"Vendor Risk helps us manage vendor security performance across a diverse client base. It’s easy to use, and the vendor security questionnaire module helps us track workflows, surface security and prioritise specific risks for remediation."
"We can now get comprehensive vulnerability reports, tied directly to specific CIs. Because of this, we’ll also be able to drive end-to-end remediation processes within ServiceNow, and tie this directly back into other areas such as GRC.”
"Having a system like UpGuard helps us sleep at night because we always know if we’ve overlooked any vulnerabilities."
“If they had a potential accounting impact, then we would insist on a SOC 1, Type 2 or SOC 2, Type 2. If they did not have an accounting impact, we had a phone call or sent a questionnaire.”
“I take a deep dive into the technical features to help the vendor when I send a remediation request.”
“I look at the newsfeed to see if any companies we do business with have had a cybersecurity incident.”
“UpGuard’s Cyber Risk scoring helps us understand which of our vendors are most likely to breach so we can take action now, before something happens."
"Open-Xchange uses a vulnerability scanner across the organization’s internal and external attack surfaces. While the scanner provides in-depth coverage, it doesn’t have asset discovery capabilities. It can only monitor what we know. It doesn’t have a perfect register of where every IT asset is, especially as we use dozens of cloud services for testing purposes.”
“Before using UpGuard, our cyber risk management processes were very immature and still developing. Even after we started using UpGuard, we weren’t leveraging the tools the best we could.”
“Before UpGuard, we had to juggle the vendors we could monitor due to our limited-licensing structure. If we partnered with a new vendor, we had to evaluate which vendors to remove to make room.”
"Our vendor security risk assessments are now a well-oiled machine from where we started using UpGuard."
"We now have an automated, robust process for validating that planned changes are made correctly. That reduces regulatory and operational risk, lowers costs, and allows us to drive continuous improvement."
"Before UpGuard, our vendor risk management activities were less effective and comprehensive, even began after a vendor was onboarded. Now it's easy to monitor them via the dashboard, and it starts before they even sign the agreement."
"One thing that's been really impressive has been the continuous little tweaks and new features that the development team has been doing. Those things keep the solution fresh and I find the new features are really, really useful."