TechValidate Research on CyberGRX


CyberGRX Case Study

Small Business Energy & Utilities Company

Introduction

This case study of a small business energy & utilities company is based on an August 2022 survey of CyberGRX customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“CyberGRX Predictive Risk Profiles provide me dynamic and immediate data on my third parties that I previously did not have with assessments alone.”

“CyberGRX is helping me improve my third-party cyber risk management program through the ability to continuously monitor and analyze my third-party risk data beyond assessments and workflows.”

“CyberGRX enables our Risk Management Team to get more involved in the vendor selection process. We can be proactive and ‘bake’ security into the selection process.”

Challenges

What were the key pain points experienced prior to using CyberGRX:

  • Completed assessments taking too long to receive
  • Procurement-focused third-party process without security involvement
  • Process was focused on assessment completion and not data analysis
  • A lack of visibility against current cyber threats involving third parties

Use Case

What do you use CyberGRX for?

  • Assessing third-party vendors as part of the procurement process (vetting and onboarding)
  • Continuously monitoring third parties as part of a cybersecurity program
  • Aligning third party control gaps to common and recent cyberattacks

Said that CyberGRX Predictive Risk Profiles are used prior to committing to a new third party in the procurement process.

Results

The surveyed company achieved the following results with CyberGRX:

  • Realized a return on their investment with CyberGRX within the first year.
  • Said that due to the Exchange model and Predictive Risk Profiles that CyberGRX provides, “I have visibility to data on more than 25% of my third parties under management.”
  • Reported that CyberGRX platform is very important to their overall third-party cyber risk management program.




About This Data

This data was sourced directly from verified users of CyberGRX by TechValidate.

TechValidate verifies the identity and organizational affiliation of all participants that contribute to published research data. When research participants so desire, we also guarantee their anonymity so that they may share information honestly and freely.


More Research on CyberGRX