Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

NRI セキュア: サイバー格付けがセキュリティ経営にもたらす価値と、導入前の注意点を徹底解説

他社様のブログ

NRI セキュア: サイバー格付けがセキュリティ経営にもたらす価値と、導入前の注意点を徹底解説
Learn more in this resource.
Japanese
5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk

Blog

5 Lessons from the Optus Data Breach for Telecom and Third-Party Risk
Explore the impact of the Optus data breach and why CISOs must rethink third-party and telecom security in today’s interconnected threat landscape.
Enterprise Cyber Risk
GRC
Third-Party Risk Management
Navigating Supply Chain Cyber Hygiene: DORA & NIS2 in the Spotlight

Event

Navigating Supply Chain Cyber Hygiene: DORA & NIS2 in the Spotlight
Learn more in this resource.
2025 Top 20 Must Read Resources to Stay Updated on Cybersecurity Threats and Trends

Blog

2025 Top 20 Must Read Resources to Stay Updated on Cybersecurity Threats and Trends
Cut through the noise with expert-trusted cybersecurity resources designed to inform, protect, and empower enterprise security leaders.
Cyber Threat Intelligence
GRC
Third-Party Risk Management
SOX Compliance Checklist: What Security Teams Need to Know in 2025

Blog

SOX Compliance Checklist: What Security Teams Need to Know in 2025
Explore our 2025 SOX compliance checklist for cybersecurity leaders. Learn key requirements, reporting timelines, and how to secure third-party risk.
Enterprise Cyber Risk
GRC
Third-Party Risk Management
Secure More, Pay Less: Up to 25% Off Cyber Insurance Premiums with SecurityScorecard

Resources

Secure More, Pay Less: Up to 25% Off Cyber Insurance Premiums with SecurityScorecard
Organizations using SecurityScorecard reduce their cyber risk — and their premiums. Our platform delivers continuous, third-party validated cybersecurity insights that lower the likelihood and impact of a third-party breach. By proactively managing your supply chain risk, you unlock measurable savings during your next cyber insurance renewal. Download the offer today and ask your broker to submit it to your Cyber Insurance underwriter ahead of your next renewal to claim your discount.
How Much Do Healthcare Data Breaches Really Cost?

Blog

How Much Do Healthcare Data Breaches Really Cost?
Learn from the most devastating healthcare data breaches in U.S. history—and how to protect your organization’s PHI, PII, and patient trust.
Cyber Threat Intelligence
Enterprise Cyber Risk
Third-Party Risk Management
Navigating Systemic Risks: Strengthening Third-Party & Supply Chain Resilience

Webinars

Navigating Systemic Risks: Strengthening Third-Party & Supply Chain Resilience
Learn more in this resource.
Cybersecurity Laws in the UK: What Businesses Need to Know in 2025

Blog

Cybersecurity Laws in the UK: What Businesses Need to Know in 2025
Understand how evolving UK regulations shape your cyber strategy—and how to stay compliant and resilient across your digital ecosystem.
Compliance
Cybersecurity
Enterprise Cyber Risk
CISOs: The Perfect SCORE With Your Board

Blog

CISOs: The Perfect SCORE With Your Board
Boards don’t operate in threat models and tech stacks. They operate in risk, revenue, and accountability. And if you want their support, you need to meet them there. SecurityScorecard created the SCORE framework to help CISOs turn cybersecurity into a board-level conversation that gets results.
Executive Viewpoint
SIM Card Hacking: What It Is, How It Works, and How to Protect Yourself

Blog

SIM Card Hacking: What It Is, How It Works, and How to Protect Yourself
SIM cards might seem like harmless pieces of plastic, but they’re often a gateway for serious cyber attacks. When hackers take over your mobile number, they can intercept private data, bypass security controls, and even drain your bank account.\r\n
Cyber Threat Intelligence
Enterprise Cyber Risk
Government
EnterpriseZine: 日本企業のアキレス腱、サプライチェーンをどう守る

メディア掲載

EnterpriseZine: 日本企業のアキレス腱、サプライチェーンをどう守る
Learn more in this resource.
Japanese
Scorecarder Spotlight: Noor Al-Baker

