Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
August 14, 2024
Continuous Accountability: Leveraging Contracts to Secure your Supply Chain
A critical problem for security and legal professionals who manage supply chain risk is that cybersecurity risks are dynamic and always shifting. You have done your due diligence and selected a vendor with strong cybersecurity controls – but how can you guarantee that your vendor maintains this type of… Read More
August 14, 2024
SecurityScorecard is now part of AWS OMNIA
SecurityScorecard is excited to announce that we are now an AWS OMNIA partner. This unlocks a critical opportunity for the 90,000 buying organizations that make up the OMNIA partner network to reduce and manage Supply Chain Cyber Risks. The third party attack surface is a fast… Read More
AWS
August 8, 2024
SecurityScorecard and ServiceNow Expand Partnership with New Capabilities for TPRM and Security Incident Response (SIR)
ServiceNow and SecurityScorecard have been longtime strategic partners, helping mutual customers measure and manage cyber risk. Today we’re highlighting the next phase of our partnership and innovation to help customers tackle the complex challenges associated with managing cyber risk in the third party ecosystem. Organizations struggle with… Read More
August 8, 2024
“More Money, More Problems:” Supply Chain Cyber Risk in the Forbes Global 2000
SecurityScorecard and its partner Cyentia recently released our joint case study of third-party cyber risk in the Forbes Global 2000 group of the world’s financially largest companies. On one hand, large companies have the advantage of greater financial and human resources to invest in security programs. Security… Read More
August 7, 2024
“What’s our number?”: Responding To Your Exposure to CrowdStrike Outage Event
Is cyber risk insurable? That question is often at the heart of the debate about the future of the cyber insurance industry. One of the primary drivers of that question is the insurance industry’s challenges when managing systemic cyber risk since many believe that systemic cyber risk has… Read More
August 5, 2024
SecurityScorecard and AWS Help Make Secure Software Procurement Faster and Easier
Organizations increasingly rely on third parties for business operations, and as a result are working with more digital suppliers than ever. According to Gartner, 60% of organizations work with more than 1,000 third parties and this number will grow. High-profile vulnerabilities such as Log4Shell are a constant… Read More
AWS
August 5, 2024
Up Level Your Amazon Security Lake with Attack Surface Intelligence
As global network infrastructure expands to include devices without traditional compute power, every organization’s attack surface becomes increasingly complex. Parallel to the increased complexity in the threat landscape is the increased scale and complexity of the signals and data necessary to produce meaningful cybersecurity insights. At its core, cybersecurity… Read More
August 2, 2024
Scorecarder Spotlight: Catarina Horta
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners. Name: Catarina Horta Role: Business Development Manager, LATAM & EMEA Tell us a little… Read More
Scorecarder Spotlight
July 19, 2024
Crowdstrike Outage: Know Your Supply Chain
Supply chain detection is vital for third-party incident response Knowing Your Supply Chain (KYSC) is becoming an increasingly important component of cyber resilience. Understanding the dependencies within your organization and those of your vendors is critical for responding to incidents effectively. Even the most reliable vendors and partners… Read More
July 17, 2024
Scorecarder Spotlight: Andrew Correll
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners. Name: Andrew Correll Role: Senior Director, Cyber Insurability Tell us a little about your professional… Read More
Scorecarder Spotlight
July 15, 2024
How to Choose the Right Supply Chain Cyber Risk Managed Service
AI isn’t what’s going to be the hot topic of the next year; it’s going to be data breaches in the supply chain and the cost that companies face by not reacting quickly to this emerging threat. The cyber attack on Change Healthcare, one of the… Read More
Professional Services
Supply Chain Cyber Risk
Third-Party Risk Management
June 25, 2024
The Role of Supply Chain Cyber Risk in U.S. Healthcare: Inside SecurityScorecard’s new report
In late February of this year, Change Healthcare experienced a massive ransomware attack. The company, a subsidiary of United Healthcare, is the largest clearinghouse for insurance billing and payments in the U.S, processing 15 billion medical claims each year. The attack had broad consequences across the healthcare… Read More
Healthcare
June 14, 2024
Cost, convenience, and compliance: The value for insurers of the Forrester Total Economic Impact Study
“We’re now identifying the greatest risks in our external infrastructure, the stuff that any hacker with one day of experience can figure out. Honestly, the ability to have all this third-party risk information aggregated and presented in a usable way for both us and the supplier is… Read More
June 11, 2024
SecurityScorecard Reduced External Third-Party Breaches by 75%
Forrester Total Economic ImpactTM Study: Automatic vendor detection, risk identification, and mitigation holistically manage supply chain cyber risk The interconnected nature of our digital economy requires a shift in how companies think about their cyber risk. Companies need to consider the broader system and how… Read More
June 10, 2024
Harmonizing Government, Policy, and Technology: Thoughts from Jeff Le, SecurityScorecard’s new VP of Global Government Affairs & Public Policy
For the past twenty years, I have had the pleasure of working at the intersection of public service, technology, and global security. As Deputy Cabinet Secretary to former California Governor Jerry Brown, I responded directly to the technology challenges that the state government faced to protect constituent data,… Read More
Executive Viewpoint
May 23, 2024
The Need for Speed: “Material” Confusion under the SEC’s Cyber Rules
This week, the SEC issued a statement addressing some of the rampant confusion and inconsistencies observed under the agency’s new cyber breach disclosure rule. The statement itself addresses a technical securities law requirement, that… Read More
Public Sector
May 21, 2024
EPA Alert Warns Nation’s Drinking Water at Risk: SecurityScorecard’s recommendations for securing critical infrastructure
“Protecting our nation’s drinking water is a cornerstone of EPA’s mission, and we are committed to using every tool, including our enforcement authorities, to ensure that our nation’s drinking water is protected from cyberattacks.” -EPA Deputy Administrator Janet McCabe This week, the U.S. Read More
May 20, 2024
SecurityScorecard Named a Leader in the Forrester Wave for Cybersecurity Risk Ratings
May 21, 2024 Dr. Aleksandr Yampolskiy and Sam Kassoumeh Today, we’re proud to announce that Forrester has named SecurityScorecard a Leader in The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2024. Forrester identified the 10 most significant vendors in cybersecurity risk ratings… Read More
May 17, 2024
Compliance, collaboration, and communication: The benefits of NIST CSF 2.0
As regulatory mandates and frameworks continue to emerge, cybersecurity leaders must continue to adapt to more than just the latest threat actor tactics, techniques, and procedures. As part of our ongoing webinar series centered on compliance, SecurityScorecard’s Senior Product Marketing Manager, Devaney Devoe, moderated a discussion… Read More
Public Sector
May 16, 2024
National Vulnerability Database (NVD) leaves thousands of vulnerabilities without analysis data
The Common Vulnerabilities and Exposures (CVE) List and National Vulnerability Database (NVD) can no longer be considered a single central source of vulnerability truth. The cybersecurity world is no doubt aware that the National Vulnerability Database (NVD) has been experiencing… Read More