IT Risk Management (ITRM) Reviews and Ratings
What are ITRM (IT Risk Management) Solutions?
The IT risk management (ITRM) market focuses on solutions that support the ITRM discipline through automating common workflows and requirements. For the purposes of defining this market, IT risks are risks within the scope and responsibility of the IT department. These include IT dependencies that create uncertainty in daily tactical business activities, and IT risk events resulting from inadequate or failed internal IT processes, people or systems, or from external events.
Product Listings
Filter by
Archer IT & Security Risk Management is software designed to enable organizations to identify, assess, monitor, and manage IT and security risks across their enterprise. The software provides centralized visibility into risk and compliance processes while supporting risk assessments, control evaluations, incident management, and regulatory reporting. It allows businesses to automate workflows, track remediation activities, and produce actionable risk insights through customizable dashboards and reports. By streamlining the management of risk, policies, and controls, the software helps organizations address threats, meet regulatory requirements, and align risk management processes with business objectives.
OneTrust Tech Risk & Compliance is a software designed to help organizations identify, assess, and manage technology-related risks while facilitating adherence to regulatory and policy requirements. The software offers features such as automated risk assessments, control monitoring, regulatory mapping, and workflow management for issue remediation. It supports integration with various technology platforms to provide a centralized view of technology risk and compliance activities. The software enables organizations to document processes, track mitigation efforts, and generate reports that support audit and compliance objectives. It addresses challenges related to complex regulatory environments, fragmented risk data, and manual compliance processes by streamlining risk identification and promoting consistent risk management practices.
Diligent One Platform is a software that integrates governance, risk and compliance functionalities to support organizational oversight and decision-making. The software offers modules for board management, risk assessment, internal controls, audit management and compliance tracking. It enables users to centralize documentation, monitor regulatory requirements, and automate reporting processes. By providing analytics and customizable dashboards, the software aims to streamline workflows and enhance transparency in managing risks and meeting compliance obligations. Diligent One Platform is designed to facilitate collaboration among stakeholders, support policy and procedure management, and help organizations address regulatory and operational challenges.
ServiceNow Governance Risk and Compliance (GRC) software offers capabilities for managing risk, compliance, and audit processes within organizations. The software integrates policies, controls, and risk assessments into a unified platform, facilitating real-time visibility into risk status and regulatory compliance. It supports automation of workflows for incident response, policy management, and audit tracking, helping organizations streamline reporting and maintain accountability. The software provides dashboards and analytics for monitoring ongoing compliance activities and identifying areas for improvement. By centralizing information and processes, ServiceNow Governance Risk and Compliance software aims to reduce manual efforts, support decision-making, and address regulatory and corporate governance requirements within business operations.
NAVEX IRM Software is designed to support organizations with integrated risk management by providing tools to identify, assess, and manage risks across various business units. The software enables users to automate risk and compliance workflows, document and track incidents, evaluate controls, and ensure regulatory adherence. Features include centralized dashboards, reporting capabilities, policy management, and audit tracking. NAVEX IRM Software assists businesses in improving visibility into risk exposure and helps facilitate the management of operational, third-party, and IT-related risks to support informed decision-making and organizational governance.
SAFE One is a software developed by SAFE Security designed to provide organizations with capabilities to measure, manage, and mitigate cyber risk across their digital infrastructure. The software utilizes data-driven risk assessment to deliver real-time, quantitative insights into the security posture of various assets, including applications, networks, and endpoints. It offers functionalities for continuous monitoring, risk modeling, and compliance reporting, enabling organizations to identify vulnerabilities, prioritize remediation efforts, and align security investments with business objectives. SAFE One addresses the business challenge of understanding and reducing cyber risk exposure by offering centralized visibility and actionable intelligence for enterprise-wide security management.
Allgress is a software designed to streamline and simplify risk management, compliance, and security operations for organizations. The software assists users in identifying, assessing, and mitigating risks associated with information technology and regulatory requirements. It provides features such as automated risk assessments, compliance tracking, policy management, and reporting capabilities. Allgress software enables businesses to categorize and prioritize risks, monitor regulatory changes, and maintain documentation for audits. By facilitating efficient risk and compliance processes, the software aims to reduce manual effort and help organizations maintain a comprehensive understanding of their risk posture.
Axonius Cybersecurity Asset Management Platform is a software that enables organizations to automate the process of discovering, inventorying, and managing technology assets across their entire infrastructure. The software collects and correlates data from various sources such as cloud providers, endpoint agents, network devices, and security solutions to provide a unified view of all assets. Through its capabilities, the software assists in identifying gaps in coverage, policy violations, and compliance issues, supporting security teams in enforcing security policies and making informed decisions. The software integrates with a wide range of existing tools to provide visibility into devices, users, and software, assisting organizations in addressing challenges related to asset visibility, security control validation, and operational efficiency.
ZenGRC is a governance, risk, and compliance software developed to assist organizations in managing risk and compliance programs across various frameworks and standards. The software centralizes risk and compliance data, automates workflows, and provides insights through customizable dashboards and reporting tools. ZenGRC enables mapping of controls and processes to industry requirements, streamlines evidence collection, and facilitates audit management. It supports integration with other security and IT management systems, aiding organizations in tracking compliance tasks, monitoring risk levels, and ensuring policy adherence. The software addresses the business problem of complex compliance management by reducing manual effort and improving visibility across regulatory and operational requirements.
IBM OpenPages is a software designed to support integrated risk management and governance, risk, and compliance functions for organizations. The software includes modules for managing operational risk, regulatory compliance, policy management, internal audit, and financial controls. It provides a unified platform that enables businesses to identify, assess, monitor, and report on various types of risks across multiple departments. With analytics, automation capabilities, and centralized data repositories, IBM OpenPages facilitates more efficient tracking and analysis of risks, enhances workflows, and helps organizations to align risk management processes with strategic objectives. This software addresses the business need to manage risks, compliance, and controls in a systematic manner to support governance and accountability.
