Panorays is a provider of third-party cyber risk management solutions, helping businesses optimize their defenses for each unique third-party relationship. Panorays provides businesses the tools to stay ahead of any emerging third-party threats and provides actionable remediations.
Do You Manage Peer Insights at Panorays?
Access Vendor Portal to update and manage your profile.
1. Ease of integration and deployment. It increases our work efficiency by reducing the manual work and provides automation (the dashboard is providing a flexible way of scrutiny of the security posture) 2. Real-time data and recommendations on the vendor's security posture. It is a very innovative product that focuses and simplifies vendor security. 3. Security rating and real time updates on how they have fixed any security issues after pen testing and provide the fix on a timely basis. Another aspect is that it is a cost-effective solution that other applications fail to provide.
Easy implementation, intuitive UI, and approachable support.
1) Surveys for 3rd party suppliers, and subsequent risk rating. This gives us an easy way to prioritise which supplier to work with, and gives us a much better understanding of their security posture than just using the tool to map their external attack surface. 2) A numerical score for the organisation, whilst simple this gives us a really easy way to report back to senior management on the progress made. Benchmarking it against industry average is also very useful. 3) Being able to input a supplier and get them scanned quickly. This almost ad-hoc approach allows us to assess potential vendors and can help us decide which vendor to go with.
From the application functionality point of view, I haven't found any issues as such, but the vendor response is a little slow sometimes (not every time) as we have to push the vendor to fill in the details of their product before we can review their current SaaS security posture of their product. But from an applications perspective it is a great product.
Lack of transparency - when there was a requirement to confirm the accuracy of presented data before engaging with a third-party and requesting remediation, it was impossible to know the source and the reason why this data was identified and why it was classified as such. Customization - the system provides standard capabilities that could be found in many other systems. When there was a request to make some customization or adjustment according to the current business processes, it was not simple and, in many cases, couldn't be done.
1) It would be nice if there was better API support, for automation. This is mostly for reporting purposes. 2) Customization of the UI could be better, e.g. default landing page, customise graphs, etc. 3) Different roles would be useful, e.g. limiting access of a user to just 3rd party risk and not the organisation's risk, and vice-versa.