Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Blog
CISOs: The Perfect SCORE With Your Board
Boards don’t operate in threat models and tech stacks. They operate in risk, revenue, and accountability. And if you want their support, you need to meet them there. SecurityScorecard created the SCORE framework to help CISOs turn cybersecurity into a board-level conversation that gets results.
Executive Viewpoint
Blog
SIM Card Hacking: What It Is, How It Works, and How to Protect Yourself
SIM cards might seem like harmless pieces of plastic, but they’re often a gateway for serious cyber attacks. When hackers take over your mobile number, they can intercept private data, bypass security controls, and even drain your bank account.\r\n
Cyber Threat Intelligence
Enterprise Cyber Risk
Government
メディア掲載
EnterpriseZine: 日本企業のアキレス腱、サプライチェーンをどう守る
Learn more in this resource.
Japanese
Blog
Scorecarder Spotlight: Noor Al-Baker
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Noor Al-Baker!
Scorecarder Spotlight
STRIKE
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590)
STRIKE Alert
Blog
SecurityScorecard In The News Q1 2025
Catch up on SecurityScorecard press coverage from Q1 2025, including TV interviews, global report-driven media coverage, North America, EMEA, and APAC press mentions, and executive bylines examining third-party breach trends, software supply chain attacks, nation-state cyber activity, and regulatory readiness.
Press
SecurityScorecard Announces Strategic Partnership with Willis
SecurityScorecard announced today a strategic partnership with Willis (a WTW business), a leading global advisory, broking and solutions company. Building on a long-standing relationship, this collaboration aims to enhance cyber risk quantification, improve insurance modeling, and strengthen enterprise security strategies for organizations worldwide.
メディア掲載
ITmedia: 北朝鮮の「Lazarus」による世界規模の攻撃 最新調査で「4つの事実」が判明
Learn more in this resource.
Japanese
Press
北朝鮮による世界規模のデータ窃取攻撃に関する最新調査レポート「Operation Phantom Circuit」を発表
Learn more in this resource.
Japanese
Press
SecurityScorecard 2025 Global Third-Party Breach Report Reveals Surge in Vendor-Driven Attacks
SecurityScorecard today released the 2025 Global Third-Party Breach Report. Using the world’s largest proprietary risk and threat data set, SecurityScorecard’s STRIKE Threat Intelligence Unit analyzed 1,000 breaches across industries and regions to uncover key attack patterns, measure the impact of third-party security failures and identify the most commonly exploited vendor relationships.
Resources
Global Third Party Breach Report
Actionable insights to reduce third-party cyber risks.
This report analyzes 1,000 breaches to provide security leaders with critical insights into industry-specific risks, attack methods, and threat actor tactics. Findings are based on SecurityScorecard’s proprietary risk and threat dataset.
Key Findings:
35.5% of breaches in 2024 were linked to third-party access, a 6.5% increase from 2023. The most frequently compromised vendors provided IT services, cloud platforms, and software solutions, with file transfer software vulnerabilities being the most exploited attack vector.
41.4% of ransomware attacks involved third-party access, with C10p responsible for the largest share, primarily exploiting file transfer and remote access software.
Retail (52.4%), technology (46.75%), and energy (46.7%) experienced the highest third-party breach rates, with stolen credentials and software supply chain compromises as primary attack vectors.
Two exploited file transfer software vulnerabilities accounted for 63.5% of all third-party vulnerability-driven breaches, impacting thousands of organizations.
Download the report now by filling out this form.
White Papers
Simplify and Automate APRA Prudential Standard CPS 230 TPRM Requirements with SecurityScorecard
Executive Summary
The Prudential Standard CPS 230, issued by the Australian Prudential Regulation Authority (APRA), is a regulatory framework designed to strengthen operational risk management, business continuity, and third-party risk management (TPRM) for APRA-regulated entities, including banks, insurers, and superannuation funds. CPS 230 aims to ensure organizations have comprehensive risk management frameworks to identify, assess, and mitigate operational and third-party risks, ensuring business continuity and resilience in the face of potential disruptions. Organizations must comply with CPS 230’s requirements by July 1, 2025.
CPS 230 focuses on enhancing operational resilience across financial and insurance sectors, with particular emphasis on third-party risk management to ensure service continuity and reduce risks associated with outsourced providers.
Research Reports
北朝鮮による世界規模のデータ窃取攻撃
北朝鮮のサイバー攻撃「Operation Phantom Circuit」の全貌を解明
最新レポートでは、北朝鮮のハッカー集団「Lazarus」による世界規模のサイバー攻撃の手口を詳細に分析。 サプライチェーン攻撃を通じて正規ソフトウェアにバックドアを仕込み、企業や開発者の機密データを巧妙に奪取する手法が明らかになりました。
233件以上の被害が確認された本攻撃の詳細や、サプライチェーンセキュリティを強化するための対策をレポートでご紹介。レポートの完全版をダウンロードして、詳細なデータと分析をご覧ください。
Japanese
Blog
What is Supply Chain Detection and Response (SCDR)?
Supply Chain Detection and Response (SCDR) is a new cybersecurity framework that identifies, prioritizes, and remediates vulnerabilities across an organization’s vendor ecosystem. Its purpose is preventing supply chain attacks from threat actors and mitigating concentration risk when critical providers experience outages or security failures.
Threat-Informed TPRM
Blog
Automating Vendor Risk Management and Assessments
Automated vendor risk assessments provide visibility into third-party vendors’ cybersecurity and enhance the third-party risk management process. Learn more.
Webinars
CPE | Cyber Risk Quantification: Measuring and Managing the Unseen Threats
Learn more in this resource.
Blog
The Principles for Fair & Accurate Security Ratings: A Focus on Confidentiality
Our Security ratings align with the Principles for Fair & Accurate Security Ratings, published by the US Chamber of Commerce. As part of this effort we strive to educate the cybersecurity community on how our products align with these important principles.
Blog
Scorecarder Spotlight: Luciano Bargmann
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Luciano Bargmann!
Scorecarder Spotlight
Blog
3 Tangible Benefits of an A Rating
Security ratings are a standard in cybersecurity. Many organizations rely on them to manage their security programs and they create ROI for the organization. Despite the potential benefits, it can be challenging for organizations who are evaluating different security ratings options to determine the value they will get from them.
Blog
Odyssey.conf 2025: Charting the Course for Cyber Resilience
Last week, SecurityScorecard hosted our second annual Odyssey.conf in Miami, Florida. This year’s conference focused on cyber resilience, providing attendees with actionable insights and cutting-edge strategies to navigate the ever-evolving threat landscape.
Threat-Informed TPRM
Blog
From Reactive to Resilient: A New Mindset for Supply Chain Cybersecurity
Key takeaways from a recent webinar featuring SecurityScorecard CISO, Steve Cobb, on how organizations can strengthen their cyber resilience in the face of evolving threats.
Threat-Informed TPRM