---
title: SecurityScorecard Reviews
meta_title: 'SecurityScorecard Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 91 reviews by the users' company size, role or industry to
  find out how SecurityScorecard works for a business like yours.
aggregate_rating:
  rating_value: 4.3
  review_count: 91
  scale: '5'
date_modified: '2026-07-17'
parent_category:
  name: Risk Assessment
  url: https://www.g2.com/categories/risk-assessment
---

# SecurityScorecard Reviews
**Vendor:** SecurityScorecard  
**Category:** [Vendor Security and Privacy Assessment Software](https://www.g2.com/categories/vendor-security-and-privacy-assessment)  
**Average Rating:** 4.3/5.0  
**Total Reviews:** 91
## About SecurityScorecard
Stopping sophisticated cyberattacks requires visibility beyond your organization. Security teams need a complete understanding of their attack surface and business ecosystem risk—including partners, contractors, third- and fourth-party vendors, and supply chains. As the industry leader in security ratings, SecurityScorecard provides actionable insights for over 12 million organizations so you can quantify trustworthiness, quickly respond to cyber risks, and strengthen cyber defenses. SecurityScorecard is a security ratings, response, and resilience company. As the industry leader in security ratings, we provide actionable insights so you can make fast, informed decisions that improve your defenses. SecurityScorecard offers the world’s most comprehensive platform for quantifying and reducing risk, so you can instantly know whether an organization deserves your trust and show others that you deserve theirs. With SecurityScorecard, you can quantify trustworthiness and instantly know the cyber risk of any company worldwide, including your business, competitors, vendors, and downstream suppliers. You can strengthen cyber defenses by accessing a stream of risk intelligence that pinpoints vulnerabilities, prioritizes next steps, and clarifies remediation plans. And you can verify vendor readiness by identifying cyber-risks posed by vendors and sub-tier suppliers throughout your ecosystem– and take action to ensure their problems don’t become your problems. What we offer: Supply Chain Cyber Risk: Your supply chain consists of your third and fourth parties as well as Nth parties that are all connected to your business. Vulnerabilities and threats in your supply chain can pose risks to your business operations. With SecurityScorecard, you can significantly reduce or eliminate the risk of compromise from a vendor or business partner. Offerings include: Third-Party Cyber Risk Management, Automatic Vendor Detection, Supply Chain Risk Intelligence, and Security Questionnaires. Threat Landscape: Go outside the wire to identify threats facing your organization and your supply chain. Leverage terabytes of data and AI-driven analytics to identify the threats that put your business at risk. Offerings include: Attack Surface Intelligence, Intelligence Feeds, and Vulnerability Intelligence. Security and Risk Operations: SecurityScorecard enables companies to see what a hacker sees across their own external attack surface so they can identify threats and take action before the bad guys have a chance to exploit critical vulnerabilities. Offerings include: External Attack Surface Management and Cyber Risk Quantification. Services: A focus on expert-led continuous improvement, actionable insights, and tailored strategies positions SecurityScorecard as a trusted partner in achieving and maintaining a robust cybersecurity posture. Offerings include: Digital Forensics &amp; Incident Response, Advisory Services, Penetration Testing, Red Team, and Tabletop Exercises. MAX: SecurityScorecard MAX is a technology-enabled supply chain cyber risk managed service. Organizations leverage SecurityScorecard&#39;s technology, expertise, and partner ecosystem to minimize supply chain risk and gain tangible business outcomes.



## SecurityScorecard Pros & Cons
**What users like:**

- Users highly value the **insightful dashboards and comprehensive features** of SecurityScorecard for daily security monitoring. (24 reviews)
- Users find SecurityScorecard&#39;s **ease of use** exceptional, enhancing daily security management with intuitive dashboards and features. (17 reviews)
- Users find the **detailed likelihood reports** of SecurityScorecard invaluable for preparing against potential attacks and improving scores. (10 reviews)
- Users praise the **unmatchable customer service** of SecurityScorecard, noting prompt and thorough responses to all concerns. (9 reviews)
- Users appreciate the **intuitive design** of SecurityScorecard, making it easy to monitor security for themselves and third parties. (8 reviews)
- Dashboard Usability (7 reviews)
- Security Management (7 reviews)
- Users value the **easy UI and vendor insights** of SecurityScorecard, enabling informed discussions about cybersecurity controls. (7 reviews)
- Comprehensive View (6 reviews)
- Features (6 reviews)

