No more typing reviews! Try our Samantha, our new voice AI agent.

Bitsight vs Cisco Umbrella comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Bitsight
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
11
Ranking in other categories
IT Vendor Risk Management (3rd), Attack Surface Management (ASM) (5th)
Cisco Umbrella
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
125
Ranking in other categories
Secure Web Gateways (SWG) (1st), Internet Security (1st), Cloud Access Security Brokers (CASB) (2nd), Domain Name System (DNS) Security (1st), Cisco Security Portfolio (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Bitsight is designed for IT Vendor Risk Management and holds a mindshare of 5.8%, down 10.8% compared to last year.
Cisco Umbrella, on the other hand, focuses on Domain Name System (DNS) Security, holds 17.5% mindshare, down 25.0% since last year.
IT Vendor Risk Management Mindshare Distribution
ProductMindshare (%)
Bitsight5.8%
OneTrust GRC8.7%
RSA Archer7.1%
Other78.4%
IT Vendor Risk Management
Domain Name System (DNS) Security Mindshare Distribution
ProductMindshare (%)
Cisco Umbrella17.5%
Palo Alto Networks DNS Security9.1%
Infoblox Advanced DNS Protection7.3%
Other66.1%
Domain Name System (DNS) Security
 

Featured Reviews

TarunKumar11 - PeerSpot reviewer
Member Of Leadership Advisory Council at a tech company with 10,001+ employees
Continuous monitoring has improved vendor risk visibility and supports strategic decisions
There are opportunities for improvement in Bitsight. Better explainability of cyber scores is something that Bitsight can work upon, along with addressing false positives. Better cloud-native visibility to identify where service providers might be exposed, and further enhancements in predictive risk and analytics are areas that can be developed. I covered the main points about needed improvements, emphasizing that everything else is operational and not a limitation on Bitsight's usage. I would rate Bitsight closer to nine, or somewhere between eight and nine, because the reasons I do not rate it a ten relate to opportunities for improvement I mentioned, such as broader risk, cyber risk intelligence, and emphasis on supply chain risk intelligence. There is potential for improvement in AI-assisted prioritization as it matures. I choose eight as my official rating of Bitsight. I chose eight as my rating for Bitsight because it needs to move in the direction of providing broader risk, cyber risk analysis, working more on supply chain risk intelligence, and using AI for prioritization further. I talked about areas of improvement concerning predictive risk analysis, reduction of false positives, and better explainability of the scores, which justifies my rating as eight rather than ten. Regarding Bitsight's AI capabilities, I am not very sure about the governance and security aspects of AI that Bitsight uses, as I am not aware of any policies they may have regarding AI usage for their services. However, I think AI should be used much more strongly to enhance predictive analysis by Bitsight. The accuracy and reliability of Bitsight's output stem from its capability of using AI effectively. AI relies on a lot of data from continuous monitoring, enabling faster risk triaging based on the outcomes generated by the AI engine. I believe it is a highly reliable outcome, and the platform has a mature rating system, provides good benchmarks, and has strong enterprise acceptance, so the outcome from the AI engine is quite reliable but can be further improved for predictive assessments.
BB
Senior Network Engineer at Mintz, Levin, Cohn, Ferris, Glovsky and Popeo, P.C.
Ensures comprehensive protection with seamless threat logging and efficient policy management
My favorite feature of Cisco Umbrella is probably just the DNS and the fact that when a security threat happens, all of that gets logged in their Umbrella portal, and it's very easy to find who's been accessing the site and how many people have accessed it, so that we can go to them and make sure they're not compromised. The features of Cisco Umbrella benefit my company by providing less time to search for things through logs, to look for what we need. It's just one place to go, and we just search for it, and we find it really fast. The fact that there's a virtual database that has all that information is great on our portal.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"If you are exactly looking for external attack surface monitoring, and you are exploring options, then Bitsight is a very good option that you can explore."
"I prefer BitSight due to its patch management capabilities. The score is a valuable feature. I have contacted the customer support through e-mail and their response rate is fast. I rate the solution a nine out of ten."
"Offers open ports from an external point of view."
"The product helps us identify the vulnerabilities of internet-facing applications."
"The solution is user-friendly."
"Bitsight has positively impacted my organization by improving security and customer trust, giving us continuous monitoring so we now find misconfigurations within hours instead of days or weeks, which directly improves our overall security posture and reduces risk as we catch high-risk exposures early, especially unexpected cloud assets or testing endpoints that accidentally went public."
"Bitsight gives me a holistic view of my entire security posture, which is something any organization would want to have after getting a tool such as Bitsight."
"Bitsight has positively impacted the organization by helping with vendor benchmarking and providing outside-in cyber visibility across hundreds of vendors, which is the biggest plus."
"This is a good solution, and there are many advantages to this solution."
"Cisco Umbrella provides a cloud management system where we can manage every client from a single workspace in our portal, and the single pane of glass management is user-friendly."
"When we have laptops that leave the building, they could connect to public WiFi before they establish a VPN connection back into the company. For that duration or that period of time when they're not docked in the network or on a VPN, they effectively don't have that full layer of security that I provide inside the building. This tool stands in during that period of time, and we extend the security settings through their basic firewall or their cloud-based firewall at that time. So, we do content filtering and control access, but they also are looking at new domains, IP addresses, and bad requests. They're blocking them on my behalf when a laptop is not sitting behind our security appliances."
"For us and for customers, it's the ease of integration with Meraki. It's just a couple of clicks. That allows us to deploy very fast, and it doesn't change the way a customer uses his service. It's just more secure."
"I am a network administrator, and for me, it is the best solution because it is easy to manage."
"What we like most is security and how easy it is to integrate with other appliances."
"Go for it; there is no better way to secure guest networks without any headaches."
"Cisco is a very efficient and on-point solution that controls the whole network and settings on one page. We can monitor the entire network."
 

