Listing Thumbnail

    Bitsight for Security Performance Management

     Info
    Sold by: Bitsight 
    Deployed on AWS
    Vendor Insights
    Drive accountability and transparency across the organization based on a uniform security performance target. With this governance framework in place, measure the effectiveness of security controls, analyze the attack surface, prioritize findings and track remediation activities. Annual subscription.
    4.6

    Overview

    Bitsight pioneered the security ratings industry in 2011, creating our cybersecurity ratings platform. Today, the Bitsight rating is known around the world as a trusted analytic to help organizations understand and manage cyber risk.

    Leveraging the Bitsight Security Rating, the only rating independently correlated to the likelihood of a breach and a company's stock performance, over 2,400 companies build trust in their cybersecurity and third-party risk management program. Bitsight helps organizations drive market decisions, like credit analysis, financial ratings, pricing, ESG frameworks, and Mergers and Acquisitions activity. This gives confidence to vendors and the extended organization, enabling a safe and more secure world by empowering better cyber risk decisions.

    Bitsight helps organizations identify, quantify, and reduce cyber risk

    Bitsight Security Performance Management (SPM) measures an organization's cybersecurity performance over time. With continuous visibility of the organization's extended digital footprint and a differentiated view of the organizations unique hierarchical structure, SPM facilitates organizational cyber risk oversight. Security leaders and their teams rely on BitSight SPM for:

    For custom pricing offers, please contact: bitsightawsmp-customoffer@bitsight.com 

    Highlights

    • 44+ trillion raw events collected & 100 billion new events collected each day
    • 40 million rated organizations worldwide with 12+ months of historical data included
    • For custom pricing offers, please contact: bitsightawsmp-customoffer@bitsight.com

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Bitsight for Security Performance Management

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    SPM Enterprise Combined
    per license (includes 20 benchmarking subscriptions)
    $138,550.00

    Vendor refund policy

    No refunds

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Device Security
    Top
    10
    In Procurement & Supply Chain, Legal & Compliance
    Top
    10
    In Centralized Risk Management

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Cyber Risk Analytics
    Advanced platform utilizing 44+ trillion raw events and 100 billion new events daily for comprehensive cybersecurity risk assessment
    Security Performance Measurement
    Continuous visibility and monitoring of an organization's extended digital footprint with performance tracking over time
    Breach Likelihood Correlation
    Security rating independently correlated to potential breach probability and organizational stock performance
    Third-Party Risk Management
    Capability to analyze and evaluate cybersecurity risks across vendor ecosystems and extended organizational networks
    Global Organizational Rating
    Comprehensive rating system covering 40 million organizations with 12+ months of historical cybersecurity performance data
    Threat Intelligence Monitoring
    Continuously monitors 10 risk factor groups using non-intrusive data collection methods and commercial and open-source threat feeds
    Cybersecurity Risk Rating
    Provides quantitative cybersecurity posture evaluation using an easy-to-understand A to F rating system
    Vendor Risk Assessment
    Enables automated questionnaire completion and validation with integrated inside-out and outside-in risk perspective
    Data Collection Methodology
    Utilizes proprietary and trusted data collection techniques for comprehensive cybersecurity assessment
    Continuous Monitoring Technology
    Performs real-time cybersecurity posture tracking across multiple organizations and risk domains
    Risk Quantification Model
    Utilizes FAIR™ Model for quantifying and analyzing cybersecurity risks with defensible methodology
    Risk Signal Aggregation
    Automatically ingests diverse telemetry signals from enterprise-wide controls to dynamically represent business risk exposure
    Risk Scenario Management
    Provides library of built-in cyber risk scenarios with capability to create custom scenarios for comprehensive risk assessment
    Multi-Party Risk Visibility
    Enables unified cyber risk visibility across first-party and third-party environments in a single integrated platform
    Real-Time Risk Tracking
    Delivers real-time, dynamic representation of cyber risk posture with continuous monitoring and assessment capabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    77 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    51%
    40%
    8%
    1%
    0%
    1 AWS reviews
    |
    76 external reviews
    External reviews are from G2  and PeerSpot .
    Suresh A.