Blog

Scorecarder Spotlight: Noor Al-Baker
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Noor Al-Baker!
Scorecarder Spotlight
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV

STRIKE

SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590)
STRIKE Alert
SecurityScorecard In The News Q1 2025

Blog

SecurityScorecard In The News Q1 2025
Catch up on SecurityScorecard press coverage from Q1 2025, including TV interviews, global report-driven media coverage, North America, EMEA, and APAC press mentions, and executive bylines examining third-party breach trends, software supply chain attacks, nation-state cyber activity, and regulatory readiness.
SecurityScorecard Announces Strategic Partnership with Willis

Press

SecurityScorecard Announces Strategic Partnership with Willis
SecurityScorecard announced today a strategic partnership with Willis (a WTW business), a leading global advisory, broking and solutions company. Building on a long-standing relationship, this collaboration aims to enhance cyber risk quantification, improve insurance modeling, and strengthen enterprise security strategies for organizations worldwide.
ITmedia: 北朝鮮の「Lazarus」による世界規模の攻撃 最新調査で「4つの事実」が判明

メディア掲載

ITmedia: 北朝鮮の「Lazarus」による世界規模の攻撃 最新調査で「4つの事実」が判明
Learn more in this resource.
Japanese
北朝鮮による世界規模のデータ窃取攻撃に関する最新調査レポート「Operation Phantom Circuit」を発表

Press

北朝鮮による世界規模のデータ窃取攻撃に関する最新調査レポート「Operation Phantom Circuit」を発表
Learn more in this resource.
Japanese
SecurityScorecard 2025 Global Third-Party Breach Report Reveals Surge in Vendor-Driven Attacks

Press

SecurityScorecard 2025 Global Third-Party Breach Report Reveals Surge in Vendor-Driven Attacks
SecurityScorecard today released the 2025 Global Third-Party Breach Report. Using the world’s largest proprietary risk and threat data set, SecurityScorecard’s STRIKE Threat Intelligence Unit analyzed 1,000 breaches across industries and regions to uncover key attack patterns, measure the impact of third-party security failures and identify the most commonly exploited vendor relationships.
Global Third Party Breach Report

Resources

Global Third Party Breach Report
Actionable insights to reduce third-party cyber risks. This report analyzes 1,000 breaches to provide security leaders with critical insights into industry-specific risks, attack methods, and threat actor tactics. Findings are based on SecurityScorecard’s proprietary risk and threat dataset. Key Findings: 35.5% of breaches in 2024 were linked to third-party access, a 6.5% increase from 2023. The most frequently compromised vendors provided IT services, cloud platforms, and software solutions, with file transfer software vulnerabilities being the most exploited attack vector. 41.4% of ransomware attacks involved third-party access, with C10p responsible for the largest share, primarily exploiting file transfer and remote access software. Retail (52.4%), technology (46.75%), and energy (46.7%) experienced the highest third-party breach rates, with stolen credentials and software supply chain compromises as primary attack vectors. Two exploited file transfer software vulnerabilities accounted for 63.5% of all third-party vulnerability-driven breaches, impacting thousands of organizations.   Download the report now by filling out this form.
Simplify and Automate APRA Prudential Standard CPS 230 TPRM Requirements with SecurityScorecard

White Papers

Simplify and Automate APRA Prudential Standard CPS 230 TPRM Requirements with SecurityScorecard
Executive Summary The Prudential Standard CPS 230, issued by the Australian Prudential Regulation Authority (APRA), is a regulatory framework designed to strengthen operational risk management, business continuity, and third-party risk management (TPRM) for APRA-regulated entities, including banks, insurers, and superannuation funds. CPS 230 aims to ensure organizations have comprehensive risk management frameworks to identify, assess, and mitigate operational and third-party risks, ensuring business continuity and resilience in the face of potential disruptions. Organizations must comply with CPS 230’s requirements by July 1, 2025. CPS 230 focuses on enhancing operational resilience across financial and insurance sectors, with particular emphasis on third-party risk management to ensure service continuity and reduce risks associated with outsourced providers.