Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Harnessing the Power of Artificial Intelligence: A closer look at the European Union’s new landmark legislation

Blog

Harnessing the Power of Artificial Intelligence: A closer look at the European Union’s new landmark legislation
Ethical implications of AI, where and how to use the technology, and understandability demand careful consideration and regulatory oversight to ensure fairness, accountability, and transparency. Against this backdrop, last week lawmakers in the European Union approved a first-of-its-kind law that will govern how businesses and organizations in the EU use artificial intelligence (AI). \r\n
Executive Viewpoint
Public Sector
Celebrating Cybersecurity Excellence: Forbes Most Cybersecure Banks, 2024

Blog

Celebrating Cybersecurity Excellence: Forbes Most Cybersecure Banks, 2024
Explore Forbes’ 2024 list of top consumer banks for cybersecurity, led by elite CISOs. Dive into their strategies for a safer digital world.
Security Ratings
What are Security Ratings?

Blog

What are Security Ratings?
Security ratings provide a comprehensive view of a company’s security performance. Learn more about what security ratings are and common use cases.
Tech Center
Crafting Your Compliance Blueprint: How Cybersecurity Leaders are Navigating SEC Mandates

Webinars

Crafting Your Compliance Blueprint: How Cybersecurity Leaders are Navigating SEC Mandates
Learn more in this resource.
Executive Viewpoint
Services
CISO Playbook: Third-Party Cyber Incident Response

Research

CISO Playbook: Third-Party Cyber Incident Response
Learn how to streamline your response efforts, communicate effectively during crises, and transform insights from past incidents into fortified defenses for your digital ecosystem.
Services
Supply Chain Cyber Risk
Third-party Cybersecurity Incident Response Readiness Plan

Blog

Third-party Cybersecurity Incident Response Readiness Plan
Explore essential strategies for third-party cybersecurity incident response readiness, minimizing supply chain vulnerabilities.
Third-Party Risk Management
CISO Playbook: Third-Party Cyber Incident Response

Research

CISO Playbook: Third-Party Cyber Incident Response
Learn how to streamline your response efforts, communicate effectively during crises, and transform insights from past incidents into fortified defenses for your digital ecosystem.
Services
Supply Chain Cyber Risk
Infosys McCamish Systems Third-Party Breach: Possible Attack Vectors and Infrastructure

Blog

Infosys McCamish Systems Third-Party Breach: Possible Attack Vectors and Infrastructure
In response to the identification of Infosys McCamish Systems (IMS) as the point of origin for a third-party data breach claimed by the LockBit ransomware group, SecurityScorecard researchers reviewed findings on the security hygiene of IMS.
Cyber Threat Intelligence
Forrester Includes SecurityScorecard in Cybersecurity Risk Ratings (CRR) Landscape Report

Blog

Forrester Includes SecurityScorecard in Cybersecurity Risk Ratings (CRR) Landscape Report
To help sift through the ever-growing field of cybersecurity ratings, Forrester recently published The Cybersecurity Risk Ratings Platforms Landscape, Q1 2024. SecurityScorecard is proud to be included in this landscape, in the company of other notable vendors in the field. Once a misunderstood technology, Cybersecurity Risk Ratings platforms (CRRs) have earned their place in the spotlight in the last several years.
Security Ratings
Breaches Beyond Borders: A Deep Dive Into Third-Party Cybersecurity Breaches

Webinars

Breaches Beyond Borders: A Deep Dive Into Third-Party Cybersecurity Breaches
Learn more in this resource.
Supply Chain Cyber Risk
Choosing Your Code Repository: Navigating the Security Landscape of Bitbucket vs GitHub

Blog

Choosing Your Code Repository: Navigating the Security Landscape of Bitbucket vs GitHub
Which code repository is more secure for enterprises—GitHub or Bitbucket? Compare their security features, risks, and third-party controls in 2025 to choose the right platform.
Tech Center
Defender for Endpoint: Transforming Endpoint Security with Advanced Threat Protection

Blog

Defender for Endpoint: Transforming Endpoint Security with Advanced Threat Protection
Explore how Microsoft’s Sentinel transforms cybersecurity with AI, offering advanced threat detection and automated responses.
Tech Center
What is Domain Hijacking and How Do I Prevent it?

Blog

What is Domain Hijacking and How Do I Prevent it?
Your domain name is not just a web address; it represents your brand, your reputation, and often, your livelihood. However, with the increasing value of domain names, they have become targets for cybercriminals seeking to exploit vulnerabilities for their gain. One such threat is domain hijacking – a serious issue that can have significant repercussions if not addressed promptly. Here, we’ll delve into what domain hijacking entails and explore practical steps to prevent it from happening to you.\r\n
Tech Center
Red Sift Rising: Tools to Level Up Your Cybersecurity Rating

Webinars

Red Sift Rising: Tools to Level Up Your Cybersecurity Rating
Learn more in this resource.
Security Ratings
What is Sentinel? Harnessing the Power of Cloud-Native SIEM for Modern Cybersecurity Challenges

Blog

What is Sentinel? Harnessing the Power of Cloud-Native SIEM for Modern Cybersecurity Challenges
Explore how Microsoft’s Sentinel SIEM solution transforms cybersecurity with AI, offering advanced threat detection and automated responses.
Tech Center
SMB Port Numbers: A Guide to Optimizing and Securing Your Network

Blog

SMB Port Numbers: A Guide to Optimizing and Securing Your Network
Explore SMB port security and optimization for your network, including risks and best practices for safeguarding your digital infrastructure.
Tech Center
New Malware Attributed to Russian Hacking Group APT28

Blog

New Malware Attributed to Russian Hacking Group APT28
Late last year, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory that reported cyberattacks targeting Ukrainian state organizations attributed to the Kremlin-backed nation-state group APT28, aka Fancy Bear/Sofacy. The advisory listed the use of a new backdoor named “OCEANMAP,” detailed in this whitepaper. \r\n
Cyber Threat Intelligence
The Future of Supply Chain Cybersecurity: Navigating the Evolving Landscape

Webinars

The Future of Supply Chain Cybersecurity: Navigating the Evolving Landscape
Learn more in this resource.
Executive Viewpoint
Supply Chain Cyber Risk
A technical analysis of the APT28’s backdoor called OCEANMAP

Research

A technical analysis of the APT28’s backdoor called OCEANMAP
Late last year, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory that reported cyberattacks targeting state organizations attributed to the Russian espionage group APT28, aka Fancy Bear/Sofacy. The advisory listed the use of a new backdoor named “OCEANMAP.” Download this whitepaper to explore a technical analysis of APT28’s tactics, techniques, and procedures.
Cyber Threat Intelligence
Enterprise Cyber Risk
Supply Chain Cyber Risk
Remediation vs Mitigation in Cybersecurity: Understanding the distinctions and strategic applications

Blog

Remediation vs Mitigation in Cybersecurity: Understanding the distinctions and strategic applications
While remediation and mitigation might seem similar, understanding their distinctions and strategic applications is paramount for building robust defense mechanisms against cyber threats.\r\n
Tech Center
Leveraging SIEM Splunk for Enhanced Cybersecurity: A Comprehensive Guide

Blog

Leveraging SIEM Splunk for Enhanced Cybersecurity: A Comprehensive Guide
In this comprehensive guide, we’ll delve into the world of SIEM Splunk and explore how organizations can leverage it to enhance their cybersecurity posture.\r\n
Tech Center