Resources

Blog

Resource Library

Clear filters

Introducing SecurityScorecard AI Agents

April 9, 2026

Introducing SecurityScorecard AI Agents
Transform your vendor risk management with new SecurityScorecard AI Agents. Learn how to automate security questionnaire management, gain real-time threat insights, and accelerate remediation to stay ahead of emerging cyber threats.
What Is a DNS Sinkhole?

April 6, 2026

What Is a DNS Sinkhole?
Learn what a DNS sinkhole is, how it blocks malicious traffic, and why security teams use sinkholing to neutralize botnets and protect their networks.
RSAC 2026 Recap: What Did RSAC 2026 Reveal About the Future of TPRM? SecurityScorecard’s TITAN AI Sets the Pace

April 1, 2026

RSAC 2026 Recap: What Did RSAC 2026 Reveal About the Future of TPRM? SecurityScorecard’s TITAN AI Sets the Pace
CEO and Co-Founder Dr. Aleksandr Yampolskiy, CISO Steve Cobb, and SecurityScorecard leaders joined chief information security officers (CISOs), partners, and industry experts at RSAC 2026 to discuss how AI, threat intelligence, and continuous monitoring are reshaping third-party risk management (TPRM). RSAC 2026 reinforced a growing gap between how organizations manage third-party risk and how that
AI Is Reshaping Cyber Risk in 2026: Why Boards Must Take Ownership Now

March 31, 2026

AI Is Reshaping Cyber Risk in 2026: Why Boards Must Take Ownership Now
Cybersecurity leaders must accept a hard truth: AI has already broken the traditional model of defense in 2026. Attackers now operate faster, at lower cost, and at greater scale than most organizations can handle. The only viable response is to rethink security as a continuous, business-driven risk function. This shift defined a recent panel at
Iran Conflict and the Expanding Cyber Front: What Government Leaders Need to Know

March 31, 2026

Iran Conflict and the Expanding Cyber Front: What Government Leaders Need to Know
When conflict escalates in the Middle East, the battlefield is never limited to geography. It extends into energy grids, government networks, transportation systems, and financial infrastructure. The current war involving Iran is no exception. While missiles and airstrikes dominate headlines, the parallel cyber dimension may prove equally consequential, particularly for regional governments, critical infrastructure operators,
SecurityScorecard Appoints Dean Sysman to Board of Directors

March 31, 2026

SecurityScorecard Appoints Dean Sysman to Board of Directors
SecurityScorecard today announced that Dean Sysman, Co-Founder and Executive Chairman of Axonius, has joined its Board of Directors as an independent director. Dean is one of the most respected builders in cybersecurity today. Sysman co-founded Axonius and scaled it into a leader in cyber asset management. The platform helps organizations maintain accurate asset inventories, reduce
What Is a Honeypot in Cybersecurity?

March 30, 2026

What Is a Honeypot in Cybersecurity?
Learn what a honeypot is in cybersecurity, how it works to detect threats, and why security teams use honeypots to gather attacker intelligence.
What Is the CAIQ Questionnaire? A Clear Guide

March 27, 2026

What Is the CAIQ Questionnaire? A Clear Guide
The CAIQ questionnaire documents a cloud provider’s security controls. Learn how it works and how to finish it without the grind.
RSAC 2026 Talk: Transforming Third-Party Risk Management From Compliance Checkboxes to Security Resilience

March 26, 2026

RSAC 2026 Talk: Transforming Third-Party Risk Management From Compliance Checkboxes to Security Resilience
The traditional approach to managing supply chain risk is broken. For years, organizations have relied on annual questionnaires and static attestations to “check the box” for compliance. However, as SecurityScorecard CISO Steve Cobb highlighted in his RSAC 2026 talk, “The Outside-In Advantage: Modernizing TPRM with AI and Threat Intelligence,” 90% of security practitioners lack confidence
SecurityScorecard and Dataminr Partner to Deliver Preemptive Cyber Defense for the Enterprise

March 24, 2026

SecurityScorecard and Dataminr Partner to Deliver Preemptive Cyber Defense for the Enterprise
Combining third party risk and external attack surface management with client-tailored threat intelligence to help organizations stop threats before they strike.
Supply Chains Are the New Front Line for Cyber Resilience

March 23, 2026

Supply Chains Are the New Front Line for Cyber Resilience
Supply chains are the top cyber resilience challenge in 2026. See how continuous monitoring and threat-informed vendor risk management protect your operations.
How to Reduce Security Questionnaire Fatigue

March 20, 2026

How to Reduce Security Questionnaire Fatigue
Answering the same security questionnaires is wearing your team out. Reduce security questionnaire fatigue with these fixes.
What Is Application Security and Best Practices for it?

March 16, 2026

What Is Application Security and Best Practices for it?
Learn what application security is and why your vendors’ AppSec gaps become your risk. Learn how continuous monitoring protects your supply chain.
What Is a Supply Chain Attack?

March 9, 2026

What Is a Supply Chain Attack?
Learn how a supply chain attack works, why it’s so dangerous, and what security measures can help protect your organization from hidden threats.
Supply Chain Cyber Risk
Threat-Informed TPRM
What the Mississippi Ransomware Attack Means for Healthcare and How to Protect Critical Infrastructure

February 25, 2026

What the Mississippi Ransomware Attack Means for Healthcare and How to Protect Critical Infrastructure
A ransomware attack shut down clinics across Mississippi. Learn how healthcare and critical infrastructure can prevent supply chain-driven cyber disruptions.
What Are the Real Security Risks of Agentic AI and OpenClaw?

February 17, 2026

What Are the Real Security Risks of Agentic AI and OpenClaw?
SecurityScorecard’s STRIKE Threat Intelligence team examines exposed OpenClaw deployments and the broader security risks of agentic AI, including remote code execution vulnerabilities, prompt injection, and the security controls organizations must implement now.
What is a CVE and Why is It Important?

February 14, 2026

What is a CVE and Why is It Important?
What is a CVE? This guide explains how security teams use Common Vulnerabilities and Exposures to identify, track, and prioritize the threats that matter most.
How Exposed OpenClaw Deployments Turn Agentic AI Into an Attack Surface

February 11, 2026

How Exposed OpenClaw Deployments Turn Agentic AI Into an Attack Surface
SecurityScorecard’s STRIKE Threat Intelligence team details new research on exposed OpenClaw agentic AI deployments, explaining how attackers can abuse them for remote code execution and infrastructure misuse. STRIKE also shared steps organizations can take to reduce exposure.
Recent Data Breach Examples

February 10, 2026

Recent Data Breach Examples
Discover how real data breach examples expose third-party risks. Learn from MOVEit, healthcare breaches, and M365 attacks to protect your business.
Strengthening National Cyber Resilience: Reflections from My Fireside Chat with ONCD Director Sean Cairncross

February 9, 2026

Strengthening National Cyber Resilience: Reflections from My Fireside Chat with ONCD Director Sean Cairncross
Mike Centrella, SecurityScorecard Head of Public Policy, shares insights from his fireside chat with the National Cyber Director Sean Cairncross on strengthening U.S. cyber resilience, deterrence, AI security, and workforce strategy.
Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence

February 9, 2026

Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence
While the world debates Moltbook’s role in the AI ecosystem, it is just the tip of the iceberg of Titanic risk. SecurityScorecard’s STRIKE team uncovered what lurks beneath: Thousands of exposed OpenClaw (Moltbot) control panels vulnerable to takeover through misconfigured access and known exploits.
STRIKE Team