Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Resources
Address issue findings in your Scorecard
Learn more in this resource.
Supply Chain Cyber Risk
Blog
SecurityScorecard and AWS Help Make Secure Software Procurement Faster and Easier
Organizations increasingly rely on third parties for business operations, and as a result are working with more digital suppliers than ever. According to Gartner, 60% of organizations work with more than 1,000 third parties and this number will grow.
AWS
Blog
Up Level Your Amazon Security Lake with Attack Surface Intelligence
As global network infrastructure expands to include devices without traditional compute power, every organization’s attack surface becomes increasingly complex. Parallel to the increased complexity in the threat landscape is the increased scale and complexity of the signals and data necessary to produce meaningful cybersecurity insights. At its core, cybersecurity is a big data problem, requiring centralization of disparate data sources in uniform structure to enable continuous analytics.
Press
G2 and SecurityScorecard Partnership Highlights Cybersecurity as a Core Component of Software Purchasing Decisions
How G2 and SecurityScorecard are empowering software buyers with security ratings.
Press
99% of Global 2000 Companies Directly Connected to a Supply Chain Breach
New research from SecurityScorecard\r\nand The Cyentia Institute identified 99% of Global 2000 companies are directly connected to\r\nvendors that have had recent breaches.
Supply Chain Cyber Risk
Third-Party Risk Management
Research
Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk
Companies among the Forbes Global 2000 stand at the forefront of economic output and influence. With great economic power comes great vulnerability, particularly in the realm of third-party risk. In the complex landscape of third-party cyber risk in this report, no organization is too big to fail.
This report aims to provide an in-depth analysis of these risks, offering insights to help Global 2000 companies and their suppliers bolster defenses and mitigate the impacts of third-party cyber threats.
Blog
Scorecarder Spotlight: Catarina Horta
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Catarina Horta!
Scorecarder Spotlight
Research Reports
「日経 225 上場企業:日本におけるサイバーセキュリティの現状」
日経225を構成する企業は、常にサイバー攻撃の脅威に曝されており、最近の世界的な出来事によって、そのリスクはますます高まっています。そのため、あらゆる脅威への対策を準備しておくことが最善です。多くの場合、企業の脆弱性はハッカーの方が詳しく認識しているため、社内でセキュリティ評価を行うことは非常に重要です。測定できないものは制御できません。 本調査では、2022 年 11 月 20 日から 2023 年 11 月 20 日までの、日経225構成銘柄の企業で、金融、製造、医療、重要インフラ、運輸の各業界の企業を対象に調査を行いました。明らかになった改善点について概要を紹介しています。(注:ハッカーによる攻撃の可能性を防ぐため、調査対象となった企業名は公表していません)
Japanese
Blog
“What’s our number?”: Responding To Your Exposure to CrowdStrike Outage Event
One of the primary drivers of that question is the insurance industry’s challenges when managing systemic cyber risk since many believe that systemic cyber risk has the potential to bankrupt the industry. While there hasn’t been a catastrophic cyber incident that has proven the skeptics right, there have been several close calls.
Press
Cyber Risk Landscape of the Global Aviation Industry, 2024
SecurityScorecard provides a detailed examination of cybersecurity vulnerabilities across the airline industry and its various supply chains.\r\n
Supply Chain Cyber Risk
Third-Party Risk Management
Research
The Cyber Risk Landscape of the Global Aviation Industry, 2024
Third-party cyber risk impacts all industries, but some industries are more vulnerable and severely affected due to the nature of their business and larger third-party networks.
SecurityScorecard researchers analyzed cyber risk across the aviation industry, including airlines and the various types of vendors they rely on. To bolster cybersecurity across the aviation industry, this research aims to elevate the priority of cyber risk within the industry’s critical security and safety discourse.
Key findings from the report include:
The cybersecurity grade of the aviation industry
How third-party breaches have impacted aviation companies
How customers contribute to third-party risk
Third-Party Risk Management
Research
An Analysis of the Cyber Security Ratings of the Top 150 Technology Vendors
Earlier this year, we collaborated with McKinsey to explore just how concentrated cyber risk is in our global economy. One of the key findings of that report: 150 companies account for 90% of the technology products and services across the global attack surface.
In this report, we take a deeper dive into those 150 technology vendors. Our analysis includes:
The % of customer relationships and products these 150 vendors comprise
Common risk factors for which these vendors receive their lowest scores
Signs of compromised machines — and types of compromise — in the past year
Security practitioners can use this report to support assessments and improvement of their organization’s security hygiene and that of their nth party vendors.
メディア掲載
ITmedia: サプライチェーンのデータ漏えいをどう防ぐ? 7つの手法を解説
サプライチェーン組織の脆弱性などをきっかけにデータ漏えいが発生するケースがしばしば見受けられます。本稿はこれを防ぐための7つの対抗策を紹介します。
Japanese
ホワイトペーパー
SecurityScorecardによるASMプロセス実現方法 ~「ASM導入ガイダンス」への準拠方法をご紹介~
パートナーの株式会社ネットワークバリューコンポネンツによるWP
Japanese
Press
SecurityScorecard Achieves TX-RAMP Provisional Certification
Texas state agencies positioned to adopt letter-grade rating system to boost cyber resilience.
Blog
Crowdstrike Outage: Know Your Supply Chain
Supply chain detection is vital for third-party incident response\r\nKnowing Your Supply Chain (KYSC) is becoming an increasingly important component of cyber resilience. Understanding the dependencies within your organization and those of your vendors is critical for responding to incidents effectively.
Blog
Scorecarder Spotlight: Andrew Correll
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Andrew Correll!
Scorecarder Spotlight
Press
SecurityScorecard「ガートナー セキュリティ&リスク・マネジメント サミット2024」にて講演
Learn more in this resource.
Japanese
Blog
How to Choose the Right Supply Chain Cyber Risk Managed Service
The time for action is now. A supply chain cyber risk managed service is the solution to identify and mitigate these growing threats proactively.
Professional Services
Supply Chain Cyber Risk
Third-Party Risk Management
メディア掲載
TECH+: 第2回 企業が押さえるべきサイバーセキュリティリスク サイバーセキュリティリスクとは
監視すべきアウトソースベンダーにまつわるリスク 8選
Japanese
Webinars
Engage Executives & Support Suppliers to Boost Cyber Resilience
Learn more in this resource.