Resources
Blog
Resource Library
December 13, 2024
A Day in the Life of a CISO: An Employee Email Discovered in a Password Dump
A Day in the Life of a CISO: An Employee Email Discovered in a Password Dump
December 13, 2024
Day in the Life of a CISO: Evaluating a Plugin Vendor
Day in the Life of a CISO: Evaluating a Plugin Vendor
December 12, 2024
How SecurityScorecard’s Supply Chain Detection and Response Protects Financial Institutions
As financial institutions continue to expand their digital ecosystems, the growing reliance on third-party vendors and service providers introduces significant cyber risks.
December 3, 2024
Grow Your MSP Practice with SecurityScorecard MAX
Transform vendor security into recurring revenue. SecurityScorecard MAX helps MSPs protect client supply chains with enterprise-grade tools, expert support, and automated risk management.
November 25, 2024
2025 Security Predictions: The Forces Reshaping Cybersecurity
What worked in 2024 may not protect you in 2025. Our experts outline what to expect and highlight hidden vulnerabilities to address to keep your company safe from attackers here.
Executive Viewpoint
Supply Chain Cyber Risk
Third-Party Risk Management
November 20, 2024
Scorecarder Spotlight: Fabio da Cruz Maciel
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Fabio da Cruz Maciel!
November 18, 2024
Vendor Risk Management: The Definitive Guide in 2025
Learn how effective vendor risk management protects your business from cybersecurity threats, compliance failures, and operational disruptions.
November 18, 2024
What Is Cyber Risk Management?
Learn what cyber risk management is and why it’s essential for protecting digital assets, reducing threats, and ensuring business resilience.
November 18, 2024
A Day in the Life of a CISO: Tackling a Major Vulnerability with Precision
A Day in the Life of a CISO: Tackling a Major Vulnerability with Precision
November 18, 2024
A Day in the Life of a CISO: Turning Data into Boardroom Confidence
A Day in the Life of a CISO: Turning Data into Boardroom Confidence
November 12, 2024
The Botnet is Back: SSC STRIKE Team Uncovers a Renewed Cyber Threat
Discover the resurgence of Volt Typhoon, a state-sponsored cyber-espionage group targeting the energy sector. Learn how they exploit legacy systems and outdated devices to embed themselves within critical infrastructure, posing a silent yet significant threat. Stay informed about the evolving tactics, global reach, and implications for national security.
STRIKE Team
November 7, 2024
What Is Port 445 (SMB)? Strategies for Secure Network Communication
Port 445 enables SMB traffic but is a prime target for ransomware and wormable exploits. Learn what it is, why it’s risky, and how to secure it.
Tech Center
November 7, 2024
Securing Port 139: Strategies to Prevent Unauthorized Access and Cyber Threats
Discover how to secure Port 139 against cyber threats with SMB protocol security, preventing unauthorized access and ensuring network safety.
Tech Center
October 29, 2024
Inside a North Korean Phishing Operation Targeting DevOps Employees
Uncover how SecurityScorecard thwarted a sophisticated phishing attack targeting our DevOps team. This blog details a North Korean state actor’s attempt to deploy a malicious backdoor through a fake job offer on social media. Learn about the evolving tactics of threat actors and how our swift response blocked potential damage. Stay informed and strengthen your defenses against these persistent cyber threats.
Nation State Actors
Phishing
STRIKE Team
October 29, 2024
The Job Offer That Wasn’t: How We Stopped an Espionage Plot
Discover how SecurityScorecard thwarted a sophisticated cyber-espionage plot disguised as a job offer. Learn about the ‘Contagious Interview’ campaign, the tactics used by the Famous Chollima group, and essential strategies to protect your organization from targeted attacks. Don’t let your next career move become a trap—stay informed and secure!
STRIKE Team
October 17, 2024
Healthcare IT Security and Compliance in 2024 and Beyond: A Comprehensive Guide
The healthcare industry remains a prime target for cyberattacks. As the industry navigates the digital landscape, ensuring cybersecurity compliance is paramount to protecting patient privacy and maintaining operational integrity.
Healthcare
Services
Tech Center
October 16, 2024
Complete Third-Party Risk Management (TPRM) Guide for 2026
Learn effective third-party risk management strategies for 2025 to protect your business from cyber threats, ensure compliance, and secure vendor networks.
Third-Party Risk Management
October 11, 2024
Scorecarder Spotlight: Segev Eliezer & David Mound
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Segev Eliezer & David Mound!
September 30, 2024
The Road Taken: Pathways to Better Compliance
Consider SecurityScorecard’s market-leading security solutions to secure your supply chain and help you in your compliance journey.
September 30, 2024
How the U.S. Department of Justice Can Improve Its Approach to Combat Ransomware Attacks
How nations can work with industry to identify meaningful metrics, standards, and KPIs to help governments improve their cybersecurity posture and build deeper supply chain resilience.
Public Sector
Supply Chain Cyber Risk
September 26, 2024
Women in Cyber 2024: Key Themes from AT&T’s Inaugural Conference
Earlier this week, SecurityScorecard had the pleasure of sponsoring AT&T’s inaugural Women in Cyber conference. From folks earlier on in their career to more seasoned professionals with 20+ years under their belt, there was a diverse group of 750+ attendees who were all interested in learning more about the cybersecurity space. We were fortunate to