MAX Managed Service
SecurityScorecardReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
97 reviews
from
and
External reviews are not included in the AWS star rating for the product.
New Implementation
What do you like best about the product?
Security Scorecard allows us to monitor the changing security posture of our suppliers
What do you dislike about the product?
One feature that would be great is to be able to nest portfolios. In the compliance tab having the ability to have a holistic view of all of our vendors that do not meet a certain control
What problems is the product solving and how is that benefiting you?
The benefits of the platform allows us to provide and additional view of risk associated with using third parties
The tool is really helful to know the security status of a company , data breaches and data issues
What do you like best about the product?
The best part is that post you know the issues & breaches of a company, you can invite them to get remediation. You can help them improve
What do you dislike about the product?
The process of adding companies to portfolio need a little improvement. Sometimes the weblink inside the company does not open up. Also sometime the tool is little slow
What problems is the product solving and how is that benefiting you?
Sending Questionnaire and assessment questions is really awesome.
Help in improving security scores of companies
Help in improving security scores of companies
Recommendations to others considering the product:
This tool is really helful as it covers different domains related to information security and very helpful to improve the score/grade of a company
Excellent tool and service behind
What do you like best about the product?
The Security Scorecard offers us what we need in terms of continuous assessment of the external network vulnerabilities tests. The webUI is user-friendly and built in a logical format, very easy to use and dig for information on it.
What do you dislike about the product?
There is no user option to re-launch the test, so you get confirmation that your fix really works. Claiming a fixed issue takes some time and a ticket to Security ScoreCard Support to validate it. Also, the propagation of the fix may take some time, before it gets reflected on the organization's score.
What problems is the product solving and how is that benefiting you?
We have a full picture of our organization's exposure on the public domain. Getting this "big picture" for the entire IP space helps us prioritize the mitigation actions and the maintenance windows for our external hosts. Also, having the issues summarized, explained, and the solution suggested for any problem that came out of scans, it's really helpful.
Recommendations to others considering the product:
Try it. Ask for a demo.
Good product, great support!
What do you like best about the product?
Very helpful team. Product is robust and accurate, we use it as a core component of our third party risk management programme and we are not dissapointed. It's great that Security Scorecard keep updating the platform and developing useful new features.
What do you dislike about the product?
Occasional false positives have caused internal and external issues
What problems is the product solving and how is that benefiting you?
Easy oversight of vendors and partners, quick resolution of issues.
Simple and straightforward tool
What do you like best about the product?
SS interface is user friendly, easy to explain to other staffs in the bank.
What do you dislike about the product?
We have started using the platform, once we mature with time we would be in better postion to provide the feedback on dislike.
What problems is the product solving and how is that benefiting you?
* Third party is always a high risk area, especially where customer information are shared.
* With traditional third party assessment approach, it is very difficult to regularly track on vulnerabilities and then its mitigation.
* With SS platform, vulnerabilities tracking & mitigation process is simplified.
* With traditional third party assessment approach, it is very difficult to regularly track on vulnerabilities and then its mitigation.
* With SS platform, vulnerabilities tracking & mitigation process is simplified.
Recommendations to others considering the product:
SS is simple to use and up to the point, support team are very helpful.
Improve supplier communication
What do you like best about the product?
SecurityScorecard supports the communication with supplier by adding more focus in potential risks and the possibility to interact.
What do you dislike about the product?
Sometimes IPs/URLs impact the score even if they are unused and only reserved for a company.
What problems is the product solving and how is that benefiting you?
Improving communication with supplier and sharpening the view on the own estate.
Recommendations to others considering the product:
SecurityScorecard puts the focus in the right direction, it is not the tool to fix your issues.
Great tool in the VRA toolkit
What do you like best about the product?
The ability to quickly ascertain the size of an org's digital presence and see whether or not they are addressing vulnerabilities appropriately; and whether or not they have open ports that are concerning.
What do you dislike about the product?