    Continuous monitoring has strengthened external security and improved customer trust

    Reviewed on Dec 10, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Bitsight  is finding vulnerabilities in the wild, especially in internet-facing web applications and networks.

    A specific example of how I have used Bitsight  is that we do not know the current ongoing issues day-to-day. There are so many vulnerabilities and zero days that are exploitable and outside. With this platform, we are able to detect vulnerabilities quickly and notify the teams using our communication channel. Along with that, it also helps us to remediate quickly because when issues are identified, they should also be included in the remediation part. That is where we were able to sort it out quickly.

    Another use case I would add is that Bitsight builds customer trust because it provides a score based on severities or how the system is currently functioning. If our system is secure and we have strengthened the full security, then we will eventually have a good score. That is going to build customer trust.

    What is most valuable?

    The best features Bitsight offers include heavily using external vulnerability scans or network scans, which we have done for a couple of years.

    What I appreciate about the external scans feature in Bitsight is that it gives us continuous visibility into our externally exposed assets, which requires finding misconfigurations or any unexpected exposures much earlier than we would have caught through manual review period scans. This essentially allows my team to find issues quickly, and as we get notified, we can validate our attack surface. It helps us to reduce blind spots. We can prioritize remediation faster and validate changes by deploying fixes. Overall, it strengthens our security posture by monitoring and supporting our compliance programs.

    Regarding Bitsight's features, they offer different aspects that I agree with, especially in external scans. They also provide a rating based on your externally facing domains, which helps us to rate our scores and aids in building customer trust. They have the capabilities to assess the attack surface, so those are the main areas they focus on.

    Bitsight has positively impacted my organization by improving security and customer trust. It is impact-focused with measurable values that show us, for example, it has reduced our mean time to detect external exposure issues before we relied on periodic scans. Plus, it gives us continuous monitoring. Now we find misconfigurations within hours instead of days or weeks, which directly improves our overall security posture. It reduces risk as we catch high-risk exposures early, especially unexpected cloud assets or testing endpoints that accidentally went public. Each early detection helps us reduce the threat exposure time and strengthen the compliance program.

    What needs improvement?

    There are areas for improvement; we do notice sometimes finding vulnerabilities which gives us visibility to find them quickly. However, there could be a mechanism they can build on top of that for validation as they identify the issues. What will the real risk be for that identifiable issue? Sometimes it could be open because of the traffic; how they detected it could be seen as vulnerable, but upon testing, it might not be a real issue. It could be a false positive because there could be a honeypot that we built. My thinking is about validation, so if they can build that validation part before they expose the risk to the specific asset, that would help. Additionally, based on their reporting, they could also build risk scores and prioritization, which would also aid us.

    I would suggest adding dashboards and custom reporting, which could help us by enabling rich custom reports with filters. That is especially for leadership because they will not look at each technical area, but overall they would be looking at the risk score and what the assets or critical exposure areas are. Customizable reporting based on requirements would be valuable.

    I chose 9 out of 10 because the reporting and dashboards would be the first thing I would consider for improvement, and then the second is about the validation part, which could probably improve to 10 out of 10.

    I cannot think of too much for additional improvements. Maybe some good automation with the API solutions that could be integrated with the CI/CD pipeline or DevOps tools we are running would also be automated and tested.

    For how long have I used the solution?

    I have been using Bitsight in my past job as well as in my current job. I would say it is around eight years.

    What do I think about the stability of the solution?

    Bitsight is stable so far.

    What do I think about the scalability of the solution?

    The scalability of Bitsight is good; it is a cloud solution, so upon usage, it scales out without being a concern at this moment.

    How are customer service and support?

    We do interact with Bitsight's support team, and we do get a response back from them as defined in the SLAs.

    I would rate the customer support from Bitsight as 10 out of 10.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Previously, I used SecurityScorecard , which is a competitor in that space. I think that Scorecard had functional issues, and because of that reason, we switched to Bitsight.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing for Bitsight is overall good with the current price model.

    I feel the current pricing model is fair. The initial setup and licensing process was straightforward. I did not face any challenges in that part.

