Try our new research platform with insights from 80,000+ expert users

Bitsight vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024
 

Categories and Ranking

Bitsight
Ranking in IT Vendor Risk Management
4th
Average Rating
8.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Attack Surface Management (ASM) (13th)
RSA Archer
Ranking in IT Vendor Risk Management
2nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
38
Ranking in other categories
GRC (1st), IT Governance (1st)
 

Mindshare comparison

As of December 2024, in the IT Vendor Risk Management category, the mindshare of Bitsight is 11.8%, down from 16.0% compared to the previous year. The mindshare of RSA Archer is 11.5%, down from 12.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
 

Featured Reviews

Alfredo Alvim - PeerSpot reviewer
Provides comprehensive insights into security posture
We work directly on their website to define all the assets that we need to scan. We have some meetings with the manager. For example, we set objectives to evaluate cyber risk periodically in our organization. One of these objectives is to assess the rating for our internal enterprise. We maintain a comprehensive database to ensure compatibility with our objectives. We aim to prevent a decrease in our security rating and maintain its value over time.
Raviteja Nekkanti - PeerSpot reviewer
User-friendly, minimal learning curve and good for security assessment
My use case is for security assessment. It's my daily task. I use it for security assessment in Azure. We have tickets where users need to submit details about an application, computer, or server. For Archer, my direct task is to assess the security risk of an application, infrastructure, or…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Offers open ports from an external point of view."
"Its customer service team responds quickly."
"I prefer BitSight due to its patch management capabilities. The score is a valuable feature. I have contacted the customer support through e-mail and their response rate is fast. I rate the solution a nine out of ten."
"The best thing about BitSight is the comprehensive list of risk vectors, covering compromised systems, diligence failures, and behavioral anomalies."
"The solution is user-friendly."
"The product helps us identify the vulnerabilities of internet-facing applications."
"Archer seamlessly integrates data systems without requiring additional software."
"It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"The most valuable features are the advanced workflow and the dashboards. This tool can present data wonderfully to management, and it is easy for them to manage the risk plans."
"Even non-technical people can be masters of the product."
"From my perspective, because I've always done it as a consultant, I do like the way it is configured. They've gone into changing the application builder interface, so it is even easier. When you're working with users, it is really easy to show them how to do things quickly and how to configure, change, and design stuff quickly."
"Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
"First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."
 

Cons

"The solution’s benchmarking should be improved."
"Its factor analysis feature could be better."
"There may be room for improvement in the methodology for identifying findings, as occasional errors occur on the technical side."
"BitSight could improve the classes and lower-level detections of anomalies that compound the information used to compute the rating."
"At the moment, when the vulnerability score decreases, it remains the same for quite a while, even though issues are resolved in 24 hours."
"Data enrichment is the major issue."
"Recently, we made a suggestion for cross references, like for one application to another. There were limitations there, so we're hoping that will be included in the next upgrade."
"An area for improvement would be the user interface. They could also offer more on-demand applications free of cost."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"In terms of what can be improved, our client always says their user experience, IU/UX in RSA Archer. They found it is not as user friendly as other tools."
"Solution could use more inbuilt applications."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"The design and advanced workflow need to be improved."
"RSA Archer might be a bit expensive for small companies because it's a vast tool."
 

Pricing and Cost Advice

"The solution's price is average."
"The product has a reasonable price."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"I am not sure about other companies, but it's quite expensive."
"Fairly highly-priced, especially for smaller companies."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The solution’s pricing is moderate."
"It is not expensive. It is reasonable. We only pay for the licensing."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
824,052 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
14%
Insurance Company
9%
Manufacturing Company
8%
Educational Organization
54%
Financial Services Firm
12%
Computer Software Company
5%
Manufacturing Company
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for BitSight?
The product is a little expensive and very oriented to large companies.
What needs improvement with BitSight?
BitSight could improve the classes and lower-level detections of anomalies that compound the information used to compute the rating. They could evolve to be a more powerful scanner of cyber hygiene...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
The user interface needs work. There are many small text boxes, like credit card size's boxes, where we need to input a lot of text. You can't see what you're typing beyond the tiny window, so you ...
What is your primary use case for RSA Archer?
We primarily use the system control module and specific IT control models for ongoing risk assessment activities. We use it on a day-to-day basis.
 

Comparisons

 

Also Known As

No data available
Archer
 

Learn More

 

Overview

 

Sample Customers

Fannie Mae, Cabela's, BNP Paribas, PWC, AIR Worldwide, Con Edison, The Container Store, OshKosh, Steris, University of South Florida, Emblem Health, Lloyds Bank
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Bitsight vs. RSA Archer and other solutions. Updated: December 2024.
824,052 professionals have used our research since 2012.