Resources

Blog

Resource Library

Clear filters

New Hire Spotlight: Riché Zamor

August 31, 2026

New Hire Spotlight: Riché Zamor
Riché Zamor, VP, Product Operations & AI Innovation, shares his first impressions of working at SecurityScorecard, what drew him to the company and what he’s most excited to build with the team.
Scorecarder Spotlight
What Is IP Reputation and How to Protect It?

August 24, 2026

What Is IP Reputation and How to Protect It?
Learn what IP reputation is, how it impacts your business, and how continuous monitoring protects your organization and vendor ecosystem from threats.
What Is Endpoint Security and Why Does It Matter?

August 24, 2026

What Is Endpoint Security and Why Does It Matter?
Learn what endpoint security is, why it matters for your organization, and how to protect every device on your network from modern cyber threats.
Scorecarder Spotlight: Emmy Chau

August 10, 2026

Scorecarder Spotlight: Emmy Chau
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.   Name: Emmy Chau Role: Senior Manager, FP&A “One of the things I appreciate most about SecurityScorecard is the opportunity to keep learning. Whether it’s partnering with teams across
Scorecarder Spotlight
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

August 5, 2026

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains

August 3, 2026

Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

July 9, 2026

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
The World Cup Has 48 Teams. Adversaries Are Playing Too.

June 15, 2026

The World Cup Has 48 Teams. Adversaries Are Playing Too.
During the 2020 Tokyo Olympics, held in 2021 after a pandemic-forced delay,  NTT Corporation recorded approximately 450 million cyberattack attempts targeting Olympic systems. The 2022 FIFA World Cup in Qatar drew similar attention from state-aligned threat actors and opportunistic criminals. The 2026 tournament, spanning three nations, 16 cities, and several million projected visitors, will be
Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline

May 15, 2026

Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline
Data quality is foundational to customer confidence. At SecurityScorecard, our Scoring platform processes data for thousands of companies daily. That scale requires more than strong engineering discipline. It requires clear validation patterns, consistent checks, and observable results across every critical stage of the pipeline. This post shares how our data engineering team uses Great Expectations,
Supply Chain Security Needs Real-Time Visibility

May 11, 2026

Supply Chain Security Needs Real-Time Visibility
Learn why supply chain security demands real-time visibility and explore 7 best practices to protect your organization from third-party cyber threats.
Building a Vendor Compliance Dashboard for Auditors

May 11, 2026

Building a Vendor Compliance Dashboard for Auditors
Build a compliance dashboard auditors actually trust. Learn how real-time vendor monitoring beats outdated quarterly assessments.
The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)

May 11, 2026

The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)
The questionnaire is the workhorse of third-party risk management. But not all questionnaires are the same and treating them like they are is one of the reasons TPRM programs fall behind. Here’s a clear-eyed look at the four types your team is juggling. 1. Initial / Intake Questionnaires Also called: Inherent Risk Questionnaire (IRQ), Vendor
Cybersecurity Questionnaire in the Age of AI

May 4, 2026

Cybersecurity Questionnaire in the Age of AI
AI is reshaping the cybersecurity questionnaire. Learn how to combine faster assessments with continuous monitoring for real-time vendor visibility.
Cyber Risk Quantification Models

May 4, 2026

Cyber Risk Quantification Models
Learn how cyber risk quantification models help organizations express security risks in financial terms. Compare FAIR, NIST, and ISO frameworks.
Amanda Smith Earns Spot on the 2026 Women of the Channel List, Showcasing SecurityScorecard’s Channel Leadership

May 4, 2026

Amanda Smith Earns Spot on the 2026 Women of the Channel List, Showcasing SecurityScorecard’s Channel Leadership
NEW YORK– May 4, 2026— SecurityScorecard, the global leader in threat-informed third-party risk management (TPRM), today announced that CRN®, a brand of The Channel Company, has recognized Amanda Smith, Director of Public Sector Channel at SecurityScorecard, on the prestigious Women of the Channel list for 2026. This annual CRN list celebrates women from vendors, distributors,
SecurityScorecard Partners with Louisiana Lieutenant Governor and Department of Culture, Recreation & Tourism to Strengthen Cyber Resilience Across Key State Agencies

April 29, 2026

SecurityScorecard Partners with Louisiana Lieutenant Governor and Department of Culture, Recreation & Tourism to Strengthen Cyber Resilience Across Key State Agencies
SecurityScorecard deploys TITAN AI to safeguard Louisiana tourism, culture, libraries, and state assets against growing supply chain risk NEW YORK– April 30, 2026—SecurityScorecard, the global leader in threat-informed third-party risk management (TPRM), today announced a partnership with Louisiana Lieutenant Governor Billy Nungesser and the Department of Culture, Recreation & Tourism to help strengthen cyber protection
What Security Teams Need to Know Now About Anthropic’s Mythos

April 29, 2026

What Security Teams Need to Know Now About Anthropic’s Mythos
SecurityScorecard CEO and Co-Founder Dr. Aleksandr Yampolskiy joined Yuka Royer on France 24 to discuss Anthropic’s Mythos model, noting that AI has compressed the time to respond to cyber threats, accelerated exploitation timelines, and made automation and collaboration essential for defense. For defenders, the issue is not just more powerful AI. It is how that power
What Security Teams Need to Know Now About Anthropic’s Mythos and AI-Driven Cyber Risk

April 29, 2026

What Security Teams Need to Know Now About Anthropic’s Mythos and AI-Driven Cyber Risk
Mythos Doesn’t Change Cyber Risk. It Removes Your Time to React. Anthropic’s Mythos reinforces a reality security teams have recognized for years: cyber risk is accelerating, and the time to respond continues to shrink. The reported discovery of a 27-year-old OpenBSD vulnerability should prompt careful consideration. It does not demonstrate that AI can identify every
Identify Shadow IT Risk with Automatic Detection

April 27, 2026

Identify Shadow IT Risk with Automatic Detection
Learn how automatic detection uncovers shadow IT risk hiding in your organization. Gain real-time visibility into unauthorized tools before they become threats.
Why SMBs Need Continuous Vendor Risk Monitoring

April 27, 2026

Why SMBs Need Continuous Vendor Risk Monitoring
Annual vendor audits leave SMBs vulnerable. Learn why continuous monitoring catches threats before they become breaches.
Rethinking the Questionnaire: Why Better Tech and More People Won’t Clear Your TPRM Backlog

April 21, 2026

Rethinking the Questionnaire: Why Better Tech and More People Won’t Clear Your TPRM Backlog
Assessment backlogs are a common challenge for Third-Party Risk Management (TPRM) programs. Most organizations tackle the problem by increasing their capacity through hiring or improving efficiency with technology. While both are important elements of the solution, organizations also need to implement the right process for prioritizing the necessary business outcomes. This is especially true for
MAX