**What users dislike:**

- Users express concern over the **lack of clarity** regarding score changes and the relevance of detected items. (4 reviews)
- Users find the **limited reporting** features insufficient for custom presentations, lacking the necessary flexibility for their needs. (4 reviews)
- Users experience **scoring issues** due to varied scores and false positives, complicating interactions and prioritization. (4 reviews)
- Users emphasize the need for **improvement in automated reporting** due to issues with false positives and vendor reliability. (3 reviews)
- Users find that **inefficient risk management** leads to false positives and lacks strong evidence for scoring decisions. (3 reviews)
- Users face **integration issues** as the system struggles with legacy systems and lacks automatic subdomain detection. (3 reviews)
- Poor Reporting (3 reviews)
- Vendor Management (3 reviews)
- Expensive (2 reviews)
- Information Overload (2 reviews)

## SecurityScorecard Reviews
  ### 1. Pleasant and easy

**Rating:** 5.0/5.0 stars

**Reviewed by:** Jason V. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 26, 2023

**What do you like best about SecurityScorecard?**

The perspective that our prospective clients trust.

**What do you dislike about SecurityScorecard?**

The automated reviews and suggestions. They monthly changes that always increase risk unessicarily.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Greatly for prospective clients.

  ### 2. Nice tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** George C. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 26, 2023

**What do you like best about SecurityScorecard?**

Easy to use and generates useful reports.

**What do you dislike about SecurityScorecard?**

nothing that I can think of. It's simple.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Public facing vulnerabilities

  ### 3. Use Security Scorecard

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Pharmaceuticals | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 26, 2023

**What do you like best about SecurityScorecard?**

Easy UI, quick visibility into unknown vendors

**What do you dislike about SecurityScorecard?**

Integration with different security tools

**What problems is SecurityScorecard solving and how is that benefiting you?**

Vendor and 3rd party risk

  ### 4. Great tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nick L. | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 16, 2023

**What do you like best about SecurityScorecard?**

Being able to validate the level of security a vendor is claiming. new scan results appear quickly and support is responsive.

**What do you dislike about SecurityScorecard?**

So far i have not found anything to dislike.

**What problems is SecurityScorecard solving and how is that benefiting you?**

I can see our 3rd party vendors and issues that might arise, as well as issues my organization may have.

  ### 5. Good insights about your third party vendor security posture.

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Internet | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 27, 2023

**What do you like best about SecurityScorecard?**

Accuracy of the data which helps to provide good informarion that can then drive better decisions.

**What do you dislike about SecurityScorecard?**

The scope sometimes is not relevant to what we are lookimg for.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Provides quick insight into security practices and maturity of our vendors and third party. Productivity has been positively impacted.

  ### 6. Great tool for cyber monitoring

**Rating:** 2.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 01, 2022

**What do you like best about SecurityScorecard?**

Security Scorecard is a premier tool for cyber monitoring. The tool has great dashboards, metrics and follow-up capabilities. The customer service experience has been well too.

**What do you dislike about SecurityScorecard?**

The tool was not as user friendly as it competitors. Its for more tech heavy users. This tool isn't ideal for collaboration with other business units such as legal/contract mgmt.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Security Scorecard was purchased to fill our gap in our third party risk management program. Our processes were manual and time intensive and this tool has helped automate the monitoring of our vendors.

  ### 7. A Good Service For Vendor Reviews

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** September 13, 2022

**What do you like best about SecurityScorecard?**

They provide a brief, in depth look at a company's external facing internet presence.  They monitor and alert me to issues with my footprint, and they also provide a quick way for me to assess whether a vendor takes security seriously.

**What do you dislike about SecurityScorecard?**

They can be sticklers when they make a mistake.  It can take multiple touch points to get them to remove an IP that isn't mine which they accidentally attributed to me.

**What problems is SecurityScorecard solving and how is that benefiting you?**

External vulnerability notifications and vendor management.

  ### 8. Good service, not the best experience

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 03, 2022

**What do you like best about SecurityScorecard?**

It has great customer service and a user-friendly interface.

**What do you dislike about SecurityScorecard?**

The lack of other clients/users represented in the system.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Vendor management and some function of third-party risk management.

  ### 9. SecurityScorecard Review

**Rating:** 4.5/5.0 stars

**Reviewed by:** Kaveen P. | Associate Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** March 22, 2022

**What do you like best about SecurityScorecard?**

Most of the functionalities are valuable. The atlas assessments are the part that I mostly like in this platform.

**What do you dislike about SecurityScorecard?**

Nothing special. This product is very good product for the banking related customers mostly.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Most of the time handled with the application-related portfolio management and IT risk management kind of things on the securityscore card.

  ### 10. SecurityScorecard review

**Rating:** 4.5/5.0 stars

**Reviewed by:** James B. | Head of Business Development, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 07, 2021

  ### 11. Enterprise IT Risk rating Tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Kunal S. | Global Vulnerability & Threat Manager, Enterprise (> 1000 emp.)