Attribution. I also manage our Scorecard and find myself spending a good deal of time sorting through IP lists to determine whether or not our cards are accurate. Parked domains can be problematic as far as introducing a significant amount of findings on scorecards (things like lack of https re-directs, spf records, etc.) This gives me a bit of pause when trying to analyse vendors' Scorecards because it can bring doubts as to the accuracy of their digital footprint (especially if they are inactive).
What problems is the product solving and how is that benefiting you?
Enabled us to identify independent advisor hosted sites that have wordpress vulnerabilities, servers w/ RDP open so we can reach out to remediate. Streamlines our Vendor Risk Assessment process, particularly when vendors are unable to provide vulnerability scans or pen test results during our due diligence process.
Recommendations to others considering the product:
Make good use of the ability to manage your own org's Scorecard. We have been able to use it to provide assurances to OUR clients, institutional investors, and FID partners as to the effectiveness of our cyber-security program.
Great product for 3rd eye view
What do you like best about the product?
We use SecurityScorecard for evaluating ourselves to ensure our public footprint is secure and use it as part of 3rd party security reviews in comparison to peers and new vendors to work with. It definitely provides an insight with data transparency and ease of use UI. Support team is super responsive and that's one of the key features.
What do you dislike about the product?
Continuous improvement are a part of SS but Email notification can be added, it will be great.
What problems is the product solving and how is that benefiting you?
We use SecurityScorecard for evaluating ourselves to ensure our public footprint is secure and use it as part of 3rd party security reviews in comparison to peers and new vendors to work with. It definitely provides an insight with data transparency and ease of use UI. Support team is super responsive and that's one of the key features.
The sucess behind SSC is its people
What do you like best about the product?
Many times you buy a security tool and after a short onboarding period, you are on your own. The experience with SSC has been the opposite. They were there and continue to be there for us. From the sales, to support, to continuous customer care, the experience has been outstanding. SSC stands behind its product and is ready and able to engage whenever we bring our third parties to the table or have any questions. They have been very responsive to our needs (e.g. training, deployment, questions by internal teams and third parties, open to feedback, etc.) The tool is helping us assess a large number of third parties that we are discovering.
What do you dislike about the product?
Does not have enough capabilities yet to gain insight on how the tool is being used within the organization.
What problems is the product solving and how is that benefiting you?
Rapid assessment and prioritization of third parties that are popping up as part of a discovery process. It is enabling us to become more agile and have more intelligent and fact-supported conversations with our third parties.
SecurityScorecard for Continuous Security Monitoring
What do you like best about the product?
What we like best about SecurityScorecard is the intuitive user experience and well organized content. The platform is very well layered to provide a wide audience with reporting, security risk metrics, and technical risk details to help support the needs of a well rounded Continuous Monitoring program. It enables its users to not only detect, but react and collaborate with in scope suppliers through the use of the vendor invite functionality. Additionally the Security Scorecard team has been beyond supportive in this journey helping the team to not only understand the tool, but how to develop processes and a program structure to maximize the value the tool brings.
What do you dislike about the product?
1) The team often finds themselves needing to refresh pages such as the insights dashboard, a supplier profile, ip inventory, etc. The data often doesn't load and we receive error messages advising us to refresh. 2) Inability to track and report on invited vendor engagements such as when the vendor was invited, did they accept the invite, when did they last login, etc. 3) Custom Scorecard data unavailable through the API.
What problems is the product solving and how is that benefiting you?
Problems Being Solved: Security Scorecard has filled the gap between our point in time, questionnaire based security assessments. This has instilled a new sense of comfort in our organization knowing that we have the ability to detect and seek remediation for possible risk prior to the next security assessment.
Benefits: The platform has enabled my team to maximize their vendor collaboration and remediation efforts through native portfolio management, dynamic filtering, and configurable real-time alerting.
Benefits: The platform has enabled my team to maximize their vendor collaboration and remediation efforts through native portfolio management, dynamic filtering, and configurable real-time alerting.
Recommendations to others considering the product:
Some recommendations our team would make to others using SecurityScorecard is to first familiarize themselves with the capabilities of the tool, become comfortable with the data, and understand how the platform will fit into your overall 3rd Party Risk Management and Security strategy prior to issuing licenses and engaging with your vendor partners.
showing 81 - 90