SecurityScorecard performs deep analysis over the exposed view of data. It creates an external IT assessment of the company in terms of domain and vendor reports. Essentially, it scans the company's landscape, trying to find vulnerabilities and exposed data that may cause digital risks.
Reviews from AWS customer
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
The most valuable feature is the ability to identify if third parties or vendors have digital threats that may impact our company
What is our primary use case?
What is most valuable?
With SecurityScorecard, the most valuable feature is the ability to identify if third parties or vendors have digital threats that may impact our company. It also scans all internal domains and IPs to find vulnerabilities in the digital landscape. The continuous monitoring capabilities have been beneficial by providing ongoing assessments of potential risks.
What needs improvement?
The pricing of the product needs improvement in Brazil.
For how long have I used the solution?
I have been using SecurityScorecard for the past year.
What do I think about the stability of the solution?
As for stability, it's 99.99% stable.
What do I think about the scalability of the solution?
The scalability of SecurityScorecard is really easy. If the user starts with twenty domains and needs to double, it's already in the platform one just needs to flag a button.
How are customer service and support?
They work pretty fast and have full knowledge of the solution. Personally, I've never had a problem with them. Sometimes there's a little delay because they need to investigate further, but overall, I'm pleased with their support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of SecurityScorecard is very easy because it's a SaaS solution. Deployment time depends on the number of companies to be monitored; for fifteen to thirty companies, it might take two or three days, or up to a week.
The vendor helps users deploy the solution and set up functionalities, making it straightforward. Usually, three to four people are involved. The vendor assigns a Customer Success Manager to the end user, who acts as the focal point for support, new questions, and functionalities.
What about the implementation team?
What was our ROI?
The best ROI with SecurityScorecard is when the end user identifies that their vendors or third parties have digital threats that need to be addressed promptly. Preventing digital threats and data leakage from vendors and partners is the best ROI.
What's my experience with pricing, setup cost, and licensing?
The pricing of SecurityScorecard is fair. I would rate it a seven. It's a bit more on the expensive side. In Brazil, for example, making a payment to the vendor involves wire transfers and high taxes, making it more expensive. Selling SecurityScorecard or any American vendor's product in the United States is very different from selling in South America or Brazil.
What other advice do I have?
Overall I would rate the solution a nine out of ten.
Données perspicaces, potentiel pour plus de rapports
Très bien
Facile à utiliser et à naviguer, sa simplicité en fait un bon produit.
Scoreard - excellent produit
- Facile à comprendre
- Facile à utiliser
- Orientation service client
- Prend les retours à cœur
- Permet d'essayer de nouvelles fonctionnalités en tant que pilote
- Pas de score agrégé pour l'ensemble de l'entreprise
Surveillance continue des tiers
Plateforme précise et omniprésente - service client incroyable
Security Scorecard ajoute de la valeur au programme de gestion des risques des tiers (TPRM)
Easy-to-deploy product with good technical support services
What is our primary use case?
The primary use case for SecurityScorecard is to assess and manage third-party cybersecurity risks within organizations.
What needs improvement?
They could improve the process with a questionnaire module for the product. At present, we have to answer multiple questions for the suppliers manually. They could automate functionality to enhance this particular area.
For how long have I used the solution?
We have been using SecurityScorecard for four years.
What do I think about the stability of the solution?
The platform is stable.
How are customer service and support?
The technical support services are good.
How would you rate customer service and support?
Positive
How was the initial setup?
The platform is easy to deploy and maintain.
What was our ROI?
Determining the return on investment (ROI) for SecurityScorecard or similar products can be complex and organization-specific. Measuring ROI in this context involves assessing the tool's effectiveness in mitigating risks and preventing potential breaches. However, it's challenging to quantify the precise impact because successfully addressing vulnerabilities may prevent security incidents that would otherwise go unnoticed. For instance, one of our clients shared a story about discovering their data on the dark web, highlighting the importance of proactive security measures.
While achieving 100% vulnerability mitigation is ideal, it takes time to ascertain how many potential breaches are prevented. Nevertheless, given the increasing reliance on online services and the critical need for robust security measures, the significance of third-party risk management must be balanced. Ultimately, while the ROI of SecurityScorecard may be challenging to measure, its role in enhancing security posture and mitigating potential risks is invaluable in today's digital landscape.
What's my experience with pricing, setup cost, and licensing?
Similar to Barracuda, SecurityScorecard's list price may appear high initially. Even though it's competitive, they offer flexible pricing structures.
What other advice do I have?
Our organization relies on numerous SaaS services for critical business functions, such as CRM and monitoring solutions. In a hypothetical scenario where a security breach occurs in the CRM database, potentially exposing our data and our clients, SecurityScorecard proves invaluable. It provides a security score, typically a percentage, based on extensive data collection from various sources, including the dark web and social networks. Let's say our CRM solution receives a security score of 78%, indicating a relatively safe status according to the information gathered by SecurityScorecard.
One of its most effective features for risk identification is its enterprise-ready automation for third-party risk measurements. Additionally, it provides valuable insights into vulnerabilities within an organization, utilizing tools such as CVE details. For instance, it can assign a score based on vulnerabilities detected, such as 60%, and specify each vulnerability by its identifier. It offers scalability and can handle large volumes of real-time data.