**Reviewed Date:** June 06, 2021

**What do you like best about SecurityScorecard?**

Vulnerability Report includes all aspect of Security, including application, IT Infrastructure, and signature reflecting with malware.It determines these vulnerability  from outside footprinting without authenticated scan, There report shows all the information which a hacker can see from outside. Also it helps the organization to decide the partner which secures their IT properly.

**What do you dislike about SecurityScorecard?**

When there is new organization with whom you wish to have  partner it takes around seven days of time to provide its risk report.
Sometime it rate higher for certificate-related vulnerability. Also some times it includes the IP misrepresentation in the report

**What problems is SecurityScorecard solving and how is that benefiting you?**

Vendor RIsk Assessment 
Report easily represented in any GRC tool

  ### 12. SecurityScorecard is a good application to scoring about security on a company I think all is ok

**Rating:** 4.0/5.0 stars

**Reviewed by:** Teddy S. | IT Application Support, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 11, 2021

**What do you like best about SecurityScorecard?**

I think the best have in Scoring feature, in there we can see what is vulnerability on our system or network

**What do you dislike about SecurityScorecard?**

So far I dislike if I see many vulnerability I must patching haha

**What problems is SecurityScorecard solving and how is that benefiting you?**

I patching my problems like update old software and close the port was exposed to the public

  ### 13. SecurityScorecard - Review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Antonio  S. | Owner

**Reviewed Date:** May 21, 2021

**What do you like best about SecurityScorecard?**

Easy to administer domains and delivery the results to the Board

**What do you dislike about SecurityScorecard?**

price structure  is a bit complicated to handle

**What problems is SecurityScorecard solving and how is that benefiting you?**

Clear picture of all external vulnerabilities for a specific domain (and all related vendors)

  ### 14. Excellent tool for vendor risk assessments

**Rating:** 4.0/5.0 stars

**Reviewed by:** Brad H. | Information Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** November 05, 2019

**What do you like best about SecurityScorecard?**

It's nice to know that they are always watching my critical vendors and I can see how they are scoring.  I also like that I can invite vendors to join SecurityScoreCard at no cost to them.

**What do you dislike about SecurityScorecard?**

No problems with SecurityScoreCard at present.

**Recommendations to others considering SecurityScorecard:**

I liked SecurityScoreCard better than Bit Sight because SecurityScoreCard grades are easily understandable.  For example, with SecurityScoreCard, a vendor can get an 89 (B), but with BitSight their grade might be 647.  A bit more difficult to interpret.

**What problems is SecurityScorecard solving and how is that benefiting you?**

All of my critical vendors go through SecurityScoreCard.

  ### 15. Good idea but badly implemented, and poorly supported

**Rating:** 1.0/5.0 stars

**Reviewed by:** Bogdan O. | Manager, Security Operations, Mid-Market (51-1000 emp.)

**Reviewed Date:** February 12, 2021

**What do you like best about SecurityScorecard?**

The idea, the chance to assess the risk level and the security posture of various competitors, business partners and service providers

**What do you dislike about SecurityScorecard?**

Some of the assessments are producing misleading reports, the grade / score appears to be arbitrary and shall not to be trusted.  Client Support is terrible.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Status comparison between my company and other business entities

  ### 16. Start a conversation with score card

**Rating:** 4.5/5.0 stars

**Reviewed by:** Randy V. |  Offensive Security Engineer Lead, Small-Business (50 or fewer emp.)

**Reviewed Date:** August 13, 2020

**What do you like best about SecurityScorecard?**

You can get a real score from many different sources within minutes, this score is updated over the time so you can get real statistics from the changes in the applications or network.

**What do you dislike about SecurityScorecard?**

If the company has not been populated before, in some cases the first discovery takes up to 7 days. A 24 hours earlier report would be a good feature

**What problems is SecurityScorecard solving and how is that benefiting you?**

I use Security Scorecard to start a conversation with my customers, the main benefit is getting more services purchased by the customer due to the to acknowledge of the failures on the network/application.

  ### 17. Good software

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 10, 2021

**What do you like best about SecurityScorecard?**

I think best feature is on scoring feature, I can compare more than one company

**What do you dislike about SecurityScorecard?**

I dislike if I must solved the issue by myself

**What problems is SecurityScorecard solving and how is that benefiting you?**

The problem I solving like close security hole was exposed on public

  ### 18. Review Challenge Response

**Rating:** 4.0/5.0 stars

**Reviewed by:** Ari S. | Technical Consultant, Small-Business (50 or fewer emp.)

**Reviewed Date:** August 10, 2020

**What do you like best about SecurityScorecard?**

I think the most helpful feature of SecurityScorecard is Digital footprint and recommendation of issue

**What do you dislike about SecurityScorecard?**

The least helpful about SecurityScorecard is Comparation similiar companies

**Recommendations to others considering SecurityScorecard:**

You can considering SecurityScorecard if you want to close any vulnerability at your website and your infrastructure because its good and have any feature for check and give you a report of your infrastructure issue.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Security Analytics

  ### 19. SSC

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** August 10, 2020

**What do you like best about SecurityScorecard?**

The automated scanning and scoring that feeds into a portal where we can manage findings, resolutions, etc.

