Introducing G2.ai, the future of software buying.Try now

Bitsight Reviews & Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Bitsight Integrations

(6)
Verified by Bitsight

Bitsight Media

Bitsight Demo - Security Ratings Over Time
Drive accountability across your organization based on uniform performance targets.
Bitsight Demo - Peer Analytics
Set realistic performance targets for your business based on the relative performance of hundreds or thousands of companies within an industry, or any meaningful group of peers.
Bitsight Demo - Cyber Risk Quantification
Deliver a financial analysis of your cyber risk exposure in just two days with this turnkey solution.
Bitsight Demo - Third-party Risk Management Tiers
Easily compare the level of inherent risk to the third party’s security rating to prioritize assessments and mitigation efforts.
Bitsight Demo - Vendor Life Cycles Management
Take control of your cyber risk across the vendor lifecycle. Drive workflow automation with cyber intelligence in your VRM/GRC platform.
Unpacking New SEC Cyber Regulations with Industry Experts (clip)
Play Bitsight Video
Unpacking New SEC Cyber Regulations with Industry Experts (clip)
Bitsight bolsters external attack surface management and assist with cyber regulation compliance
Play Bitsight Video
Bitsight bolsters external attack surface management and assist with cyber regulation compliance
Introducing Bitsight Third-Party Vulnerability Response
Play Bitsight Video
Introducing Bitsight Third-Party Vulnerability Response
Product Avatar Image

Have you used Bitsight before?

Answer a few questions to help the Bitsight community

Bitsight Reviews (69)

Reviews

Bitsight Reviews (69)

4.6
69 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
SW
Lead Information Security Engineer
Enterprise (> 1000 emp.)
"Great tool for managing external sourced vulnerabilities"
What do you like best about Bitsight?

The organization of vulnerability findings by severity, risk vector, type of vulnerability makes it helpful to organize and report on your vulnerabilities. Many findings have been from areas we either didnt know about, or never knew were vulnerable. While the GUI interface is extremely well organized and easy to use, I found it quite helpful using the Bitsight API structure to pull finding totals by Risk Vector, Grade, etc into a spreadsheet that gets regularly updated every few hours. Bitsight has not only helped our company's security posture, but also helped in my knowledge of website construction on a deeper level than I previously had, and Ive been in this field as a developer and a security analyst for over 30 years. Of all the security tools we employ here, Bitsight is probably my preferred tool to use. I find it challenging and easy at the same time.

I find the customer support team an excellent resource. In my 4 years of working with them now, Im sure Ive aggrivated them to no degree with my relentless questions and requests. But they are always there and willing to help me.

I use Bitsight everyday. Its part of my job. I consider it to be my 3rd arm. The loss of this tool would be a significant change in my career. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

As helpful as it can be, at times there are areas that can be improved as well. Bitsight isnt as always as thorough as it could be. While it does in depth scanning of many of our external resources. there are several with the same vulnerabilities that seemingly get overlooked. Or its like one group of findings gets found one month.. two months later, another group is found with the same vulnerabilities. Also Id love to see a bit more transparency about the formulas used in calculating grades, and RV scores.

Lately, my use of customer support has been not as frequent as their response time has dropped off a bit. Where I used to get responses to questions within a few hours to a day.. now it seems many questions go several days before they get a first response. Review collected by and hosted on G2.com.

CL
Account Executive | Cybersecurity Advisor
Mid-Market (51-1000 emp.)
"Strategic insights that go beyond scores"
What do you like best about Bitsight?

BitSight delivers strategic insights that go far beyond traditional scoring. As consultants, we leverage its continuous monitoring, benchmarking, and cyber intelligence capabilities to build truly risk-informed roadmaps. The addition of Identity Intelligence and dark web monitoring has significantly raised the bar in threat visibility — helping our clients act faster and smarter. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

While the platform is powerful, there’s room for improvement in real-time customization and GRC-native integrations. Advanced users may also wish for more granular control when correlating findings with internal telemetry. That said, the platform continues to evolve fast — and the partnership and roadmap discussions with BitSight have been outstanding. Review collected by and hosted on G2.com.

RC
SOC Services Manager
Mid-Market (51-1000 emp.)
"Great Security Benchmarking Tool"
What do you like best about Bitsight?

Have been using it for around 5 years and it's a must have tool for us since its used on more than a weekly basis. Has been a great tool since the start and has been growing with bigger and better features in this time keeping up to date with current needs.

The interface is very user friendly and intuitive, with implementation being fast for most use cases and integration to our workflow has been great as well. I have a great response time from support team. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

As is usual with these types of platforms, false positives are always something negative that's not really all BitSight's fault at times, but it could be better, specifically with risk vectors related to web app and web headers security settings. Review collected by and hosted on G2.com.

Response from Asha May of Bitsight

Hello Rodrigo - Thank you for taking the time to share your experience in working with Bitsight for 5 years! We appreciate and strive to support all our customers. And, it is especially exciting to know those who continue to see value in our partnership for multiple years. Please continue to engage with your account team and share feedback.

Verified User in Insurance
AI
Enterprise (> 1000 emp.)
"Great for Risk Monitoring, But Alert Email Config Needs Improvement"
What do you like best about Bitsight?

