Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

SecurityScorecard

SecurityScorecard

Reviews from AWS customer

3 AWS reviews

External reviews

100 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    E Danquah

Security scoring has guided our vulnerability prioritization and now informs leadership decisions

  • January 15, 2026
  • Review from a verified AWS customer

What is our primary use case?

My main use case for SecurityScorecard is monitoring vulnerabilities that are affecting our domain.

What is most valuable?

The best features SecurityScorecard offers for me are mainly being able to properly position my organization's security posture because of the score that is provided. I am able to know if we are doing well by assigning the quality or assigning the security posture to a score. It helps put things into perspective for me and I am able to know to what extent a vulnerability exists and the level of threat and the level of information breach each vulnerability is associated with.

The score helps me to inform leadership where we truly are at with regards to our security posture as an organization. It is also able to help me prioritize which vulnerabilities to remediate, which is more important, and which one needs immediate attention. It also helps me paint the best picture of our security position to management.

SecurityScorecard helps my organization know how well we are performing with regards to our security posture, and we are able to close security gaps when they are raised in SecurityScorecard.

What needs improvement?

I realized that because my company was acquired by a bigger organization, SecurityScorecard started associating other portfolio company vulnerabilities to our score, which was not helpful because it was giving us wrong data and giving us vulnerabilities we did not have. When you dive deep, you realize that the vulnerabilities are not associated with our domain. If SecurityScorecard could improve anything, it would be making sure the algorithm pulls the right data for the right domain.

For how long have I used the solution?

I have been using SecurityScorecard for two years.

What do I think about the stability of the solution?

SecurityScorecard is stable in my experience.

How are customer service and support?

Customer support is timely. Anytime I have had to dispute anything with regards to our score or the vulnerabilities being highlighted on our domain, they address it within seventy-two hours and change or update the score.

How would you rate customer service and support?

What other advice do I have?

A typical workflow includes logging into SecurityScorecard, seeing which vulnerabilities have been flagged with regards to my domain, and then working with the engineers to have those vulnerabilities mitigated. After that, I upload the evidence into SecurityScorecard so that it can be taken off our score.

One of the benefits I have realized while using SecurityScorecard was that there was a vulnerability with our website and with the insights we got from SecurityScorecard, we were able to take a better decision of building a custom website instead of going with the template we had at the time.

Initially, SecurityScorecard monitoring was being managed by my CISO. However, with the simplicity of the dashboard and the information and the data in SecurityScorecard, he was able to easily hand it over to me, who did not have any prior experience, and I was able to quickly get the hang of things. He did not have to supervise or step in again and he was able to totally hand it over to me.

If you want a simple dashboard that is easy to understand and lets you know the vulnerabilities affecting your domain, SecurityScorecard is a good product for that. I would rate this product eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Tasim Carku

Continuous monitoring has improved our security rating and simplified vulnerability remediation

  • December 29, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is to keep an eye on our vulnerabilities and also monitor which companies follow us in the platform, and we keep track when our score drops so we can fix it.

For tracking vulnerabilities or monitoring our score with SecurityScorecard, we take action based on our score, and a few people in our group have access there so they check it daily, monitor our IPs, and if there is something they need to discard. We have one specialist who fixes the vulnerabilities, and when he fixes things, he reports back to SecurityScorecard so we keep our score as high as possible, preferably at least A, and we have noticed some customers sharing reports from your platform where they needed us to have this A score.

SecurityScorecard is quite simple and easy to use, and we just need to keep track when we receive those notifications from the tool.

What is most valuable?

The best features SecurityScorecard offers are that it is easy to use and quite easy to understand what the vulnerabilities are and how to fix them. I appreciate the interface where you can see in one screen pretty much everything, and I also appreciate the feature where you can see the number of customers who follow you in the platform.

The interface of SecurityScorecard stands out for me because it is very easy. In one dashboard, you can see pretty much everything. I appreciate the nice colors that are easy to follow, and I also appreciate the graphs in the platform.

SecurityScorecard has impacted my organization positively as it was a surprise to notice that many of our customers follow us there, and the tool scans the web twice per day, so we can see how hackers and what they can see from our publicly available IPs.

Specific outcomes or metrics that show how SecurityScorecard has helped my organization include our score improving quite a lot. We started with a C or maybe D and reached the A, keeping it above 90 points, which has impacted us because it is now a metric our management follows.

What needs improvement?