**What do you dislike about SecurityScorecard?**

Adjusted scoring seems to be to frequent
Patching cadence findings show in the score improvement plan generation and you cannot resolve those until the time elapses
I don't like the patching cadence logic and it is to rigid of a scoring mechanism for large organizations with multiple environments with an online presence.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Visibility into our digital footprint and a risk based scoring report

  ### 20. Security Scorecards: Excellent insight to security posture

**Rating:** 5.0/5.0 stars

**Reviewed by:** jason k. | Director, IT, Small-Business (50 or fewer emp.)

**Reviewed Date:** August 10, 2020

**What do you like best about SecurityScorecard?**

Consistent view to our posture, continually updated.

**What do you dislike about SecurityScorecard?**

Need better grouping for my industry for comparison.

**What problems is SecurityScorecard solving and how is that benefiting you?**

We had an issue previously how to show our clients and executives where we stand security posture wise.

  ### 21. Easy to use platform. Great customer service.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ron I. | Enterprise (> 1000 emp.)

**Reviewed Date:** August 10, 2020

**What do you like best about SecurityScorecard?**

Intuitive platform. Great customer support.

**What do you dislike about SecurityScorecard?**

Not sure about all the details around how SSC determines/generates an organizational scorecard.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Improving a Third Party Vendors SSC score. Increased cybersecurity posture of our organization and others.

**Official Response from Phoebe Fasulo:**

> Hi Ron,
Thank you for your review, we love hearing that our platform is easy to use and our customer success team is supporting you well.
Additionally, SecurityScorecard is committed to Trust & Transparency, which is why we have a detailed white paper (https://view.highspot.com/viewer/5f3562d28117171c996735fb) on our scoring methodology available for anyone to read. This is where you can find all the details around how SecurityScorecard determines an organization's score. You can find the white paper and additional insights on our Trust Portal (https://trust.securityscorecard.com/).

I hope this helps,
Phoebe

  ### 22. Holistic view of a company's digital security performance

**Rating:** 4.0/5.0 stars

**Reviewed by:** Mike L. | CISO, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 07, 2019

**What do you like best about SecurityScorecard?**

SecurityScoreCard provides a comprehensive view of the security of an organization's digital footprint.    Their team provides great support and pricing is competitive.

**What do you dislike about SecurityScorecard?**

Security ratings may be negatively impacted by non-critical assets, such as parked domains.    The dynamic nature of public cloud deployments where public IP addresses and services are dynamic may lead to false positives, and it can be time consuming to trace down the reason why assets have been assigned to your company which are not part of one's current asset inventory.

**Recommendations to others considering SecurityScorecard:**

I recommend SSC as a tool for both in house IT and Security teams to ascertain and monitor their own digital footprint, particularly for cloud service providers, as well as enterprise customers who are tasked with ascertaining the risk profile of their key suppliers.

**What problems is SecurityScorecard solving and how is that benefiting you?**

SecurityScoreCard is a useful tool in the vendor risk management tool chest which, when combined with 3rd party attestations like SOC reports and Pen tests provides a holistic view of the security practices are key suppliers as well as competitors.

  ### 23. Great tool in the VRA toolkit

**Rating:** 3.0/5.0 stars

**Reviewed by:** Aaron G. | IT Governance, Risk & Compliance Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** October 30, 2019

**What do you like best about SecurityScorecard?**

The ability to quickly ascertain the size of an org's digital presence and see whether or not they are addressing vulnerabilities appropriately; and whether or not they have open ports that are concerning.

**What do you dislike about SecurityScorecard?**

Attribution. I also manage our Scorecard and find myself spending a good deal of time sorting through IP lists to determine whether or not our cards are accurate. Parked domains can be problematic as far as introducing a significant amount of findings on scorecards (things like lack of https re-directs, spf records, etc.) This gives me a bit of pause when trying to analyse vendors' Scorecards because it can bring doubts as to the accuracy of their digital footprint (especially if they are inactive).

