Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Third-party Cybersecurity Incident Response Readiness Plan

Blog

Third-party Cybersecurity Incident Response Readiness Plan
Explore essential strategies for third-party cybersecurity incident response readiness, minimizing supply chain vulnerabilities.
Third-Party Risk Management
CISO Playbook: Third-Party Cyber Incident Response

Research

CISO Playbook: Third-Party Cyber Incident Response
With 98% of companies exposed to risks via third-party vendors, understanding and operationalizing an effective third-party cyber incident response is more critical than ever. In this playbook, we’ll cover how you can Streamline your response efforts Communicate effectively during crises, and Transform insights from past incidents into fortified defenses for your digital ecosystem   Delve into actionable steps and best practices, ensuring your response plan is not just a protocol but a robust shield against the escalating threats in the digital landscape.
Services
Supply Chain Cyber Risk
Infosys McCamish Systems Third-Party Breach: Possible Attack Vectors and Infrastructure

Blog

Infosys McCamish Systems Third-Party Breach: Possible Attack Vectors and Infrastructure
In response to the identification of Infosys McCamish Systems (IMS) as the point of origin for a third-party data breach claimed by the LockBit ransomware group, SecurityScorecard researchers reviewed findings on the security hygiene of IMS.
Cyber Threat Intelligence
Forrester Includes SecurityScorecard in Cybersecurity Risk Ratings (CRR) Landscape Report

Blog

Forrester Includes SecurityScorecard in Cybersecurity Risk Ratings (CRR) Landscape Report
To help sift through the ever-growing field of cybersecurity ratings, Forrester recently published The Cybersecurity Risk Ratings Platforms Landscape, Q1 2024. SecurityScorecard is proud to be included in this landscape, in the company of other notable vendors in the field. Once a misunderstood technology, Cybersecurity Risk Ratings platforms (CRRs) have earned their place in the spotlight in the last several years.
Security Ratings
Breaches Beyond Borders: A Deep Dive Into Third-Party Cybersecurity Breaches

Webinars

Breaches Beyond Borders: A Deep Dive Into Third-Party Cybersecurity Breaches
Learn more in this resource.
Supply Chain Cyber Risk
Choosing Your Code Repository: Navigating the Security Landscape of Bitbucket vs GitHub

Blog

Choosing Your Code Repository: Navigating the Security Landscape of Bitbucket vs GitHub
Which code repository is more secure for enterprises—GitHub or Bitbucket? Compare their security features, risks, and third-party controls in 2025 to choose the right platform.
Tech Center
Defender for Endpoint: Transforming Endpoint Security with Advanced Threat Protection

Blog

Defender for Endpoint: Transforming Endpoint Security with Advanced Threat Protection
Explore how Microsoft’s Sentinel transforms cybersecurity with AI, offering advanced threat detection and automated responses.
Tech Center
What is Domain Hijacking and How Do I Prevent it?

Blog

What is Domain Hijacking and How Do I Prevent it?
Your domain name is not just a web address; it represents your brand, your reputation, and often, your livelihood. However, with the increasing value of domain names, they have become targets for cybercriminals seeking to exploit vulnerabilities for their gain. One such threat is domain hijacking – a serious issue that can have significant repercussions if not addressed promptly. Here, we’ll delve into what domain hijacking entails and explore practical steps to prevent it from happening to you.\r\n
Tech Center
Red Sift Rising: Tools to Level Up Your Cybersecurity Rating

Webinars

Red Sift Rising: Tools to Level Up Your Cybersecurity Rating
Learn more in this resource.
Security Ratings
What is Sentinel? Harnessing the Power of Cloud-Native SIEM for Modern Cybersecurity Challenges

Blog

What is Sentinel? Harnessing the Power of Cloud-Native SIEM for Modern Cybersecurity Challenges
Explore how Microsoft’s Sentinel SIEM solution transforms cybersecurity with AI, offering advanced threat detection and automated responses.
Tech Center
SMB Port Numbers: A Guide to Optimizing and Securing Your Network

Blog

SMB Port Numbers: A Guide to Optimizing and Securing Your Network
Explore SMB port security and optimization for your network, including risks and best practices for safeguarding your digital infrastructure.
Tech Center
New Malware Attributed to Russian Hacking Group APT28

