Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

TITAN ASSESS: AI Pre-fill from Vendor Policies

Video

TITAN ASSESS: AI Pre-fill from Vendor Policies
In this installment of SecurityScorecard’s TITAN demo series, see AI pre-fill from vendor policies in action and find out how much faster your team moves through assessments when the manual work disappears.
Demo Tuesdays
What Is the Third-Party Risk Management Maturity Model

Blog

What Is the Third-Party Risk Management Maturity Model
The third-party risk management maturity model turns vague TPRM goals into measurable stages. See the levels and how to move yours forward.
TITAN WATCH: Introduction

Video

TITAN WATCH: Introduction
In Episode 4 of SecurityScorecard’s Demo Tuesday series, get an introduction to TITAN Watch — and see how security teams are moving from stale, periodic reviews to continuous, always-on intelligence across their entire vendor ecosystem.
Demo Tuesdays
La résilience cyber en 2026: Pourquoi les chaînes d’approvisionnement sont en première ligne
La résilience cyber en 2026: Pourquoi les chaînes d’approvisionnement sont en première ligne
Le rapport Global Cybersecurity Outlook 2026 du Forum économique mondial lance un avertissement clair aux dirigeants des secteurs public et privé: le risque cyber dépasse désormais les frontières du pare-feu. Le secteur public est particulièrement exposé à cette réalité. Les missions gouvernementales dépendent d’un réseau de fournisseurs, de prestataires de services managés, de plateformes cloud
How to Secure Your CI/CD Pipeline

Blog

How to Secure Your CI/CD Pipeline
Your CI/CD pipeline can ship a breach as fast as a feature. Learn the CI/CD pipeline security threats, controls, and practices that close the gap.
The Questionnaire Trap

Ebook

The Questionnaire Trap
Your TPRM program was designed to reduce risk – but bloated questionnaires, annual audit cycles, and vendor fatigue may be doing the opposite. This eBook draws on candid insights from experienced risk management practitioners to help you escape the questionnaire trap and build a smarter, more effective vendor assessment program. Learn how to shift from a checkbox-compliance mindset to an evidence-driven approach that actually reduces third-party risk. We’ll guide you through: Understanding why more questions don’t equal more security – and the data that proves it. Diagnosing the three failure modes that make most questionnaires ineffective. Adopting a documentation-first model that cuts assessment time without sacrificing rigor. Moving from calendar-driven audits to trigger-based TPRM that responds to real risk events. Leveraging AI as a force multiplier – while keeping human judgment where it belongs.
AI Agents – KEV Remediation

Video

AI Agents – KEV Remediation
In Episode 3 of SecurityScorecard’s Demo Tuesday series, see how TITAN AI Agents automate KEV remediation workflows — so your team spends less time triaging and more time closing exposures.
Demo Tuesdays
How Open Source Risk Threatens Your Vendors

Blog

How Open Source Risk Threatens Your Vendors
Open source risk follows every vendor into your supply chain. See where it hides, how attackers exploit it, and what continuous monitoring solves.
How State-Sponsored Cyber Attacks Use Third Parties

Blog

How State-Sponsored Cyber Attacks Use Third Parties
State-sponsored cyber attacks increasingly target vendors to reach high-value organizations. Learn how nation-state actors exploit third parties and how to defend.
TITAN AI Demo Series: Unlocking the Driftnet API for Deeper Third-Party Visibility

Video

TITAN AI Demo Series: Unlocking the Driftnet API for Deeper Third-Party Visibility
In the latest installment of our Demo Tuesday series, learn how the Driftnet API gives TPRM, SOC, and threat hunting teams real-time visibility into third-party exposures before attackers exploit them.
Demo Tuesdays
Identity-Based Attacks and Third-Party Risk

Blog

Identity-Based Attacks and Third-Party Risk
Identity attacks now account for 59% of breaches, and vendors are the fastest-growing entry point. Learn how to protect your supply chain.
The World Cup Has 48 Teams. Adversaries Are Playing Too.

Blog

The World Cup Has 48 Teams. Adversaries Are Playing Too.
During the 2020 Tokyo Olympics, held in 2021 after a pandemic-forced delay,  NTT Corporation recorded approximately 450 million cyberattack attempts targeting Olympic systems. The 2022 FIFA World Cup in Qatar drew similar attention from state-aligned threat actors and opportunistic criminals. The 2026 tournament, spanning three nations, 16 cities, and several million projected visitors, will be
Compliance vs Security: What Passing an Audit Misses

Blog

Compliance vs Security: What Passing an Audit Misses
Compliance vs security explained. A passed audit proves controls existed on one day, not that you are secure. Close the gap.
Beyond the Backlog: Why Tech and Talent Aren’t Fixing Your TPRM Questionnaires

Webinars

Beyond the Backlog: Why Tech and Talent Aren’t Fixing Your TPRM Questionnaires
Learn more in this resource.
What Secure by Design Means for Vendor Vetting

Blog

What Secure by Design Means for Vendor Vetting
Secure by design means building security in from the start. Learn what it means for vendor vetting and how to assess whether your vendors actually follow it.
Mythos and CVE/KEV Management

Video

Mythos and CVE/KEV Management
Check out this quick demo video to see how our new AI agents — like the KEV Remediation Plan Agent — help teams identify exposed vendors, prioritize the vulnerabilities that matter most, and generate remediation guidance in minutes.
Demo Tuesdays
Vendor Offboarding: The Step TPRM Teams Forget

Blog

Vendor Offboarding: The Step TPRM Teams Forget
Vendor offboarding is the stage most teams skip. See why lingering vendor access turns into breach risk, and how to close the gap.
Living Off the Land Attacks Explained

Blog

Living Off the Land Attacks Explained
Living off the land attacks use legitimate system tools to evade detection. Learn how LOTL techniques work, who uses them, and how to reduce your exposure.
How Ransomware as a Service Has Changed

Blog

How Ransomware as a Service Has Changed
Ransomware-as-a-service has transformed who can launch a ransomware attack and how. Learn how the RaaS model works and how to defend your supply chain.
How Cloud Misconfiguration Exposes Vendor Networks

Blog

How Cloud Misconfiguration Exposes Vendor Networks
Cloud misconfiguration is one of the most common causes of data breaches. Learn how vendor cloud misconfigurations create risk and how to reduce your exposure.
What Agentic AI Security Risks Mean for CISOs

Blog

What Agentic AI Security Risks Mean for CISOs
Agentic AI introduces security risks traditional controls weren’t built for. Learn what CISOs need to know about securing autonomous AI systems and supply chains.