
here's an overview of the typical implementation process for Panorays software:
• Initial Setup
This step is typically quick, as Panorays is a SaaS platform requiring no installation
• Vendor Onboarding
Can take up to 48 hours for newly imported vendors to be scanned and assessed
• Customization
Set up custom questionnaires and risk scoring criteria
• Integration
Set up single sign-on (SSO) if desired
• Training
Panorays offers training resources to facilitate this process
• Initial Assessments
This includes automated questionnaires and external attack surface scans
• Review and Remediation
Utilize the platform's collaboration tools for this process
• Continuous Monitoring Setup
Ensure real-time updates on vendors' security postures
The total implementation time can vary depending on the organization's size and complexity, but Panorays is generally known for its fast implementation. Most organizations can likely get the system up and running within a few weeks to a couple of months, with the bulk of the time spent on vendor onboarding and initial assessments.
Panorays can be customized to fit specific business needs. Here are several data points that demonstrate the platform's customization capabilities:
Customized Security Questionnaires: Panorays offers automated customized security questionnaires that include only the questions relevant for each supplier.
Flexible Pricing Packages: The platform provides flexible packages that allow businesses to build the right plan for their specific needs.
Tailored Risk Assessments: Panorays allows organizations to customize security standards and risk scoring criteria to match their specific requirements.
API Integration: The platform offers a JSON-based REST API that enables easy integration of Panorays elements into any modern application, allowing for customized workflows and data exchange.
Customizable Alerts: Users can configure alerts and ongoing monitoring parameters to suit their specific risk management needs.
Industry-Specific Compliance: Panorays supports various regulatory compliance standards (e.g., GDPR, CCPA, NYDFS), allowing businesses to tailor their assessments to their industry-specific requirements.
Vendor-Specific Assessments: The platform enables customization of risk assessments based on the specific nature of each vendor relationship.
Flexible Integrations: Panorays allows for integration with various third-party tools and systems, enabling businesses to customize their overall risk management ecosystem.
Webinars and Videos: Panorays provides a variety of webinars and videos that cover essential topics related to third-party security, compliance with regulations, vendor risk management, and more. These resources are designed to help users understand the fundamentals and advanced aspects of third-party risk management.
Security Awareness and Training: Panorays conducts information security awareness campaigns to ensure that employees are aligned with security practices and aware of their duties. This includes online and in-person sessions about new threats in the cybersecurity world, which can be beneficial for new users to stay updated on the latest security practices.
Partner Program: Panorays has a 360-Degree Partner Program that includes various tiers such as Standard, Advanced, and Premier. This program involves sales enablement, pre-sales enablement, creating joint go-to-market strategies, and regular collaboration through deal management, annual business plans, and quarterly business reviews (QBRs). This structured approach helps partners and new users integrate Panorays solutions effectively.
Training and Certifications: As part of their partner journey, Panorays offers training and certifications to ensure that users and partners are well-equipped to manage Panorays projects and understand how to work with Panorays Customer Success Managers (CSMs).
Panorays implements several security measures to protect data:
Real-Time Ratings: Assigns a unique Risk DNA to each third-party connection, allowing for continuous adaptation of security measures.
Continuous Detection: Detects the entire threat landscape and immediately alerts users of vulnerabilities and breaches.
Collaboration and Communication: Facilitates collaboration with third parties to respond to threats and keeps an audit of all communication.
Frequency of Updates: Panorays provides quarterly updates, as indicated by the release notes for Q1’24 and Q4’23. These updates introduce new features, enhancements, and improvements to the platform.
Content of Updates: Each update typically includes a range of enhancements such as improved remediation management, API improvements, customizable email templates, inventory management, and new features like Smart Validation and Supply Chain Discovery. These updates aim to streamline the third-party assessment process, improve visibility, accuracy, and in-platform communication.
Management of Updates: The updates are managed through a detailed release process. For example, the Q4’23 release introduced bulk task creation for remediation management, API improvements, and enhanced cyber news categorization. The Q1’24 release focused on AI features like Smart Validation, segmentation of third parties, and automatic reminders for remediation tasks.
Communication and Documentation: Panorays provides detailed release notes that document the changes, new features, and improvements included in each update. These notes help users understand the enhancements and how to leverage them effectively.
