Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

MAX Managed Service

SecurityScorecard

Reviews from AWS customer

2 AWS reviews

External reviews

100 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Tasim Carku

Continuous monitoring has improved our security rating and simplified vulnerability remediation

  • December 29, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is to keep an eye on our vulnerabilities and also monitor which companies follow us in the platform, and we keep track when our score drops so we can fix it.

For tracking vulnerabilities or monitoring our score with SecurityScorecard, we take action based on our score, and a few people in our group have access there so they check it daily, monitor our IPs, and if there is something they need to discard. We have one specialist who fixes the vulnerabilities, and when he fixes things, he reports back to SecurityScorecard so we keep our score as high as possible, preferably at least A, and we have noticed some customers sharing reports from your platform where they needed us to have this A score.

SecurityScorecard is quite simple and easy to use, and we just need to keep track when we receive those notifications from the tool.

What is most valuable?

The best features SecurityScorecard offers are that it is easy to use and quite easy to understand what the vulnerabilities are and how to fix them. I appreciate the interface where you can see in one screen pretty much everything, and I also appreciate the feature where you can see the number of customers who follow you in the platform.

The interface of SecurityScorecard stands out for me because it is very easy. In one dashboard, you can see pretty much everything. I appreciate the nice colors that are easy to follow, and I also appreciate the graphs in the platform.

SecurityScorecard has impacted my organization positively as it was a surprise to notice that many of our customers follow us there, and the tool scans the web twice per day, so we can see how hackers and what they can see from our publicly available IPs.

Specific outcomes or metrics that show how SecurityScorecard has helped my organization include our score improving quite a lot. We started with a C or maybe D and reached the A, keeping it above 90 points, which has impacted us because it is now a metric our management follows.

What needs improvement?

I suggest that SecurityScorecard could be improved by giving a little more specifics on how the scanning works and how you are able to detect those IPs, including more details on the privacy side about how the scanner operates and how it is sometimes allowed to do those scans. Additionally, it might be good to understand how to quickly fix or report the quite a lot of false positives, perhaps through a self-checkout feature or something similar.

The features of SecurityScorecard are quite adequate and do not need anything added.

For how long have I used the solution?

I have been using SecurityScorecard for about two and a half years.

What do I think about the stability of the solution?

SecurityScorecard is stable.

What do I think about the scalability of the solution?

SecurityScorecard's scalability is easy to scale.

How are customer service and support?

The customer support for SecurityScorecard is amazing.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I did not previously use a different solution, as no solution of this kind was used before.

How was the initial setup?

Before choosing SecurityScorecard, we did not evaluate other options.

What about the implementation team?

My experience with pricing, setup cost, and licensing is that we still have the free version, but we have an offer from your side, which I think is straightforward.

What was our ROI?

I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.

What's my experience with pricing, setup cost, and licensing?

I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we did not evaluate other options.

What other advice do I have?

I would rate SecurityScorecard a solid nine out of ten.

I chose a nine because I appreciate the features a lot, but there is still room for small improvements, those that I mentioned above.

SecurityScorecard is deployed in my organization in a public cloud.

The cloud provider we use for SecurityScorecard is Microsoft Azure.

My advice for others looking into using SecurityScorecard is to use it as soon as possible and you will know the difference. My overall review rating for SecurityScorecard is nine.


    Adriana Cumbajin

Continuous monitoring has improved vendor risk insights and supports faster security decisions

  • December 16, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is to qualify the surface and the domain of the company, and to detect vulnerabilities or assess the protection made by my client.

What is most valuable?

I provide quick visibility into the vendor's external security posture to my clients. Another situation could be highlighting specific risk areas instead of just a general score. Additionally, I support data-driven conversations with stakeholders and vendors.

SecurityScorecard helps us identify potential vulnerabilities early, reduce third-party risk, and make more informed security decisions without relying only on questionnaires or self-reporting information.

SecurityScorecard positively helps us quickly assess vendor risks and understand an organization's external security posture without spending a lot of time on manual reviews. In particular, it helps us identify security gaps early, prioritize follow-up actions, and have more informed conversations with vendors and internal stakeholders.