The continuous monitoring feature significantly enhances the ability to manage risks by providing real-time data collection on suppliers. We can observe fluctuations in their security levels over time, sometimes even every month. We can create alerts for high-risk situations, enabling organizations to respond promptly to potential security threats or vulnerabilities identified within their supplier network.
The product's security ratings are helpful. While there may be occasional false positives, it does not function as a scanning solution. Instead, it presents the same information that hackers could potentially exploit.
While I haven't worked with other cybersecurity rating solutions, I can attest to its strengths based on my experience. One notable advantage is their extensive data collection capabilities, surpassing many competitors in the market. They gather a wide range of information, resulting in a vast database that includes many suppliers or companies. It is easy to integrate with other tools.
I rate it a nine out of ten.
A reasonably stable product that provides recommendations to improve the scores
What is our primary use case?
This tool is a platform for monitoring and assessing the security posture of organizations and also helps to improve the posture by recommendations
How has it helped my organization?
This tool is a platform for monitoring and assessing the security posture of organizations and also helps to improve the posture by recommendations
What is most valuable?
Security Ratings, Continuous Monitoring, & Benchmarking are most useful
What needs improvement?
SecurityScorecard's technical team's response time is an area that my company expects to be made faster. As per the tool's SLAs, three days is way too much time for a user to wait for a response.
SecurityScorecard is an online scanning tool. Apart from the web scanning feature, SecurityScorecard should be available for use on Android or iOS for app scanning purposes and then provide a status to the user.
From the perspective of a customer, I would always want the price of the solution to be on the cheaper side.
For how long have I used the solution?
I have been using SecurityScorecard for more than two years.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Around three to four people in my company use the product.
My company has no plans to increase the use of the solution.
How are customer service and support?
Apart from the delay in response time, I am happy with SecurityScorecard's technical team.
I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Long ago, my company used to use another solution.
How was the initial setup?
I rate the product's initial setup phase a nine on a scale of one to ten, where one is a difficult setup phase, and ten is an easy setup process.
The solution is deployed on a multi-hybrid cloud.
The solution can be deployed in hardly two or three hours.
What other advice do I have?
SecurityScorecard has improved our company's vendor risk assessment process since it basically gives us the comparison of the competitors and certain vulnerabilities which we can report from an external view or a third party view, giving us an improvement area to work on, which might we might not have focused a lot, or maybe it might be overlooked upon by us. SecurityScorecard helps our company get better scores. The tools help fix the vulnerabilities, which in turn improves scores, making it a valuable product for us.
A scenario where SecurityScorecard enabled better decision-making for IT projects includes an incident involving a couple of domain names that my company used to use in the past since sometimes we see that some applications were replicated. My company forgot to clean up the DNS names. Once my company gets to know from SecurityScorecard that our application has vulnerabilities, I may not have renewed the certificate considering that the application is no longer in use, owing to which our company might lose track of it, during which SecurityScorecard helps us to do the cleanup. There are many places where the right certificates are not installed, or maybe there is a small application vulnerability, which the tool can catch from the external view. This can be let known to our company since there is an action we take to fix such areas.
Our company operates in the online classified market.
The features of SecurityScorecard that are the most beneficial for security monitoring are the reports generated with the help of external audit and vulnerability assessment.
The platform's grading system helps prioritize our company's security concerns since it helps us in the area of scores and provides the competition score. The tool also provides recommendations to improve the scores, which is helpful.
In the identification of potential threats, SecurityScorecard helps our organization since it does black box analysis. With the black box analysis, the tool helps us in the area of external websites where we cannot do many things directly, after which the tool shares an unbiased status with our company.
SecurityScorecard's reporting capabilities support our company's compliance initiatives since it has a dashboard with credentials through which we can get the vulnerabilities reported. The product should provide an option so that it has the ability to fix the reported vulnerability at the same time that it is reported by allowing users to raise a ticket directly with SecurityScorecard's team. After the aforementioned steps are followed, SecurityScorecard can conduct a scanning process and add up the score, which basically gives me the complete trend by allowing me to say last month's trend versus the current month's trend or maybe the last scan versus the current month's scan.
I would tell those who plan to use the solution that it is a straightforward product to use.
I rate the product a nine out of ten.
Which deployment model are you using for this solution?
Helps identify our environment's vulnerabilities
What is our primary use case?
We use SecurityScorecard for reporting.
How has it helped my organization?
The solution helps identify our environment's vulnerabilities.
What is most valuable?
SecurityScorecard's most valuable feature is easy reporting.
What needs improvement?
The tool needs to have the ability to mitigate vulnerabilities with alternative solutions.
For how long have I used the solution?
I have been working with the solution for three years.
What do I think about the stability of the solution?
I rate SecurityScorecard's stability a seven out of ten.
What do I think about the scalability of the solution?
I rate the solution's scalability a seven out of ten.
How was the initial setup?
SecurityScorecard's deployment is easy.
What was our ROI?
I have seen ROI with the tool's use but cannot quantify it.
What other advice do I have?
I rate the product a seven out of ten.