Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Third-Party Risk Management Framework: How to Select the Right One

Blog

Third-Party Risk Management Framework: How to Select the Right One
Third parties come with significant cyber security risks. Learn how to select the right risk management framework.
Beyond the Perimeter: Why CISOs Need Threat-Informed TPRM

Blog

Beyond the Perimeter: Why CISOs Need Threat-Informed TPRM
Organizations rely heavily on external vendors and suppliers, creating complex supply chains vital for operations. However, this introduces a new dimension of risk: supply chain attacks move fast. While standard TPRM focuses on compliance, Threat-Informed TPRM is a proactive, data-first defense engine designed to stop attacks before they reach your network. The Growing Threat of
Supply Chain Cyber Risk
Threat-Informed TPRM
Verdane

Case Studies

Verdane
How Verdane improved investment decisions and portfolio company cyber support using SecurityScorecard.
The CEO’s Take: Bridging the Cybersecurity Divide To Address Cyber Risk

Webinars

The CEO’s Take: Bridging the Cybersecurity Divide To Address Cyber Risk
Learn more in this resource.
Simplify and Automate NIS2 TPRM Requirements with SecurityScorecard

Data Sheet

Simplify and Automate NIS2 TPRM Requirements with SecurityScorecard
The Network and Information Systems Directive (NIS 2) is a comprehensive set of regulations adopted by the European Union (EU) to enhance the cybersecurity resilience of critical sectors in the face of increasing ICT risks. The regulation focuses on: Risk management: NIS 2 mandates organizations to implement comprehensive cybersecurity risk management frameworks, including identifying and assessing ICT risks, implementing controls to mitigate these risks, and regularly testing the effectiveness of these controls. ICT cybersecurity incident management: NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and Testing: NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and Third-Party Risk Management (TPRM): NIS 2 requires organizations to establish robust processes for ICT cybersecurity incident management, including incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and In this extended data sheet, we’ll outline these key components of NIS 2 in more depth and guide you through how you can use SecurityScorecard to enable compliance and operational resilience.
Simplify and Automate DORA TPRM Requirements with SecurityScorecard

Data Sheet

Simplify and Automate DORA TPRM Requirements with SecurityScorecard
The Digital Operational Resilience Act (DORA) is a comprehensive set of regulations adopted by the European Union (EU) to enhance the operational resilience of the financial sector in the face of increasing ICT risks. The regulation focuses on: Risk management: It mandates organizations to implement comprehensive risk management frameworks, including identifying and assessing ICT risks, implementing controls to mitigate these risks, and regularly testing the effectiveness of these controls. ICT incident management: DORA requires financial entities to establish robust processes for ICT incident management, encompassing incident detection, response, and reporting. Organizations need to define roles and responsibilities, establish communication protocols, and conduct regular testing to ensure their incident response capabilities are adequate. Testing: The act emphasizes the importance of regular testing, including penetration testing, vulnerability assessments, and business continuity and disaster recovery exercises, to verify the resilience of systems and processes. Third-Party Risk Management (TPRM): DORA places significant emphasis on managing third-party ICT service providers. Organizations must conduct thorough risk assessments, incorporate DORA TPRM requirements into contracts, and continuously monitor the security posture of their third parties. In this extended data sheet, we’ll outline these key components of DORA in more depth and guide you through how you can use SecurityScorecard to enable compliance and operational resilience.
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign

Research

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
During STRIKE’s investigation of Operation 99, our team identified multiple command-and-control (C2)\r\nservers active since September 2024.
STRIKE Team
Operation Phantom Circuit:  North Korea’s Global Data Exfiltration Campaign

Blog

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
In December 2024, a routine software update concealed a global threat. Attackers from the Lazarus Group, based in North Korea, infiltrated trusted development tools, compromising hundreds of victims worldwide. This sophisticated campaign, code-named “Phantom Circuit,” targeted cryptocurrency and technology developers, employing advanced obfuscation techniques through proxy servers in Hasan, Russia.
STRIKE Team
Building a High-Performing Supply Chain Incident Response Team

Webinars

Building a High-Performing Supply Chain Incident Response Team
Supply chain security is no longer an afterthought. With increasing threats and the potential for devastating consequences, organizations must proactively address supply chain risks. In this webinar, we will discuss how a well-structured supply chain incident response team can address these challenges and mitigate risks.
Threat-Informed TPRM
MONOist: 製造業のサプライチェーンセキュリティ対策に欠かせない「TPRM」とは?