In terms of measurable positives regarding risk reduction, we were able to identify high-risk vendors earlier, and we complete assessments thirteen or fourteen percent faster since we rely less on lengthy questionnaires and manual evidence collection.

What needs improvement?

SecurityScorecard could be improved with more detailed remediation guidance, better customization of scoring, and stronger integration with GRC and vendor management tools.

It could also use better reporting and alert customization as well as a more intuitive user interface.

For how long have I used the solution?

I have been using SecurityScorecard for six months.

What do I think about the stability of the solution?

In my experience, SecurityScorecard is stable and operates faster without issues of downtime or reliability.

What do I think about the scalability of the solution?

My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.

How are customer service and support?

We have support, and whenever I need it, my colleagues and I find that the support team is quick and responsive, helping to resolve any questions.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Azure or another solution called Socradar before switching to SecurityScorecard.

How was the initial setup?

My experience with the pricing has been positive because the platform is robust and user-friendly, and the setup was straightforward. Regarding licensing, my organization has a limitation on the number of domains or vendors we can integrate, but it depends on the type of license that I have.

What was our ROI?

We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we evaluated other vendors such as Azure and Socradar, but we chose SecurityScorecard for the pricing.

What other advice do I have?

My advice would be to take full advantage of the continuous monitoring and vendor insights, explore the dashboards and alerts early, and understand the license limits, specifically regarding the number of domains or vendors you can track or add in the dashboard for monitoring.

We are a partner with SecurityScorecard.

I think the interview could improve by involving discussions on how to assess other companies with risks in different areas.

I would appreciate a short poem or haiku that summarizes this review. I have provided a review rating of eight out of ten.


    JeffBrown

Continuous vendor risk insight has improved cloud visibility but still needs fresher data

  • December 12, 2025
  • Review from a verified AWS customer

What is our primary use case?

SecurityScorecard is used across healthcare, financial services, retail, and hospitality. It is also being adopted in the services industry, including by CPAs and legal firms.

What is most valuable?

SecurityScorecard continuously scans just about every IP address out there, which means there is information available about virtually every company. For third-party risk management, this tool allows me to obtain that information without having to build my own database from scratch using tools that do not provide this capability. The information is readily available and accessible. SecurityScorecard also provides substantial insight and detailed information specifically about how secure companies' cloud environments are, allowing for quick identification of issues with authentication or other areas.

There are both advantages and disadvantages to their approach. The continuous scanning of companies all the time ensures that there is always current information available about the third-party vendors and companies being monitored. However, the downside is that the information may be several days old, so it is not always current. Despite this limitation, using SecurityScorecard enabled us to obtain information about every one of our third parties that our clients are interested in monitoring.

My focus has been primarily on third-party risk. The automated alerts allow us to receive feedback as they update their information and when something comes up, which impacts the risk rating for each vendor or third party.

What needs improvement?

The ability to perform an automatic scan at any point in time to refresh information and provide the most current data would be helpful. Setting up automated scans on a schedule where information is more than a week old so that a forced automatic scan could be triggered for a particular company would be beneficial. This would ensure that current information is being used when monitoring different clients.

Overall, SecurityScorecard is a good product, and they need to continue developing it. There are challenges around third-party risk management. When providing risk management for your own company, it does everything you want it to do. However, for managing third parties, there are still some challenges, mainly because some aspects are out of their control since you do not have control over another company's risk or infrastructure and cannot dictate whether they are making changes. Overall, SecurityScorecard provides good information, but I am always looking for something that is more automated and would provide a better and more detailed picture of third-party risk profiles.

For how long have I used the solution?

I have used or evaluated SecurityScorecard on and off for the last eight years, and I have clients that leverage and use it on a regular basis. I would say I am certainly familiar with it over the last ten years, using it intermittently, so at least five years of consistent experience.

How are customer service and support?

I do not rate many software companies highly on the support side. I would give SecurityScorecard about a seven out of ten. They could improve in terms of response time and other areas, but they are not terrible.

How would you rate customer service and support?

Positive

How was the initial setup?

SecurityScorecard can be complex during setup, and I would recommend that anyone implementing it get help setting it up because it is not as straightforward as people might think. Getting third parties set up and configuring how you will do that and what you will search for can be complicated. Unfortunately, many clients today are looking for a button to push with everything being done for them automatically. I would recommend using third-party assistance in getting things set up the way you want.

