This August, Bitsight announced the release of several new risk vectors specifically chosen to help organizations identify and manage risks across their own networks and the networks of their third parties. Bitsight chose those new risk vectors to enhance the insights across the “spectrum of risk” and provide a more comprehensive picture of an organization’s security posture.
As your vendor ecosystem scales, your vendor risk management strategy needs to scale, and monitor evolving risk across your portfolio of vendors becomes an increasingly difficult challenge. We are pleased to announce the release of two new alert types to help you stay up to date with the latest security ratings changes, Risk Vector Grade and NIST Cyber Security Framework (CSF) Grade alerts.
Bitsight alerts monitor your vendor portfolio for changes based on your risk appetite and alert preferences. We recommend that you tier your vendor portfolio by business function criticality and set unique alert preferences for each. For example, you may have a low risk appetite for your Tier 1 vendors, who store customer’s personally identifiable information (PII). You can then use Risk Vector Grade alerts and set alert preferences to receive decrease alerts when grades go below a “B” and critical decrease alerts when grades go below a “C.” As vendor tier risk appetite increases, alert preference stringency decreases.