I suggest that SecurityScorecard could be improved by giving a little more specifics on how the scanning works and how you are able to detect those IPs, including more details on the privacy side about how the scanner operates and how it is sometimes allowed to do those scans. Additionally, it might be good to understand how to quickly fix or report the quite a lot of false positives, perhaps through a self-checkout feature or something similar.

The features of SecurityScorecard are quite adequate and do not need anything added.

For how long have I used the solution?

I have been using SecurityScorecard for about two and a half years.

What do I think about the stability of the solution?

SecurityScorecard is stable.

What do I think about the scalability of the solution?

SecurityScorecard's scalability is easy to scale.

How are customer service and support?

The customer support for SecurityScorecard is amazing.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did not previously use a different solution, as no solution of this kind was used before.

How was the initial setup?

Before choosing SecurityScorecard, we did not evaluate other options.

What about the implementation team?

My experience with pricing, setup cost, and licensing is that we still have the free version, but we have an offer from your side, which I think is straightforward.

What was our ROI?

I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.

What's my experience with pricing, setup cost, and licensing?

I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we did not evaluate other options.

What other advice do I have?

I would rate SecurityScorecard a solid nine out of ten.

I chose a nine because I appreciate the features a lot, but there is still room for small improvements, those that I mentioned above.

SecurityScorecard is deployed in my organization in a public cloud.

The cloud provider we use for SecurityScorecard is Microsoft Azure.

My advice for others looking into using SecurityScorecard is to use it as soon as possible and you will know the difference. My overall review rating for SecurityScorecard is nine.


    Adriana Cumbajin

Continuous monitoring has improved vendor risk insights and supports faster security decisions

  • December 16, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is to qualify the surface and the domain of the company, and to detect vulnerabilities or assess the protection made by my client.

What is most valuable?

I provide quick visibility into the vendor's external security posture to my clients. Another situation could be highlighting specific risk areas instead of just a general score. Additionally, I support data-driven conversations with stakeholders and vendors.

SecurityScorecard helps us identify potential vulnerabilities early, reduce third-party risk, and make more informed security decisions without relying only on questionnaires or self-reporting information.

SecurityScorecard positively helps us quickly assess vendor risks and understand an organization's external security posture without spending a lot of time on manual reviews. In particular, it helps us identify security gaps early, prioritize follow-up actions, and have more informed conversations with vendors and internal stakeholders.

In terms of measurable positives regarding risk reduction, we were able to identify high-risk vendors earlier, and we complete assessments thirteen or fourteen percent faster since we rely less on lengthy questionnaires and manual evidence collection.

What needs improvement?

SecurityScorecard could be improved with more detailed remediation guidance, better customization of scoring, and stronger integration with GRC and vendor management tools.

It could also use better reporting and alert customization as well as a more intuitive user interface.

For how long have I used the solution?

I have been using SecurityScorecard for six months.

What do I think about the stability of the solution?

In my experience, SecurityScorecard is stable and operates faster without issues of downtime or reliability.

What do I think about the scalability of the solution?

My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.

How are customer service and support?

We have support, and whenever I need it, my colleagues and I find that the support team is quick and responsive, helping to resolve any questions.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Azure or another solution called Socradar before switching to SecurityScorecard.

How was the initial setup?

My experience with the pricing has been positive because the platform is robust and user-friendly, and the setup was straightforward. Regarding licensing, my organization has a limitation on the number of domains or vendors we can integrate, but it depends on the type of license that I have.

What was our ROI?

We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we evaluated other vendors such as Azure and Socradar, but we chose SecurityScorecard for the pricing.

What other advice do I have?

My advice would be to take full advantage of the continuous monitoring and vendor insights, explore the dashboards and alerts early, and understand the license limits, specifically regarding the number of domains or vendors you can track or add in the dashboard for monitoring.

We are a partner with SecurityScorecard.

I think the interview could improve by involving discussions on how to assess other companies with risks in different areas.

I would appreciate a short poem or haiku that summarizes this review. I have provided a review rating of eight out of ten.


    Aayush Gangwar

Vendor risk monitoring has strengthened our security posture and reduced insurance costs

  • December 08, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is for vendor risk identification, along with active threat intel on our organization.

A quick example of how I use SecurityScorecard for vendor risk identification is when we wanted to onboard a vendor for a vulnerability management tool. One additional step during our due diligence in terms of security and compliance was to verify the SecurityScorecard and BitSight scorecard rating. Based on that rating, we were able to make an informed decision that the vendor is from a security-first organization that prioritizes security, which gave them an upper hand during the competitive bidding. The highest rating was one of the metrics during our review process.