What's my experience with pricing, setup cost, and licensing?

The setup cost is a little higher than some of the other products out there. However, SecurityScorecard has a lot of features, so they are fairly competitive.

Which other solutions did I evaluate?

Other than their dashboards, which have a lot of information and are set up quite nicely, SecurityScorecard provides granular and more detailed information than some other products, specifically regarding cloud capabilities. Much of the functionality you are starting to see in many products is being offered by SecurityScorecard. SecurityScorecard has been around longer than many of the other solutions, and they have many built-in capabilities that some other solutions are just starting to implement now.

What other advice do I have?

For remediation efforts, SecurityScorecard helps by identifying third-party suppliers where risk ratings are going up. Because I use it for third-party monitoring, we watch third parties and SecurityScorecard identifies when there is another potential risk that has affected their rating level. I can then alert my clients that they have a vendor that is potentially at risk, giving us the opportunity to react faster.

I am not a formal partner with the company yet, but we do conduct evaluations on behalf of our clients. I give SecurityScorecard a seven out of ten overall rating.


    Akhilesh Mishra

Continuous monitoring has strengthened our external posture and improved cyber insurance decisions

  • December 08, 2025
  • Review from a verified AWS customer

What is our primary use case?

My main use case for SecurityScorecard is that most of the time, the customer is looking for a solution which can provide all vulnerabilities and rate, security rate, and it also performs scanning of their domain, subdomain, and IP address. Customers can easily determine what weak passwords and policy configurations exist and can easily find out vulnerabilities.

A specific example of how a customer has used SecurityScorecard to solve a problem is that I have given SecurityScorecard to multiple customers, and they were looking to understand what vulnerabilities they have and what ratings they have.

I must add that SecurityScorecard continuously monitors the cybersecurity posture of the vendor, supplier, partner, SaaS platform, and others. Most of the time, the customer does not know what ports are open and whether they are exposed to vulnerabilities or weak SSL, TLS configuration, or malware signals, or misconfigured DNS. They also do not know whether their credentials are leaked. SecurityScorecard can help with this. For external attack surface monitoring, it is very useful.

What is most valuable?

The best features SecurityScorecard offers are cyber insurance underwriting and risk scoring, which I think are the best use cases, where the customer can easily reduce underwriting time and detect sudden posture changes.

Regarding how the risk scoring and cyber insurance features help my customers, they help detect sudden posture changes and evaluate the cyber hygiene of insured entities and price policies.

I would also add that it provides value for security posture management and executive reporting. It provides simple, visual, letter grade, and easy to explain metrics and score histories. Regarding the value it provides, it converts complex security issues into business-friendly language, which helps executives and the board understand cyber risk. It supports governance and risk metrics. Compliance support and auditing provide continuous monitoring, showcasing external posture over time, detecting misconfiguration that violates standards, and help with frameworks such as NIST 800 and ISO 27001, PCI DSS, HIPAA, DORA, and SOC 2.

SecurityScorecard has positively impacted my organization and my customers by providing numerous benefits. Customers easily obtain the score, which is a use case I value greatly. Customers can easily determine what ports are open and many other things so that they can secure their DNS, applications, and networks effectively.

My customers have seen measurable outcomes and specific improvements, as they have improved compliance and security with the help of SecurityScorecard.

What needs improvement?

SecurityScorecard can be improved. As it currently stands, it does a good job monitoring public-facing devices and the internet and DNS. If SecurityScorecard could also help their customers internally by developing their tool or feature so that customer devices that are not only public-facing can be monitored, it would be more beneficial.

For how long have I used the solution?

I have been using SecurityScorecard for the last five to six years.

What do I think about the stability of the solution?

SecurityScorecard is stable.

What do I think about the scalability of the solution?

The scalability of SecurityScorecard is fine, and there is no challenge with its scalability. As of now, I have not faced any issues with the scalability of SecurityScorecard.

How are customer service and support?

