor Risk
Score 10.0 out of 10
N/A
Upguard automates third party risk assessment workflows, and sends instant notifications about vendors’ security in one centralized dashboard with UpGuard’s Vendor Risk.N/A
Pricing
BitSight Security RatingsUpGuard Vendor Risk
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
BitSight Security RatingsUpGuard Vendor Risk
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
BitSight Security RatingsUpGuard Vendor Risk
Considered Both Products
BitSight Security Ratings

No answer on this topic

UpGuard Vendor Risk
Chose UpGuard Vendor Risk
We’ve evaluated other third-party security rating platforms, including those which focus heavily on questionnaires, self-assessments, and point-in-time reviews. UpGuard's usp is continuous monitoring and external risk visibility, automated questionnaires, which reduced our …
Best Alternatives
BitSight Security RatingsUpGuard Vendor Risk
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies

No answers on this topic

No answers on this topic

Enterprises
GEP SMART
GEP SMART
Score 8.3 out of 10
GEP SMART
GEP SMART
Score 8.3 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
BitSight Security RatingsUpGuard Vendor Risk
Likelihood to Recommend
5.0
(1 ratings)
-
(0 ratings)
User Testimonials
BitSight Security RatingsUpGuard Vendor Risk
Likelihood to Recommend
Bitsight Technologies
If you are considering BitSight Security Ratings as a portion or bulk of a larger vendor management project you will be well served in letting the risk scores be an indication of how closely you need to examine a vendor. However, you should not base your assessment solely on the risk score provided. The risk score is based on publicly available data and can be inaccurate.
Read full review
UpGuard (formerly ScriptRock)
UpGuard Vendor Risk is great when we need a quick view of a vendor’s external security posture, especially during fast-paced onboarding. It’s also very useful for continuous monitoring with visibility into changes at Vendor's side without repeatedly chasing vendors for updates. The only scenario it is not very helpful, is small vendors / start ups that dont have an external footprint, but in that case the questionnaire's can be used.
Read full review
Pros
Bitsight Technologies
  • Security hygiene tracking over time
  • Understandable risk score based on observations
  • Predictability model of potential cyber security issues based on security habits.
Read full review
UpGuard (formerly ScriptRock)
  • Helped us automate our vendor risk questionnaires
  • Helps us continuously monitor our high-risk vendors
  • All vendor risk data is in one place, organized by risk level, criticality, and status
Read full review
Cons
Bitsight Technologies
  • Since data is based on public registration IP and domain data can be stale depending on ISP/Domain registration update delays.
  • Correcting a false detection is a month-long endeavor and requires the company with the impacted score to clean up BitSight's data.
  • Customer service for incorrect data is convoluted and requires a deep understanding of domain registration to correct the data. The responsibility for correcting data is placed solely on the customer's shoulders.
Read full review
UpGuard (formerly ScriptRock)
  • Integration with GRC systems, ticketing platforms could be stronger
  • More configurable dashboards will be helpful
Read full review
Usability
Bitsight Technologies
No answers on this topic
UpGuard (formerly ScriptRock)
It gives overall risk visibility into our supply chain
Read full review
Alternatives Considered
Bitsight Technologies
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are aggregate data that can provide insight into the security habits of a potential vendor and should be considered as an addition to most vendor management projects. However, they both provide metrics based on hygiene and not on data-defined risk. In concert with a platform to evaluate risk based on data and to inform the overall evaluation of a vendor, BitSight Security Ratings can be made to shine. Just understand that you may have to validate some data.
Read full review
UpGuard (formerly ScriptRock)
We’ve evaluated other third-party security rating platforms, including those which focus heavily on questionnaires, self-assessments, and point-in-time reviews.
UpGuard's usp is continuous monitoring and external risk visibility, automated questionnaires, which reduced our reliance on manual follow-ups. That said, most tools in this space still need to be complemented with internal reviews and contract-level risk assessments, depending on the vendor and use case.
Read full review
Return on Investment
Bitsight Technologies
  • Wasted resource hours cleaning up data to correct erroneous risk score.
  • Extra time spent addressing calls from clients about erroneous risk score data.
  • Extra time validating risk score provided by BitSight Security Ratings for potential vendors to ensure valid data.
Read full review
UpGuard (formerly ScriptRock)
  • reduce the time and effort spent on vendor due diligence
  • it has improved our ability to identify higher-risk vendors early and focus remediation efforts where they matter most, rather than treating all vendors the same
  • more informed risk decisions
Read full review
ScreenShots