What you want to do
You can't secure what you don't know about. A security assessment starts by defining what you are assessing, and that includes every piece of software your business relies on.
Once you know your software assets, the next step is to understand the key security controls in place for each one. Most businesses now run a large share of their software as Software-as-a-Service (SaaS). For these, much of the security comes from the supplier, so you need to know what each supplier offers out of the box.
Why this matters
- Hidden gaps. A supplier may offer multi-factor authentication (MFA), but it only protects you if you have switched it on.
- Supplier risk. A supplier with a history of data breaches may put your business data at greater risk.
- Recovery. If a SaaS service loses your data, you need to know whether the supplier can restore it, or whether you need your own backup.
- Time. Researching every supplier by hand is slow, and the information is spread across websites, trust centres and news reports.
Features and benefits
By mapping what each supplier offers back to how your business actually uses it, you quickly get a clear view of your software risk.
- Confirm MFA is switched on. See which suppliers offer MFA, then check whether your business has set it up for each one.
- Understand supplier risk. Use a supplier's data breach history and security certifications to judge how much risk they may pose.
- Plan for data loss. Know which SaaS services include backups and where you may need your own backup arrangement.
- Save hours of research. Get a summary for each supplier in moments instead of searching websites and news reports by hand.
- Keep it all in one place. Findings are stored against each asset in your asset register, ready to use in your security assessment.
How Assuredly helps: Supplier Research
For customer with AI enabled accounts, the Assuredly Assets module includes AI-supported Supplier Research. When you add a software asset, Assuredly can research the supplier for you and summarise the key security information you need.
Supplier Research gives you an instant summary of:
- Supplier security certifications, such as ISO 27001 or SOC 2
- SaaS service backup offerings, including whether the supplier backs up your data and how
- Data breach history, covering any publicly reported breaches
- MFA availability, showing whether the product supports multi-factor authentication
The results are added straight into your asset register, so you can review them alongside the rest of your asset information.
How to conduct Supplier Research
Follow these steps to research a supplier for one of your software assets.
- Log into Assuredly - Sign in to your Assuredly account.
- Go to the Asset Module and Add an asset
- Enter the supplier details - Complete the asset details, making sure you include: Supplier name, for example the company that provides the software and Supplier website, so the research can find the right supplier and Product you use, as many suppliers offer several products with different security features
- Select Research Supplier - Select Research Supplier to start the AI-supported research.
- Wait for the research to complete. The research runs automatically.
When it finishes, four new fields are added to the asset in your asset register, each with a summary:
- Supplier Security Certifications
- SaaS Service Backup Offerings
- MFA Availability
- Data Breach History
Next steps
Compare the findings with how your business uses each product:
- MFA available? Check that MFA is switched on for all users of that product.
- No supplier backup? Consider whether you need your own backup of that data.
- Past data breaches or missing certifications? Review the supplier's risk and record any actions in your assessment.
Related help
Manage assets in Groups.
Learn how to create custom attributes for your assets.