Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

SecurityScorecard and ServiceNow Expand Partnership with New Capabilities for TPRM and Security Incident Response (SIR)

Blog

SecurityScorecard and ServiceNow Expand Partnership with New Capabilities for TPRM and Security Incident Response (SIR)
ServiceNow and SecurityScorecard have been longtime strategic partners, helping mutual customers measure and manage cyber risk. Today we’re highlighting the next phase of our partnership and innovation to help customers tackle the complex challenges associated with managing cyber risk in the third party ecosystem.
Third-Party Risk Management: Detecting and Responding to Supply Chain Cyber Risks

Webinars

Third-Party Risk Management: Detecting and Responding to Supply Chain Cyber Risks
Learn more in this resource.
Supply Chain Cyber Risk
Third-Party Risk Management
ITmedia: サプライチェーンのセキュリティ評価で注意したい15の項目

メディア掲載

ITmedia: サプライチェーンのセキュリティ評価で注意したい15の項目
サプライチェーンセキュリティのリスクが高まる今、自社に関連するサプライチェーンがきちんと対策をしているかどうかをどうチェックすればいいでしょうか。15の評価項目を解説します。
Japanese
“More Money, More Problems:” Supply Chain Cyber Risk in the Forbes Global 2000

Blog

“More Money, More Problems:” Supply Chain Cyber Risk in the Forbes Global 2000
SecurityScorecard and its partner Cyentia recently released our joint case study of third-party cyber risk in the Forbes Global 2000 group of the world’s financially largest companies. On one hand, large companies have the advantage of greater financial and human resources to invest in security programs. Security costs money, and other SecurityScorecard research has established a correlation between cyber security hygiene on one hand and financial means on the other. On the other hand, greater size means that larger companies have more attack surface to protect and greater third-party risk exposure through their typically larger number of vendors and other third parties, as SecurityScorecard also found in an analysis of large technology companies. This paper delves further into the heightened risk exposure that comes with operating at a larger scale.
Use Action Plans to collaborate with your vendors on security improvements

Resources

Use Action Plans to collaborate with your vendors on security improvements
Learn more in this resource.
Supply Chain Cyber Risk
Integrate Marketplace Apps into your security workflows

Resources

Integrate Marketplace Apps into your security workflows
Learn more in this resource.
Supply Chain Cyber Risk
Understanding your Scorecard

Resources

Understanding your Scorecard
Learn more in this resource.
Supply Chain Cyber Risk
Manage and validate your Digital Footprint

Event

Manage and validate your Digital Footprint
Learn more in this resource.
Services
Supply Chain Cyber Risk
Address issue findings in your Scorecard

Resources

Address issue findings in your Scorecard
Learn more in this resource.
Supply Chain Cyber Risk
SecurityScorecard and AWS Help Make Secure Software Procurement Faster and Easier

Blog

SecurityScorecard and AWS Help Make Secure Software Procurement Faster and Easier
Organizations increasingly rely on third parties for business operations, and as a result are working with more digital suppliers than ever. According to Gartner, 60% of organizations work with more than 1,000 third parties and this number will grow.
AWS
Up Level Your Amazon Security Lake with Attack Surface Intelligence

Blog

Up Level Your Amazon Security Lake with Attack Surface Intelligence
As global network infrastructure expands to include devices without traditional compute power, every organization’s attack surface becomes increasingly complex. Parallel to the increased complexity in the threat landscape is the increased scale and complexity of the signals and data necessary to produce meaningful cybersecurity insights. At its core, cybersecurity is a big data problem, requiring centralization of disparate data sources in uniform structure to enable continuous analytics.
G2 and SecurityScorecard Partnership Highlights Cybersecurity as a Core Component of Software Purchasing Decisions

Press

G2 and SecurityScorecard Partnership Highlights Cybersecurity as a Core Component of Software Purchasing Decisions
How G2 and SecurityScorecard are empowering software buyers with security ratings.
99% of Global 2000 Companies Directly Connected to a Supply Chain Breach

Press

99% of Global 2000 Companies Directly Connected to a Supply Chain Breach
New research from SecurityScorecard\r\nand The Cyentia Institute identified 99% of Global 2000 companies are directly connected to\r\nvendors that have had recent breaches.
Supply Chain Cyber Risk
Third-Party Risk Management
Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk

