Driving Greater Prioritization In Vendor Risk Management

Noah Simon | December 13, 2016

With third parties becoming a major attack vector into organizations, BitSight is focused on enabling security and vendor risk professionals to better prioritize their efforts when it comes to identifying and monitoring cyber security risks across their vendor ecosystem.  BitSight Security Ratings customers can now prioritize issues and receive customized alerts when the aggregate performance of multiple companies change.

Remediation Strategy

The BitSight Security Ratings portal now features a Remediation Strategy section to help risk and security stakeholders focus on improving their organization’s security posture. As we have shown, organizations with a higher security rating are less likely to experience a publicly-disclosed data breach. This new capability highlights the risk vectors that have the highest Rating Impact and quantitatively identifies where organizations should focus remediation efforts. Strategies are presented from most to least Rating Impact.

remediation strategy.pngThe strategy is available for all companies in a customer's portfolio and provides information to prioritize remediation efforts, enhance security effectiveness, and guide security conversations with third parties and business associates. Companies who take advantage of this feature can strengthen their security posture and drive security progress across their entire supply chain.

Want to see how your security posture could be improved? Schedule an appointment today!

Folder Level Alerting

Customers can now set folder-level alerts to be notified when the aggregate security posture of multiple companies changes. Many customers are already using folders to segment their third parties into different buckets based off the business function they provide and risk they pose. Folder level alerts provide the ability for customers to set specific rating alerts for each folder, allowing the customer to set more stringent alert preferences for Tier 1 vendors and looserDemo Request - Third Party preferences for Tier 2 or 3 vendors. Alerts deliver critical information right to your inbox and provide  the insight that you need to manage third party risk.

Customers can use folder level alerting as an important reporting mechanism on the health of their vendor risk program. If organizations are frequently getting alerts for rating drops, it’s possible their vendor risk management strategy needs to be revisited.

Suggested Posts

How DataOps is Transforming How Business Handles Data

You are building a mission-critical big data infrastructure. You have a team of talented software engineers who are dragged into internal meetings with various stakeholders and customers as data and product Subject Matter Experts. You have...


BitSight Security Ratings Platform Expands Its Visibility in Compromised Systems

Since creating the Security Ratings market in 2011, a core component of BitSight’s value to users has been providing industry-leading comprehensive visibility into malware communications.


Advanced Security Benchmarking with BitSight Peer Analytics

On March 4th, BitSight released  Peer Analytics, the newest advanced analytics module from the leader in security ratings. This allows organizations to better understand and manage their security performance in relation to their industry...

Subscribe to get security news and updates in your inbox.