BitSight
{{Short description|American cybersecurity ratings company}}
{{Use mdy dates|date=February 2025}}
{{Use American English|date=January 2025}}
{{Infobox company
| name = BitSight Technologies, Inc.
| logo =
| logo_size =
| type = Private
| founders = {{Unbulleted list
| Nagarjuna Venna
| Stephen Boyer
}}
| key_people = {{Unbulleted list|Stephen Harvey (CEO)|Stephen Boyer (CINO)|Dave Casion (CTO)}}
| industry = {{unbulleted list| Cybersecurity| Risk management}}
| homepage = {{URL|bitsight.com}}
| foundation = {{start date and age|2011}}
| location = 111 Huntington Avenue
Boston, Massachusetts, United States
}}
BitSight Technologies, Inc. is a cybersecurity ratings company that analyzes companies, government agencies, and educational institutions.{{cite web|url=https://www.npr.org/sections/thetwo-way/2018/03/30/597987182/as-atlanta-seeks-to-restore-services-ransomware-attacks-are-on-the-rise|title=As Atlanta Seeks To Restore Services, Ransomware Attacks Are On The Rise|last=Romo|first=Vanessa|date=30 March 2018|publisher=NPR|language=English|accessdate=10 October 2018|quote=Data compiled by BitSight, a cybersecurity ratings company, is even more staggering. A 2016 report analyzing government, health care, finance, retail, education and utilities concluded that education institutions are most likely to be on the receiving end of a ransomware attack.}}{{cite web|url=https://qz.com/1000272/its-not-just-the-nhs-in-the-internet-of-things-everything-is-more-hackable-than-you-think/|title=Why is it so easy for hackers to infiltrate - our mistakes|last=Clarke|first=Richard|date=13 June 2017|publisher=Quartz|language=English|accessdate=11 October 2018|quote=BitSight, a Boston firm that ranks companies for their level of cybersecurity, compared five industries: health care, finance, retail, utilities, and federal agencies.}} It is based in Back Bay, Boston.{{cite web|url=https://www.bostonglobe.com/business/talking-points/2018/05/16/investors-dump-shares/LXlDhR19o6wRlKrn0LBibL/story.html|title=Investors dump GE shares|date=17 May 2018|publisher=The Boston Globe|language=English|accessdate=11 October 2018|quote=Cybersecurity ratings firm BitSight is setting its sights on a move to the Back Bay, to a space that is roughly double the size of its existing headquarters in Cambridge. The venture capital-backed firm has leased 48,000 square feet across two floors in the Prudential Center, at the 111 Huntington Ave. tower owned by Boston Properties. BitSight currently employs about 145 people in Cambridge, but will likely have 170 by January and another 30-plus by the end of next year after it moves to Boston.|author=Jon Chesto}} Security ratings that are delivered by BitSight are used by banks and insurance companies among other organizations.{{cite web|url=https://techcrunch.com/2018/06/28/bitsight-a-provider-of-security-ratings-raises-60m-at-a-valuation-of-around-600m/|title=BitSight, a provider of security ratings, raises $60M at a valuation of around $600M|last=Lunden|first=Ingrid|date=10 July 2018|publisher=TechCrunch|accessdate=11 October 2018|quote=. Typical customers include large to mid-sized organizations, and while BitSight doesn’t provide specific names it says the list includes seven of the top 10 cyber insurers, 20 percent of Fortune 500 companies, and three of the top five investment banks, an impressive list. Others that use these ratings are cyber insurance companies, when devising what kind of rates to charge customers, and also to monitor those customers after they are insured. And they are also used by companies, Turner says, to assess acquisition targets when a company is going through due diligence; or before making investments.}}
The company rates more than 200,000 organizations with respect to their cybersecurity.{{cite web |last1=Whitney |first1=Lance |title=Windows 7 remains an albatross at many large organizations |url=https://www.techrepublic.com/article/windows-7-remains-an-albatross-at-many-large-organizations/ |website=TechRepublic|publisher=CBS Interactive |accessdate=24 January 2020 |date=21 January 2020}}
History
BitSight was founded in 2011 by Nagarjuna Venna and Stephen Boyer and currently has both United States-based and international employees.{{cite web|url=https://www.bizjournals.com/boston/news/2018/05/16/bitsight-to-double-hq-size-in-move-from-cambridge.html|title=BitSight to double HQ size in move from Cambridge to Boston|last=O'Brien|first=Kelly J.|date=16 May 2018|publisher=Boston Business Journal|language=English|accessdate=10 October 2018}} In 2016, BitSight raised US$40 million in funding in the month of September.