Vanta’s Trust Management Platform helps organizations identify, assess, and manage IT security risks through automation and continuous monitoring. Over 10,000 teams rely on Vanta to streamline IT risk assessments, maintain compliance with 35+ security frameworks, and improve visibility into risk exposure. By centralizing IT risk management processes, Vanta enables Security, GRC, and IT professionals to reduce operational overhead, improve efficiency, and strengthen their security posture.
Sai360 IT Risk & Cybersecurity is a software designed to help organizations identify, manage, and mitigate IT risks and cybersecurity threats. The software enables users to assess risk levels, monitor compliance with regulatory frameworks, and establish governance processes for information security. It provides tools for tracking vulnerabilities, managing incidents, performing audits, and automating workflows associated with risk management. Through centralized dashboards and reporting, the software facilitates visibility into risk posture and supports decision-making by providing data on threats, remediation progress, and control effectiveness. Sai360 IT Risk & Cybersecurity addresses the business challenge of safeguarding digital assets and maintaining regulatory compliance within complex IT environments.
MetricStream IT Risk Management is a software designed to help organizations identify, assess, monitor, and manage IT risks and compliance requirements. The software provides tools for documenting and tracking IT assets, evaluating vulnerabilities, and implementing risk mitigation strategies. It offers features for automated risk assessments, issue management, policy and compliance tracking, and reporting. MetricStream IT Risk Management supports the alignment of IT risk management processes with organizational objectives and regulatory requirements, enabling a structured approach to risk identification, analysis, and response. The software also facilitates workflows for issue remediation and enables organizations to gain visibility into their IT risk posture.
Balbix is a cybersecurity software that provides organizations with an automated approach to identify, prioritize, and manage cyber risk across their digital assets. The software uses continuous data collection and advanced analytics to create a comprehensive inventory of assets, assess vulnerabilities, and evaluate risk exposure. Balbix offers features such as risk-based vulnerability management, attack surface analysis, and actionable remediation workflows. It enables teams to quantify cyber risk in financial terms, helping organizations to prioritize resources and investments based on potential impact. The software aims to streamline security operations and supports compliance initiatives by providing detailed reporting and insights into the organization’s security posture.
LogicManager is a risk management software designed to help organizations identify, assess, and monitor risks across various business processes. The software enables users to streamline compliance management, automate workflows, and document policies and controls. It offers modules for governance, risk, compliance, incident management, and audit processes, integrating data to enhance reporting and accountability. LogicManager assists organizations in centralizing information, tracking remediation activities, and ensuring alignment with regulatory requirements. Its features support decision-making by providing a structured approach to risk identification and mitigation, making it suitable for managing enterprise risk and improving operational resilience.
Resolver RiskVision is a software designed to support enterprises in managing governance, risk, and compliance processes. The software enables organizations to identify, assess, and address risks through features such as automated workflow, centralized documentation, and risk assessment tools. It allows for tracking of incidents, monitoring regulatory compliance, and reporting on risk metrics across multiple departments. RiskVision facilitates collaboration among stakeholders and helps standardize risk management practices, aiming to improve visibility into risk posture and streamline the process of responding to potential threats. The software addresses business challenges related to operational risk, regulatory requirements, and policy management by providing a structured framework for risk analysis and mitigation.
Censinet Third-Party Vendor Risk Management Software Platform is a software designed to help organizations manage and assess risks associated with third-party vendors. The software offers features for automating vendor assessments, streamlining due diligence processes, and managing documentation related to risk and compliance. It enables users to identify, track, and mitigate risks by providing tools for workflow automation, reporting, and real-time risk scoring. The software is designed to address challenges related to third-party risk visibility, regulatory compliance, and efficient data collection, allowing organizations to make informed decisions about vendor relationships and reduce potential risks across the supply chain.
Sevco Security is a cloud-native asset intelligence platform that is delivered across 4 key dimensions:
1. Comprehensive Inventory: Sevco provides a complete, continuous view of an organization's IT environment by tracking all assets integrated with every source of inventory within the enterprise, eliminating blind spots that are present in any single system.
2. Asset context & detail: Sevco aggregates details tracked from each IT and security system into a single, unified view.
3. Tracking multiple asset types: Sevco tracks devices, users, software and vulnerabilities and the relationships between each type.
4. Real-time and recorded history of assets: Sevco monitors every IT and security system in real-time and remembers each asset's history.
The Sevco Venn Diagram and query capabilities identify security gaps and vulnerabilities enabling teams to prioritize risks.
Panaseer Platform is a software designed for cybersecurity and risk management, enabling organizations to automatically aggregate and analyze data from various security tools and IT assets. The software provides visibility into security controls coverage, identifies gaps, and supports compliance reporting by integrating disparate data sources into a unified dashboard. It helps organizations measure security posture, prioritize remediation activities, and generate reports for stakeholders. The software addresses the challenge of manual and fragmented security measurement processes, facilitating data-driven decision making and continuous monitoring of security controls within complex enterprise environments.
isorobot is a software designed to facilitate enterprise process automation and management. It enables organizations to map, analyze, and optimize business processes, aiding in the alignment of operations with strategic objectives. The software allows for modeling and monitoring workflows, performance metrics, and compliance with relevant standards. It provides features for document management, incident tracking, and risk management, supporting organizations in identifying process inefficiencies and maintaining regulatory adherence. isorobot is utilized to streamline operations and drive consistency in processes across various business units.



















