Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

MAX Managed Questionnaires

Video

MAX Managed Questionnaires
In this installment of SecurityScorecard’s Demo Tuesday series, see MAX Managed Questionnaires in action and what your security program looks like when your team is free to focus on risk strategy instead of assessment admin.
Demo Tuesdays
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

Blog

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
Meeting BNM RMiT 2025: A Guide to Third-Party & Supply Chain Cyber Risk Requirements

White Papers

Meeting BNM RMiT 2025: A Guide to Third-Party & Supply Chain Cyber Risk Requirements
On 28 November 2025, Bank Negara Malaysia issued one of the most significant overhauls to Malaysian financial sector cybersecurity regulation in recent years. The revised Risk Management in Technology (RMiT) policy expands who’s in scope, mandates continuous monitoring of third-party vendors, introduces SBOM requirements, and enforces stricter SLAs for incident disclosure and remediation. This white paper breaks down what changed, what it means for your third-party risk program, and how to operationalise and evidence the new obligations at scale. 28 Nov 2025 — the date RMiT was revised and reissued by BNM New entities in scope — including certain non-bank merchant acquirers and intermediary remittance institutions Continuous monitoring now mandatory — periodic, questionnaire-based assessment is explicitly no longer sufficient 12M+ entities rated across SecurityScorecard’s global intelligence network RMiT 2025 isn’t a checkbox exercise. It’s a shift in how cyber risk is governed.
TITAN ASSESS: Send questionnaires

Video

TITAN ASSESS: Send questionnaires
In Episode 5 of SecurityScorecard’s Demo Tuesday series, see how TITAN Assess streamlines the entire questionnaire outreach process — so your team spends less time on admin and more time acting on what vendors actually tell you.
Demo Tuesdays
TITAN ASSESS: Building an Assessment Template with Titan Agent

Video

TITAN ASSESS: Building an Assessment Template with Titan Agent
In this installment of SecurityScorecard’s TITAN demo series, see how TITAN Agent uses AI to build customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.
Demo Tuesdays
TITAN ASSESS: AI Pre-fill from Vendor Policies

Video

TITAN ASSESS: AI Pre-fill from Vendor Policies
In this installment of SecurityScorecard’s TITAN demo series, see AI pre-fill from vendor policies in action and find out how much faster your team moves through assessments when the manual work disappears.
Demo Tuesdays
TITAN WATCH: Introduction

Video

TITAN WATCH: Introduction
In Episode 4 of SecurityScorecard’s Demo Tuesday series, get an introduction to TITAN Watch — and see how security teams are moving from stale, periodic reviews to continuous, always-on intelligence across their entire vendor ecosystem.
Demo Tuesdays
La résilience cyber en 2026: Pourquoi les chaînes d’approvisionnement sont en première ligne
La résilience cyber en 2026: Pourquoi les chaînes d’approvisionnement sont en première ligne
Le rapport Global Cybersecurity Outlook 2026 du Forum économique mondial lance un avertissement clair aux dirigeants des secteurs public et privé: le risque cyber dépasse désormais les frontières du pare-feu. Le secteur public est particulièrement exposé à cette réalité. Les missions gouvernementales dépendent d’un réseau de fournisseurs, de prestataires de services managés, de plateformes cloud
The Questionnaire Trap

Ebook

The Questionnaire Trap
Your TPRM program was designed to reduce risk – but bloated questionnaires, annual audit cycles, and vendor fatigue may be doing the opposite. This eBook draws on candid insights from experienced risk management practitioners to help you escape the questionnaire trap and build a smarter, more effective vendor assessment program. Learn how to shift from a checkbox-compliance mindset to an evidence-driven approach that actually reduces third-party risk. We’ll guide you through: Understanding why more questions don’t equal more security – and the data that proves it. Diagnosing the three failure modes that make most questionnaires ineffective. Adopting a documentation-first model that cuts assessment time without sacrificing rigor. Moving from calendar-driven audits to trigger-based TPRM that responds to real risk events. Leveraging AI as a force multiplier – while keeping human judgment where it belongs.
AI Agents – KEV Remediation

