Resources

Blog

Resource Library

Clear filters

SecurityScorecard Cybersecurity Data Incorporated into S&P Global Market Intelligence’s Newly Launched Supplier Risk Indicator™

October 12, 2023

SecurityScorecard Cybersecurity Data Incorporated into S&P Global Market Intelligence’s Newly Launched Supplier Risk Indicator™
Discover how S&P Global Market Intelligence’s Supplier Risk Indicator™ revolutionizes business relationships by assessing financial resilience, conduct, and information security. Secure your supply chain now.
Services
Zero‑Day Attack Prevention: How to Prepare

October 11, 2023

Zero‑Day Attack Prevention: How to Prepare
Learn how to prevent zero‑day attacks with hardening, detection prep, virtual patching, and a 24–72 hour response checklist, even before a patch exists.
Tech Center
Qualitative vs. Quantitative Cybersecurity Risk Assessment: What’s the Difference?

September 28, 2023

Qualitative vs. Quantitative Cybersecurity Risk Assessment: What’s the Difference?
Formulating a cybersecurity risk assessment methodology is an essential part of building a robust information security program to identify key information assets and their value to the organization. By using this data, it is then possible for management to determine whether their existing security measures are adequate and investigate its risk profile.\r\n\r\nThere are two primary risk assessment methodologies: qualitative and quantitative risk assessments. But to build an effective IT security risk assessment methodology, you will need to incorporate both quantitative and qualitative approaches to paint an accurate picture of risk. Let’s take a closer look.
Tech Center
What is the Cost of Cyber Liability Insurance?

September 20, 2023

What is the Cost of Cyber Liability Insurance?
The cost of cyber liability insurance can vary based on factors such as business size, industry, risk profile, and coverage needs.
Cyber Insurance
Executive Viewpoint
Tech Center
Using a Standardized Approach for Measuring Cybersecurity in Government

September 12, 2023

Using a Standardized Approach for Measuring Cybersecurity in Government
One of the highlights of last week’s annual Billington CyberSecurity Summit was a fireside chat on Friday with Anne Neuberger, deputy national security adviser for cyber and emerging technology. In her talk, Neuberger stressed the importance of not only keeping our critical infrastructure secure but harnessing an accurate and repeatable way of measuring it to ensure progress.
Public Sector
The Top 7 Cyberattacks on U.S. Government: A closer look at the evolving landscape of cybersecurity

September 9, 2023

The Top 7 Cyberattacks on U.S. Government: A closer look at the evolving landscape of cybersecurity
Cyberattacks are an increasingly significant threat to governments worldwide. This blog post examines some of the top cyberattacks on US government.
Public Sector
Tech Center
6 Myths About Cybersecurity Ratings (and 1 Truth): The Current State Of The Cybersecurity Ratings Industry And Where It Can Improve

August 15, 2023

6 Myths About Cybersecurity Ratings (and 1 Truth): The Current State Of The Cybersecurity Ratings Industry And Where It Can Improve
Cybersecurity ratings are a valuable asset in defending your organization. Learn about popular cybersecurity myths and what security ratings can do for you.
Security Ratings
Top 5 Security Vulnerabilities of 2023

August 7, 2023

Top 5 Security Vulnerabilities of 2023
Why 2023 is a year of ‘digital forest fires’: New Attack Surface Intelligence Research from SecurityScorecard 2023 is a year of “digital forest fires.” The MOVEit and the Barracuda Networks’ email supply chain attacks underscore the massive butterfly effect a single software flaw can have on the threat landscape. Supply chain attacks spread like a
Cyber Threat Intelligence
Supply Chain Cyber Risk
3 Takeaways: New SEC Cyber Risk Disclosure Rules

July 27, 2023

3 Takeaways: New SEC Cyber Risk Disclosure Rules
Blog: New rules require a detailed assessment of supply chain and organizational resilience
Services
What is Cyber Threat Hunting?

July 12, 2023

What is Cyber Threat Hunting?
Master cyber threat hunting with expert techniques and tools to find hidden threats before they cause data breaches.
Cyber Threat Intelligence
Tech Center
What is Threat Intelligence in Cybersecurity?

