Resources
Blog
Resource Library
October 12, 2023
SecurityScorecard Cybersecurity Data Incorporated into S&P Global Market Intelligence’s Newly Launched Supplier Risk Indicator™
Discover how S&P Global Market Intelligence’s Supplier Risk Indicator™ revolutionizes business relationships by assessing financial resilience, conduct, and information security. Secure your supply chain now.
Services
October 11, 2023
Zero‑Day Attack Prevention: How to Prepare
Learn how to prevent zero‑day attacks with hardening, detection prep, virtual patching, and a 24–72 hour response checklist, even before a patch exists.
Tech Center
September 28, 2023
Qualitative vs. Quantitative Cybersecurity Risk Assessment: What’s the Difference?
Formulating a cybersecurity risk assessment methodology is an essential part of building a robust information security program to identify key information assets and their value to the organization. By using this data, it is then possible for management to determine whether their existing security measures are adequate and investigate its risk profile.\r\n\r\nThere are two primary risk assessment methodologies: qualitative and quantitative risk assessments. But to build an effective IT security risk assessment methodology, you will need to incorporate both quantitative and qualitative approaches to paint an accurate picture of risk. Let’s take a closer look.
Tech Center
September 20, 2023
What is the Cost of Cyber Liability Insurance?
The cost of cyber liability insurance can vary based on factors such as business size, industry, risk profile, and coverage needs.
Cyber Insurance
Executive Viewpoint
Tech Center
September 12, 2023
Using a Standardized Approach for Measuring Cybersecurity in Government
One of the highlights of last week’s annual Billington CyberSecurity Summit was a fireside chat on Friday with Anne Neuberger, deputy national security adviser for cyber and emerging technology. In her talk, Neuberger stressed the importance of not only keeping our critical infrastructure secure but harnessing an accurate and repeatable way of measuring it to ensure progress.
Public Sector
September 9, 2023
The Top 7 Cyberattacks on U.S. Government: A closer look at the evolving landscape of cybersecurity
Cyberattacks are an increasingly significant threat to governments worldwide. This blog post examines some of the top cyberattacks on US government.
Public Sector
Tech Center
August 15, 2023
6 Myths About Cybersecurity Ratings (and 1 Truth): The Current State Of The Cybersecurity Ratings Industry And Where It Can Improve
Cybersecurity ratings are a valuable asset in defending your organization. Learn about popular cybersecurity myths and what security ratings can do for you.
Security Ratings
August 7, 2023
Top 5 Security Vulnerabilities of 2023
Why 2023 is a year of ‘digital forest fires’: New Attack Surface Intelligence Research from SecurityScorecard 2023 is a year of “digital forest fires.” The MOVEit and the Barracuda Networks’ email supply chain attacks underscore the massive butterfly effect a single software flaw can have on the threat landscape. Supply chain attacks spread like a
Cyber Threat Intelligence
Supply Chain Cyber Risk
July 27, 2023
3 Takeaways: New SEC Cyber Risk Disclosure Rules
Blog: New rules require a detailed assessment of supply chain and organizational resilience
Services
July 12, 2023
What is Cyber Threat Hunting?
Master cyber threat hunting with expert techniques and tools to find hidden threats before they cause data breaches.
Cyber Threat Intelligence
Tech Center
July 6, 2023
What is Threat Intelligence in Cybersecurity?
Threat intelligence helps you understand, prevent, and mitigate cyber threats. Learn how threat intelligence can benefit your business.
Tech Center
June 23, 2023
Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat
Recently, a critical vulnerability tracked as CVE-2023-27997 was identified in Fortinet Fortigate appliances. This vulnerability has been exploited by the Chinese APT group Volt Typhoon, among others, targeting governments and organizations worldwide. \r\n\r\nAs a result, Fortinet has released an urgent patch for affected systems. For a more detailed understanding of this vulnerability and the corresponding patch, you can read this Fortinet blog post.\r\n
Cyber Threat Intelligence
June 22, 2023
Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory
During an interview on Nasdaq Trade Talks, SecurityScorecard CEO, Aleksandr Yampolskiy, discussed the impact of upcoming regulations by the SEC.
Services
June 20, 2023
SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation
SecurityScorecard shares its findings into a widespread MOVEit exploit which affected a number of high profile organizations.
Cyber Threat Intelligence
June 7, 2023
Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations
Learn about SecurityScorecard’s investigation into the Zellis breach, which uncovered over 2.500 vulnerable servers across 790 organizations.
Cyber Threat Intelligence
May 16, 2023
SecurityScorecard’s Partnership with the TSA Helping to Secure the Nation’s Critical Infrastructure
As part of our continued commitment to making the world a safer place, SecurityScorecard recently partnered with the Transportation Security Administration (TSA). This partnership will enable the agency to more accurately monitor and assess the cyber health of the nation’s pipeline, rail, and aviation transportation systems.
April 14, 2023
Prepare for Zero-Day Threats: Military and Private Sector Leaders Share Their Insights
Leading cybersecurity experts Major General John F. Wharton, (US Army retired); Oleg Strizhak, Shell’s Digital Supply Chain Risk Manager; and Sam Curry, the CISO of Zscaler, recently sat down with SecurityScorecard’s President of International Operations Matthew McKenna to discuss how organizations can prepare themselves and their supply chains for zero-day attacks, preventing and responding to them, as well as best practices for supply chain risk management.
Cyber Threat Intelligence
Public Sector
April 12, 2023
7 Factors that Drive Cyber Risk: New Research from Marsh McLennan and SecurityScorecard
Cyber risk is dynamic and influenced by a wide range of variables, quantifying it requires numerous, continuously updated data points.
Cyber Insurance
April 4, 2023
6 Ways To Use SecurityScorecard APIs and Integrations
Optimize your security workflows and deliver intelligence with the largest ecosystem of integrated technology partners. Learn more.
Security Ratings
February 7, 2023
SecurityScorecard releases list of Killnet open proxy IP addresses
In the wake of Killnet’s latest DDoS attack on U.S. hospitals on January 30, SecurityScorecard has made its KillNet open proxy IP blocklist available to the public. This list is the product of the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team’s ongoing research into KillNet. We released this list to help organizations better defend themselves against KillNet and other groups like it by preventing traffic from exploitable assets. In this blog, we’ll explain how we developed this proxy list and our recommendations for preventing DDos attacks.
Cyber Threat Intelligence
February 1, 2023
Close Encounters of the Third- (and Fourth-) Party Kind: The Blog
Let’s dive deeper into some other insights that help us understand the true extent of exposure from third- and fourth-party relationships.
Supply Chain Cyber Risk