Research

Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk
Companies among the Forbes Global 2000 stand at the forefront of economic output and influence. With great economic power comes great vulnerability, particularly in the realm of third-party risk. In the complex landscape of third-party cyber risk in this report, no organization is too big to fail. This report aims to provide an in-depth analysis of these risks, offering insights to help Global 2000 companies and their suppliers bolster defenses and mitigate the impacts of third-party cyber threats.
Scorecarder Spotlight: Catarina Horta

Blog

Scorecarder Spotlight: Catarina Horta
Our series “Scorecarder Spotlight” showcases our talented employees and the incredible work they do. Meet Catarina Horta!
Scorecarder Spotlight
「日経 225 上場企業:日本におけるサイバーセキュリティの現状」

Research Reports

「日経 225 上場企業:日本におけるサイバーセキュリティの現状」
日経225を構成する企業は、常にサイバー攻撃の脅威に曝されており、最近の世界的な出来事によって、そのリスクはますます高まっています。そのため、あらゆる脅威への対策を準備しておくことが最善です。多くの場合、企業の脆弱性はハッカーの方が詳しく認識しているため、社内でセキュリティ評価を行うことは非常に重要です。測定できないものは制御できません。 本調査では、2022 年 11 月 20 日から 2023 年 11 月 20 日までの、日経225構成銘柄の企業で、金融、製造、医療、重要インフラ、運輸の各業界の企業を対象に調査を行いました。明らかになった改善点について概要を紹介しています。(注:ハッカーによる攻撃の可能性を防ぐため、調査対象となった企業名は公表していません)
Japanese
“What’s our number?”: Responding To Your Exposure to CrowdStrike Outage Event

Blog

“What’s our number?”: Responding To Your Exposure to CrowdStrike Outage Event
One of the primary drivers of that question is the insurance industry’s challenges when managing systemic cyber risk since many believe that systemic cyber risk has the potential to bankrupt the industry. While there hasn’t been a catastrophic cyber incident that has proven the skeptics right, there have been several close calls.
Cyber Risk Landscape of the Global Aviation Industry, 2024

Press

Cyber Risk Landscape of the Global Aviation Industry, 2024
SecurityScorecard provides a detailed examination of cybersecurity vulnerabilities across the airline industry and its various supply chains.\r\n
Supply Chain Cyber Risk
Third-Party Risk Management
The Cyber Risk Landscape of the Global Aviation Industry, 2024

Research

The Cyber Risk Landscape of the Global Aviation Industry, 2024
Third-party cyber risk impacts all industries, but some industries are more vulnerable and severely affected due to the nature of their business and larger third-party networks. SecurityScorecard researchers analyzed cyber risk across the aviation industry, including airlines and the various types of vendors they rely on. To bolster cybersecurity across the aviation industry, this research aims to elevate the priority of cyber risk within the industry’s critical security and safety discourse. Key findings from the report include: The cybersecurity grade of the aviation industry How third-party breaches have impacted aviation companies How customers contribute to third-party risk
Third-Party Risk Management
An Analysis of the Cyber Security Ratings of the Top 150 Technology Vendors

Research

An Analysis of the Cyber Security Ratings of the Top 150 Technology Vendors
Earlier this year, we collaborated with McKinsey to explore just how concentrated cyber risk is in our global economy. One of the key findings of that report: 150 companies account for 90% of the technology products and services across the global attack surface. In this report, we take a deeper dive into those 150 technology vendors. Our analysis includes: The % of customer relationships and products these 150 vendors comprise Common risk factors for which these vendors receive their lowest scores Signs of compromised machines — and types of compromise — in the past year   Security practitioners can use this report to support assessments and improvement of their organization’s security hygiene and that of their nth party vendors.
ITmedia: サプライチェーンのデータ漏えいをどう防ぐ? 7つの手法を解説

メディア掲載

ITmedia: サプライチェーンのデータ漏えいをどう防ぐ? 7つの手法を解説
サプライチェーン組織の脆弱性などをきっかけにデータ漏えいが発生するケースがしばしば見受けられます。本稿はこれを防ぐための7つの対抗策を紹介します。
Japanese