Blog

New Malware Attributed to Russian Hacking Group APT28
Late last year, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory that reported cyberattacks targeting Ukrainian state organizations attributed to the Kremlin-backed nation-state group APT28, aka Fancy Bear/Sofacy. The advisory listed the use of a new backdoor named “OCEANMAP,” detailed in this whitepaper. \r\n
Cyber Threat Intelligence
The Future of Supply Chain Cybersecurity: Navigating the Evolving Landscape

Webinars

The Future of Supply Chain Cybersecurity: Navigating the Evolving Landscape
Learn more in this resource.
Executive Viewpoint
Supply Chain Cyber Risk
A technical analysis of the APT28’s backdoor called OCEANMAP

Research

A technical analysis of the APT28’s backdoor called OCEANMAP
A technical analysis of the APT28’s backdoor called OCEANMAP   Late last year, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory that reported cyberattacks targeting state organizations attributed to the Russian espionage group APT28, aka Fancy Bear/Sofacy. The advisory listed the use of a new backdoor named “OCEANMAP.” Download this whitepaper to explore a technical analysis of APT28’s tactics, techniques, and procedures.
Cyber Threat Intelligence
Enterprise Cyber Risk
Supply Chain Cyber Risk
Remediation vs Mitigation in Cybersecurity: Understanding the distinctions and strategic applications

Blog

Remediation vs Mitigation in Cybersecurity: Understanding the distinctions and strategic applications
While remediation and mitigation might seem similar, understanding their distinctions and strategic applications is paramount for building robust defense mechanisms against cyber threats.\r\n
Tech Center
Leveraging SIEM Splunk for Enhanced Cybersecurity: A Comprehensive Guide

Blog

Leveraging SIEM Splunk for Enhanced Cybersecurity: A Comprehensive Guide
In this comprehensive guide, we’ll delve into the world of SIEM Splunk and explore how organizations can leverage it to enhance their cybersecurity posture.\r\n
Tech Center
Analyzing FERPA Violation Examples to Strengthen Data Privacy in Education

Blog

Analyzing FERPA Violation Examples to Strengthen Data Privacy in Education
The Family Educational Rights and Privacy Act (FERPA) is a crucial piece of legislation designed to safeguard students’ educational records. Despite its importance, FERPA violations still occur, highlighting the need for continuous vigilance and proactive measures to strengthen data privacy in education.
Tech Center
What Are Proactive Ransomware Prevention Strategies for 2025?

Blog

What Are Proactive Ransomware Prevention Strategies for 2025?
Ransomware threats are evolving fast. This guide explores the most effective prevention strategies for 2025, from zero trust to supply chain resilience.
Attack Surface Management
Tech Center
TechTarget: セキュリティ領域の生成AI動向予測

メディア掲載

TechTarget: セキュリティ領域の生成AI動向予測
2022年11月にAI(人工知能)技術を搭載したチャットbot「ChatGPT」が登場したことをきっかけに、テキストや画像などを自動生成するAI技術「生成AI」(ジェネレーティブAI)ブームが起きた
Japanese
SecurityScorecard 2024 Global Third-Party Cybersecurity Breach Report: Software supply chain is top target for ransomware groups

Blog

SecurityScorecard 2024 Global Third-Party Cybersecurity Breach Report: Software supply chain is top target for ransomware groups
The SecurityScorecard Global Third-Party Breach Report uses the world’s largest proprietary risk and threat dataset to provide unique insights into the intricate web of supply chain vulnerabilities exploited by ransomware groups.\r\n
Cyber Threat Intelligence
Supply Chain Cyber Risk
SecurityScorecard Third-Party Breach Report Reveals Software Supply Chain as Top Target for Ransomware Groups

Press

SecurityScorecard Third-Party Breach Report Reveals Software Supply Chain as Top Target for Ransomware Groups
SecurityScorecard today released its Global Third-Party Cybersecurity Breach Report. Using the world’s largest proprietary risk and threat data set, SecurityScorecard STRIKE threat hunters analyzed threat groups’ mass exploitation of supply chain vulnerabilities.