Black Kite
Third-party cyber risk rating platform (formerly NormShield) providing continuous, automated vendor risk assessment across technical, financial, and compliance dimensions.
Visit Website ↗ + Add to CompareOverview
Black Kite, rebranded from NormShield in 2020, provides a third-party cyber risk rating platform that continuously and automatically evaluates vendor risk from technical, financial, and compliance perspectives, helping organizations determine which suppliers and partners pose the greatest risk to their business. Rather than relying on periodic vendor security questionnaires alone, the platform pulls in externally observable technical signals alongside financial health indicators to give a more complete, ongoing risk picture across an organization’s supply chain.
Founded in 2016 (as NormShield) and based in Boston, Massachusetts, Black Kite has raised $36 million in total funding, including a $22 million Series B led by Volition Capital in 2021 with participation from Moore Strategic Ventures, Glasswing Ventures, and Data Point Capital. The platform is reviewed on Gartner Peer Insights and competes directly with several other established third-party/vendor cyber risk rating providers, making its financial-risk-quantification angle a meaningful but not category-defining differentiator.
Innovation Matrix Assessment
Has iterated from its NormShield-era product into a broader financial/technical/compliance risk rating platform since its 2020 rebrand.
Gives risk and vendor management teams continuous, automated visibility into third-party cyber risk without relying solely on periodic questionnaires.
$36M total funding including a $22M Series B led by Volition Capital reflects solid, established investor confidence.
Third-party/vendor cyber risk rating is a mature, competitive category; Black Kite's financial-risk quantification angle differentiates it modestly rather than fundamentally.
Reviewed on Gartner Peer Insights with real enterprise vendor-risk-program usage, though no independent efficacy studies specific to breach prevention were found.
Third-party and supply chain risk remains a growing, durable concern as organizations increasingly depend on complex vendor ecosystems.
Why CISOs Should Care
Gives vendor risk management teams continuous, automated third-party risk visibility across technical, financial, and compliance dimensions, reducing reliance on static questionnaires.
What Makes It Different
Combines externally observable technical risk signals with financial health quantification in a single rating, rather than a purely technical security rating.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
An established, well-funded third-party risk rating vendor; Incremental Innovator in a mature, competitive category.
Editorial Note: Claims vs. Verified Findings
Funding figures and rebrand history are corroborated by SecurityWeek and PR Newswire; specific rating-accuracy claims were not independently verified.
Sources
Alternatives to Black Kite
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…