I received the following questions from an inquisitive undergraduate student eager to learn more about Bitsight and security ratings. He posed excellent and insightful questions, and I thought that I would share our exchange in case others might be wanting to ask the same questions. Thanks, Nick!
Bitsight rates companies on their level of security across different vectors. How do you assure potential customers that these ratings are credible?
Bitsight customers put our ratings to the test every day. Our consistent execution with respect to quality and dependability has earned the trust of some of the world's largest, most prestigious, and demanding organizations.
In addition to the demands and scrutiny of each of our customers, we have undergone a process review and ratings attestation by one of the world's top-ranked audit firms who needed to perform the cybersecurity audit before it could our recommend and include our service as part of an offering to its clients.
I see cyber security as a black swan business--even if a company is 99% secure, that small vulnerability could be exploited and take down the whole business. Do you think it’s dangerous to assign a number or a grade to a company’s security status? Could this lead to overconfidence amongst boards of directors and CEOs?
I agree that an attacker only needs to exploit a single vulnerability to penetrate and potentially damage an organization. Bitsight does not claim to see all security outcomes, and a high rating does not guarantee perfect security outcomes (i.e. no control failures or breaches). That would be reckless and no approach could even begin to make that claim. In fact, we aren't "protecting" systems but rather measuring outcomes. We are in the risk management business. There are no perfectly secure systems. There will always be some chance of a failure; however, the data have proven and continue to prove that high performing organizations take deliberate actions and execute better from a protection, detection, and response perspective than lower performing organizations. Different organizations doing different things are getting different results. These outcomes are measurable by Bitsight and factor into the ratings.
Just like with credit scores, there is a spectrum or spread of performance that can be used to model, price and better manage risks. A high credit score is not a guarantee that you will not default on your debt but rather the results of a model that is comprised of a historical track record compared against others that demonstrate that default is less likely. Our research has continued to support this analogy in security ratings. Here is one of our latest pieces of research that provides backing for these assertions. We see that high performing organizations work to protect against failures but have realized that they can't prevent all failures. Given the organizational acceptance that eventually some control will fail, high performing organizations have also invested in capabilities to respond and recover quickly before catastrophic failure.
It is important to remember that Bitsight provides key metrics for performance, but its ratings and service do not constitute a complete risk management program. CEO's and Boards need data to drive better risk management practices. The absence of data has created an environment of what we refer to as "optimism bias." Many executives have been overconfident in their security performance in many cases because they lacked the data to tell them otherwise. We are advancing the state of risk management by providing risk managers and executives accessible metrics that drive better data-driven questions and conversations about managing security risk that were never before possible.
You raised a $24mm Series A in 2013 from Menlo, Flybridge, and a few others. How did you choose your investors and was it hard to get them to buy into such a large series A?
In every case we were introduced to investors by a trusted reference. We had all had either worked directly with the investor previously or had contacts or associates who had.
Our investors believed in the incredible team that we had assembled and the large and transformative market opportunity that we were creating. We also had extremely supportive and influential customers who could vouch for the value of our service and vision.