-
“UpGuard’s Cyber Risk scoring helps us understand which of our vendors are most likely to breach so we can take action now, before something happens."
-
"We now have an automated, robust process for validating that planned changes are made correctly. That reduces regulatory and operational risk, lowers costs, and allows us to drive continuous improvement."
-
"UpGuard was able to give us insight immediately into our online profile and identify our cyber risk."
-
"UpGuard to quickly assess the security profile of new company acquisitions to determine their impact on the company’s own security posture. The CIO notes that with so many third-party vendors to manage, immediate security score feedback is instrumental in providing accurate risk assessment."
-
“The biggest factor for us was time, We needed a tool that wouldn’t take more time to manage than the value it provided. UpGuard was by far the most efficient and user-friendly.”
-
“We’re stewards of public funds, When we choose a vendor, we need to justify that decision. Now, if anyone questions why we selected a particular provider, we can point to an independent, third-party assessment. That transparency is crucial.”
-
"Before UpGuard, conducting proper research for each vendor would eat up a lot of time – Does it comply with our requirements? Where is their data located? Do they have privacy policies."
-
"Our vendor security risk assessments are now a well-oiled machine from where we started using UpGuard."
-
“We check the dashboard daily. Our score reflects how well we are doing. The higher the score, the more confident we are in our security posture.”
-
“Before using UpGuard, our cyber risk management processes were very immature and still developing. Even after we started using UpGuard, we weren’t leveraging the tools the best we could.”
-
"Having an automated way to look at the attack surface is a great way to flag things like unmanned pages or EOL apps. It’s a low-hanging fruit to improve our security."
-
"UpGuard provides me an overview of the security across all the schools and helps me fix these security issues."
-
“If they had a potential accounting impact, then we would insist on a SOC 1, Type 2 or SOC 2, Type 2. If they did not have an accounting impact, we had a phone call or sent a questionnaire.”
-
“I take a deep dive into the technical features to help the vendor when I send a remediation request.”
-
“I look at the newsfeed to see if any companies we do business with have had a cybersecurity incident.”