**Recommendations to others considering SecurityScorecard:**

Make good use of the ability to manage your own org's Scorecard. We have been able to use it to provide assurances to OUR clients, institutional investors, and FID partners as to the effectiveness of our cyber-security program.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Enabled us to identify independent advisor hosted sites that have wordpress vulnerabilities, servers w/ RDP open so we can reach out to remediate. Streamlines our Vendor Risk Assessment process, particularly when vendors are unable to provide vulnerability scans or pen test results during our due diligence process.

  ### 24. Best bang for the Buck in SecurityScore space

**Rating:** 5.0/5.0 stars

**Reviewed by:** Marvin G. | Mgr, Corporate Security Architecture, Enterprise (> 1000 emp.)

**Reviewed Date:** October 26, 2019

**What do you like best about SecurityScorecard?**

We use SecurityScorecard in a variety of ways; 1) watching ourselves to ensure our Internet footprint secure & following best practices, 2) as part of 3rd party security reviews/approvals of new vendors/SaaS, etc., and 3) Industry benchmarking & Board reporting.  4) We're just beginning to look at corporate spend & map that back to a SecurityScore-based heatmap for a more corporate view.  Also, the ability to quickly add previously unscored companies is a great feature.

**What do you dislike about SecurityScorecard?**

Biggest thing to me is around the lack of email notifications when user-initiatied 'offline/adhoc' processes are requested, which today requires the requestor to remember and go back & check, like: 1) requesting a new company be reviewed, which generally takes 3-5 days,  2) when security score reports have been requested, etc.  Improving here would greatly improve the user experience.

**Recommendations to others considering SecurityScorecard:**

The biggest value to us is the continuous monitoring of ourselves, and taking action on score changes.  From my perspective, continuous monitoring of 3rd parties hasn't been all that valuable to date - we found we didn't do anything with the alerts.  We're looking into integration with ServiceNow to enhance the approval process vs. being disjointed today - hope is to streamline the process.

**What problems is SecurityScorecard solving and how is that benefiting you?**

We're in our 2nd full year of use, and improved our overall score from 73-C to 98-A.  SecurityScorecard has brought to light several best practices that weren't being followed (especially around Email security & DNS (SPF/DKIM), SSL best practices, as well as, garbage collection, not to mention keeping tabs on a sprawling web presence.  While it was a tremendous amount of work to clean up the environment, it's now relatively easy to keep clean, enabling us to see a drastic reduction in the number of successful web attacks, as well as, increasing the effectiveness of the advanced security capability of our email filtering capability, resulting in reductions in the number of actual phish in users' mailboxes.

  ### 25. Rich Risk Information in a Clean GUI

**Rating:** 5.0/5.0 stars

**Reviewed by:** Chris K. | Information Security Advisor, Enterprise (> 1000 emp.)

**Reviewed Date:** October 15, 2019

**What do you like best about SecurityScorecard?**

I appreciate the way Security Scorecard brings together publically available risk information and provides an initial risk analysis. The GUI interface makes it easy to drill deeper into areas of interest and the Historical trending allows you to materialize risk reduction. The ability to invite vendors to see their scorecard is a nice touch combined with allowing the customer to question, refute, or resolve any identified vulnerability.

**What do you dislike about SecurityScorecard?**

The tool does a great job at managing a vendor with a wealth of information but lacks tools to effectively and efficiently manage entire portfolios of hundreds of vendors. There are few options to bubble to the surface highest risk issues across and entire portfolio and recently identified and posted vulnerabilities so that risk mitigation efforts can begin. The Breach Insight feature is lacking in credibility and effectiveness. The lack of CVE numbers & CVSS security ratings can led to subjective opinion of risk by Security Scorecard versus the collaborative\standard presented by a CVE\CVSS.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Currently we are monitoring 1000+ third parties identifying the worst performing companies overall as well as within specific risk areas or specific vulnerabilities. Once alerted or identified then proactive efforts are taken to verify the potential vulnerability and work with the third party to mitigate. We are also leveraging the breach\incident alerts to review potential impact and risk exposure and liabilities.  

  ### 26. Excellent tool and service behind

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 01, 2019

**What do you like best about SecurityScorecard?**

The Security Scorecard offers us what we need in terms of continuous assessment of the external network vulnerabilities tests. The webUI is user-friendly and built in a logical format, very easy to use and dig for information on it. 

**What do you dislike about SecurityScorecard?**

There is no user option to re-launch the test, so you get confirmation that your fix really works. Claiming a fixed issue takes some time and a ticket to Security ScoreCard Support to validate it. Also, the propagation of the fix may take some time, before it gets reflected on the organization's score.

**Recommendations to others considering SecurityScorecard:**

Try it. Ask for a demo. 

**What problems is SecurityScorecard solving and how is that benefiting you?**

We have a full picture of our organization's exposure on the public domain. Getting this "big picture" for the entire IP space helps us prioritize the mitigation actions and the maintenance windows for our external hosts. Also, having the issues summarized, explained, and the solution suggested for any problem that came out of scans, it's really helpful.

