In the security ratings market, some offerings claim that a staggering percentage of the data they leverage is proprietary, and downplay the value of externally sourced data. While these companies may state that (close to) 100% of their data collection on IP maps, DNS records, event data and more is proprietary, there are several reasons why this is problematic. Let’s break down the myths surrounding this issue one at a time.
Myth #1: You have more control over your data if the majority is proprietary.
While this is certainly something that makes sense in theory, it is simply not the case. At Bitsight, we possess the largest proprietary data set (including our ownership of AnubisNetworks, widely regarded as the largest global sinkhole infrastructure) and consider it a cornerstone to both our vision and mission. However, we also recognize the value of gathering data from a variety of outside sources and partners. For every data element that is input into our system, our data science team looks for redundancies and correlations in the outside data, ensuring that the data is objective, verifiable and actionable. Cross-correlation is key; it allows us to validate figures that may seem slightly off-center. While others may think they possess more control over their strictly proprietary data, having data from outside sources gives Bitsight data more validity, and subsequently, gives us both more control and a better understanding of the security landscape. Using outside data sources, Bitsight is also able to identify false positives and de-duplicate our data set, providing more actionable data to our customers; this is something companies only using proprietary data are not able to do.
Myth #2: Having a majority percentage of proprietary data allows you to cut costs (and transfer that to lower pricing).
While relying strictly on proprietary data may provide the illusion of keeping all data collection and analysis in-house, organizations will have to make massive investments in data infrastructure to make this business model even remotely sustainable. To understand how to acquire the correct data, clean it, and analyze it, companies will need to rely heavily on investing in the right team and tools. It may seem as though keeping this process strictly internal would be more cost effective, but in reality it places more strain on company resources. Using outside sources for data alleviates some of this strain; it stands as a smart investment in terms of both data validity and resource requirements.
Myth #3: You can effectively understand third party security postures using only proprietary data.
If security ratings organizations rely solely on proprietary data, it is going to take them a very long time to scale and meet the breadth of data across the internet that is needed to fully understand a third party’s security posture. Third-party data providers are often subject matter experts in their respective domains (email security, mobility, file sharing, IoT, etc), giving them the most actionable data available on the market today. At Bitsight, scalability is a top priority — we understand that as the amount of security events continues to increase, so does the amount of data out there. We continue to invest in finding new and innovative data sources that can give us breadth and visibility into third party networks that no other provider can today.