There are two main features that assist us. The first to be able to monitor our risk posture from an external perspective and compare ourselves with other like businesses. The other which is currently very important is the ability to monitor our Thirds Parties and be able to make risk based decisions on whether we do business with them. This is important due to APRA 230 requirements Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

At the moment there are some limitations in how we can configure alert emails. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market (51-1000 emp.)
"Easy to use. Actionable data and pinpoints where to focus efforts. Immediate ROI."
What do you like best about Bitsight?

BitSight provides our team an outside-in view of our security posture. The daily security ratings are easy to track and give clear insight into areas like potential compromised systems, risky behavior, and probable past incidents. As part of our multi-layered security strategy, BitSight adds a unique layer of visibility that complements our internal tools, helping us with potential blind spots and external risks that we might otherwise miss. I especially like the Ratings Tree as it breaks down risk across different business units so we can quickly pinpoint where to focus our efforts. It doesn’t replace our internal monitoring or detection tools, but its part of our multi-layered defense where BitSight provides an essential external perspective that strengthens our overall defense and helps us communicate and prioritize cybersecurity with leadership. Further Luisa from the CS team is an amazing contact and so is Ciaran; with both of them we're confident we're getting the services that we need without waiting days for a reply. Its also easy to implement and integrate. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

It's good for us. So nothing I can think of at the moment. Review collected by and hosted on G2.com.

Brian M.
BM
It Security Architect / Manager of Attack Surface Mgmt
Enterprise (> 1000 emp.)
"My overall BitSight experience has been positive."
What do you like best about Bitsight?

I have found the most value in two things :

1) The findings table which combines asset discovery with EASM to provide a solid list of issues to be reviewed and addressed

2) The 3rd Party cyber risk module which allows me to compare my overall security posture with similar companies in my vertical. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

I understand why it is this way, but sometimes it takes a long time to change the security "score" after I've made positive improvements to my company's security posture. Alot of work goes in to implementing the fixes and it can take a long time to see the benefit. Review collected by and hosted on G2.com.

MB
Cybersecurity Risk Specialist
Enterprise (> 1000 emp.)
"Bitsight CM Review"
What do you like best about Bitsight?

Positive Bitsight CM List: - Bitsight Scan - Risk Vectors - Asset Distribution - Security Rating - Security Incidents - Ratings Tree - Findings - PDF Report flexibility - Alerts and notifications Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

Negative Bitsight CM List: - Collaboration (EVA) - there was some issues with getting vendors access to SPM, but I think it's been fixed since. However, I don't think it's always clear to vendors how to access the SPM when we send them the EVA invitation. If there was a tip sheet or another document available to explain what SPM is giving them and what they can do with the data provided with the access. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Enterprise (> 1000 emp.)
"Reliable Security Ratings and Excellent Support Experience"
What do you like best about Bitsight?

Bitsight provides clear, data-driven security ratings that help benchmark our organization’s cybersecurity posture and evaluate third-party vendors. The intuitive dashboards and detailed analytics allow for quick risk assessments and informed decision-making.

Data Transparency: The platform provides visibility into the specific risk vectors affecting the rating, allowing our team to prioritize mitigation efforts.

Regulatory Alignment: Bitsight’s reports are helpful for communicating risk posture to stakeholders and auditors.

Responsive Support: Their support staff is knowledgeable and responsive, helping us quickly resolve questions and get the most from the tool. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

Until recently, the remediation timeline for reflected improvements in the score can be slow, even after fixing identified issues. This sometimes creates a disconnect between our internal posture and the external rating. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise (> 1000 emp.)
"Excellent Support"
What do you like best about Bitsight?

I really appreciate how available and responsive the Bitsight team is when I have questions. They’re always willing to discuss details and help clarify how to get the most out of the platform. Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

I’d like the lifetime expiration to be shorter once an asset is removed, to avoid ongoing impact on the overall score — though I understand that’s part of the observation process. Review collected by and hosted on G2.com.

RC
Third Party Cyber Risk Analyst
Small-Business (50 or fewer emp.)
"Tool is good, managed service has improved greatly, but at quite the premium cost"
What do you like best about Bitsight?

the finding details, customer service is usually pretty good from managed service employees and bitsight support, rarely any down from the platform time as I use it daily Review collected by and hosted on G2.com.

What do you dislike about Bitsight?

not being able to send questionnaires to some third parties without having to submit a support ticket.... by far the worst feature. The questionnaire Issue Management is lacking (sending issues back to vendor and having them respond), overall the Bitsight tools function very much like separate tools, don't work together, at times the managed service employee's lack of cyber knowledge is very apparent as they are way overly reliant on Bitsight's scoring system, lack of AI features as competitors implement them Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

11 months

Average Discount

11%

Perceived Cost

$$$$$

How much does Bitsight cost?

Data powered by BetterCloud.

Estimated Price

$$k - $$k

Per Year

Based on data from 19 purchases.

Bitsight Comparisons
Product Avatar Image
SecurityScorecard
Compare Now
Product Avatar Image
UpGuard
Compare Now
Product Avatar Image
Tenable Vulnerability Management
Compare Now
Bitsight Features
Customized Vendor Pages
Centralized Vendor Catalog
Questionnaire Templates
Risk Scoring
Monitoring And Alerts
Vendor Performance
Notifications
Oversight
Scoring
Product Avatar Image
Product Avatar Image