メディア掲載

MONOist: 製造業のサプライチェーンセキュリティ対策に欠かせない「TPRM」とは?
Learn more in this resource.
Japanese
日東工業株式会社 様

事例

日東工業株式会社 様
株式会社ネットワークバリューコンポネンツによる導入事例
Japanese
The CISO’s Take: Securing the Future of Financial Services & More

Webinars

The CISO’s Take: Securing the Future of Financial Services & More
Learn more in this resource.
SecurityScorecard Report: 58% of Breaches Impacting Leading U.S. Federal Contractors Caused by Third-Party Attack Vectors

Press

SecurityScorecard Report: 58% of Breaches Impacting Leading U.S. Federal Contractors Caused by Third-Party Attack Vectors
Report highlights the urgent need for federal contractors to address third-party risks as cybersecurity gaps threaten national security
5 Reasons to Integrate Continuous Monitoring into Your TPRM Program

Blog

5 Reasons to Integrate Continuous Monitoring into Your TPRM Program
Learn 5 reasons your organization should integrate continuous monitoring into their third-party risk management program. Read SecurityScorecard’s blog
Security Assessment of the Top 100 U.S. Gov’t Contractors

Research

Security Assessment of the Top 100 U.S. Gov’t Contractors
Federal contractors are integral to supporting the operations of the U.S. government. However, as these contractors face evolving cyber threats, it’s critical to understand the vulnerabilities that could affect their ability to secure sensitive data and provide essential services. This report examines the security ratings and breach histories of the top 100 U.S. government contractors, uncovering significant gaps that could disrupt government functions and expose sensitive information. Key Findings: 58% of breaches were caused by third-party vulnerabilities, posing a direct threat to both contractors and the government. 35% of contractors had at least one publicly reported breach, with some experiencing multiple incidents, indicating a recurring security problem. Ransomware groups were responsible for 41.25% of breaches, and the frequency of attacks on third-party vendors (46.5%) is rising. 28% of contractors had malware infections or compromised devices, showing a need for stronger internal security measures. Defense and intelligence contractors had the highest security ratings, but technology and telecommunications contractors were among the lowest.   Download this report to learn more about the current landscape and discover practical steps that can be taken to enhance the security of the federal supply chain.
What is the Threat Landscape?

Blog

What is the Threat Landscape?
Discover the current threat landscape and learn how to identify, assess, and mitigate evolving cyber risks to protect your organization from potential attacks.
What Is an Attack Vector? 20 Common Ways Hackers Break In and How to Prevent Them

Blog

What Is an Attack Vector? 20 Common Ways Hackers Break In and How to Prevent Them
Learn the 20 most common attack vectors hackers use to breach organizations and the best prevention strategies cybersecurity teams can adopt today.
Attack Surface Management
Tech Center
Operation 99: North Korea’s Cyber Assault on Software Developers

Blog

Operation 99: North Korea’s Cyber Assault on Software Developers
On January 9, the SecurityScorecard STRIKE team uncovered Operation 99, a cyberattack by the Lazarus Group, North Korea’s state-sponsored hacking unit.
STRIKE Team
How Security Ratings Help Build Strong Business Relationships

Blog

How Security Ratings Help Build Strong Business Relationships
See how security ratings allow you to strengthen business relationships by giving you the information you need to enable stronger business outcomes. Learn more about security ratings for business.
Securing Patient Data: A Guide to Managed Services for Supply Chain Detection and Response in Healthcare

Blog

Securing Patient Data: A Guide to Managed Services for Supply Chain Detection and Response in Healthcare
Patient data is among the most sensitive and valuable information in the healthcare industry. A single breach can have devastating consequences. Learn how a managed service for SCDR can help.
Threat-Informed TPRM
Securing Your Financial Ecosystem: A Guide to TPRM Managed Services

Blog

Securing Your Financial Ecosystem: A Guide to TPRM Managed Services
Learn more about the critical role of Managed Services for Third-Party Risk Management (TPRM) for your financial institution.
Threat-Informed TPRM