Release notes

New SIG Lite questionnaire, plus big improvements to risk assessments

Annie Luu October 25, 2023

SIG Lite questionnaire added to library

The Shared Assessments Standardized Information Gathering (SIG) Lite questionnaire has been added to our questionnaire library. SIG Lite is designed to provide a broad, high-level understanding of a third party’s internal information security controls. Like our other questionnaires SIG includes incorporated cybersecurity ratings, automated risk detection and is integrated with standard questionnaire workflows. To learn more, see Questionnaire Library.

Improved risk assessments

We’ve made improvements to the risk assessment workflow to make it more intuitive and flexible including:

  • The ability to add comments to individual risks in risk assessments, making it easier to capture all your risk management activity within the platform.
  • Improvements to the commentary section, with a more flexible template that is divided into sections, giving you more flexibility to present the risk assessment report according to your needs.
  • Addition of more merge tags to pre-fill vendor information including scores, tiers and attributes, so you can generate comprehensive pre-filled commentary for your risk assessment.

These improvements have been available in limited release, and are now generally available to all Vendor Risk customers. To learn more see Using the risk assessment framework in UpGuard.

Show date when domains/IPs are first detected

Maintaining control of your asset inventory requires knowing when new sites first become publicly accessible. To help with this we now show the date the domain was first scanned on the domain or IP address details panel.

New workflow to request additional evidence documents

To assist with vendor risk assessments, we have made the process of collecting additional evidence documents (such as certifications and other security documentation) easier by adding a workflow to request additional evidence documents directly from vendors. Vendors can load documents directly to the platform, avoiding having to request and upload those documents outside the platform. To learn more see How to capture additional evidence.

Other improvements

  • We’ve added an unverified vulnerability and compromise detection for Cisco IOS XE CVE-2023-20198.
  • We’ve added a column on the Typosquatting page to allow users to sort by creation date. When a permutation has been registered more recently, it can be an indicator that it is more likely a threat.
  • We’ve built more flexibility into the questionnaire builder, allowing you to add custom numbering to your questionnaire. To learn more see How to use the questionnaire builder.
  • This release also includes a number of bug fixes.
View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more

Updated application usage policy controls

Mark Barber June 17, 2026
Read more

New threat signal: Published MCP server definitions

Mark Barber June 3, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950