Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

SecurityScorecardとBlinkOpsが技術提携-セキュリティ体制の可視化、自動化、制御をかつてないレベルで実現

Press

SecurityScorecardとBlinkOpsが技術提携-セキュリティ体制の可視化、自動化、制御をかつてないレベルで実現
Learn more in this resource.
Japanese
DIGITAL X: ステップ2:サプライチェーン全体のリスクを継続的に評価しインシデントに対応する

メディア掲載

DIGITAL X: ステップ2:サプライチェーン全体のリスクを継続的に評価しインシデントに対応する
Learn more in this resource.
Japanese
ADT

Case Studies

ADT
“SecurityScorecard helps us monitor vendors that are outside of our systems, and it also gives us visibility into our own vulnerabilities. Many vendors are under a continuous monitoring portfolio, and we’ve been able to use the tool during issues like MOVEit and the Log4j vulnerability.”
10 Cybersecurity Criteria for Smarter Vendor Selection

Blog

10 Cybersecurity Criteria for Smarter Vendor Selection
Learn the 10 most critical cybersecurity criteria to include in your vendor selection process. Make smarter, risk-informed decisions before onboarding third parties.
DORA, NIS2 : Maîtriser les risques cyber liés aux tiers

Webinars

DORA, NIS2 : Maîtriser les risques cyber liés aux tiers
Au-delà d’un simple impératif de conformité ponctuel, les directives DORA et NIS2 établissent de nouvelles références réglementaires visant à garantir une résilience cyber sur le long terme.
DORA
NIS2
What Is Residual Risk and How Do You Mitigate It?

Blog

What Is Residual Risk and How Do You Mitigate It?
Learn what residual risk is in cybersecurity, how to measure and reduce it, and why complete risk elimination is a myth. Understand strategies to manage what remains after controls are applied.
Chinese APT Hacking Routers to Build Espionage Infrastructure

Resources

Chinese APT Hacking Routers to Build Espionage Infrastructure
Learn more in this resource.
STRIKE News
What Does CIRCIA Require—and How Can You Prepare for Reporting Cyber Incidents?

Blog

What Does CIRCIA Require—and How Can You Prepare for Reporting Cyber Incidents?
Learn what the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires, who it applies to, and how your organization can prepare for faster, smarter breach response.
What is the Difference Between IT Risk Management and Cybersecurity?

Blog

What is the Difference Between IT Risk Management and Cybersecurity?
Explore how IT risk management and cybersecurity differ—and where they overlap. Learn how to align both for a stronger, more resilient organization.
Why Education is a Growing Cyber Target

Blog

Why Education is a Growing Cyber Target
Why educational institutions face rising cyberattacks and what they can do to improve their cybersecurity posture.
Cybersecurity
SecurityScorecard Report Reveals 5 in 6 Organizations at Risk Due to Immature Supply Chain Security

Press

SecurityScorecard Report Reveals 5 in 6 Organizations at Risk Due to Immature Supply Chain Security
SecurityScorecard today released its 2025 Supply Chain Cybersecurity Trends Survey, revealing that 88% of cybersecurity leaders are concerned about supply chain cyber risks.
2025 Supply Chain Cybersecurity Trends: Why Visibility Is the Next Competitive Advantage

Research

2025 Supply Chain Cybersecurity Trends: Why Visibility Is the Next Competitive Advantage
A handful of technology giants now control the infrastructure that powers the global economy. Traditional cybersecurity threats target individual companies, but today’s most devastating attacks exploit the few critical chokepoints that entire industries depend on. Against this backdrop of rising systemic risk, SecurityScorecard set out to assess how enterprises are managing their third-party risk. The responses from nearly 550 CISOs and cybersecurity leaders worldwide reveal a dangerous gap in organizational preparedness. Key findings include: High Concern: 88% of organizations are worried about supply chain cyber risks. Frequent Attacks: Over 70% experienced a significant third-party cyber incident last year; 5% had 10 or more. Poor Visibility: Less than half of organizations monitor even 50% of their extended supply chain for cyber threats. Passive Response: Only 26% integrate incident response into their third-party risk management (TPRM) programs, often relying on assessments or insurance. Misaligned Responsibilities: When breaches occur, TPRM teams often shift the burden to already overloaded Security Operations Center (SOC) staff.
Supply Chain Cyber Risk
Third-Party Risk Management
China-Nexus ‘LapDogs’ Network Thrives on Backdoored SOHO Devices

Resources

China-Nexus ‘LapDogs’ Network Thrives on Backdoored SOHO Devices
Learn more in this resource.
STRIKE News
What Is Triage in Cybersecurity Incident Response?

Blog

What Is Triage in Cybersecurity Incident Response?
Discover how cybersecurity triage works during incident response. Learn best practices for assessing and prioritizing threats before they escalate.
Building a Vendor Risk Management Program: Strategies for Success

Blog

Building a Vendor Risk Management Program: Strategies for Success
Learn how to build a vendor risk management (VRM) program that aligns with modern cyber threats. Discover essential steps, tools, and continuous monitoring strategies for supply chain protection.
A sneaky cyber espionage campaign is exploiting IoT devices and home office routers – here’s what you need to know

Resources

A sneaky cyber espionage campaign is exploiting IoT devices and home office routers – here’s what you need to know
Learn more in this resource.
STRIKE News
What Is MXToolbox and How Can You Use It Securely?

Blog

What Is MXToolbox and How Can You Use It Securely?
Discover how MXToolbox works for DNS, SPF, and blacklist monitoring, and learn how to use it securely without leaking email infrastructure insights to threat actors.
What Is FIPS 140-3 and Why Does It Matter for Security Compliance?

Blog

What Is FIPS 140-3 and Why Does It Matter for Security Compliance?
Learn what FIPS 140-3 certification entails, why it’s critical for federal and industry cybersecurity compliance, and how to ensure your cryptographic modules meet the standard.
Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign

Blog

Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign
SecurityScorecard’s STRIKE team uncovered a new China-Nexus ORB Network targeting the United States and Southeast Asia. Read the report to gain an in-depth look at the LapDogs ORB network, its custom malware, and its role in cyberespionage.
STRIKE Team
Understanding Third-Party Risk: Identifying and Mitigating External Threats

Blog

Understanding Third-Party Risk: Identifying and Mitigating External Threats
Learn how to identify, assess, and mitigate third-party cybersecurity risks. Discover the most common vulnerabilities, threat actor behavior, and how to monitor threats in 2025.
Sender Policy Framework (SPF): How It Stops Email Spoofing

Blog

Sender Policy Framework (SPF): How It Stops Email Spoofing
Learn how SPF works to prevent email spoofing, how to configure SPF records, and why it’s critical for securing your domain from phishing campaigns.