Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Bolstering Supply Chain Security with Enhanced Japanese Language Support

Blog

Bolstering Supply Chain Security with Enhanced Japanese Language Support
SecurityScorecard has significantly expanded Japanese language support across key areas of the platform.
SecurityScorecard Applauds House Passage of the PILLAR Act as a Milestone for National Cyber Resilience

Blog

SecurityScorecard Applauds House Passage of the PILLAR Act as a Milestone for National Cyber Resilience
The U.S. House of Representatives has officially passed the PILLAR Act, a landmark effort aimed at strengthening America’s cyber resilience across federal, state, local, tribal, and territorial (SLTT) partners. SecurityScorecard is proud to see growing bipartisan and industry support for a bill that prioritizes continuous visibility, supply-chain security, and actionable threat intelligence at a time
What Is HTTPS and Why Is It Essential for Cybersecurity?

Blog

What Is HTTPS and Why Is It Essential for Cybersecurity?
What Is HTTPS? Learn about secure web protocols, SSL certificates, encryption best practices, and emerging cybersecurity threats.
How SecurityScorecard Enhances AuditBoard’s RiskOversight and TPRM

Blog

How SecurityScorecard Enhances AuditBoard’s RiskOversight and TPRM
Learn how SecurityScorecard integrates with AuditBoard to give GRC teams unified visibility into both vendor risk and internal cyber health, driving continuous, audit-ready compliance.
Third-Party Risk Management
Risky Bulletin: Sha1-Hulud npm worm returns, with destructive behavior

Resources

Risky Bulletin: Sha1-Hulud npm worm returns, with destructive behavior
Learn more in this resource.
STRIKE News
How Global Enterprises Use GRC Platforms to Translate Security Ratings Into Business Risk

Blog

How Global Enterprises Use GRC Platforms to Translate Security Ratings Into Business Risk
Learn how businesses use SecurityScorecard to convert security ratings into quantified business impact by integrating with AuditBoard, Diligent, ServiceNow, LogicGate, or Archer.
How GRC Professionals Can Integrate SecurityScorecard into Every Phase of TPRM Programs

Blog

How GRC Professionals Can Integrate SecurityScorecard into Every Phase of TPRM Programs
Learn how GRC professionals use SecurityScorecard with AuditBoard, Diligent, ServiceNow, LogicGate, Process Unity or Archer to evolve third-party risk management programs from discrete, periodic checks into always-on, automated risk monitoring engines. This GRC Manager’s Guide outlines practical steps for enhancing TPRM.
Third-Party Risk Management
Why GRC Programs Fail Without Continuous Cyber Risk Intelligence

Blog

Why GRC Programs Fail Without Continuous Cyber Risk Intelligence
Static assessments no longer protect growing supply chains. Learn how Governance, Risk, and Compliance (GRC) teams use AuditBoard, Diligent, ServiceNow, LogicGate, Process Unity and Archer with SecurityScorecard for continuous cyber risk intelligence.
GRC
CISA to prioritize new hires in 2026: report

Resources

CISA to prioritize new hires in 2026: report
Learn more in this resource.
STRIKE News
Why a $50 Billion Investment Will Propel Rural Health Cyber Transformation

Blog

Why a $50 Billion Investment Will Propel Rural Health Cyber Transformation
Explore how the $50 billion Rural Health Transformation Program from the Centers for Medicare & Medicaid Services (CMS) supports rural health transformation, and why cybersecurity needs to be prioritized.
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router

Blog

Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
SecurityScorecard’s STRIKE team uncovers how attackers turned thousands of ASUS routers into a worldwide spy network.
STRIKE Team
What Is an Exploit? Vulnerabilities and Threat Mitigation

Blog

What Is an Exploit? Vulnerabilities and Threat Mitigation
Every cybersecurity professional faces a constant battle against threats that target the weakest points in their digital infrastructure. While organizations invest heavily in defensive technologies, attackers continue to find new ways to bypass these protections using sophisticated techniques that turn software weaknesses into powerful weapons. What once required advanced technical knowledge and significant resources can
From Checkbox Compliance to Active Defense: Mastering the Supply Chain Cybersecurity Maturity Curve

Webinars

From Checkbox Compliance to Active Defense: Mastering the Supply Chain Cybersecurity Maturity Curve
Learn more in this resource.
AI-Powered Third-Party Risk Management: Go Beyond the Score

Webinars

AI-Powered Third-Party Risk Management: Go Beyond the Score
What if you could harness the power of AI to transform your third-party risk management program? In today’s complex supply chain risk environment, managing cyber risk is no longer just about receiving a single security rating and traditional vendor assessments. Manual processes leave security teams spending countless hours gathering data and chasing down responses. This time-consuming, reactive approach leaves you vulnerable and unable to focus on the most critical threats. You need a smarter, more efficient way that provides deeper, proactive insights, such as industry benchmarking for vendors and automating workflows to prioritize the highest-risk issues.
Cyber Focus Interview: Dr. Aleksandr Yampolskiy Analyzes the Rise of Third-Party and Supply Chain Cyber Risks

Blog

Cyber Focus Interview: Dr. Aleksandr Yampolskiy Analyzes the Rise of Third-Party and Supply Chain Cyber Risks
SecurityScorecard CEO Dr. Aleksandr Yampolskiy joined Frank Cilluffo on the McCrary Institute’s Cyber Focus podcast to break down why third-, fourth-, and fifth-party risk has become “the new epidemic in cybersecurity,” and why today’s digital interdependence is pushing systemic risk to historic levels.
Why Singapore’s Cybersecurity Risks are Surging and How To Tackle Third-Party Risk

Blog

Why Singapore’s Cybersecurity Risks are Surging and How To Tackle Third-Party Risk
71.4% of companies in Singapore have experienced a third-party breach. In a recent webinar, security experts analyzed the latest SecurityScorecard research on what is putting Singapore’s most vital sectors at risk.
What is a Prompt Injection Attack: What CISOs Need to Know

Blog

What is a Prompt Injection Attack: What CISOs Need to Know
What is a prompt injection attack? Learn how this AI security threat manipulates language models, real examples, and strategies to protect your systems.
Adversarial AI: When Attackers and Defenders Become Equals

Blog

Adversarial AI: When Attackers and Defenders Become Equals
In SecurityScorecard’s latest fireside chat, Adversarial AI: The New Symmetric Threat Landscape, CEO and Co-Founder Dr. Aleksandr Yampolskiy Yampolskiy sat down with Dr. Srinivas Mukkamala, CEO of Securin, to examine how AI is driving both innovation and empowering attackers.
Why Every CEO Needs a CISO or CIO on the Board and How to Get a Board Seat if You Are One

Blog

Why Every CEO Needs a CISO or CIO on the Board and How to Get a Board Seat if You Are One
Trewstar Corporate Board Services Founder and CEO Beth Stewart and SecurityScorecard’s Co-Founder and CEO Dr. Aleksandr Yampolskiy share why CEOs need a CISO and CIO on their board to translate tech expertise into boardroom strategy.
What is 5G Network Security?

Blog

What is 5G Network Security?
Learn what 5G security means for your organization. Discover the key risks, architecture vulnerabilities, and how to protect your vendor ecosystem.
What is Lateral Movement in Cybersecurity?

Blog

What is Lateral Movement in Cybersecurity?
Learn about lateral movement and how cyber attackers use it to move deeper into networks, access sensitive data, and how to detect and stop them.