Cons

"We found that some of the findings are clear false positives, but they still report that, and based on that, the rating goes down until we rectify them."
"Since if the number of findings increases for a particular month, your overall risk score decreases, which can become a challenge for a team working on this particular issue."
"There may be room for improvement in the methodology for identifying findings, as occasional errors occur on the technical side."
"I would rate Bitsight closer to nine, or somewhere between eight and nine, because the reasons I do not rate it a ten relate to opportunities for improvement I mentioned, such as broader risk, cyber risk intelligence, and emphasis on supply chain risk intelligence."
"Its factor analysis feature could be better."
"There has been quite a bit of data discrepancy in BitSight."
"BitSight could improve the classes and lower-level detections of anomalies that compound the information used to compute the rating."
"At the moment, when the vulnerability score decreases, it remains the same for quite a while, even though issues are resolved in 24 hours."
"Cisco Umbrella could be improved by making the policies more granular, as in some cases, it's difficult to find the correct link to open a specific site securely."
"I would like for them to continue building on IPS and IDS functionalities."
"I would like the product to offer more security features, such as IPS, IDS, DDoS prevention, etc."
"I think it's a very basic solution, and because of that, we provide it to the small business market."
"The different levels of security, such as backend security and internet security, need improvement."
"We would like them to add more features to Cisco Umbrella."
"There are a couple of interface issues. I know that they say that there are feature enhancements that are noted. For example, we've got the Cisco Meraki security appliances, and there, we geofence our company to where we're allowed to send and receive traffic. So, in our case, by default, we only allow traffic to six different countries, which allows us to effectively prevent traffic for the majority of bad players in the world, but they don't give you an easy way to do that in Cisco Umbrella. With Cisco Meraki, I can specify or pick the countries. I can say that I want to only allow traffic from these six countries, and I'm done. With Cisco Umbrella, I have to rely on the fact that they're going to prevent traffic to other countries. They're going to decide if it's good or bad."
"From my perspective, I would Cisco Umbrella to give more exposure to my sales engineers. I know I can call them whenever I have an issue, however, more frequent meetings would be awesome."
 

Pricing and Cost Advice

"The solution's price is average."
"The product has a reasonable price."
"The price depends on the use case, and it's a bit linear. But it depends on the customer's strategy and how Cisco plans to optimize the costs."
"The pricing was marvelous."
"Cisco should make the solution cheaper."
"Our costs were negotiated, and they are okay."
"You can request an evaluation license​."
"​The pricing is fair."
"The price could be lower."
"The pricing is great and very competitive with the rest of the market."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Manufacturing Company
10%
Insurance Company
7%
Computer Software Company
6%
Computer Software Company
15%
Manufacturing Company
8%
Financial Services Firm
8%
Non Profit
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Large Enterprise8
By reviewers
Company SizeCount
Small Business50
Midsize Enterprise31
Large Enterprise52
 

Questions from the Community

What needs improvement with BitSight?
There was one case scenario where a lot of parked domains were observed for a particular organization that we were monitoring via Bitsight. Bitsight flagged a missing web application header althoug...
What advice do you have for others considering BitSight?
If you are exactly looking for external attack surface monitoring, and you are exploring options, then Bitsight is a very good option that you can explore. I have not worked upon any other solution...
What is your primary use case for BitSight?
I was primarily using Bitsight for attack surface monitoring and external attack surface monitoring use case. I was monitoring all the alerts and the risk score that Bitsight provides. We mainly fo...
Which is the better security solution - Cisco Umbrella or Zscaler?
Cisco Umbrella and Zscaler Internet Access are two broad-spectrum Internet security solutions that I have tried. Zscaler Internet Access is a good option for carrying out multiple security functi...
Which is the better security solution - Cisco Umbrella or Microsoft Cloud App Security?
Cisco Umbrella is an integral component of the Cisco SASE architecture. It integrates security in a single, cloud-native solution, unifying multiple features like DNS-layer security, threat intelli...
What is your experience regarding pricing and costs for Cisco Umbrella?
The pricing for Cisco Umbrella is fair compared to other platforms out there for DNS security. We acquired it as a bundle with other Cisco purchases.
 

Also Known As

No data available
OpenDNS
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Cabela's, Belgium Center for Cybersecurity, Fordham University, RBC, Max Life Insurance, Schneider Electric
Chart Industries, City of Aspen, Eastern Mountain Sports, FLEXcon, George Washington University, Jackson Municipal Airport Authority, Ohio Public Library Information Network, PTC, Richland Community College, Smart Motors, Tulane University, VeriClaim
Find out what your peers are saying about SecurityScorecard, OneTrust, BitSight and others in IT Vendor Risk Management. Updated: May 2026.
896,942 professionals have used our research since 2012.