Data Security

Certified as Coupa Business Spend Management Platform Ready SecurityScorecard Security Ratings

prnewswire | January 06, 2021

SecurityScorecard, the worldwide pioneer in network protection evaluations, today reported it has incorporated with Coupa Software (NASDAQ: COUP) to offer its Security Ratings information in the Coupa Business Spend Management (BSM) Platform. Coupa ensured SecurityScorecard's Security Ratings for use inside its cloud-based stage that engages organizations around the globe with the perceivability and control they need to settle on more brilliant spending choices.

The coordination makes SecurityScorecard's information accessible in the Coupa BSM Platform, empowering clients to effectively comprehend and quantify the online protection stance of any association. With the reconciliation, obtainment experts can:

Survey Vendor Cybersecurity Posture: View the general evaluation, the 10 factor evaluations of information that include a merchant's SecurityScorecard Security Rating, alongside discoveries related with each factor

Assess a Vendor's Historical Performance: With admittance to a half year of a sellers' score history, Coupa clients can comprehend an organization's recorded exhibition

Organize Vendors for Review: Use SecurityScorecard Security Ratings to figure out which merchants to organize for more profound surveys dependent on their online protection hazard act

Build up Required Minimum Scores: Determine gauge SecurityScorecard grades for sellers and afterward influence nonstop observing to guarantee merchants stay on target

Draw in Vendors: Invite sellers to join SecurityScorecard for nothing so they can improve scores by following up on issue-level remediation direction

"As more organizations work with an increased number of third parties and expand their own digital footprint, the need for measuring the cybersecurity risk at scale is imperative now," said Roger Goulart, senior vice president of Business Development and Alliances at Coupa. "We're proud to integrate with SecurityScorecard to give our customers even greater cybersecurity risk insights and enable our customers to instantly rate, benchmark, and monitor the cybersecurity posture of their vendors."

As an affirmed CoupaLink arrangement, the SecurityScorecard coordination for Coupa meets the prerequisites set up by Coupa through its CoupaLink Certified Technology program. The CoupaLink program empowers programming accomplices to fabricate correlative arrangements that effectively interface into the Coupa stage. Clients advantage by improving their business spend and diminishing business hazard while decreasing the expense of outsider programming incorporation.

"Connecting SecurityScorecard Security Ratings into the Coupa Business Spend Management Platform provides our joint customers with a streamlined way to increase their visibility into vendor risk and decrease their overall risk exposure," said Randy Streu, Vice President of Strategic Alliances at SecurityScorecard. "We look forward to our relationship with Coupa to further help customers transform the way they assess vendor cyber health as a critical part of managing their business spend."

About SecurityScorecard
SecurityScorecard is the global leader in cybersecurity ratings and the only service with over a million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 1,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, and cyber insurance underwriting. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every company has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

Spotlight

Risk-Based Authorization solves two challenges: it allows users to gain access from anywhere and ensures that access is secure. Find out how to frustrate attackers, not users with RBA in this guide

Spotlight

Risk-Based Authorization solves two challenges: it allows users to gain access from anywhere and ensures that access is secure. Find out how to frustrate attackers, not users with RBA in this guide

Related News

Enterprise Security, Platform Security, Software Security

ReasonLabs Joins Microsoft Active Protections Program to Enhance Cybersecurity for Millions of Consumers Worldwide

Prnewswire | July 04, 2023

ReasonLabs, the cybersecurity pioneer equipping families and individuals with the same level of cyber protection used by major global companies, today announced that it has joined Microsoft Active Protections Program (MAPP), a program that allows security software providers early access to security data from Microsoft to enable them to provide faster updates to their customers. As a member of MAPP, ReasonLabs will receive advanced access to security vulnerability data from the Microsoft Security Response Center (MSRC) ahead of Microsoft's monthly security update. This information will allow ReasonLabs to better mitigate zero- and one-day vulnerabilities for their users prior to official patches from Microsoft and others. "ReasonLabs is proud to be a member of the Microsoft Active Protections Program, joining the ranks of leading organizations working to strengthen cyber protections for consumers and businesses around the world," said Kobi Kalif, CEO of ReasonLabs. "The data we will receive from Microsoft Security Response Center will enable us to better protect our customers and ensure our products remain on the cutting edge of the industry." "Receiving the latest vulnerability updates from Microsoft's Security Response Center will help us provide even greater protection to our users located in more than 180 countries worldwide. Pairing this information with ReasonLab's research arm, the Threat Intelligence Center, will solidify its place in the industry at the front line of threat intelligence research and prevention," said Yaniv Dudu, VP of Security at ReasonLabs. About ReasonLabs ReasonLabs is a cybersecurity pioneer equipping tens of millions of families and individuals worldwide with the same level of cyber protection utilized by Fortune 500 companies. Its AI-powered, next-generation antivirus engine scans billions of files around the world to predict and prevent cyberattacks in real-time, 24/7. Its flagship product, RAV Endpoint Protection, together with its other products combine to form a multilayered solution that safeguards home users against next-generation threats. Co-Founded in 2016 by seasoned cybersecurity expert Andrew Newman—an architect of Microsoft's native cybersecurity program, Microsoft Defender—ReasonLabs is based in New York and Tel Aviv.