Customers are getting good support 24/7 from SecurityScorecard. I would rate the customer support for SecurityScorecard nine out of 10.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, customers were sometimes using FireCompass and sometimes different tools, and some customers were net new, fresh customers using SecurityScorecard for the first time. The payback period of SecurityScorecard is less than six months from an ROI perspective. Sometimes the customer evaluates other options such as FireCompass before choosing SecurityScorecard.

How was the initial setup?

My experience with pricing, setup cost, and licensing is that pricing is acceptable as per the Indian market.

What about the implementation team?

As of now, the customer is happy, and I have not seen any complaints from the customer regarding purchasing SecurityScorecard.

What was our ROI?

When I talk about the return on investment with SecurityScorecard, the customer feedback shows that it is good from an ROI perspective. I have observed that the customer is getting 176% ROI over three years, and they are happy with it.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that pricing is acceptable as per the Indian market.

Which other solutions did I evaluate?

Sometimes the customer evaluates other options such as FireCompass before choosing SecurityScorecard.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Aayush Gangwar

Vendor risk monitoring has strengthened our security posture and reduced insurance costs

  • December 08, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for SecurityScorecard is for vendor risk identification, along with active threat intel on our organization.

A quick example of how I use SecurityScorecard for vendor risk identification is when we wanted to onboard a vendor for a vulnerability management tool. One additional step during our due diligence in terms of security and compliance was to verify the SecurityScorecard and BitSight scorecard rating. Based on that rating, we were able to make an informed decision that the vendor is from a security-first organization that prioritizes security, which gave them an upper hand during the competitive bidding. The highest rating was one of the metrics during our review process.

We also utilize SecurityScorecard for active threat intel, so any security issues detected by SecurityScorecard pertaining to our organization are kept at the utmost priority, and we invest considerable time in fixing those security issues.

How has it helped my organization?

Since we onboarded SecurityScorecard, our organization has been positively impacted by significantly improving our security maturity. We rely on the results from SecurityScorecard to determine what prioritizations to make, alongside promoting a security-first culture in terms of our vendors.

I have seen measurable changes since starting with SecurityScorecard. When we began, our security score was a B, and after prioritizing many security issues and promoting a security-first mindset, we eventually achieved an A rating.

What is most valuable?

The best features SecurityScorecard offers, in my experience, include the technical mitigation along with a detailed graph on what exactly the security issue is. I also appreciate the feature where the vendor's security score is being published.

I particularly value the Jira integration, so any issue identified as part of the threat intel activity can be directly updated through our Jira. I also appreciate the automation feature where I receive daily notifications whenever there is a change in our risk.

What needs improvement?

In terms of improvements, I feel SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high. Details on the technical mitigation would help my non-technical teams understand the security issues better.

I think improvements could be made on the reporting side as well, such as the ability to download customizable reports. While SecurityScorecard offers various kinds of reports now, they are limited to predefined formats. Having the ability to choose specific fields for an automated report would be very helpful.

For how long have I used the solution?

I have been using SecurityScorecard for a little over three years.

What do I think about the stability of the solution?

I find SecurityScorecard stable for our organization, as I have not encountered any downtime. I also appreciate the browser extension feature that identifies the SecurityScorecard score for any organization.

What do I think about the scalability of the solution?

We did not track the scalability metrics for SecurityScorecard. Although we faced some challenges during the initial onboarding with our vendor, the support team helped streamline everything for a very smooth experience.

How are customer service and support?

I have interacted with the customer support team from SecurityScorecard, and they have been very helpful throughout the onboarding process and continue to assist us with bi-monthly sync-up calls whenever we face issues with the platform regarding risk and how to improve our security score.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

We did not previously use any other solutions before SecurityScorecard.

How was the initial setup?

SecurityScorecard is deployed in our organization using a hybrid cloud setup.

What was our ROI?

I have seen a return on investment, as we observed a significant improvement in our security scores. When we onboarded to SecurityScorecard, we were at a security score of B+, and based on the issues identified, we managed to move to A, resulting in a lower insurance premium cost for us and considerable cost savings overall, which made our management very pleased with the progress.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing for SecurityScorecard, since it does not require active deployment on our side being a SaaS-first company, I expected slightly lower pricing. However, the sales insight was very helpful and contributed to a smooth onboarding process.