Video

AI Agents – KEV Remediation
In Episode 3 of SecurityScorecard’s Demo Tuesday series, see how TITAN AI Agents automate KEV remediation workflows — so your team spends less time triaging and more time closing exposures.
Demo Tuesdays
TITAN AI Demo Series: Unlocking the Driftnet API for Deeper Third-Party Visibility

Video

TITAN AI Demo Series: Unlocking the Driftnet API for Deeper Third-Party Visibility
In the latest installment of our Demo Tuesday series, learn how the Driftnet API gives TPRM, SOC, and threat hunting teams real-time visibility into third-party exposures before attackers exploit them.
Demo Tuesdays
The World Cup Has 48 Teams. Adversaries Are Playing Too.

Blog

The World Cup Has 48 Teams. Adversaries Are Playing Too.
During the 2020 Tokyo Olympics, held in 2021 after a pandemic-forced delay,  NTT Corporation recorded approximately 450 million cyberattack attempts targeting Olympic systems. The 2022 FIFA World Cup in Qatar drew similar attention from state-aligned threat actors and opportunistic criminals. The 2026 tournament, spanning three nations, 16 cities, and several million projected visitors, will be
Beyond the Backlog: Why Tech and Talent Aren’t Fixing Your TPRM Questionnaires

Webinars

Beyond the Backlog: Why Tech and Talent Aren’t Fixing Your TPRM Questionnaires
Learn more in this resource.
Mythos and CVE/KEV Management

Video

Mythos and CVE/KEV Management
Check out this quick demo video to see how our new AI agents — like the KEV Remediation Plan Agent — help teams identify exposed vendors, prioritize the vulnerabilities that matter most, and generate remediation guidance in minutes.
Demo Tuesdays
TPRM: De la gestion statique au pilotage en temps réel

White Papers

TPRM: De la gestion statique au pilotage en temps réel
Moderniser la gestion des risques tiers grâce à l’IA et à la Threat Intelligence Pendant des décennies, la gestion des risques tiers (TPRM) s’est résumée à un exercice statique, réalisé à un instant précis, par fichiers et questionnaires interminables. Mais aujourd’hui, cette approche constitue un risque opérationnel majeur. À mesure que se multiplient les dépendances, une seule vulnérabilité enfouie dans une bibliothèque logicielle peut déclencher une panne mondiale en quelques secondes. Alors que 90 % des responsables cyber se disent convaincus de leur résilience, à peine 22 % des programmes TPRM internes évaluent plus de la moitié de leur écosystème de fournisseurs. Pour combler cet écart, les organisations doivent abandonner la conformité réactive au profit d’une intelligence continue, où les données en temps réel et l’analyse prédictive remplacent l’audit annuel obsolète. Téléchargez ce guide pour découvrir: Les trois piliers du TPRM moderne : intégrer la télémétrie en temps réel, les signaux issus des adversaires et une orchestration pilotée par l’IA pour dépasser la conformité purement statique. Réduire drastiquement les délais d’intégration : réduire le temps d’intégration d’un nouveau fournisseur de 42 jours à seulement 42 heures, grâce à l’automatisation et le pré-remplissage intelligent, pilotés par l’IA. La Threat Intelligence comme multiplicateur de force : Associer une vision externe (Outside-In) à une vision interne pour identifier en temps réel les expositions zero-day et les risques de concentration. Le virage agentique : évoluer vers des agents IA capables de surveiller les risques de manière autonome et de déclencher des demandes de remédiation sans intervention humaine.
Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline

Blog

Building Trust In Data: How We Added Data Quality Checks To Our Scoring Data Pipeline
Data quality is foundational to customer confidence. At SecurityScorecard, our Scoring platform processes data for thousands of companies daily. That scale requires more than strong engineering discipline. It requires clear validation patterns, consistent checks, and observable results across every critical stage of the pipeline. This post shares how our data engineering team uses Great Expectations,
SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot

Report

SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot
SecurityScorecard researchers used Driftnet’s internet-scale discovery capabilities to analyze the network footprint of a small U.S. municipal utility provider that also operates as the town’s internet service provider (ISP). The investigation identified widespread exposure across internet-facing systems, including vulnerable surveillance equipment, exposed Industrial Control Systems (ICS), weak encryption configurations, and End-of-Life (EoL) Windows devices. The utility provider operates its own Autonomous System (AS), meaning internet connectivity and critical infrastructure services exist within the same broader operational environment. This convergence creates a concentrated point of failure where disruption to one service can affect others across the community. Over a six-month period, Driftnet identified 1,498 services across 692 IP addresses. Of those, 446 IPs (64%) exhibited at least one technical issue that increased exposure risk. SecurityScorecard’s Driftnet engine identifies 150% more internet-facing services than previous scanning methodologies, uncovering exposures traditional approaches miss. Findings included: 30 instances of Dahua and Hikvision surveillance equipment inside the entire footprint of the utilities AS. Banned internet protocol (IP) cameras could enable Man-in-the-Middle (MitM) attacks, Distributed Denial of Service (DDoS) attacks, malware-based campaigns, and more. Exposed ICS, SCADA, and OT-related services directly reachable from the internet. At least three /24 clusters hosting ICS or IOT services and consumer devices on the same broadcast domain. Weak or misconfigured encryption across 382 IP addresses, in addition to cleartext FTP and HTTP and unrecognized Certificate Authorities. EoL Windows hosts reachable via Server Message Block (SMB) and NetBIOS. A relic from the past, rarely ever makes an appearance outside of OT environments. 25 Known Exploited Vulnerabilities (KEVs) identified across internet-facing services. Convergence of a utility and ISP creates a single point of failure. Power delivery and internet reside on the same AS. Incidents on one impacts the other. The research also identified multiple network segments where consumer-grade devices, surveillance systems, and ICS-related technologies operated within the same local network environment. This lack of segmentation increases the likelihood that compromise of a lower-security system could enable lateral movement toward operational infrastructure. To understand the full scope of the findings, download the full report today to see how Driftnet delivers the visibility organizations need to move from reactive security to continuous, threat-informed defense.
STRIKE Alert
STRIKE News
STRIKE Team
SecurityScorecard Acquires Driftnet to Power Real-Time, Threat-Informed Third-Party Risk Management

Press

SecurityScorecard Acquires Driftnet to Power Real-Time, Threat-Informed Third-Party Risk Management
NEW YORK– May 14, 2026 – SecurityScorecard, the global leader in threat-informed third-party risk management (TPRM), today announced it has completed the acquisition of Driftnet, a pioneer in global internet scanning and next-generation threat intelligence. This acquisition will bring Driftnet’s high-fidelity internet discovery engine into SecurityScorecard’s TITAN AI platform, giving TPRM, Security Operations, and threat
A Roadmap to Modern TPRM

Ebook

A Roadmap to Modern TPRM
Understanding the 4 Stages, the Gaps, and TPRM Priorities for Various Stakeholders Traditional Third-Party Risk Management (TPRM) programs, relying on static data and annual assessments, are failing to secure supply chains, exposing organizations to the 35%+ of breaches originating from third parties. This eBook provides a roadmap to understanding the disconnect between modern threats and
The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)

Blog

The Four Questionnaires Your TPRM Team Is Managing (And Struggling to Keep Up With)
The questionnaire is the workhorse of third-party risk management. But not all questionnaires are the same and treating them like they are is one of the reasons TPRM programs fall behind. Here’s a clear-eyed look at the four types your team is juggling. 1. Initial / Intake Questionnaires Also called: Inherent Risk Questionnaire (IRQ), Vendor
Unrivaled Global Telemetry for Proactive Defense and Threat Hunting

Data Sheet

Unrivaled Global Telemetry for Proactive Defense and Threat Hunting
Learn more in this resource.