“We had basic questions regarding business processes and security controls, but wanted to go deeper to provide high-level reporting that provided clarity into the vendor.”
"If a vendor score drops below 600, we know there is a security issue with that vendor and we work with them to remediate that."
"Upguard has helped us de-risk our organisation, with solutions that are both reliable and accurate in producing fact-based information about our key suppliers, that we can proactively act on in order to help keep our platforms secure and stable."
"UpGuard provides me an overview of the security across all the schools and helps me fix these security issues."
"Our vendor security risk assessments are now a well-oiled machine from where we started using UpGuard."
“If you’re familiar with Active Directory Group Policy, then UpGuard makes a lot of sense. Ultimately you have this environment and you have this policy you’re applying to it. We’re also using Octopus Deploy and UpGuard uses many of the same methodologies. The two products complement each other.“
“Before UpGuard, we had to juggle the vendors we could monitor due to our limited-licensing structure. If we partnered with a new vendor, we had to evaluate which vendors to remove to make room.”
"One thing that's been really impressive has been the continuous little tweaks and new features that the development team has been doing. Those things keep the solution fresh and I find the new features are really, really useful."
“If they had a potential accounting impact, then we would insist on a SOC 1, Type 2 or SOC 2, Type 2. If they did not have an accounting impact, we had a phone call or sent a questionnaire.”
“I take a deep dive into the technical features to help the vendor when I send a remediation request.”
“I look at the newsfeed to see if any companies we do business with have had a cybersecurity incident.”
“The UpGuard user experience was much nicer than other platforms and easier to use, while other platforms felt more outdated and not as friendly.”
"Open-Xchange uses a vulnerability scanner across the organization’s internal and external attack surfaces. While the scanner provides in-depth coverage, it doesn’t have asset discovery capabilities. It can only monitor what we know. It doesn’t have a perfect register of where every IT asset is, especially as we use dozens of cloud services for testing purposes.”
"Thanks to UpGuard’s custom questionnaire builder, the custom questionnaire we have created will significantly speed up our vendor assessment process. Many assessments will be reviewed and approved in only half an hour."