  ### 27. The sucess behind SSC is its people

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Food Production | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

Many times you buy a security tool and after a short onboarding period, you are on your own. The experience with SSC has been the opposite. They were there and continue to be there for us. From the sales, to support, to continuous customer care, the experience has been outstanding. SSC stands behind its product and is ready and able to engage whenever we bring our third parties to the table or have any questions. They have been very responsive to our needs (e.g. training, deployment, questions by internal teams and third parties, open to feedback, etc.) The tool is helping us assess a large number of third parties that we are discovering.

**What do you dislike about SecurityScorecard?**

Does not have enough capabilities yet to gain insight on how the tool is being used within the organization.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Rapid assessment and prioritization of third parties that are popping up as part of a discovery process. It is enabling us to become more agile and have more intelligent and fact-supported conversations with our third parties.

  ### 28. Outstanding new perspective on third party risk.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

The SecurityScorecard platform provides insights that an organization would otherwise not have related to security.  Understanding where critical risks may exist dramatically reduces the risk posture of the third party population through coordinated remediation requests and efforts.

**What do you dislike about SecurityScorecard?**

The only downside to the use of he platform, and it is a very minor negative, would be the inability to create very granular alerts within the platform.  The current alerting, while extremely beneficial, does require a little research after a notification is received to understand the underlying problem.

**Recommendations to others considering SecurityScorecard:**

It is highly recommended to explore the options available to the end user through the vast array of API endpoints.  Detailed information can be obtained and parsed through scripting and automation.  The remediation support that the SecurityScorecard team provides through their validation efforts is also top notch.  The customer success managers work alongside you throughout both the implementation and training process as well as navigating the ongoing usage of the platform.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Through the use of the multiple API endpoints, performing periodic checks for public breaches across the vendor population has been completely automated.  Additionally, the alert capabilities provides great insight into pressing issues that a vendor's attention should be focused on for remediation purposes to reduce their inherent risk.

  ### 29. Great product for 3rd eye view

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

We use SecurityScorecard for evaluating ourselves to ensure our public footprint is secure and use it as part of 3rd party security reviews in comparison to peers and new vendors to work with. It definitely provides an insight with data transparency and ease of use UI. Support team is super responsive and that's one of the key features.

**What do you dislike about SecurityScorecard?**

Continuous improvement are a part of SS but Email notification can be added, it will be great.

**What problems is SecurityScorecard solving and how is that benefiting you?**

We use SecurityScorecard for evaluating ourselves to ensure our public footprint is secure and use it as part of 3rd party security reviews in comparison to peers and new vendors to work with. It definitely provides an insight with data transparency and ease of use UI. Support team is super responsive and that's one of the key features.

  ### 30. SecurityScorecard for Continuous Security Monitoring 

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Insurance | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

What we like best about SecurityScorecard is the intuitive user experience and well organized content. The platform is very well layered to provide a wide audience with reporting, security risk metrics, and technical risk details to help support the needs of a well rounded Continuous Monitoring program. It enables its users to not only detect, but react and collaborate with in scope suppliers through the use of the vendor invite functionality. Additionally the Security Scorecard team has been beyond supportive in this journey helping the team to not only understand the tool, but how to develop processes and a program structure to maximize the value the tool brings.

**What do you dislike about SecurityScorecard?**

1) The team often finds themselves needing to refresh pages such as the insights dashboard, a supplier profile, ip inventory, etc. The data often doesn't load and we receive error messages advising us to refresh. 2) Inability to track and report on invited vendor engagements such as when the vendor was invited, did they accept the invite, when did they last login, etc. 3) Custom Scorecard data unavailable through the API.

**Recommendations to others considering SecurityScorecard:**

Some recommendations our team would make to others using SecurityScorecard is to first familiarize themselves with the capabilities of the tool, become comfortable with the data, and understand how the platform will fit into your overall 3rd Party Risk Management and Security strategy prior to issuing licenses and engaging with your vendor partners.

**What problems is SecurityScorecard solving and how is that benefiting you?**

Problems Being Solved: Security Scorecard has filled the gap between our point in time, questionnaire based security assessments. This has instilled a new sense of comfort in our organization knowing that we have the ability to detect and seek remediation for possible risk prior to the next security assessment.
Benefits: The platform has enabled my team to maximize their vendor collaboration and remediation efforts through native portfolio management, dynamic filtering, and configurable real-time alerting.

  ### 31. Great utility for a reasonable cost!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Research | Enterprise (> 1000 emp.)

