Try our new research platform with insights from 80,000+ expert users

Share your experience using Panorays

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 99,000+ reviews on PeerSpot:

reviewer2774376 - PeerSpot reviewer
Senior Manager and Global Capability Lead - Offensive Security at a tech vendor with 10,001+ employees
Real User
Have improved external security monitoring and vendor oversight but still face accuracy challenges in scan results
Pros and Cons
  • "Bitsight gives me a holistic view of my entire security posture, which is something any organization would want to have after getting a tool such as Bitsight."
  • "We found that some of the findings are clear false positives, but they still report that, and based on that, the rating goes down until we rectify them."

What is our primary use case?

My main use case for Bitsight when I was at Virtusa was to monitor the external security posture for Virtusa, as Bitsight rates your company based on findings on external assets.

I was part of the internal security team and Bitsight used to report findings, such as open ports on specific IP addresses or web applications owned by Virtusa, and based on that it used to give a rating on the severity based on how severe the vulnerability is or the possibility of any vulnerability. I used to take that information and then fix that problem internally. That is how we used to use Bitsight. Our main aim was to use Bitsight to enhance the security of the company so that our score is good on Bitsight, which really matters.

What is most valuable?

The best features Bitsight offers, in my experience, are the ratings that it gives to vulnerabilities and how frequently they conduct scans for a particular company. Bitsight also used to manage our third-party providers regarding how their security is, so it is better for us to manage the vendors we are currently engaged with and the third-party vendors so that we are aware of their security posture as well, instead of us monitoring their security. That is the most useful use case from Bitsight.

Bitsight gives me a holistic view of my entire security posture, which is something any organization would want to have after getting a tool such as Bitsight. It was sufficient in that way, serving the purpose that we took Bitsight for, and there is something that we continued our relationship. We had annual contracts and then we renewed it every year based on the performance of Bitsight.

We had internal KPIs based on the number of findings that we finalized from Bitsight and then tracked it internally to work on that. The more vulnerabilities that we close, the rating would subsequently reflect on Bitsight because they work independently; they do not work as we do inside the company. As long as we are fixing the vulnerabilities, we used to see the score getting improved, and that is something that the board of directors and the internal community were looking for.

What needs improvement?

Bitsight's scan could be more rigorous and then more accurate.

I think it would be good to try to see each and everything of the company in a more accurate way.

Their scan scheduling could be improved and they could take more inputs from the companies they are working with. If they can speed up that process, they would obviously increase that score. We found that some of the findings are clear false positives, but they still report that, and based on that, the rating goes down until we rectify them. So that is something they need to work towards; the number of false positives they are rating should focus on producing more accurate results to get a higher rating.

How are customer service and support?

Bitsight had a professional support service where whenever there are any ratings which we know to be a false positive and a wrong finding, we used to get on a call with support from Bitsight to submit our review as to what we found and what the evidence is for it being a false positive, and they used to consider that and then try to revise that internally and adjust the rating accordingly.

Bitsight is a useful tool to monitor your external posture and it is backed by a good professional support service. The respective other teams such as pre-sales, support service, and customer success team are very good in terms of dealing with customers, so there is something to look for in such products.

How would you rate customer service and support?

Neutral

Which other solutions did I evaluate?

There is nothing particularly unique about Bitsight because we were also using another product along with Bitsight, and we used to compare the results of Bitsight with that tool and then try to see what the unique proposition or the unique findings are that we can evaluate and then work internally.

What other advice do I have?

If the ratings were very poor, low, or below the benchmark that we expected for Virtusa, we used to have a meeting with them, and then try to negotiate if they can improve their security, or else we would discontinue the business with them. So to that extent, we took actions based on the findings that we got from Bitsight. I give Bitsight a six out of ten for this review.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Flag as inappropriate
Rakesh-Gogane - PeerSpot reviewer
Principal Security Architect at Nagarro
MSP
Top 20
Has supported cloud-specific threat scanning but lacks coverage across hybrid and third-party workloads
Pros and Cons
  • "My experience with AWS technical support is very good, I didn't face any specific challenges, and even the documentation of AWS is good for both Microsoft, which is Azure, and AWS."
  • "The false positive rate of Amazon Inspector is a little high, and it is not covering all different applications and scanning."

What is our primary use case?

I mostly use Amazon Inspector for vulnerability scanning on AWS native applications. For hybrid applications, we have different security scanners.

What is most valuable?

I assess that the integration part with CloudTrail and CloudWatch is good for application monitoring. CloudTrail basically creates the trail. CloudWatch is mostly for native application monitoring, but it's not something we can use as a centralized monitoring tool. It's not a tool that can be used as a security incident event management SIEM solution. It's a monitoring tool for native applications.

What needs improvement?

They might launch support for third-party environments in the next version regarding the best features in Amazon Inspector from my perspective.

The false positive rate of Amazon Inspector is a little high, and it is not covering all different applications and scanning. It mostly covers specific native applications, and I think as per my understanding, it doesn't cover third-party environments or hybrid environments.

For how long have I used the solution?

I have been working with Amazon Inspector for approximately six to seven years.

How are customer service and support?

My experience with AWS technical support is very good. I didn't face any specific challenges, and even the documentation of AWS is good for both Microsoft, which is Azure, and AWS.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup of Amazon Inspector is straightforward. It's not a very simple implementation.

What's my experience with pricing, setup cost, and licensing?

I am not honestly sure about the pricing side of Amazon Inspector, but that is taken care of by a separate team. I believe it's cheaper than the other third-party solutions.

What other advice do I have?

My advice is that Amazon Inspector is a good tool for covering the cloud environment, but if organizations want to go with a hybrid environment, there are other solutions that are much better than Inspector.

On a scale from one to ten, I rate this solution a six.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Flag as inappropriate