In 2014, BitSight acquired AnubisNetworks, a Portugal-based cybersecurity firm that tracks real-time data threats.{{cite web|url=https://venturebeat.com/2014/10/21/security-ratings-company-bitsight-acquires-a-threat-analytics-service/|title=Security ratings company BitSight acquires threat analytics service|last=Reader|first=Ruth|date=21 October 2014|publisher=VentureBeat|language=English|accessdate=11 October 2018|quote=Security ratings company BitSight Technologies just picked up a small Portugal-based threat intelligence company called AnubisNetworks.}}{{cite web|url=https://www.bizjournals.com/boston/blog/startups/2014/10/bitsight-technologies-acquires-cybersecurity-firm.html|title=BitSight Technologies acquires cybersecurity firm AnubisNetworks|last=Castellanos|first=Sara|date=23 October 2014|publisher=Boston Business Journal|language=English|accessdate=10 October 2018|quote=Cambridge-based BitSight Technologies, which rates businesses on their cyber security performance, has acquired Portugal firm AnubisNetworks, which tracks real-time data threats.}}
By September 2016, BitSight had raised $40 million in a Series C round led by GGV Capital, with participation from Flybridge Capital Partners, Globespan Capital Partners, Menlo Ventures, Shaun McConnon, and the VC divisions of Comcast Ventures, Liberty Global Ventures, and Singtel Innov8.{{cite web|url=https://www.wsj.com/articles/cybersecurity-ratings-startup-bitsight-raises-40m-1473939005?mod=djemVentureCapitalPro&tpl=vc|title=Cybersecurity Ratings Startup BitSight Raises $40M|last=Zakrzewski|first=Cat|date=15 September 2016|publisher=The Wall Street Journal|language=English|accessdate=10 October 2018|quote=BitSight Technologies Inc. has raised $40 million to provide security ratings. GGV Capital led the Series C round, with participation from existing investors Flybridge Capital Partners, Globespan Capital Partners, Menlo Ventures and the company’s chief executive, Shaun McConnon. The venture arms of Comcast Ventures, Liberty Global Ventures and Signtel Innov8 also participated.}}{{cite web|url=https://www.bostonglobe.com/business/2016/09/15/bitsight-raises-expand-security-ratings-software/Si4XIFMKtKDG8B0bx1bHNK/story.html|title=BitSight raises $40M to expand IT security ratings software|last=Woodward|first=Curt|date=15 September 2016|publisher=The Boston Globe|language=English|accessdate=10 October 2018|quote=Investors are pouring another $40 million into BitSight Technologies Inc., a Cambridge startup that analyzes Internet traffic to generate the equivalent of a credit score for a company’s risk of cybersecurity attacks.}}{{cite web |last1=Kuchler |first1=Hannah |title=Insurers tap cyber security ratings to limit liabilities |url=https://www.ft.com/content/1cfd5d28-c26f-11e6-81c2-f57d90f6741a |publisher=Financial Times |language=English |date=8 January 2017|quote=Bitsight recently announced a fundraising of $40m, led by GGV Capital, as it expands to cater for insurers’ desire to know more about the security weaknesses of their potential — and existing — customers.}}
Shaun McConnon stepped down as the CEO of BitSight in July 2017 but remains the executive chairman of the board. The CEO position was filled by Tom Turner in 2017,{{cite web|url=https://www.bizjournals.com/boston/news/2017/06/30/longtime-cybersecurity-exec-to-step-down-as.html|title=Longtime cybersecurity exec to step down as BitSight CEO|last=O'Brien|first=Kelly J.|date=30 July 2017|publisher=Boston Business Journal|language=English|accessdate=11 October 2018|quote=He's adamant that he's not retiring, but after leading three Massachusetts cybersecurity companies to $1 billion worth of total exit value and a fourth to the verge of an IPO, Shaun McConnon is done being a CEO at his latest company. McConnon will step down as CEO of Cambridge-based cybersecurity ratings company BitSight Technologies Inc. on July 1, but will stay on as the executive chairman of BitSight's board. BitSight's chief operating officer Tom Turner will take over as top executive.}} and then by Stephen Harvey in 2020.{{cite web|title=BitSight Appoints Stephen Harvey as Chief Executive Officer |url=https://www.prnewswire.com/news-releases/bitsight-appoints-stephen-harvey-as-chief-executive-officer-300981919.html |website=PR Newswire |accessdate=15 February 2020 |date=7 January 2020}}
