“We had basic questions regarding business processes and security controls, but wanted to go deeper to provide high-level reporting that provided clarity into the vendor.”
"If a vendor score drops below 600, we know there is a security issue with that vendor and we work with them to remediate that."
"Upguard has helped us de-risk our organisation, with solutions that are both reliable and accurate in producing fact-based information about our key suppliers, that we can proactively act on in order to help keep our platforms secure and stable."
"The UpGuard platform automatically identifies pockets of our exposure to 4th party vendor risk. When a major outage is announced, we know in a matter of minutes how this could affect our vendors’ ability to serve us and, in turn, our ability to serve our clients."
“UpGuard’s real-time security scoring system is beneficial. I get immediate feedback after releasing new functionality or responding to a highlighted risk. Seeing your security score go up is gratifying, almost like winning in a video game. Hence, it provides a psychological incentive to take care of the otherwise mundane task.”
“We check the dashboard daily. Our score reflects how well we are doing. The higher the score, the more confident we are in our security posture.”
“You see relevant information about a vendor in one place, including their location, security score.”
"We’re not just asking our vendors security questions. We’re also performing scans to confirm there are no security concerns. This helps us automate the security questionnaire process."
"One thing that's been really impressive has been the continuous little tweaks and new features that the development team has been doing. Those things keep the solution fresh and I find the new features are really, really useful."
“UpGuard’s Cyber Risk scoring helps us understand which of our vendors are most likely to breach so we can take action now, before something happens."
"Before UpGuard, conducting proper research for each vendor would eat up a lot of time – Does it comply with our requirements? Where is their data located? Do they have privacy policies."
"UpGuard was able to give us insight immediately into our online profile and identify our cyber risk."
"Before UpGuard, our vendor risk management activities were less effective and comprehensive, even began after a vendor was onboarded. Now it's easy to monitor them via the dashboard, and it starts before they even sign the agreement."
“If they had a potential accounting impact, then we would insist on a SOC 1, Type 2 or SOC 2, Type 2. If they did not have an accounting impact, we had a phone call or sent a questionnaire.”
“I take a deep dive into the technical features to help the vendor when I send a remediation request.”