Resources

Blog

Resource Library

Clear filters

New Hire Spotlight: Riché Zamor

August 31, 2026

New Hire Spotlight: Riché Zamor
Riché Zamor, VP, Product Operations & AI Innovation, shares his first impressions of working at SecurityScorecard, what drew him to the company and what he’s most excited to build with the team.
Scorecarder Spotlight
What Is IP Reputation and How to Protect It?

August 24, 2026

What Is IP Reputation and How to Protect It?
Learn what IP reputation is, how it impacts your business, and how continuous monitoring protects your organization and vendor ecosystem from threats.
What Is Endpoint Security and Why Does It Matter?

August 24, 2026

What Is Endpoint Security and Why Does It Matter?
Learn what endpoint security is, why it matters for your organization, and how to protect every device on your network from modern cyber threats.
What Is Internet Intelligence?

August 22, 2026

What Is Internet Intelligence?
Internet intelligence turns raw web data into a real-time view of your exposure and third-party risk. Learn what it is and how it works.
How Ransomware 3.0 Changes Your Risk Exposure

August 17, 2026

How Ransomware 3.0 Changes Your Risk Exposure
Ransomware 3.0 runs autonomously on AI. See how security teams can harden defenses, monitor third parties, and stay ahead of this new threat.
What Is Continuous Threat Exposure Management (CTEM)?

August 14, 2026

What Is Continuous Threat Exposure Management (CTEM)?
Continuous threat exposure management (CTEM) is a five-stage Gartner framework to find, validate, and prioritize the exposures attackers can exploit.
What Are DORA Compliance Requirements

August 10, 2026

What Are DORA Compliance Requirements
Learn what DORA compliance requirements mean for financial entities, from ICT risk management and incident reporting to third-party oversight.
Scorecarder Spotlight: Emmy Chau

August 10, 2026

Scorecarder Spotlight: Emmy Chau
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.   Name: Emmy Chau Role: Senior Manager, FP&A “One of the things I appreciate most about SecurityScorecard is the opportunity to keep learning. Whether it’s partnering with teams across
Scorecarder Spotlight
What Is Internet-Wide Scanning, and How Attackers Use It

August 7, 2026

What Is Internet-Wide Scanning, and How Attackers Use It
Internet-wide scanning lets attackers find exposed hosts fast. See how it works and how to spot your exposure before they do.
How SOC Automation Improves Threat Response

August 7, 2026

How SOC Automation Improves Threat Response
SOC automation helps security teams respond faster, cut false positives, and scale operations. Learn the top use cases, benefits, and challenges.
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

August 5, 2026

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
How to Manage AI Vendor Risk

August 3, 2026

How to Manage AI Vendor Risk
Manage AI vendor risk with a framework for vetting AI capabilities, auditing data flows, and bringing AI tools into continuous monitoring.
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains

August 3, 2026

Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.
How to Identify a Critical Vendor

July 27, 2026

How to Identify a Critical Vendor
Identifying a critical vendor is a CISO’s discipline. Learn how to build a defensible list, run a bankruptcy stress test, and monitor continuously.
How to Secure Your SaaS Supply Chain

July 20, 2026

How to Secure Your SaaS Supply Chain
Most SaaS supply chain attacks start at a forgotten vendor. Learn how to map, monitor, and secure every third-party app touching your data.
What Is Cybersecurity M&A and Why It Matters

July 13, 2026

What Is Cybersecurity M&A and Why It Matters
Cybersecurity M&A turns every deal into a cyber risk question. See what cybersecurity M&A is, why it matters, and the role of cyber due diligence.
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

July 9, 2026

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
What Is the Third-Party Risk Management Maturity Model

July 6, 2026

What Is the Third-Party Risk Management Maturity Model
The third-party risk management maturity model turns vague TPRM goals into measurable stages. See the levels and how to move yours forward.
How to Secure Your CI/CD Pipeline

June 29, 2026

How to Secure Your CI/CD Pipeline
Your CI/CD pipeline can ship a breach as fast as a feature. Learn the CI/CD pipeline security threats, controls, and practices that close the gap.
How Open Source Risk Threatens Your Vendors

June 22, 2026

How Open Source Risk Threatens Your Vendors
Open source risk follows every vendor into your supply chain. See where it hides, how attackers exploit it, and what continuous monitoring solves.
How State-Sponsored Cyber Attacks Use Third Parties

June 22, 2026

How State-Sponsored Cyber Attacks Use Third Parties
State-sponsored cyber attacks increasingly target vendors to reach high-value organizations. Learn how nation-state actors exploit third parties and how to defend.