Spotlight

Report:

The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2024

How does Forrester define the Cybersecurity Risk Ratings Platforms market in 2024?

The CRR market has existed for more than a decade but is transitioning from maturity challenges to increased value delivery. The market is slowly evolving from 'help me understand' toward 'help me do more.' Vendors are investing more in technical accuracy and efficiency, expanding services to meet security and third-party risk management demands. The majority of CRR customers today use these platforms to enhance their third-party cyber risk assessment and monitoring capabilities. Trust, continuous improvement in discovery and attribution methods, and understanding the difference between risk ratings and risk quantification are critical factors shaping the market's future.

Key Facts for The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2024 in 2024

How did the Cybersecurity Risk Ratings Platforms market evolve in 2024?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cybersecurity Risk Ratings Platforms space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research evaluates 10 cybersecurity risk ratings (CRR) platform providers using 25 criteria grouped into three categories: current offering, strategy, and market presence. The evaluation examines how vendors deliver ratings, technical accuracy, services, and support to meet security and third-party risk management demands. It includes detailed vendor profiles highlighting strengths and weaknesses, placement classifications (Leaders, Strong Performers, Contenders, Challengers), and recommendations for which vendors best fit specific customer needs.

Q: Who should use this research?

A: Security and risk professionals should use this research to select the right CRR platform provider for their needs. The report helps buyers understand vendor differentiation across technical capabilities (asset discovery, ratings methodology, analytics), strategic direction (innovation, vision, roadmap), and use case fit (TPRM, attack surface management, cyber insurance, compliance). The Excel-based vendor comparison tool allows customization of criteria weightings to match individual requirements.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this evaluation, vendors must have: 1) An enterprise-class platform offering with comprehensive CRR capabilities that provides public ratings and supports third-party cyber risk management, external attack surface management, and exposure management use cases; 2) Client mindshare and market relevance, meaning Forrester clients actively ask about these vendors during inquiries and interviews; and 3) At least $10 million in global revenue directly from their CRR products.

Q: What are some reasons for not being included in this report?

A:

  • Platform does not provide public ratings functionality
  • Solution is not enterprise-class or comprehensive in CRR capabilities
  • Vendor does not support the full range of use cases (third-party cyber risk management, external attack surface management, exposure management)
  • Less than $10 million in annual CRR product revenue
  • Lack of client mindshare or market relevance among Forrester clients
  • Vendor does not actively compete in the CRR market
  • Declined to participate or only partially participated in the evaluation process

Q: What should buyers consider when evaluating products in this market?

A:

  • Look for providers that obsess over trust - making trust an imperative in the way they do business, recognizing the fiduciary-like level of responsibility associated with publishing public ratings
  • Evaluate vendors that continuously improve their discovery and attribution methods, using ASM techniques to give rated entities more control over their data and reduce false-positives
  • Understand the difference between risk ratings and risk quantification - ratings are scores based on security indicators correlating with risk (likelihood side only), while CRQ directly measures probability and material impact of risk scenarios
  • Assess vendor commitment to integrity, consistency, competency, and transparency in their ratings methodologies
  • Consider how well vendors balance technical accuracy with operational efficiency
  • Evaluate the breadth of services and support for security and TPRM use cases beyond basic ratings

Q: How has the Cybersecurity Risk Ratings Platforms market evolved in 2024?

A:

  • CRR market transitioning from 'help me understand' toward 'help me do more'
  • Vendors reorienting delivery methods, investing more in technical accuracy and efficiency
  • Expansion of services and support to meet more relevant security and TPRM demands
  • Majority of CRR customers using platforms to enhance third-party cyber risk assessment and monitoring capabilities
  • Trust becoming imperative as ratings gain position among regulators, insurance providers, governments, and contracts
  • Increased focus on discovery and attribution methods using external attack surface management (ASM) techniques
  • Growing distinction between risk ratings (security indicators correlating with risk) and cyber risk quantification (probability and material impact measurement)
  • Rising customer frustration with false-positives requiring better asset validation
  • CRR vendors assuming fiduciary-like levels of responsibility for published public ratings

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering (50% weighting) measures each vendor's position on the vertical axis and evaluates the strength of current product capabilities including asset discovery, ratings methodology, vendor management, security analytics, remediation, integrations, and user experience. Strategy (50% weighting) measures position on the horizontal axis and evaluates forward-looking elements including vision, innovation, roadmap, partner ecosystem, adoption approach, pricing model, community engagement, and supporting services.

Reference

View Leaders
View Vendor Movements