Which other solutions did I evaluate?

Before choosing SecurityScorecard, we evaluated BitSight Scorecard. SecurityScorecard offered better pricing and I found its UI excellent to use, so we decided to move to SecurityScorecard.

What other advice do I have?

My advice for others looking into using SecurityScorecard is that I truly appreciate the platform. It has been very helpful for our security journey, providing insights that enrich our vendor compliance processes, particularly during vendor onboarding where we review SecurityScorecard results for our vendors. I believe the platform is very beneficial for the company, and SecurityScorecard as a tool for vendor security management is essential for organizational development. I would rate this overall experience an 8 out of 10.


    Information Technology and Services

Cybersecurity Analyst

  • October 09, 2025
  • Review provided by G2

What do you like best about the product?
Support from team. I like the likelihoods reports to help us help our customers prepare for possible attacks.
What do you dislike about the product?
There is nothing I dislike about Security Scorecard.
What problems is the product solving and how is that benefiting you?
Security Scorecard is assisting me with ensuring I advise our customers of any possible vulnerabilities or breaches that could potentially impact their foot print.


    David Q.

The Gold Standard for Security Ratings

  • August 16, 2025
  • Review provided by G2

What do you like best about the product?
Its interface is deceptively simple with incredible functionality. I've rolled this out in three organizations, and EVERY time, it's found THE critical gaps (e.g.- expired SSL certificates). Daily use: it is my first dashboard check in the morning. PowerPoint Integration : Easily share insights with my leadership via PowerPoint.
What do you dislike about the product?
The very first setup had to do small adjustments not to score non-critical assets. It would help to have an onboarding wizard for this.
What problems is the product solving and how is that benefiting you?
It has also done away with self-assessment “security theater.” We are now trusted by our clients when it comes to rating and sales cycles within IT security has been reduced by 30%.


    Brad H.

Industry Benchmarking at Its Best

  • August 16, 2025
  • Review provided by G2

What do you like best about the product?
It is very rare a platform can benchmark our security posture against our peers. It was extremely easy to implement and we were up and running in less than days. Completely game changing features like monitors for compromised credentials and DNS health checking. Proactive: Support will frequently suggest optimizations
What do you dislike about the product?
Sometimes scores will vary because of things like CDN outages which may cause unnecessary alerts. Another option would be a “pause monitoring” feature for maintenance windows.
What problems is the product solving and how is that benefiting you?
Our boardroom discussions have changed, and executives now hold leaders accountable when scores dip. The platform also allowed us to discover a cloud storage bucket misconfiguration before it could be exploited.


    Thomas B.

Objective Metrics for Security Posture

  • August 15, 2025
  • Review provided by G2

What do you like best about the product?
Since SecurityScorecard does not utilize any such data, the vendor ratings are impartial. The customers think of it as a no-brainer with one neutral benchmark. Understanding customer service & user-friendliness of platform (even for non-technical stakeholders).
What do you dislike about the product?
Ratings sometimes are unfairly strong about subjects a business cannot control (e.g. shared hosting providers) — More filters in data can be helpful
What problems is the product solving and how is that benefiting you?
It allows advisors to be more objective when discussing risk with clients by presenting hard data points on top of the perception. The audit process is faster, and the reliability and confidence of stakeholders are higher than they were prior to them.


    Chris L.

External Vulnerability Management External Attack Surface

  • August 15, 2025
  • Review provided by G2

What do you like best about the product?
tHIS TOO IS A SIMPLE man when it comes to ease of use and an insane one for the depth. I rely on it daily for our public security posture and the MS Power BI integration (thru API's) allows simple dashboarding. This is another huge one, the amount of features dark web monitoring, IP reputation checks etc really does save us hours and hours compared to doing it all manually. Unmatchable customer service, every concern is catered in hours.
What do you dislike about the product?
The initial integration work was a bit hard because of some legacy systems we have here, but their team really helped us. The only issue is that it doesn't detect all the subdomains (so you must type them manually).
What problems is the product solving and how is that benefiting you?
It identified seen assets, but right now blind spots or new asset categories such as old test envs. It has greatly reduced our attack surface, and helps us out a lot in negotiations when it comes to cyber insurance.