    What was our ROI?

    I do not have a good answer regarding return on investment with Bitsight.

    Which other solutions did I evaluate?

    Before choosing Bitsight, I did not evaluate too many options, but I compared between Bitsight and Scorecard, along with one more tool that I lost the name of, but Bitsight won out of those three.

    What other advice do I have?

    My advice for others looking into using Bitsight is that it is definitely a great tool, especially to identify blind spots. If your applications are internet-facing and you have customers using your products or your cloud-based solutions, whether SaaS or PaaS, this tool is going to build trust between the customer and the provider. As the tool deploys for your application or domains, it continuously scans and finds vulnerabilities and reports them. As you find and report, it is also going to build your domain score, showing how well you are doing with publicly available applications, especially those that are internet-facing. I gave this review a rating of 9 out of 10.

    Tarang Parmar

    Automated monitoring has strengthened our vulnerability visibility and improved remediation workflows

    Reviewed on Dec 09, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Bitsight  is to identify the available vulnerabilities on the network side, and I rely on it for that the most.

    What is most valuable?

    The best features that Bitsight  offers include the way of presenting the data, which is very good because you can get proof while reviewing your findings. This helps our infrastructure team identify and fix those findings.

    Those features help our team by making things easier. For example, if we have a specific security header missing, Bitsight shows us that, such as HSTS being missing, providing specific details on what header is lacking on our websites.

    I would add that Bitsight has a task assignment feature that allows us to keep assigning tasks to different team members so they can work on the specific findings assigned to them. Additionally, it has report features, enabling us to generate reports and send them to our clients to show how well we are remediating issues. We can also share our score with the client to improve our client relations.

    Bitsight has positively impacted our organization. After using it, we discovered many things. As I mentioned, we have many vulnerabilities available, and it keeps identifying and showing us them, which is valuable.

    What needs improvement?

    Bitsight has been good overall, and I do not see any negative points. However, if another organization can spy on us, that is concerning, as they can see our score and we cannot see theirs.

    I wish for the addition of features such as leak credentials within Bitsight, which would be more useful because we need to rely on some other third-party tools. If those features were available, there would be no need to use additional tools.

    I chose 8 out of 10 because if we receive invites from clients every 45 days, our subscription ends, and we have to renew it. Additionally, it does not show vulnerabilities according to the CVSS score or the impact they are causing. Instead, it labels these vulnerabilities as bad or one, which can be confusing for those unfamiliar with identifying errors. It would be better to categorize them as high vulnerability, critical vulnerability, or low vulnerability.

    What other advice do I have?

    A quick specific example of how I have used Bitsight to identify a vulnerability is when it helped us catch bad and one vulnerabilities we mostly search for, giving us a better idea if we have any public IP available on the internet that can directly expose us and is already bypassing our firewalls. Those IPs we need to make private to secure ourselves.

    In my day-to-day work with Bitsight, we do not have to do any manual scans. We just put our company name and the details, and it automatically identifies all our assets and all our internal things and all the details, such as NS lookup and any other technique it is using. We discover multiple things such as open ports, CSV vulnerabilities, missing security headers, and publicly available IP addresses.

    Regarding specific outcomes, earlier we had a bad score of around 600 with many vulnerabilities. After using Bitsight, we know about vulnerabilities whenever they are published or observed, and we keep remediating those vulnerabilities. This actually increased our score to 670.

    My advice to others looking into using Bitsight is that it provides a lot of information that was not available before, and it is especially good in recon as it can identify many things about an organization that have never been found earlier, making it a valuable tool.

    Overall, I believe Bitsight is good because everything is covered, including user management, so I have no additional thoughts beyond that. I give this product a rating of 8 out of 10.

