Resources

Blog

Resource Library

Clear filters

The Vanishing Window: Why We Built SecurityScorecard for What Comes Next

September 22, 2026

The Vanishing Window: Why We Built SecurityScorecard for What Comes Next
A response to IDC’s 2026 Spotlight on the shift from periodic to continuous, threat-informed third-party risk management.
AI Security Cannot Depend on Everyone Slowing Down

September 15, 2026

AI Security Cannot Depend on Everyone Slowing Down
Frontier labs are calling for the industry to slow down. Our adversaries didn’t get the memo. The world’s first benchmark for AI in third-party risk management shows what we should be building instead: measurement, not just restraint.
How to Present Cyber Risk to the Board: A CISO’s Reporting Framework

September 4, 2026

How to Present Cyber Risk to the Board: A CISO’s Reporting Framework
CISOs now face direct board accountability for vendor risk. Here’s a practical framework for turning security data into a board-ready risk narrative — with a template to get started.
AI Agents in TPRM: What They Actually Do (and What They Don’t)

August 31, 2026

AI Agents in TPRM: What They Actually Do (and What They Don’t)
AI agents in TPRM do more than summarize findings. See what agentic AI actually automates in a third-party risk program — and how to tell real from hype.
New Hire Spotlight: Riché Zamor

August 31, 2026

New Hire Spotlight: Riché Zamor
Riché Zamor, VP, Product Operations & AI Innovation, shares his first impressions of working at SecurityScorecard, what drew him to the company and what he’s most excited to build with the team.
Scorecarder Spotlight
What Is Nth-Party Risk?

August 28, 2026

What Is Nth-Party Risk?
Nth-party risk is the exposure hidden inside your vendors’ vendors. Learn why traditional TPRM can’t see it and how continuous outside-in monitoring fills the gap.
What Is IP Reputation and How to Protect It?

August 24, 2026

What Is IP Reputation and How to Protect It?
Learn what IP reputation is, how it impacts your business, and how continuous monitoring protects your organization and vendor ecosystem from threats.
What Is Endpoint Security and Why Does It Matter?

August 24, 2026

What Is Endpoint Security and Why Does It Matter?
Learn what endpoint security is, why it matters for your organization, and how to protect every device on your network from modern cyber threats.
What Is Internet Intelligence?

August 22, 2026

What Is Internet Intelligence?
Internet intelligence turns raw web data into a real-time view of your exposure and third-party risk. Learn what it is and how it works.
What Is Threat-Informed TPRM and Why Compliance-Driven Programs Leave You Exposed

August 19, 2026

What Is Threat-Informed TPRM and Why Compliance-Driven Programs Leave You Exposed
Compliance-driven TPRM programs document risk — they don’t reduce it. Learn what threat-informed third-party risk management looks like and why the difference matters when attackers move in hours.
How Ransomware 3.0 Changes Your Risk Exposure

August 17, 2026

How Ransomware 3.0 Changes Your Risk Exposure
Ransomware 3.0 runs autonomously on AI. See how security teams can harden defenses, monitor third parties, and stay ahead of this new threat.
Why Traditional Vendor Questionnaires Are Outdated

August 15, 2026

Why Traditional Vendor Questionnaires Are Outdated
Vendor questionnaires were built for a slower era. Learn why point-in-time assessments fail modern security teams — and what threat-informed TPRM looks like instead.
What Is Continuous Threat Exposure Management (CTEM)?

August 14, 2026

What Is Continuous Threat Exposure Management (CTEM)?
Continuous threat exposure management (CTEM) is a five-stage Gartner framework to find, validate, and prioritize the exposures attackers can exploit.
What Are DORA Compliance Requirements

August 10, 2026

What Are DORA Compliance Requirements
Learn what DORA compliance requirements mean for financial entities, from ICT risk management and incident reporting to third-party oversight.
Scorecarder Spotlight: Emmy Chau

August 10, 2026

Scorecarder Spotlight: Emmy Chau
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest to continue their development as lifelong learners.   Name: Emmy Chau Role: Senior Manager, FP&A “One of the things I appreciate most about SecurityScorecard is the opportunity to keep learning. Whether it’s partnering with teams across
Scorecarder Spotlight
What Is Internet-Wide Scanning, and How Attackers Use It

August 7, 2026

What Is Internet-Wide Scanning, and How Attackers Use It
Internet-wide scanning lets attackers find exposed hosts fast. See how it works and how to spot your exposure before they do.
How SOC Automation Improves Threat Response

August 7, 2026

How SOC Automation Improves Threat Response
SOC automation helps security teams respond faster, cut false positives, and scale operations. Learn the top use cases, benefits, and challenges.
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity

August 5, 2026

Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
How to Make the Most of Your SecurityScorecard Free Trial

August 4, 2026

How to Make the Most of Your SecurityScorecard Free Trial
Most free trial users only check their score once. Here’s how to use every feature available — from self-monitoring and vendor checks to ASI searches — to get real value from day one.
How to Manage AI Vendor Risk

August 3, 2026

How to Manage AI Vendor Risk
Manage AI vendor risk with a framework for vetting AI capabilities, auditing data flows, and bringing AI tools into continuous monitoring.
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains

August 3, 2026

Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.