**Reviewed Date:** November 14, 2019

**What do you like best about SecurityScorecard?**

SecurityScorecard presents security metrics that are easy to understand and present to upper management. It has given me ammo to change some low-hanging security settings without burdening my staff.

**What do you dislike about SecurityScorecard?**

There can be some false positive when looking at the scorecards of vendors because they may use cloud resources which are shared by other companies so malware sources or IP reputation might have been affected by the other companies using the same resource.

**What problems is SecurityScorecard solving and how is that benefiting you?**

It is a fast way to give a surface look at the security postures of other vendors or peers. It allows me to push for security changes.

  ### 32. A valued resource and a true partner.  

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Insurance | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

In a word: ACCESSIBILITY.  Everyone makes you feel like your issues actually matter and will elevate to the appropriate people.  The escalation path never feels like someone trying to satiate you.  

**What do you dislike about SecurityScorecard?**

Random errors and slowdowns.  It can take a LONG TIME to generate a report.  

**Recommendations to others considering SecurityScorecard:**

Simply has better support than BitSight.  If you feel that you're on the fence, ask to speak to the customer success team.  It's honestly one of their best features - the people.  

**What problems is SecurityScorecard solving and how is that benefiting you?**

I don't know how we would perform proper ongoing monitoring if not for SSC.  Using the individualized domain reporting for Inherent Risk calculations have also proven to be integral.  

  ### 33. Great Interface and 

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Human Resources | Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2019

**What do you like best about SecurityScorecard?**

Super User friendly interface
Great insight into the security posture
The detailed report analysis are best in class compared to other reporting tools

**What do you dislike about SecurityScorecard?**

Domain/IP mapping for company entities is fairly inaccurate
I would like to see improvements to the bottom three scorecard domains (Hacker Chatter, Information Leak and Social Engineering), they tend to never change

**What problems is SecurityScorecard solving and how is that benefiting you?**

Security Scorecard helps our team kick start the our Vendor Security Risk Assessments. We are able to leverage scores and findings during our vendor review process. I'm a huge fan of the different changes we can make to the dashboard. I also find the security news section insightful. 

  ### 34. Great insights into your own security stance and your vendor’s

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 06, 2019

**What do you like best about SecurityScorecard?**

Comprehensive research presented well. Quick and helpful support team!

**What do you dislike about SecurityScorecard?**

Sometimes items get misidentified a few times until the algorithm get updated. As the support team is quick in removing demonstrated incorrect entries, this isn’t a big detractor.

**What problems is SecurityScorecard solving and how is that benefiting you?**

The main driver was to have a near continuous monitoring of our external infrastructure for open vulnerabilities and incorrect/insecure configurations. We found a number of improvements and improved our standing significantly. We also react faster to new vulnerabilities.
A secondary driver was to review our vendors; this provided some helpful insights and some interesting conversations with underperforming vendors.

  ### 35. Simple and straightforward tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Banking | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 31, 2019

**What do you like best about SecurityScorecard?**

SS interface is user friendly, easy to explain to other staffs in the bank. 

**What do you dislike about SecurityScorecard?**

We have started using the platform, once we mature with time we would be in better postion to provide the feedback on dislike.

**Recommendations to others considering SecurityScorecard:**

SS is simple to use and up to the point, support team are very helpful.

**What problems is SecurityScorecard solving and how is that benefiting you?**

* Third party is always a high risk area, especially where customer information are shared. 
* With traditional third party assessment approach, it is very difficult to regularly track on vulnerabilities and then its mitigation. 
* With SS platform, vulnerabilities tracking & mitigation process is simplified.

  ### 36. Best 3rd party vendor management tool for the money

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 22, 2019

**What do you like best about SecurityScorecard?**

I am able to review our vendors in real time to frameworks such as PCI, HIPAA and many more. We had a vendor say they were HIPAA compliant and I was able to show them they were not according to security scorecard

**What do you dislike about SecurityScorecard?**

They make so many improvements to the product at this point it would only be nitpicking 

**Recommendations to others considering SecurityScorecard:**

Start off with 5 vendors. You can switch them up on a daily basis. If you need more then you can buy more later.

**What problems is SecurityScorecard solving and how is that benefiting you?**

We are able to watch our vendors and make informed decisions on new vendors.  

  ### 37. New Implementation 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Banking | Enterprise (> 1000 emp.)

**Reviewed Date:** November 04, 2019

**What do you like best about SecurityScorecard?**

Security Scorecard allows us to  monitor the changing security posture of our suppliers

**What do you dislike about SecurityScorecard?**

One feature that would be great is to be able to nest portfolios.  In the compliance tab having the ability to have a holistic view of all of our vendors that do not meet a certain control

**What problems is SecurityScorecard solving and how is that benefiting you?**

The benefits of the platform allows us to provide and additional view of risk associated with using third parties 

  ### 38. Improve supplier communication

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Information Services | Enterprise (> 1000 emp.)