Read More

Web Security Tools, Cloud Security

Tenable Unveils Comprehensive Web Application and API Scanning Capabilities for Nessus Expert

GlobeNewswire | September 01, 2023

Tenable®, the Exposure Management company, today announced web application and API scanning in Tenable Nessus Expert, new features that provide simple and comprehensive vulnerability scanning for modern web applications and APIs. Web application and API scanning in Nessus Expert are dynamic application security testing (DAST) features that enable security practitioners to proactively identify and assess web applications and APIs for known vulnerabilities. This includes OWASP Top 10 vulnerabilities in custom application code and known vulnerabilities found in third-party components. Backed by Tenable Research, Nessus provides broad and accurate vulnerability coverage for web applications and APIs – spanning web application servers, content management systems, web frameworks, programming languages and JavaScript libraries. The result is fewer false positives and negatives, ensuring security practitioners know the true risks in their applications. “Web applications are under siege and the security practitioners in charge of protecting them face numerous challenges,” said Glen Pendley, chief technology officer, Tenable. “With Nessus Expert – the gold standard in vulnerability assessment – we’re tackling the crux of these challenges head on by widening visibility into web applications and APIs. Whether the apps are running on-prem or in the public cloud, Nessus Expert assesses their exposures and provides security practitioners, consultants and pentesters with actionable results quickly.” Nessus Expert is the industry’s first vulnerability assessment solution that spans traditional IT assets and the dynamic modern attack surface, including the external attack surface, cloud infrastructure and now, web applications and APIs. This new feature and functionality enables security practitioners to: Set-up new web app and API scans and easily generate comprehensive results Rapidly discover known vulnerabilities and cyber hygiene issues using predefined scan templates for SSL/TLS certificates and HTTP header misconfigurations Identify all web applications, APIs and underlying components owned by a given organization Confidently and safely scan environments without disruptions or delays About Tenable Tenable® is the Exposure Management company. Approximately 43,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. As the creator of Nessus®, Tenable extended its expertise in vulnerabilities to deliver the world’s first platform to see and secure any digital asset on any computing platform. Tenable customers include approximately 60 percent of the Fortune 500, approximately 40 percent of the Global 2000, and large government agencies. Learn more at tenable.com.

Read More

Cloud Security

Cisco Secure Application to Provide Business Risk Observability

Cisco | September 15, 2023

Cisco Secure Application, new to the Cisco Full-Stack Observability Platform, brings application and security teams together to secure cloud-native application development and deployment. The platform integrates Cisco's industry-leading security products' security intelligence with application performance data to provide business context with security findings. Cisco-exclusive business risk observability enables IT professionals to identify, assess, and prioritize risk and fix application security concerns based on potential business impact. Cisco, a worldwide technology leader that offers innovative software-defined networking, cloud, and security solutions, has unveiled the availability of the Cisco Secure Application, formerly known as Security Insights for Cloud Native Application Observability, on the Cisco Full-Stack Observability platform. This integration empowers organizations to seamlessly unite their application and security teams, facilitating the secure development and deployment of modern applications. The latest release of Cisco Secure Application extends its capabilities to securely manage both cloud-native and hybrid applications. In an effort to assist organizations in bolstering their cloud-native applications security, Cisco has introduced the new Cisco Secure Application offering, which is available on Cisco's recently introduced Full-Stack Observability platform. This solution equips customers with enhanced visibility and intelligent insights regarding business risk in various cloud environments. As a result, businesses gain the ability to more effectively prioritize and respond to security risks that could impact revenue and reputation in real time, leading to a reduction in overall organizational risk profiles. As organizations strive to provide smooth digital experiences, IT teams have faced growing demands to transition to modern, distributed applications. According to a recent study by Cisco, 92% of global technologists acknowledge that the urgency to innovate and adapt to evolving customer needs has often resulted in compromised application security during software development. As a consequence, organizations have become susceptible to security vulnerabilities and threats. They face broader attack surfaces and gaps in their application security layer due to the isolation of teams. These teams face challenges in obtaining adequate visibility and the necessary business context for prioritizing vulnerabilities. Consequently, organizations are witnessing a surge in security incidents within the modern environment, thereby jeopardizing customer data and the reputation of their businesses. Mark Leary, Research Director, IDC, stated, Cisco's extensive domain experience across multi-cloud and hybrid environments and comprehensive full tech stack oversight positions the company well to assist customers bring business risk observability, application observability, and security intelligence data together. Combined, they give customers access to the critical information they need to make smarter decisions about their application security [Source – Cision PR Newswire] Senior VP and General Manager of Cisco Full-Stack Observability and AppDynamics, Ronak Desai, said, An organization's ability to swiftly assess risks based on potential business impact, align teams and triage threats is entirely dependent on understanding where vulnerabilities exist, the severity of those risks, the likelihood they’ll be exploited, and the risk to the business of each issue. This business risk observability can enable IT professionals understand and prioritize those risks and is uniquely delivered by Cisco. The availability of Cisco Secure Application on the Cisco Full-Stack Observability platform is a crucial next step in our commitment to providing customers with the tools they need to provide unmatched and secure digital experiences across multi-cloud and hybrid environments. [Source – Cision PR Newswire]

Read More