Resources

Blog

Resource Library

Clear filters

What Is PII? How to Protect Personally Identifiable Information in 2025

May 8, 2025

What Is PII? How to Protect Personally Identifiable Information in 2025
Personally identifiable information (PII) remains a prime target for threat actors. Learn what qualifies as PII in 2025—and how to defend it.\r\n
Guide to Developing a Business Continuity Plan

May 8, 2025

Guide to Developing a Business Continuity Plan
Explore business continuity in cybersecurity. Learn how a continuity plan helps assess threats, reduce risk, and protect operations from attacks.
Safeguarding Against Subdomain Takeover

May 8, 2025

Safeguarding Against Subdomain Takeover
Learn what subdomain takeover is and how to prevent it with best practices and continuous monitoring.
What Is a Cyber Threat? What Risk Leaders Need to Know

May 7, 2025

What Is a Cyber Threat? What Risk Leaders Need to Know
Learn what cyber threats are, how they work, and why recognizing them is essential to reducing organizational risk.\r\n
Assembling the Dream Team: Building a High-Performing Supply Chain Incident Response Team

May 6, 2025

Assembling the Dream Team: Building a High-Performing Supply Chain Incident Response Team
This article explores the key elements of building a high-performing supply chain incident response team to effectively mitigate and respond to these threats.
Threat-Informed TPRM
Scorecarder Spotlight: Chandra Sekhar Betha

May 5, 2025

Scorecarder Spotlight: Chandra Sekhar Betha
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.
Scorecarder Spotlight
How Do You Back Up Business-Critical Data?

May 2, 2025

How Do You Back Up Business-Critical Data?
Building a Reliable Backup Strategy Against Cyberattacks and Disruptions Using Best Practices for Cyber Resilience
Enterprise Cyber Risk
MAX
Third-Party Risk Management
What Do You Do If Your Password Appears in a Data Leak?

May 1, 2025

What Do You Do If Your Password Appears in a Data Leak?
7 Steps to Secure Your Digital Life After a Password Breach
Enterprise Cyber Risk
GRC
Phishing
What Is a Proxy Server? Understanding Security Risks and Corporate Use Cases

April 30, 2025

What Is a Proxy Server? Understanding Security Risks and Corporate Use Cases
How Proxy Servers Work and Why They Matter in Enterprise Security
Third-Party Risk Management
Threat-Informed TPRM
Fines, Jail Time, and Criminal Charges for DDoS Attacks

April 29, 2025

Fines, Jail Time, and Criminal Charges for DDoS Attacks
Fines, Are DDoS Attacks Illegal? Find out the laws and penalties in this blog.
Security Ratings
Supply Chain Cyber Risk
Third-Party Risk Management
5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk

April 24, 2025

5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk
Explore the impact of the Optus data breach and why CISOs must rethink third-party and telecom security in today’s interconnected threat landscape.
Enterprise Cyber Risk
GRC
Third-Party Risk Management
2025 Top 20 Must Read Resources to Stay Updated on Cybersecurity Threats and Trends

April 23, 2025

2025 Top 20 Must Read Resources to Stay Updated on Cybersecurity Threats and Trends
Cut through the noise with expert-trusted cybersecurity resources designed to inform, protect, and empower enterprise security leaders.
Cyber Threat Intelligence
GRC
Third-Party Risk Management
SOX Compliance Checklist: What Security Teams Need to Know in 2025

April 22, 2025

SOX Compliance Checklist: What Security Teams Need to Know in 2025
Explore our 2025 SOX compliance checklist for cybersecurity leaders. Learn key requirements, reporting timelines, and how to secure third-party risk.
Enterprise Cyber Risk
GRC
Third-Party Risk Management
How Much Do Healthcare Data Breaches Really Cost?

April 16, 2025

How Much Do Healthcare Data Breaches Really Cost?
Learn from the most devastating healthcare data breaches in U.S. history—and how to protect your organization’s PHI, PII, and patient trust.
Cyber Threat Intelligence
Enterprise Cyber Risk
Third-Party Risk Management
Cybersecurity Laws in the UK: What Businesses Need to Know in 2025

April 15, 2025

Cybersecurity Laws in the UK: What Businesses Need to Know in 2025
Understand how evolving UK regulations shape your cyber strategy—and how to stay compliant and resilient across your digital ecosystem.
Compliance
Cybersecurity
Enterprise Cyber Risk
CISOs: The Perfect SCORE With Your Board

April 11, 2025

CISOs: The Perfect SCORE With Your Board
Boards don’t operate in threat models and tech stacks. They operate in risk, revenue, and accountability. And if you want their support, you need to meet them there. SecurityScorecard created the SCORE framework to help CISOs turn cybersecurity into a board-level conversation that gets results.
Executive Viewpoint
SIM Card Hacking: What It Is, How It Works, and How to Protect Yourself

April 11, 2025

SIM Card Hacking: What It Is, How It Works, and How to Protect Yourself
SIM cards might seem like harmless pieces of plastic, but they’re often a gateway for serious cyber attacks. When hackers take over your mobile number, they can intercept private data, bypass security controls, and even drain your bank account.\r\n
Cyber Threat Intelligence
Enterprise Cyber Risk
Government
Scorecarder Spotlight: Noor Al-Baker

April 9, 2025

Scorecarder Spotlight: Noor Al-Baker
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Noor Al-Baker!
Scorecarder Spotlight
SecurityScorecard In The News Q1 2025

April 2, 2025

SecurityScorecard In The News Q1 2025
Catch up on SecurityScorecard press coverage from Q1 2025, including TV interviews, global report-driven media coverage, North America, EMEA, and APAC press mentions, and executive bylines examining third-party breach trends, software supply chain attacks, nation-state cyber activity, and regulatory readiness.
What is Supply Chain Detection and Response (SCDR)?

March 21, 2025

What is Supply Chain Detection and Response (SCDR)?
Supply Chain Detection and Response (SCDR) is a new cybersecurity framework that identifies, prioritizes, and remediates vulnerabilities across an organization’s vendor ecosystem. Its purpose is preventing supply chain attacks from threat actors and mitigating concentration risk when critical providers experience outages or security failures.
Threat-Informed TPRM
Automating Vendor Risk Management and Assessments

March 18, 2025

Automating Vendor Risk Management and Assessments
Automated vendor risk assessments provide visibility into third-party vendors’ cybersecurity and enhance the third-party risk management process. Learn more.