In June 2018, BitSight closed $60 million in Series D funding, bringing the company's total funding to $155 million. BitSight's Series D financing was led by Warburg Pincus, with participation from existing investors Menlo Ventures, GGV Capital and Singtel Innov8.{{cite web|url=https://techcrunch.com/2018/06/28/bitsight-a-provider-of-security-ratings-raises-60m-at-a-valuation-of-around-600m/|title=BitSight, a provider of security ratings, raises $60M at a valuation of around $600M|last=Lunden|first=Ingrid|date=10 July 2018|publisher=TechCrunch|language=English|accessdate=10 October 2018|quote=BitSight, which provides an ongoing, changing “risk security posture” of some 1,200 organizations, has raised $60 million in a Series D round led by Warburg Pincus, funding that it will use to expand its risk management solutions — specifically in areas like analytics — and overall business development. This brings the total raised by BitSight to $155 million. Tom Turner, BitSight’s CEO, said the company was not disclosing its valuation with this round, but he hinted that it was ten times more than the company’s valuation at its Series A. That round, according to figures from PitchBook, was at $60 million post-money, meaning that the company is now valued at around $600 million. Others in this round include Menlo Ventures, GGV Capital and Singtel Innov8, all previous investors.}}{{cite web|url=https://www.reuters.com/article/us-bitsight-funding-idUSKCN11L0JD|title=Cyber-ratings firm BitSight raises $40 million, GGV Capital leads round|date=15 September 2016|work=Reuters|language=English|accessdate=11 October 2018|author=Jim Finkle, Bill Rigby|quote=BitSight Technologies, a firm that sells cyber security ratings on businesses to insurers, said on Thursday that it has closed $40 million in series C funding, in a round led by GGV Capital. Previous investors that joined the round include Flybridge Capital Partners, Globespan Capital Partners, Menlo Ventures and Shaun McConnon.}}
In 2018, the company was located in Cambridge but purchased property in order to shift to Back Bay, where BitSight is currently located. Forbes has estimated BitSight's revenue as being $100 million as of 2018.
In 2021, BitSight acquired VisibleRisk, a cyber risk assessment startup company and received a $250 million investment from Moody's Corporation.{{Cite web |last=Novinson |first=Michael |date=2021-09-13 |title=BitSight Buys Startup VisibleRisk, Gets $250M From Moody's |url=https://www.crn.com/news/security/bitsight-buys-startup-visiblerisk-gets-250m-from-moody-s |access-date=2023-11-15 |website=CRN |language=en}}{{Cite web |title=Moody's to invest $250 million in BitSight and create a 'cybersecurity risk platform' |url=https://www.zdnet.com/article/moodys-to-invest-250-million-in-bitsight-create-cybersecurity-risk-platform/ |access-date=2023-11-13 |website=ZDNET |language=en}}
In 2023, BitSight partnered with Schneider Electric to develop a new way to quantify operational technology risk.{{Cite web |title=BitSight, Schneider Electric partner to quantify OT risk {{!}} TechTarget |url=https://www.techtarget.com/searchsecurity/news/252529063/BitSight-Schneider-Electric-partner-to-quantify-OT-risk |access-date=2023-11-15 |website=Security |language=en}}
In 2024, Bitsight acquired Cybersixgill, a real-time cyber threat intelligence company.{{Cite web |title=Bitsight Completes Acquisition of Cyber Threat Intelligence Leader, Cybersixgill {{!}} Cybersixgill |url=https://cybersixgill.com/company/press/bitsight-completes-acquisition-of-cyber-threat-intelligence-leader-cybersixgill|access-date=2024-12-20 |website=Security |language=en}}
Services
Organizations purchase BitSight's services in order to understand "security risks associated with sharing sensitive data with business partners."{{cite web|url=https://venturebeat.com/2016/09/15/bitsight-raises-40-million-to-help-companies-rate-partner-firms-cybersecurity-credentials/|title=BitSight raises $40 million to help companies rate partner firms' cybersecurity credentials|last=Sawers|first=Paul|date=15 September 2016|publisher=VentureBeat|language=English|accessdate=11 October 2018|quote=Founded in 2011, BitSight offers a platform that helps companies mitigate security risks associated with sharing sensitive data with business partners.