Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

North Korean hackers impersonated recruiters to steal credentials from over 1,500 developer systems

Resources

North Korean hackers impersonated recruiters to steal credentials from over 1,500 developer systems
Learn more in this resource.
STRIKE News
Third-Party Risk Management Regulations: What You Should Know

Blog

Third-Party Risk Management Regulations: What You Should Know
Third-party risk management regulations may seem like red tape nuisance at first, but these regulations ultimately reduce your organization’s risk as well. Learn more.
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages

Resources

New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
Learn more in this resource.
STRIKE News
保険業界に影響を及ぼす侵害の59%はサードパーティへの攻撃ベクトルに起因

Press

保険業界に影響を及ぼす侵害の59%はサードパーティへの攻撃ベクトルに起因
Learn more in this resource.
Japanese
Lazarus Group Targets Developers Through NPM Packages and Supply Chain Attacks

Blog

Lazarus Group Targets Developers Through NPM Packages and Supply Chain Attacks
North Korea’s Lazarus Group is evolving its tactics again. The latest campaign, dubbed Operation Marstech Mayhem, introduces an advanced implant named “Marstech1.”
STRIKE Team
Lazarus Group is Infecting Open-Source Code. Are You at Risk?

Research

Lazarus Group is Infecting Open-Source Code. Are You at Risk?
North Korea’s Lazarus Group is hiding malware inside GitHub repositories and NPM packages, compromising developers and cryptocurrency platforms. Their targets: your code, your wallets, your users.
STRIKE Team
Breaking Silos with SCDR: How SOCs & TPRM Teams Drive Integrated Cyber Strategies

Webinars

Breaking Silos with SCDR: How SOCs & TPRM Teams Drive Integrated Cyber Strategies
Learn more in this resource.
Threat-Informed TPRM
SecurityScorecard Reaffirms FedRAMP and Achieves StateRAMP Ready Status

Press

SecurityScorecard Reaffirms FedRAMP and Achieves StateRAMP Ready Status
U.S. federal, state and local agencies to adopt SecurityScorecard SCDR to secure supply chains with confidence
A Deep Peek at DeepSeek

Blog

A Deep Peek at DeepSeek
DeepSeek’s rapid ascent in the AI space has made it impossible to ignore. Its sophisticated models and AI assistant have captured global attention. And, while headlines focus on DeepSeek’s capabilities, STRIKE research exposes critical security flaws, hidden data flows, and unanswered questions about who has access to the data and why.
STRIKE Team
Insurance Carriers Face Unprecedented Supply Chain Cyber Threats

Research

Insurance Carriers Face Unprecedented Supply Chain Cyber Threats
SecurityScorecard’s analysis of 150 leading insurance companies exposes a critical weakness: even carriers with robust security are being compromised through their supply chain partners. Our data reveals that threat actors are deliberately exploiting lower-scoring vendors to breach otherwise well-defended insurance organizations. Key Findings: Third-party breach rate hits record 59% in insurance – more than double the global average, with ransomware dominating the attack landscape Insurance carriers outperform vendors in security scores but face heightened risk through weaker supply chain partners Cross-industry software vulnerabilities caused 37% of breaches – nearly triple the rate of insurance-specific software issues U.S. carriers face disproportionate targeting despite strong security postures, with 79% of multi-breach victims being U.S.-based   Download the Report and get the detailed analysis and practical recommendations for strengthening your supply chain security
SecurityScorecard Report: 59% of Breaches Impacting Insurance Sector Caused by Third-Party Attack Vectors

Press

SecurityScorecard Report: 59% of Breaches Impacting Insurance Sector Caused by Third-Party Attack Vectors
Report highlights need to address third-party risks as cybersecurity gaps threaten critical services and policyholder trust.
ScanNetSecurity: 「SecurityScorecard」が自らを ASM と名乗らない理由

メディア掲載

ScanNetSecurity: 「SecurityScorecard」が自らを ASM と名乗らない理由
Learn more in this resource.
Japanese
Max Data Processing Agreement

