*Please note: The details in this article are not currently on in product and are only on for specific customers participating in our beta release.
The Build Portfolio is your main page to add companies to your portfolio, request data on companies, and add company contacts to a company in your portfolio. If a company doesn't exist in our exchange, you can create a new company and request data on it. The Build Portfolio page can be reached by either using the "Add Company+" button atop the Portfolio Management Table or the "Request Data" button in the "Access" column.
The Build Portfolio Page has four sections:
Company information is necessary to create an appropriate profile for the company. The fields necessary include:
- Company Name
- Alternate Name
- Zip Code
If you are requesting data on a registered company, a contact will not be required. This registered contact will appear on the page and will receive all request communications. You will not be able to edit or delete these contacts.
If you are requesting data on a company that is not registered, a company contact will be required to add. You will have the ability to add multiple contacts, but please note that the first contact added will be the one to receive all updates on the request. The necessary information for recipients includes:
- First Name
- Last Name
- Email Address
- Phone Number
If you no longer need a contact you added to appear under the Add Recipient section, you will have the ability to delete them from the list. Please note, we do not have functionality to edit contacts yet. We advise that if you want to edit a contact, on your added recipients list, you should delete the contact and re-add them with the correct information.
If a company has a completed assessment on the CyberGRX Exchange, the third party's Account Administrator or Assessment Owner must first authorize your request to access. You can begin this process by selecting the existing assessment and submitting your request via the "confirm" button. You can view the status of the request in the "Access" column of the Portfolio Management Table, and it will read "requested," "approved," or "denied."
If a company does not have a completed assessment on the CyberGRX Exchange, you can select any of the following assessments and submit a request:
- Tier 1 Assessment with Validation - Intended for highest-risk parties only. Extensive and validated examination of a cyber risk program at the control level via strength, coverage, and timeliness data.
- Tier 2 Assessment with Validation - Intended for high to medium-risk third parties. Robust and validated examination of a cyber risk program's implementation and management.
- Tier 2 Assessment - Intended for medium to low-risk third parties. Robust examination of how a cyber risk program is implemented and managed.
Once the assessment is selected and submitted via the "confirm" button, you can return to the Portfolio Management Table and track the request status in the "Data" column. If a third party hasn’t begun the assessment, the status will read “Not Started,” with the hover-over providing details on the type of assessment requested and the requested date. If the assessment is underway, the status will read “In Progress,” with the hover-over detailing the type of assessment requested, the requested date, and the percentage of the assessment completed. When the third party has completed the assessment, the status will read “Completed.”
Once all information is added and necessary items selected, press "confirm" to send the request for data to the recipient(s).