We also utilize SecurityScorecard for active threat intel, so any security issues detected by SecurityScorecard pertaining to our organization are kept at the utmost priority, and we invest considerable time in fixing those security issues.

How has it helped my organization?

Since we onboarded SecurityScorecard, our organization has been positively impacted by significantly improving our security maturity. We rely on the results from SecurityScorecard to determine what prioritizations to make, alongside promoting a security-first culture in terms of our vendors.

I have seen measurable changes since starting with SecurityScorecard. When we began, our security score was a B, and after prioritizing many security issues and promoting a security-first mindset, we eventually achieved an A rating.

What is most valuable?

The best features SecurityScorecard offers, in my experience, include the technical mitigation along with a detailed graph on what exactly the security issue is. I also appreciate the feature where the vendor's security score is being published.

I particularly value the Jira integration, so any issue identified as part of the threat intel activity can be directly updated through our Jira. I also appreciate the automation feature where I receive daily notifications whenever there is a change in our risk.

What needs improvement?

In terms of improvements, I feel SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high. Details on the technical mitigation would help my non-technical teams understand the security issues better.

I think improvements could be made on the reporting side as well, such as the ability to download customizable reports. While SecurityScorecard offers various kinds of reports now, they are limited to predefined formats. Having the ability to choose specific fields for an automated report would be very helpful.

For how long have I used the solution?

I have been using SecurityScorecard for a little over three years.

What do I think about the stability of the solution?

I find SecurityScorecard stable for our organization, as I have not encountered any downtime. I also appreciate the browser extension feature that identifies the SecurityScorecard score for any organization.

What do I think about the scalability of the solution?

We did not track the scalability metrics for SecurityScorecard. Although we faced some challenges during the initial onboarding with our vendor, the support team helped streamline everything for a very smooth experience.

How are customer service and support?

I have interacted with the customer support team from SecurityScorecard, and they have been very helpful throughout the onboarding process and continue to assist us with bi-monthly sync-up calls whenever we face issues with the platform regarding risk and how to improve our security score.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

We did not previously use any other solutions before SecurityScorecard.

How was the initial setup?

SecurityScorecard is deployed in our organization using a hybrid cloud setup.

What was our ROI?

I have seen a return on investment, as we observed a significant improvement in our security scores. When we onboarded to SecurityScorecard, we were at a security score of B+, and based on the issues identified, we managed to move to A, resulting in a lower insurance premium cost for us and considerable cost savings overall, which made our management very pleased with the progress.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing for SecurityScorecard, since it does not require active deployment on our side being a SaaS-first company, I expected slightly lower pricing. However, the sales insight was very helpful and contributed to a smooth onboarding process.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we evaluated BitSight Scorecard. SecurityScorecard offered better pricing and I found its UI excellent to use, so we decided to move to SecurityScorecard.

What other advice do I have?

My advice for others looking into using SecurityScorecard is that I truly appreciate the platform. It has been very helpful for our security journey, providing insights that enrich our vendor compliance processes, particularly during vendor onboarding where we review SecurityScorecard results for our vendors. I believe the platform is very beneficial for the company, and SecurityScorecard as a tool for vendor security management is essential for organizational development. I would rate this overall experience an 8 out of 10.


    Computer & Network Security

A solid tool for external security insights

  • April 07, 2025
  • Review provided by G2

What do you like best about the product?
SecurityScorecard offers us an external perspective of our security vulnerabilities, which helps us prioritize solutions that could otherwise go undiscovered. It’s like having a continual audit from a hacker’s viewpoint, and that’s helped us detect and solve flaws before they become huge problems.
What do you dislike about the product?
The possibilities for integration are somewhat limited. We use a number of different security technologies; it would be wonderful if SecurityScorecard could automatically link with them to streamline some of our processes. Right now, it seems a little compartmentalized.
What problems is the product solving and how is that benefiting you?
It’s providing us a complete perspective of our third-party risks, which has helped our vendor screening process significantly.


    Vishal G.

A Powerful Tool for Cyber Risk Management

  • April 03, 2025
  • Review provided by G2

What do you like best about the product?
It is a game-changer in security risk . It's easy-to-understand rating system simplifies security data, making it simply to assess cyber risks. It is the best tool for the checking and improving score. it lists all the problem which causes the low and score and helps to increase the score.
What do you dislike about the product?
You could be blamed for security holes that aren't even in your machine.
and Keeping us best in the industry to increase the score.
What problems is the product solving and how is that benefiting you?
SecurityScorecard comes to solve the problems of vulnerability breaches identified in the main sites of a domain, in my case it helps me detect the vulnerabilities I have and gives me visibility to the address.