**Reviewed Date:** October 31, 2019

**What do you like best about SecurityScorecard?**

SecurityScorecard supports the communication with supplier by adding more focus in potential risks and the possibility to interact. 

**What do you dislike about SecurityScorecard?**

Sometimes IPs/URLs impact the score even if they are unused and only reserved for a company. 

**Recommendations to others considering SecurityScorecard:**

SecurityScorecard puts the focus in the right direction, it is not the tool to fix your issues. 

**What problems is SecurityScorecard solving and how is that benefiting you?**

Improving communication with supplier and sharpening the view on the own estate.

  ### 39. Good product, great support!

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Insurance | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 01, 2019

**What do you like best about SecurityScorecard?**

Very helpful team. Product is robust and accurate, we use it as a core component of our third party risk management programme and we are not dissapointed. It's great that Security Scorecard keep updating the platform and developing useful new features. 

**What do you dislike about SecurityScorecard?**

Occasional false positives have caused internal and external issues

**What problems is SecurityScorecard solving and how is that benefiting you?**

Easy oversight of vendors and partners, quick resolution of issues.

  ### 40. The tool is really helful to know the security status of a company , data breaches and data issues

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** November 01, 2019

**What do you like best about SecurityScorecard?**

The best part is that post you know the issues & breaches of a company, you can invite them to get remediation. You can help them improve

**What do you dislike about SecurityScorecard?**

The process of adding companies to portfolio need a little improvement. Sometimes the weblink inside the company does not open up. Also sometime the tool is little slow

**Recommendations to others considering SecurityScorecard:**

This tool is really helful as it covers different domains related to information security and very helpful to improve the score/grade of a company

**What problems is SecurityScorecard solving and how is that benefiting you?**

Sending Questionnaire and assessment questions is really awesome.
Help in improving security scores of companies

  ### 41. SS helps me do my job

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Retail | Enterprise (> 1000 emp.)

**Reviewed Date:** October 17, 2019

**What do you like best about SecurityScorecard?**

Easy to understand rating system.  Evaluation against industry peers.

**What do you dislike about SecurityScorecard?**

Not every vendor has a ScoreCard available

**What problems is SecurityScorecard solving and how is that benefiting you?**

Used to evaluate vendors and third party risk


## SecurityScorecard Discussions
  - [Apart from Third Party &amp; Supplier Risk Management, How can we use other functionality of SS?](https://www.g2.com/discussions/apart-from-third-party-supplier-risk-management-how-can-we-use-other-functionality-of-ss) - 1 comment, 1 upvote
  - [What is SecurityScorecard used for?](https://www.g2.com/discussions/what-is-securityscorecard-used-for) - 1 comment
  - [How much does BitSight cost?](https://www.g2.com/discussions/how-much-does-bitsight-cost) - 1 comment
  - [Why SecurityScorecard?](https://www.g2.com/discussions/why-securityscorecard) - 1 comment

- [View SecurityScorecard pricing details and edition comparison](https://www.g2.com/products/securityscorecard/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-07-20+01%3A55%3A37+-0500&secure%5Bsession_id%5D=46250286-644d-4e2a-8678-880b5655b6b5&secure%5Btoken%5D=98884577b249ef2440b2bfe565aa33d8761ba084ab4da3df0a2676f3fdb67592&format=llm_user)
## SecurityScorecard Integrations
  - [Microsoft PowerPoint](https://www.g2.com/products/microsoft-powerpoint/reviews)

## SecurityScorecard Features
**Functionality**
- Customized Vendor Pages
- Centralized Vendor Catalog
- Questionnaire Templates
- User Access Control

**Generative AI**
- AI Text Generation

**Risk assessment**
- Risk Scoring
- 4th Party Assessments
- Monitoring And Alerts
- AI Monitoring

**Monitoring - IT Risk Management**
- AI Monitoring

**Generative AI - Vendor Security and Privacy Assessment**
- Text Summarization
- Text Generation

**Agentic AI - IT Risk Management**
- Autonomous Task Execution
- Multi-step Planning

## Top SecurityScorecard Alternatives
  - [UpGuard Vendor Risk](https://www.g2.com/products/upguard-vendor-risk/reviews) - 4.5/5.0 (722 reviews)
  - [Bitsight](https://www.g2.com/products/bitsight/reviews) - 4.5/5.0 (76 reviews)
  - [LogicGate Risk Cloud](https://www.g2.com/products/logicgate-risk-cloud/reviews) - 4.6/5.0 (189 reviews)

