Skip to content

Black Kite

Third-party cyber risk rating platform (formerly NormShield) providing continuous, automated vendor risk assessment across technical, financial, and compliance dimensions.

Visit Website ↗ + Add to Compare
62/100Incremental Innovator

Overview

Black Kite, rebranded from NormShield in 2020, provides a third-party cyber risk rating platform that continuously and automatically evaluates vendor risk from technical, financial, and compliance perspectives, helping organizations determine which suppliers and partners pose the greatest risk to their business. Rather than relying on periodic vendor security questionnaires alone, the platform pulls in externally observable technical signals alongside financial health indicators to give a more complete, ongoing risk picture across an organization’s supply chain.

Founded in 2016 (as NormShield) and based in Boston, Massachusetts, Black Kite has raised $36 million in total funding, including a $22 million Series B led by Volition Capital in 2021 with participation from Moore Strategic Ventures, Glasswing Ventures, and Data Point Capital. The platform is reviewed on Gartner Peer Insights and competes directly with several other established third-party/vendor cyber risk rating providers, making its financial-risk-quantification angle a meaningful but not category-defining differentiator.

Innovation Matrix Assessment

Innovation Velocity 6/10

Has iterated from its NormShield-era product into a broader financial/technical/compliance risk rating platform since its 2020 rebrand.

Operational Value 7/10

Gives risk and vendor management teams continuous, automated visibility into third-party cyber risk without relying solely on periodic questionnaires.

Market Momentum 6/10

$36M total funding including a $22M Series B led by Volition Capital reflects solid, established investor confidence.

Category Disruption 5/10

Third-party/vendor cyber risk rating is a mature, competitive category; Black Kite's financial-risk quantification angle differentiates it modestly rather than fundamentally.

Real-World Efficacy 6/10

Reviewed on Gartner Peer Insights with real enterprise vendor-risk-program usage, though no independent efficacy studies specific to breach prevention were found.

Enduring Relevance 7/10

Third-party and supply chain risk remains a growing, durable concern as organizations increasingly depend on complex vendor ecosystems.

Why CISOs Should Care

Gives vendor risk management teams continuous, automated third-party risk visibility across technical, financial, and compliance dimensions, reducing reliance on static questionnaires.

What Makes It Different

Combines externally observable technical risk signals with financial health quantification in a single rating, rather than a purely technical security rating.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

An established, well-funded third-party risk rating vendor; Incremental Innovator in a mature, competitive category.

Editorial Note: Claims vs. Verified Findings

Funding figures and rebrand history are corroborated by SecurityWeek and PR Newswire; specific rating-accuracy claims were not independently verified.

Sources