As outsourcing significant business functions is now common practice for most organizations, major third-party data breaches are rapidly taking over news headlines.
Ponemon Institute and IBM’s 2019 Cost of a Data Breach Report found the average cost of a breach has increased from $370,000 to $4.29 million, with third-party involvement listed as one of the main reasons. An eSentire surveyfrom the same year highlights that 44% of firms surveyed have experienced a significant data breach caused by a third-party vendor.
With Gartner reporting 60% of organizations as having 1000+ third-party relationships, effectively managing the cybersecurity risks they create and practicing vendor due diligence proves increasingly difficult.
Information security teams often also rely on manual risk reporting methods which are time and labor-intensive. Many organizations are now turning to automated third-party risk management (TPRM) solutions that automate data breach detection capabilities, provide real-time insights, and streamline remediation workflows.
We assess three TPRM solutions, BitSight, CyberGRX, and UpGuard, to help you make an informed decision before investing in the right solution for your needs.
BitSight Technologies is a Cambridge, MA-based company that aims to quantify the external cybersecurity posture of organizations using publicly accessible data.
BitSight’s security ratings are used by security and cybersecurity riskprofessionals to conduct due diligence research for vendor risk management programs, private equity, M&A activities, and more.
Additionally, these security ratings are used for attack surface analytics, industry benchmarking, and the assessment of fourth-party risk.
CyberGRX is based in Denver, Colorado in the United States and founded by Fred Kneip in 2015. CyberGRX provides enterprises and their third-parties with a cost-effective and scalable approach to third-party cyber risk management.
It does this by collecting data and cyber risk assessments in a structured format and then sharing them on their information exchange platform. This allows assessors to quickly access information about a vendor while reducing the operational overhead for the vendor by reducing the number of similar questionnaires they need to fill out.
In December 2019, CyberGRX announced it had raised $40 million in Series D funding led by ICONIQ Capital.