}}{{cite web|url=https://www.csoonline.com/article/3247834/risk-management/cyber-insurance-in-the-2018-regulatory-landscape.html|title=Cyber insurance in the 2018 regulatory landscape|last=Schoenberg|first=Carter|date=16 January 2018|publisher=CSO|accessdate=11 October 2018|quote=Some firms have tools for existing clients or potential clients to measure how good of a risk they are. Some firms are using BitSight or similar technologies.}}{{cite web|url=https://www.bizjournals.com/boston/blog/startups/2015/02/q-a-bitsight-technologies-new-vp-of-business.html|title=Q&A: BitSight Technologies' new VP of business development talks cybersecurity|last=Olcott|first=Jacob|date=12 February 2015|publisher=Boston Business Journal|language=English|accessdate=11 October 2018|quote=This is Olcott's sixth week at BitSight Technologies, a four-year-old company that rates businesses on their cyber security performance — which has proven to be an essential service for organizations looking for third-party vendors they can trust.}} As of 2018, BitSight serves clients, including Lowe's, AIG, and Safeway.{{cite web|url=https://www.inc.com/will-yakowicz/cyber-insurers-hottest-product-might-not-handle-disaster.html|title=In an Era of Major Hacks, Cyber Insurance May Be the Industry's Riskiest Bet Yet|last=Yakowicz|first=Will|date=19 September 2017|publisher=Inc.|language=English|accessdate=11 October 2018|quote=But that long history of data on past catastrophes does not exist in the cyber insurance policy world, says Stephen Boyer, the CTO and co-founder of risk-rating company BitSight, a company that assesses company risk for cyber policies written by AIG, Travelers, and others.}}{{cite web|url=https://www.forbes.com/sites/amyfeldman/2016/12/14/the-septuagenarian-whiz-kid-behind-cybersecurity-startup-bitsight/#62c6805b53d2|title=Meet The 72-Year-Old 'Whiz Kid' Behind Cybersecurity Startup BitSight|last=Feldman|first=Amy|date=14 December 2016|work=Forbes|language=English|accessdate=11 October 2018|quote=FORBES estimates BitSight's revenues will reach $50 million in 2017 and $100 million in 2018, when McConnon hopes to take the company public. He expects it to be profitable by 2019.}}{{cite web|url=https://www.bostonglobe.com/business/2016/09/15/bitsight-raises-expand-security-ratings-software/Si4XIFMKtKDG8B0bx1bHNK/story.html|title=BitSight raises $40M to expand IT security ratings software|last=Woodward|first=Curt|date=15 September 2016|publisher=The Boston Globe|language=English|accessdate=11 October 2018|quote=BitSight customers, which include Lowe's, Ferrari, and The Hartford, use the startup's security ratings when they're deciding whether to do business with another company{{snd}} buying its products, making an acquisition offer, or writing an insurance contract, Turner said.}}
BitSight assembles models that produce company ratings, which are based on a scale that enables insurers to rule on the ability of businesses to receive coverage.{{cite web |last1=Kuchler |first1=Hannah |title=Insurers tap cyber security ratings to limit liabilities |url=https://www.ft.com/content/1cfd5d28-c26f-11e6-81c2-f57d90f6741a |publisher=Financial Times |language=English |date=8 January 2017|quote=Then, it creates a model that rates companies on a scale and insurers use the rating to decide if applicants get coverage.}} It produces ratings for 200,000 organizations as of 2020.
With respect to its services, Amy Feldman of Forbes wrote that "Customers pay on a subscription basis with annual fees ranging from a few thousand dollars to analyze a single company to more than $1 million to review thousands of suppliers."{{cite web|url=https://www.forbes.com/sites/amyfeldman/2016/12/14/the-septuagenarian-whiz-kid-behind-cybersecurity-startup-bitsight/#62c6805b53d2|title=Meet The 72-Year-Old 'Whiz Kid' Behind Cybersecurity Startup BitSight|last=Feldman|first=Amy|date=14 December 2016|work=Forbes|language=English|accessdate=11 October 2018}} Similar to a credit score, BitSight's ratings range from 250 to 900.{{cite web|url=https://www.nytimes.com/2017/05/07/technology/hackers-exploit-celebrities-vendor-chains.html?_r=0|title=Hackers Find Celebrities' Weak Links in Their Vendor Chains|last=Perlroth|first=Nicole|date=7 May 2017|work=The New York Times|language=English|accessdate=11 October 2018|quote=BitSight uses a scoring system of 250 to 900, similar to a credit score. SecurityScorecard gives grades from A to F.}}
References
{{reflist|2}}