

RSA Archer and SecurityScorecard are competing products in risk management and cybersecurity. SecurityScorecard is perceived to have an edge in addressing cybersecurity threats, while RSA Archer demonstrates strong performance in risk management.
Features: RSA Archer is known for its capabilities in integrated risk management, audit management, and compliance tracking. Its extensive functionalities support the tracking of enterprise risks and regulatory requirements. SecurityScorecard offers real-time cybersecurity risk ratings, continuous monitoring of vendor risks, and advanced cybersecurity analytics providing actionable insights.
Room for Improvement: RSA Archer could benefit from simplifying its deployment process and further enhancing its user friendliness. While its customization options are beneficial, they could be streamlined for more ease. SecurityScorecard might improve the configurability of its report options and expand its capabilities in consolidating third-party risk management with possible integration features for other security tools.
Ease of Deployment and Customer Service: RSA Archer requires a complex deployment due to its comprehensive nature but offers robust support systems to assist customers. SecurityScorecard benefits from a quicker deployment, offering intuitive processes and responsive customer service to handle technical challenges.
Pricing and ROI: RSA Archer involves a higher setup cost attributed to its extensive capabilities, with potential for substantial ROI in compliance and risk management. SecurityScorecard features a flexible pricing structure, providing strong ROI in cybersecurity monitoring at a lower initial cost. For cybersecurity-focused organizations, SecurityScorecard presents a cost-effective solution with significant return potential.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
This resulting in a lower insurance premium cost for us and considerable cost savings overall, which made our management very pleased with the progress.
The biggest benefit is visibility, allowing organizations to understand their risks, vulnerabilities, and potential threats.
We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.
They are responsive and perform well in technical support.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They need better organization to support their customer volume.
they continue to assist us with bi-monthly sync-up calls whenever we face issues with the platform regarding risk and how to improve our security score
I would rate the customer support for SecurityScorecard nine out of 10.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
The product is suitable for medium to large businesses, typically with a revenue range from $200 million to a couple of billion dollars.
My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
The tool has stability, and it allows me to automate whatever process I have.
I find SecurityScorecard stable for our organization, as I have not encountered any downtime.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
It would be helpful if RSA Archer had the capability for two-way integration because, in any information technology area, having the ability to provide feedback is beneficial.
There is a need for more active rather than passive third-party risk management features to truly mitigate risks.
SecurityScorecard could enhance some of the integrations based on AI platforms, where I could receive suggestions from the AI tool regarding why SecurityScorecard rates specific issues as critical or high.
If SecurityScorecard could help their customers internally by developing their tool or feature so that customer devices that are not only public-facing can be monitored, it would be more beneficial.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
There are more expensive and cheaper options available.
I expected slightly lower pricing.
Pricing is acceptable as per the Indian market.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
The tool has stability, and it allows me to automate whatever process I have.
It combines threat intel data with vulnerability information to increase risk ratings and provides insights into third-party supply chain risks.
I particularly value the Jira integration, so any issue identified as part of the threat intel activity can be directly updated through our Jira.
It converts complex security issues into business-friendly language, which helps executives and the board understand cyber risk.
| Product | Market Share (%) |
|---|---|
| SecurityScorecard | 8.1% |
| RSA Archer | 8.0% |
| Other | 83.9% |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 25 |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 5 |
| Large Enterprise | 2 |
RSA Archer is a solution designed to help your organization manage policies, controls, risks, assessments, and deficiencies across your lines of business. RSA helps you manage your digital risk with a range of capabilities and expertise including integrated risk management, threat detection and response, identity and access management, as well as fraud prevention.
The solution also allows you to adapt a broad range of solutions to your requirements and is a good option for both big and small companies.
RSA Archer Features
RSA Archer has many valuable key features. Some of the most useful ones include:
RSA Archer Benefits
There are many benefits to implementing RSA Archer. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the RSA Archer solution.
A Specialist, RSA Archer at a tech services company, says, “RSA Archer is a valuable tool because it can manage the end-to-end functioning of any enterprise GRC module, such as compliance and risk management or business continuity plans and the entire BCM module. RSA Archer also provides many out-of-the-box solutions, which are use cases derived from the standards for GRC or risk management, governance, and compliance. It provides an end-to-end mechanism for business users on a single platform. That includes reporting, managing workflow, creating documentation, or tracking a process where you need to get approval from the various levels within the organization's hierarchy.”
PeerSpot user Krishnendu S., Vice President at a financial services firm, mentions, "It is enterprise-wide accessible. So, it is very helpful for all the employees in our bank. They can log in and do their risk management activities. It has a few inbuilt modules that are helpful for doing risk management activities, such as issue management, risk identification, risk assessment, and policy exception management. It also has some inbuilt workflows inside these modules. They are also helpful."
A Sr. Internal Auditor at an energy/utilities company comments, "Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
Another PeerSpot user, Manash B., Technology Manager at a tech services company, explains, "RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
SecurityScorecard provides comprehensive cybersecurity insights with features such as notifications for score changes and configurable reporting, supporting team collaboration. It emphasizes multi-factor authentication and continuous monitoring for improved risk assessments.
SecurityScorecard specializes in assessing third-party cybersecurity risks, enhancing security posture, and analyzing exposed data. It offers automated information gathering and vendor reports, aiding in vulnerability assessments for supply chain risk management. Users value the Attack Surface Index and recommendations for security improvements, though faster technical response times and better cost-effectiveness, especially in Brazil, are desired. Enhancements such as app scanning and more efficient vulnerability management could expand its capabilities.
What are the key features of SecurityScorecard?SecurityScorecard is utilized in industries for managing third-party cybersecurity threats by providing detailed vulnerability assessments and automated reporting. Its implementation aids supply chain risk management and enhances industry-specific security strategies, with room for improvement in technical response times and dark web intelligence inclusion.
We monitor all IT Vendor Risk Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.