Resources
Blog
Resource Library
January 11, 2024
Threat Intelligence Research: Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has been investigating covert infrastructure linked to Volt Typhoon, a state-sponsored threat actor group believed to act on behalf of the People’s Republic of China. The group conducts multiple types of cyberattacks, but its use of compromised small office and home office (SOHO) equipment such as routers and firewalls is a recurring theme.
Cyber Threat Intelligence
January 10, 2024
Vendor Risk Management vs Third Party Risk Management vs Enterprise Risk Management: What’s the Difference?
Third-Party, Vendor, and Enterprise Risk Management are often used interchangeably, but they are not always the same. Learn which is right for your business.
Tech Center
January 10, 2024
7 Incident Response Metrics and How to Use Them
A robust incident response plan provides quantitative data. Check out these seven incident response metrics and how to use them.
Tech Center
January 10, 2024
SecurityScorecard 10 Risk Factors Explained
Trust begins with transparency. Check out SecurityScorecard’s ten risk factors, which are explained in an easy-to-understand manner that enables business and IT leaders to create meaningful conversations around cybersecurity risk and compliance.
Tech Center
January 9, 2024
Introducing Security Ratings for Telecommunications, Internet Service Providers, and Cloud Providers: Collaborating on enhancements with industry leaders
Telecommunications, Internet Service Providers, and Cloud Providers are some of the most critical sectors on the planet. But they are also prime targets for nation-state attacks and other threat actor groups. And their reliance on vast networks of third-party vendors, partners, and service providers creates a need for a comprehensive cybersecurity approach tailored specifically to the sector.
Security Ratings
January 8, 2024
8 Types of Vendor Risks That Are Important to Monitor in 2025
Discover how to manage vendor risk by understanding and monitoring various threats, ensuring your business stays secure from third-party vulnerabilities.
Tech Center
January 5, 2024
What Is Cybersecurity Risk and How Do You Manage It in 2025?
Explore what cybersecurity risk means in 2025 and how organizations can effectively assess, mitigate, and monitor cyber threats across their digital and third-party ecosystems
Tech Center
January 5, 2024
2025 Third-Party Vendor Risk Management in the Financial Industry
With an established third-party risk management program, financial organizations are better able to identify and address vendor cyber risk. Learn more.
Tech Center
January 5, 2024
What is Cyber Attack Insurance? Best Practices for Protection
Cyber attack insurance is increasingly essential to protect your organization from cyber threats and their consequences. Learn more.
Cyber Insurance
Executive Viewpoint
Tech Center
January 4, 2024
The Most Important Security Metrics to Maintain Compliance: Best Practices for Prioritizing Cyber Resilience
Security metrics are a great way to ensure your organization is meeting industry standards. Here are a few key performance indicators to track for maintaining compliance.
Security Ratings
Tech Center
January 3, 2024
What is a Cybersecurity Assessment?
A cybersecurity assessment helps security teams determine whether or not an organization is properly prepared to protect its assets against a range of threats. Learn more.
Tech Center
January 2, 2024
20 Cybersecurity Metrics & KPIs to Track in 2025
Explore the top cybersecurity metrics for 2025. Learn how to measure risk, performance, and vendor exposure across your organization and supply chain.\r\n
Security Ratings
Tech Center
January 2, 2024
How to Perform A Cybersecurity Risk Analysis in 2024
Identify, manage, and safeguard data, and assets that could be vulnerable to a cyberattack. Learn how to perform a cyber security risk analysis.
Tech Center
December 23, 2023
In-Depth Review: How SecurityScorecard Stacks Up Against UpGuard in 2024
In the dynamic world of cybersecurity, choosing the right platform can be pivotal for an organization’s digital safety. As we delve into 2024, two major players, SecurityScorecard and UpGuard, continue to make waves. This in-depth review compares these two companies and highlights how SecurityScorecard’s offerings often outshine those of UpGuard. SecurityScorecard: User-friendly and comprehensive User experience and accessibility: SecurityScorecard
Security Ratings
December 19, 2023
Applying the Churchill Knowledge Audit to Cybersecurity: The Importance of Security Ratings
As a CISO, I am frequently pitched by companies promising to transform or revolutionize my job. I shrug off most pitches because they don’t add any value to what I’m doing. But every once in a while, an organization comes along that offers something new.
Executive Viewpoint
December 14, 2023
Optimizing Incident Response with Advanced Threat Intelligence
Here’s how modern threat intelligence tools can refine and improve an organization’s incident response strategies.
Cyber Threat Intelligence
Tech Center
December 7, 2023
2025 Guide to Completing a Vendor Risk Management Questionnaire
Vendor risk management is increasingly crucial in 2025 as enterprises integrate more cloud-based solutions into their IT ecosystems. With this shift comes greater compliance risks, making the verification of vendors’ security controls and regular security audits essential. Understanding and managing these risks effectively requires ongoing communication with third—and fourth-party vendors. Utilizing a vendor risk management
Tech Center
November 22, 2023
C-Suite Liability & Cybersecurity: Navigating a New Era of Enforcement
It’s well established that corporate directors have fiduciary “duties of care” to protect their companies against major risks and compliance failures. Only recently have courts clarified that these duties now extend to the C-Suite — CEOs, CISOs, GCs and other key executives now face personal liability for failing to safeguard their companies.
Executive Viewpoint
November 20, 2023
Decoding the Boardroom: A Fortune 500 CISO’s Guide to Winning Hearts and Budgets
It’s imperative for CISOs to learn how to speak the language of their boards and stakeholders, oh by the way…it’s not cyber risk probability! Board members and business stakeholders prefer economic terminology over tech talk.
Executive Viewpoint
Security Ratings
November 9, 2023
What are Tabletop Exercises?
One of the best ways to prepare your organization for a security incident and reduce the cost of a breach is by putting your incident response plan to the test with tabletop exercises. Here we’ll explore the objectives of tabletop exercises and how they can improve your organization’s security posture.
Services
Tech Center
October 24, 2023
SecurityScorecard Achieves FedRAMP® ‘Ready’ Designation
U.S. federal agencies positioned to adopt A to F letter-grade rating system
Public Sector
Security Ratings