Data Ownership
Panorays' policy on data ownership is outlined in their terms of service and privacy policy documents. Here are the key points:
Ownership of Software and Services: The software provided by Panorays is licensed, not sold, to the user. Panorays retains all worldwide rights, title, and interest in and to the software and security rating services, including all intellectual property rights.
Responsibility for Data: Users are responsible for the backup of their security data. Panorays does not operate as an archive or file storage service, and users must implement their own backup plans and safeguards appropriate for their requirements.
Data Portability
Panorays' policy on data portability includes the following aspects:
Right to Data Portability: Users have the right to be provided with a copy of the information Panorays holds on them in a structured, machine-readable format. This allows users to transfer their data to another service or platform.
Data Transfers: Panorays engages in data transfers based on adequacy decisions by the European Commission or standard contractual clauses to ensure compliance with GDPR. Internal transfers within the Panorays group are covered by an intragroup agreement to maintain data protection standards.
Scalability of Infrastructure: Panorays leverages Google Kubernetes Engine (GKE) to provide a stable, scalable, and managed infrastructure. This allows Panorays to scale its services almost instantly, enabling the company to double its customer base and scale its infrastructure with minimal overheads.
Service-Based Architecture: The move to a service-based architecture running on GKE allows Panorays to automate much of the DevOps management, making it easy to adapt and change services as needed. This flexibility ensures that Panorays can scale its power and memory at great speed to meet the demands of its clients.
Dynamic Risk Assessments: Panorays' platform includes dynamic risk assessments that adapt to the changing Risk DNA of each third-party connection. This continuous adaptation allows organizations to scale their security measures in response to evolving threats and business needs.
Automated Third-Party Cyber Risk Management: The platform automates third-party questionnaires, compliance templates, and AI-powered validations, which can be scaled up or down based on the volume of third-party assessments required by the organization.
Contract Renewal
Renewal Process: Contract renewal refers to the process of extending or continuing a contractual agreement beyond its initial expiration date. This can involve certain amendments or modifications to the original terms. Renewal discussions should ideally begin well in advance of the contract expiration date to allow sufficient time for negotiations, amendments, and evaluation of alternative options if necessary. It is recommended to start the process at least three to six months prior to expiration.
Automatic Renewals: Some contracts may include provisions for automatic renewal. However, it is crucial to review the contract terms to avoid being locked into a contract that no longer meets the organization's needs.
Negotiation of Terms: During the renewal process, both parties have the opportunity to renegotiate the terms and conditions of their agreement. This includes aspects such as price, delivery timeframes, payment terms, performance requirements, and other contractual obligations. Renewal discussions provide an opportunity to address potential issues with the previous contract and renegotiate more favorable terms, such as payment and delivery terms, performance levels, and cost reductions.
Benefits of Renewal: Contract renewals help maintain continuity and stability within a business relationship, provide predictable revenue streams, and reduce the costs associated with acquiring new customers or vendors. Renewals also offer opportunities for upgrades and cross-selling, allowing organizations to introduce clients to newer features, additional services, or upgraded offerings.
Contract Cancellation
The agreement may be terminated by either party with written notice, subject to the terms outlined in the agreement.
Notice Period: For agreements with a term of one year or longer, a cancellation of the renewal must be received at least 30 days prior to the last day of the term. If the agreement is not canceled in time, it will automatically renew for another term equal to the length of the last term.
Effect of Termination: Upon termination, the customer must cease all access to and use of the software and security rating services. Certain sections of the agreement, such as those related to liability, indemnification, and proprietary rights, will survive termination.
ISO/IEC 27001:2022: Panorays has achieved certification for this international standard for information security management.
GDPR (General Data Protection Regulation): Panorays enables assessment of vendor compliance with GDPR requirements.
CCPA (California Consumer Privacy Act): The platform supports compliance assessment for CCPA.
NYDFS (New York Department of Financial Services) Cybersecurity Regulation: Panorays helps organizations assess vendor compliance with this regulation.
Industry-specific regulations: Panorays allows for assessment of vendor compliance with various industry-specific regulations and standards, though specific examples are not provided in the search results.