TechValidate Research on CyberGRX


CyberGRX Case Study

Medium Enterprise Security Products & Services Company

Introduction

This case study of a medium enterprise security products & services company is based on a May 2023 survey of CyberGRX customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“CyberGRX has made customer requests easier to handle and allows us to head off assessment requests.”

Challenges

What key pain points have you experienced prior to using CyberGRX?

  • Too much time needed to address customer follow-up questions or requests post-assessment share

Use Case

What do you use CyberGRX for?

  • Proactively sharing our CyberGRX assessment with customers who send us assessment requests outside of CyberGRX
  • Assessing our own third party vendors as part of the procurement and/or risk management process

When asked what role the CyberGRX assessment occupies within their overall program, they said “It is the default assessment used for all current and prospective customer requests.”

In the next 6-12 months, which of the following ways will you use CyberGRX to improve your risk posture?

  • Authorize more CyberGRX customers access to our CyberGRX assessment data
  • Use CyberGRX to manage our organization’s own third-party ecosystem (request assessments from others)

Results

Compared to other tools, how would you rate the following features of CyberGRX?

  • CyberGRX Assessment: Better
  • Proactive Sharing: Significantly Better
  • Framework Mapper: Significantly Better
  • Threat Profiles: Better
  • Evidence Upload and Sharing: Better
  • Assessment Results and Findings: Better
  • Predictive Risk Profile: Better

Thinking about the challenges typically encountered in a third-party cyber risk management program, how well has CyberGRX helped you improve your overall program management?

  • Lack of control over cyber reputation and risk posture due to use of security ratings and outside-in scanning tools: somewhat reduced this challenge
  • Too much time needed to address questions or requests post-assessment authorization: somewhat reduced this challenge

On a monthly basis, they said that CyberGRX has contributed 10-15 hours of time savings within their third-party cyber risk program.

CyberGRX has enabled us to:

  • Share our security assessment data with any customer
  • Have higher confidence in our risk posture and cyber reputation




About This Data

This data was sourced directly from verified users of CyberGRX by TechValidate.

TechValidate verifies the identity and organizational affiliation of all participants that contribute to published research data. When research participants so desire, we also guarantee their anonymity so that they may share information honestly and freely.


More Research on CyberGRX