Resources

Blog

Resource Library

Clear filters

Harmonizing Government, Policy, and Technology: Thoughts from Jeff Le, SecurityScorecard’s new VP of Global Government Affairs & Public Policy

June 10, 2024

Harmonizing Government, Policy, and Technology: Thoughts from Jeff Le, SecurityScorecard’s new VP of Global Government Affairs & Public Policy
For the past twenty years, I have had the pleasure of working at the intersection of public service, technology, and global security. As Deputy Cabinet Secretary to former California Governor Jerry Brown, I responded directly to the technology challenges that the state government faced to protect constituent data, deliver key services and resources to its residents, and recover from emergencies and disasters.\r\n
Executive Viewpoint
The Need for Speed: “Material” Confusion under the SEC’s Cyber Rules

May 23, 2024

The Need for Speed: “Material” Confusion under the SEC’s Cyber Rules
This week, the SEC issued a statement addressing some of the rampant confusion and inconsistencies observed under the agency’s new cyber breach disclosure rule.
Public Sector
EPA Alert Warns Nation’s Drinking Water at Risk: SecurityScorecard’s recommendations for securing critical infrastructure

May 21, 2024

EPA Alert Warns Nation’s Drinking Water at Risk: SecurityScorecard’s recommendations for securing critical infrastructure
the U.S. Environmental Protection Agency (EPA) warned that cyberattacks against water utilities across the country are becoming more frequent and more severe.
SecurityScorecard Named a Leader in the Forrester Wave for Cybersecurity Risk Ratings

May 20, 2024

SecurityScorecard Named a Leader in the Forrester Wave for Cybersecurity Risk Ratings
Today, we’re proud to announce that Forrester has named SecurityScorecard a Leader in The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2024.
National Vulnerability Database (NVD) leaves thousands of vulnerabilities without analysis data

May 16, 2024

National Vulnerability Database (NVD) leaves thousands of vulnerabilities without analysis data
The Common Vulnerabilities and Exposures (CVE) List and National Vulnerability Database (NVD) can no longer be considered a single central source of vulnerability truth\r\n
Compliance, collaboration, and communication: The benefits of NIST CSF 2.0

May 15, 2024

Compliance, collaboration, and communication: The benefits of NIST CSF 2.0
The new NIST CSF 2.0 empowers cybersecurity leaders to proactively address evolving threats and safeguard their organization’s assets, operations, and reputation.
Public Sector
What is Security Information and Event Management (SIEM)?

May 15, 2024

What is Security Information and Event Management (SIEM)?
Security Information and Event Management (SIEM) has emerged as a critical component of modern cybersecurity strategies. This blog post delves into what SIEM is, its core functionalities, benefits, and why it’s essential for organizations of all sizes.\r\n
Tech Center
Cybersecurity leadership in an era of public-private partnerships

May 14, 2024

Cybersecurity leadership in an era of public-private partnerships
Learn about the shared responsibility between public and private organizations in combating cyber threats.
Public Sector
RSA 2024: The Art of Possible

May 13, 2024

RSA 2024: The Art of Possible
Get a recap of SecurityScorecard’s trip to RSA 2024!
SecurityScorecard and Intel: Digging Past the Surface for Enhanced Protection

May 13, 2024

SecurityScorecard and Intel: Digging Past the Surface for Enhanced Protection
Explore how SecurityScorecard and Intel can jointly help organizations improve their security posture and controls.
Using Metrics that Matter to Protect Critical Infrastructure

May 10, 2024

Using Metrics that Matter to Protect Critical Infrastructure
Critical infrastructure owners and operators face significant challenges with technology, staff resources, and expertise to better manage cyber resilience.
Public Sector
Security Ratings
Examining the Concentration of Cyber Risk: How supply chains and global economies can adapt

May 2, 2024

Examining the Concentration of Cyber Risk: How supply chains and global economies can adapt
This research points to an extreme concentration of cyber risk in just 15 vendors worldwide, while also detailing a surge in adversaries exploiting third-party vulnerabilities.
Third-Party Risk Management
Insights from the Experts: Legal, Compliance, and Security Perspectives on SEC Regulations

April 26, 2024

Insights from the Experts: Legal, Compliance, and Security Perspectives on SEC Regulations
SecurityScorecard recently hosted a webinar discussing the implications of the new rules and how compliance, security, and legal experts can elevate their game to meet these new regulations.
Public Sector
Streamlining Your Vulnerability Management Process

April 18, 2024

Streamlining Your Vulnerability Management Process
Use this step-by-step guide to streamline your vulnerability management process and maintain a robust cybersecurity posture.
Attack Surface Management
Optimizing Rsync Port Configurations for Enhanced Performance and Security

April 18, 2024

Optimizing Rsync Port Configurations for Enhanced Performance and Security
Explore the nuances of optimizing Rsync port configurations for an optimal balance between performance and security.\r\n
Tech Center
Cyberattack at Sisense Puts Critical Infrastructure on Alert

April 11, 2024

Cyberattack at Sisense Puts Critical Infrastructure on Alert
SecurityScorecard details the large-scale cyberattack on Sisense, a major business analytics software company used by both the private and public sectors.
Public Sector
Change Healthcare Ransomware Attack Spotlights Single Point of Failure with Third-Party Vendor

April 10, 2024

Change Healthcare Ransomware Attack Spotlights Single Point of Failure with Third-Party Vendor
The ongoing cyberattack on Change Healthcare, a major player in medical claims processing in the United States, had profound repercussions across the healthcare sector.
Healthcare
Third-Party Risk Management
How SecurityScorecard STRIKE Identifies Zero Days in the Wild

April 9, 2024

How SecurityScorecard STRIKE Identifies Zero Days in the Wild
Discover how SecurityScorecard’s Zero-Day-as-a-Service (ZDaaS) identifies new and emerging zero-day threats across your third-party vendor landscape.
Cyber Threat Intelligence
SecurityScorecard Unveils the Industry’s Most Predictive Cybersecurity Risk Ratings with Refined Scoring Algorithm

April 9, 2024

SecurityScorecard Unveils the Industry’s Most Predictive Cybersecurity Risk Ratings with Refined Scoring Algorithm
As businesses strive to reinforce their defenses against these evolving threats, the need for a reliable and predictive cybersecurity risk assessment tool has never been greater.
Security Ratings
Examining NIST CSF 2.0: Everything you need to know

April 4, 2024

Examining NIST CSF 2.0: Everything you need to know
In 2014, the National Institute of Standards and Technology (NIST) released its Cybersecurity Framework (CSF) to help organizations better understand, reduce, and communicate cybersecurity risk. Ten years later, NIST has released Version 2.0.
Executive Viewpoint
The Cybersecurity of the S&P 500: An in-depth analysis from SecurityScorecard

April 3, 2024

The Cybersecurity of the S&P 500: An in-depth analysis from SecurityScorecard
With the Securities and Exchange Commission’s (SEC) mandate to disclose cybersecurity incidents, SecurityScorecard released the 2024 SecurityScorecard S&P 500 Cyber Threat Report.
Security Ratings
Supply Chain Cyber Risk