    Prateek R.

SecurityScorecard is a must for prevent breach and improve cyber hygiene across the supply chain

  • April 01, 2025
  • Review provided by G2

What do you like best about the product?
early breach detection and improved security posture
What do you dislike about the product?
Vulnerability list could have been better .
What problems is the product solving and how is that benefiting you?
early breach detection . Giving insight about the security posture


    Consumer Goods

Good, but could use better reporting features

  • March 31, 2025
  • Review provided by G2

What do you like best about the product?
The security assessments are obvious and actionable. I especially enjoy the way the platform breaks down ratings by category, such as network security or application security, which makes it easier to target areas for development.
What do you dislike about the product?
The reporting feature seems a little simple. While the dashboards are useful for day-to-day monitoring, developing bespoke reports for executive presentations or audits needs more flexibility than what’s presently supplied.
What problems is the product solving and how is that benefiting you?
We utilize SecurityScorecard to assess our security performance against industry peers. This has been very motivating for our team and has helped us gain extra money for security efforts by displaying concrete results.


    reviewer2542620

Enhance vendor risk management with comprehensive analysis

  • November 07, 2024
  • Review provided by PeerSpot

What is our primary use case?

SecurityScorecard is primarily used for supply chain risk management.

How has it helped my organization?

The product is included in our portfolio as we are a cybersecurity distributor.

What is most valuable?

The features customers are most interested in are third and fourth-party vendor analysis and questionnaires.

For how long have I used the solution?

The product got onboarded a couple of months ago.

What do I think about the stability of the solution?

No one complained about the stability.

What do I think about the scalability of the solution?

The ones that tried it liked it, although some wanted a different solution.

How was the initial setup?

The initial setup takes just a couple of days and doesn't require any installation.

What other advice do I have?

I'd rate the solution eight out of ten.


    Antonio Scola

The most valuable feature is the ability to identify if third parties or vendors have digital threats that may impact our company

  • July 12, 2024
  • Review provided by PeerSpot

What is our primary use case?

SecurityScorecard performs deep analysis over the exposed view of data. It creates an external IT assessment of the company in terms of domain and vendor reports. Essentially, it scans the company's landscape, trying to find vulnerabilities and exposed data that may cause digital risks.

What is most valuable?

With SecurityScorecard, the most valuable feature is the ability to identify if third parties or vendors have digital threats that may impact our company. It also scans all internal domains and IPs to find vulnerabilities in the digital landscape. The continuous monitoring capabilities have been beneficial by providing ongoing assessments of potential risks.

What needs improvement?

The pricing of the product needs improvement in Brazil.

For how long have I used the solution?

I have been using SecurityScorecard for the past year.

What do I think about the stability of the solution?

As for stability, it's 99.99% stable.

What do I think about the scalability of the solution?

The scalability of SecurityScorecard is really easy. If the user starts with twenty domains and needs to double, it's already in the platform one just needs to flag a button.

How are customer service and support?

They work pretty fast and have full knowledge of the solution. Personally, I've never had a problem with them. Sometimes there's a little delay because they need to investigate further, but overall, I'm pleased with their support.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of SecurityScorecard is very easy because it's a SaaS solution. Deployment time depends on the number of companies to be monitored; for fifteen to thirty companies, it might take two or three days, or up to a week.

The vendor helps users deploy the solution and set up functionalities, making it straightforward. Usually, three to four people are involved. The vendor assigns a Customer Success Manager to the end user, who acts as the focal point for support, new questions, and functionalities.

What about the implementation team?


What was our ROI?

The best ROI with SecurityScorecard is when the end user identifies that their vendors or third parties have digital threats that need to be addressed promptly. Preventing digital threats and data leakage from vendors and partners is the best ROI.

What's my experience with pricing, setup cost, and licensing?

The pricing of SecurityScorecard is fair. I would rate it a seven. It's a bit more on the expensive side. In Brazil, for example, making a payment to the vendor involves wire transfers and high taxes, making it more expensive. Selling SecurityScorecard or any American vendor's product in the United States is very different from selling in South America or Brazil.

What other advice do I have?

Overall I would rate the solution a nine out of ten.