Resources

Max Data Processing Agreement
Learn more in this resource.
Third-Party Risk Management Framework: How to Select the Right One

Blog

Third-Party Risk Management Framework: How to Select the Right One
Third parties come with significant cyber security risks. Learn how to select the right risk management framework.
Beyond the Perimeter: Why CISOs Need Threat-Informed TPRM

Blog

Beyond the Perimeter: Why CISOs Need Threat-Informed TPRM
Organizations rely heavily on external vendors and suppliers, creating complex supply chains vital for operations. However, this introduces a new dimension of risk: supply chain attacks move fast. While standard TPRM focuses on compliance, Threat-Informed TPRM is a proactive, data-first defense engine designed to stop attacks before they reach your network. The Growing Threat of
Supply Chain Cyber Risk
Threat-Informed TPRM
Verdane

Case Studies

Verdane
How Verdane improved investment decisions and portfolio company cyber support using SecurityScorecard.
The CEO’s Take: Bridging the Cybersecurity Divide To Address Cyber Risk

Webinars

The CEO’s Take: Bridging the Cybersecurity Divide To Address Cyber Risk
Learn more in this resource.
Simplify and Automate NIS2 TPRM Requirements with SecurityScorecard

Data Sheet

Simplify and Automate NIS2 TPRM Requirements with SecurityScorecard
The Network and Information Systems Directive (NIS 2) is a comprehensive set of regulations adopted by the European Union (EU) to enhance the cybersecurity resilience of critical sectors in the face of increasing ICT risks. The regulation focuses on: Risk management: NIS 2 mandates organizations to implement comprehensive cybersecurity risk management frameworks, including identifying and assessing ICT risks, implementing controls to mitigate these risks, and regularly testing the effectiveness of these controls. ICT cybersecurity incident management: NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and Testing: NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and Third-Party Risk Management (TPRM): NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and In this extended data sheet, we’ll outline these key components of NIS 2 in more depth and guide you through how you can use SecurityScorecard to enable compliance and operational resilience.
Simplify and Automate DORA TPRM Requirements with SecurityScorecard

Data Sheet

Simplify and Automate DORA TPRM Requirements with SecurityScorecard
The Digital Operational Resilience Act (DORA) is a comprehensive set of regulations adopted by the European Union (EU) to enhance the operational resilience of the financial sector in the face of increasing ICT risks. The regulation focuses on: Risk management: It mandates organizations to implement comprehensive risk management frameworks, including identifying and assessing ICT risks, implementing controls to mitigate these risks, and regularly testing the effectiveness of these controls. ICT incident management: DORA requires financial entities to establish robust processes for ICT incident management, encompassing incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and conduct regular testing to ensure their incident response capabilities are adequate. Testing: The act emphasizes the importance of regular testing, including penetration testing, vulnerability assessments, and business continuity and disaster recovery exercises, to verify the resilience of systems and processes. Third-Party Risk Management (TPRM): DORA places significant emphasis on managing third-party ICT service providers. Organizations must conduct thorough risk assessments, incorporate DORA TPRM requirements into contracts, and continuously monitor the security posture of their third parties. In this extended data sheet, we’ll outline these key components of DORA in more depth and guide you through how you can use SecurityScorecard to enable compliance and operational resilience.
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign

Research

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
During STRIKE’s investigation of Operation 99, our team identified multiple command-and-control (C2)\r\nservers active since September 2024.
STRIKE Team
Operation Phantom Circuit:  North Korea’s Global Data Exfiltration Campaign

Blog

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
In December 2024, a routine software update concealed a global threat. Attackers from the Lazarus Group, based in North Korea, infiltrated trusted development tools, compromising hundreds of victims worldwide. This sophisticated campaign, code-named “Phantom Circuit,” targeted cryptocurrency and technology developers, employing advanced obfuscation techniques through proxy servers in Hasan, Russia.
STRIKE Team