July 6, 2023

What is Threat Intelligence in Cybersecurity?
Threat intelligence helps you understand, prevent, and mitigate cyber threats. Learn how threat intelligence can benefit your business.
Tech Center
Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat

June 23, 2023

Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat
Recently, a critical vulnerability tracked as CVE-2023-27997 was identified in Fortinet Fortigate appliances. This vulnerability has been exploited by the Chinese APT group Volt Typhoon, among others, targeting governments and organizations worldwide. \r\n\r\nAs a result, Fortinet has released an urgent patch for affected systems. For a more detailed understanding of this vulnerability and the corresponding patch, you can read this Fortinet blog post.\r\n
Cyber Threat Intelligence
Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory

June 22, 2023

Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory
During an interview on Nasdaq Trade Talks, SecurityScorecard CEO, Aleksandr Yampolskiy, discussed the impact of upcoming regulations by the SEC.
Services
SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation

June 20, 2023

SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation
SecurityScorecard shares its findings into a widespread MOVEit exploit which affected a number of high profile organizations.
Cyber Threat Intelligence
Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations

June 7, 2023

Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations
Learn about SecurityScorecard’s investigation into the Zellis breach, which uncovered over 2.500 vulnerable servers across 790 organizations.
Cyber Threat Intelligence
SecurityScorecard’s Partnership with the TSA Helping to Secure the Nation’s Critical Infrastructure

May 16, 2023

SecurityScorecard’s Partnership with the TSA Helping to Secure the Nation’s Critical Infrastructure
As part of our continued commitment to making the world a safer place, SecurityScorecard recently partnered with the Transportation Security Administration (TSA). This partnership will enable the agency to more accurately monitor and assess the cyber health of the nation’s pipeline, rail, and aviation transportation systems.
Prepare for Zero-Day Threats: Military and Private Sector Leaders Share Their Insights

April 14, 2023

Prepare for Zero-Day Threats: Military and Private Sector Leaders Share Their Insights
Leading cybersecurity experts Major General John F. Wharton, (US Army retired); Oleg Strizhak, Shell’s Digital Supply Chain Risk Manager; and Sam Curry, the CISO of Zscaler, recently sat down with SecurityScorecard’s President of International Operations Matthew McKenna to discuss how organizations can prepare themselves and their supply chains for zero-day attacks, preventing and responding to them, as well as best practices for supply chain risk management.  
Cyber Threat Intelligence
Public Sector
7 Factors that Drive Cyber Risk: New Research from Marsh McLennan and SecurityScorecard

April 12, 2023

7 Factors that Drive Cyber Risk: New Research from Marsh McLennan and SecurityScorecard
Cyber risk is dynamic and influenced by a wide range of variables, quantifying it requires numerous, continuously updated data points.
Cyber Insurance
6 Ways To Use SecurityScorecard APIs and Integrations

April 4, 2023

6 Ways To Use SecurityScorecard APIs and Integrations
Optimize your security workflows and deliver intelligence with the largest ecosystem of integrated technology partners. Learn more.
Security Ratings
SecurityScorecard releases list of Killnet open proxy IP addresses

February 7, 2023

SecurityScorecard releases list of Killnet open proxy IP addresses
In the wake of Killnet’s latest DDoS attack on U.S. hospitals on January 30, SecurityScorecard has made its KillNet open proxy IP blocklist available to the public. This list is the product of the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team’s ongoing research into KillNet. We released this list to help organizations better defend themselves against KillNet and other groups like it by preventing traffic from exploitable assets. In this blog, we’ll explain how we developed this proxy list and our recommendations for preventing DDos attacks.
Cyber Threat Intelligence
Close Encounters of the Third- (and Fourth-) Party Kind: The Blog

February 1, 2023

Close Encounters of the Third- (and Fourth-) Party Kind: The Blog
Let’s dive deeper into some other insights that help us understand the true extent of exposure from third- and fourth-party relationships.
Supply Chain Cyber Risk