    Insurance

    Great for Risk Monitoring, But Alert Email Config Needs Improvement

    Reviewed on Nov 05, 2025
    Review provided by G2
    What do you like best about the product?
    There are two main features that assist us. The first to be able to monitor our risk posture from an external perspective and compare ourselves with other like businesses. The other which is currently very important is the ability to monitor our Thirds Parties and be able to make risk based decisions on whether we do business with them. This is important due to APRA 230 requirements
    What do you dislike about the product?
    At the moment there are some limitations in how we can configure alert emails.
    What problems is the product solving and how is that benefiting you?
    It is allowing us to achieve compliance with APRA 230 in terms of meeting TPRM obligations. It also allows our GRC team to do risk assessment of Third Parties as well as assisting in assessing compliance to ISO 27001 or SOC standards
    Hospital & Health Care

    Resourceful and Reliable, with Occasional Glitches

    Reviewed on Nov 04, 2025
    Review provided by G2
    What do you like best about the product?
    how resourceful it is! very reliable and user friendly.
    What do you dislike about the product?
    sometimes it glitches out, but all systems have a tendency to do that from time to time.
    What problems is the product solving and how is that benefiting you?
    being collaborative in unique ways.
    reviewer2774376

    Have improved external security monitoring and vendor oversight but still face accuracy challenges in scan results

    Reviewed on Nov 03, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Bitsight  when I was at Virtusa was to monitor the external security posture for Virtusa, as Bitsight  rates your company based on findings on external assets.

    I was part of the internal security team and Bitsight used to report findings, such as open ports on specific IP addresses or web applications owned by Virtusa, and based on that it used to give a rating on the severity based on how severe the vulnerability is or the possibility of any vulnerability. I used to take that information and then fix that problem internally. That is how we used to use Bitsight. Our main aim was to use Bitsight to enhance the security of the company so that our score is good on Bitsight, which really matters.

    What is most valuable?

    The best features Bitsight offers, in my experience, are the ratings that it gives to vulnerabilities and how frequently they conduct scans for a particular company. Bitsight also used to manage our third-party providers regarding how their security is, so it is better for us to manage the vendors we are currently engaged with and the third-party vendors so that we are aware of their security posture as well, instead of us monitoring their security. That is the most useful use case from Bitsight.

    Bitsight gives me a holistic view of my entire security posture, which is something any organization would want to have after getting a tool such as Bitsight. It was sufficient in that way, serving the purpose that we took Bitsight for, and there is something that we continued our relationship. We had annual contracts and then we renewed it every year based on the performance of Bitsight.

    We had internal KPIs based on the number of findings that we finalized from Bitsight and then tracked it internally to work on that. The more vulnerabilities that we close, the rating would subsequently reflect on Bitsight because they work independently; they do not work as we do inside the company. As long as we are fixing the vulnerabilities, we used to see the score getting improved, and that is something that the board of directors and the internal community were looking for.

    What needs improvement?

    Bitsight's scan could be more rigorous and then more accurate.

    I think it would be good to try to see each and everything of the company in a more accurate way.

    Their scan scheduling could be improved and they could take more inputs from the companies they are working with. If they can speed up that process, they would obviously increase that score. We found that some of the findings are clear false positives, but they still report that, and based on that, the rating goes down until we rectify them. So that is something they need to work towards; the number of false positives they are rating should focus on producing more accurate results to get a higher rating.

    How are customer service and support?

    Bitsight had a professional support service where whenever there are any ratings which we know to be a false positive and a wrong finding, we used to get on a call with support from Bitsight to submit our review as to what we found and what the evidence is for it being a false positive, and they used to consider that and then try to revise that internally and adjust the rating accordingly.

    Bitsight is a useful tool to monitor your external posture and it is backed by a good professional support service. The respective other teams such as pre-sales, support service, and customer success team are very good in terms of dealing with customers, so there is something to look for in such products.

    How would you rate customer service and support?

    Neutral

    Which other solutions did I evaluate?

    There is nothing particularly unique about Bitsight because we were also using another product along with Bitsight, and we used to compare the results of Bitsight with that tool and then try to see what the unique proposition or the unique findings are that we can evaluate and then work internally.

    What other advice do I have?

    If the ratings were very poor, low, or below the benchmark that we expected for Virtusa, we used to have a meeting with them, and then try to negotiate if they can improve their security, or else we would discontinue the business with them. So to that extent, we took actions based on the findings that we got from Bitsight. I give Bitsight a six out of ten for this review.

    View all reviews