Resources

Blog

Resource Library

Clear filters

Identity-Based Attacks and Third-Party Risk

June 15, 2026

Identity-Based Attacks and Third-Party Risk
Identity attacks now account for 59% of breaches, and vendors are the fastest-growing entry point. Learn how to protect your supply chain.
The World Cup Has 48 Teams. Adversaries Are Playing Too.

June 15, 2026

The World Cup Has 48 Teams. Adversaries Are Playing Too.
During the 2020 Tokyo Olympics, held in 2021 after a pandemic-forced delay,  NTT Corporation recorded approximately 450 million cyberattack attempts targeting Olympic systems. The 2022 FIFA World Cup in Qatar drew similar attention from state-aligned threat actors and opportunistic criminals. The 2026 tournament, spanning three nations, 16 cities, and several million projected visitors, will be
Compliance vs Security: What Passing an Audit Misses

June 12, 2026

Compliance vs Security: What Passing an Audit Misses
Compliance vs security explained. A passed audit proves controls existed on one day, not that you are secure. Close the gap.
What Secure by Design Means for Vendor Vetting

June 8, 2026

What Secure by Design Means for Vendor Vetting
Secure by design means building security in from the start. Learn what it means for vendor vetting and how to assess whether your vendors actually follow it.
Vendor Offboarding: The Step TPRM Teams Forget

June 5, 2026

Vendor Offboarding: The Step TPRM Teams Forget
Vendor offboarding is the stage most teams skip. See why lingering vendor access turns into breach risk, and how to close the gap.
Living Off the Land Attacks Explained

June 1, 2026

Living Off the Land Attacks Explained
Living off the land attacks use legitimate system tools to evade detection. Learn how LOTL techniques work, who uses them, and how to reduce your exposure.
How Ransomware as a Service Has Changed

June 1, 2026

How Ransomware as a Service Has Changed
Ransomware-as-a-service has transformed who can launch a ransomware attack and how. Learn how the RaaS model works and how to defend your supply chain.
How Cloud Misconfiguration Exposes Vendor Networks

May 25, 2026

How Cloud Misconfiguration Exposes Vendor Networks
Cloud misconfiguration is one of the most common causes of data breaches. Learn how vendor cloud misconfigurations create risk and how to reduce your exposure.
What Agentic AI Security Risks Mean for CISOs

May 25, 2026

What Agentic AI Security Risks Mean for CISOs
Agentic AI introduces security risks traditional controls weren’t built for. Learn what CISOs need to know about securing autonomous AI systems and supply chains.
How Deepfake Phishing Powers Business Email Compromise

May 18, 2026

How Deepfake Phishing Powers Business Email Compromise
Deepfake phishing uses AI-generated voice and video to impersonate trusted contacts. Learn how these attacks work and how to defend your organization.
Software Bill of Materials and Supply Chain Risk

May 18, 2026

Software Bill of Materials and Supply Chain Risk
A software bill of materials documents every component in your software supply chain. Learn what SBOMs are, why they matter, and how to build a program that holds up.
Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline

May 15, 2026

Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline
Data quality is foundational to customer confidence. At SecurityScorecard, our Scoring platform processes data for thousands of companies daily. That scale requires more than strong engineering discipline. It requires clear validation patterns, consistent checks, and observable results across every critical stage of the pipeline. This post shares how our data engineering team uses Great Expectations,
Why Password Spraying Attacks Target Your Vendors

May 11, 2026

Why Password Spraying Attacks Target Your Vendors
Password spraying attacks use one password across many accounts to avoid lockouts. Learn how attackers target your vendors and how to stop them.
How to Meet Cyber Insurance Requirements

May 11, 2026

How to Meet Cyber Insurance Requirements
Learn what cyber insurance requirements insurers expect, how to close third-party risk gaps, and how continuous monitoring strengthens your coverage.
Supply Chain Security Needs Real-Time Visibility

May 11, 2026

Supply Chain Security Needs Real-Time Visibility
Learn why supply chain security demands real-time visibility and explore 7 best practices to protect your organization from third-party cyber threats.
Building a Vendor Compliance Dashboard for Auditors

May 11, 2026

Building a Vendor Compliance Dashboard for Auditors
Build a compliance dashboard auditors actually trust. Learn how real-time vendor monitoring beats outdated quarterly assessments.
The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)

May 11, 2026

The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)
The questionnaire is the workhorse of third-party risk management. But not all questionnaires are the same and treating them like they are is one of the reasons TPRM programs fall behind. Here’s a clear-eyed look at the four types your team is juggling. 1. Initial / Intake Questionnaires Also called: Inherent Risk Questionnaire (IRQ), Vendor
Passive DNS Explained: Vendor and Threat Infrastructure

May 8, 2026

Passive DNS Explained: Vendor and Threat Infrastructure
Passive DNS Explained: Vendor and Threat Infrastructure
What Is Typosquatting? Attack Types and Prevention

May 8, 2026

What Is Typosquatting? Attack Types and Prevention
Typosquatting is a domain attack using misspelled, look-alike URLs to trick users. Learn the types, real examples, and how to prevent it.
How to Run a Supply Chain Risk Assessment

May 4, 2026

How to Run a Supply Chain Risk Assessment
Learn how to run a supply chain risk assessment, identify supplier vulnerabilities, and build a program that stays current between reviews.
Cybersecurity Questionnaire in the Age of AI

May 4, 2026

Cybersecurity Questionnaire in the Age of AI
AI is reshaping the cybersecurity questionnaire. Learn how to combine faster assessments with continuous monitoring for real-time vendor visibility.