Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Blog
SecurityScorecard introduces new partner certifications
New program educates and inspires partners to consolidate cybersecurity outcomes with the SecurityScorecard platform
Supply Chain Cyber Risk
Blog
From Confusion to Clarity: Red Sift Breaks Down Google and Yahoo’s Email Security Requirements
Understand how to comply with Google and Yahoo’s new email security requirements and ensure your organization’s emails are delivered effectively. Discover how SecurityScorecard can help.
Supply Chain Cyber Risk
Blog
Decoding Cyber Security Innovations with SecurityScorecard CEO Alex Yampolskiy
SecurityScorecard CEO Aleksandr Yampolskiy sat down with NightDragon CEO Dave DeWalt and unveiled his deep-rooted passion for cybersecurity.
Executive Viewpoint
Webinars
Rebuilding Trust: Introducing the Global Cyber Resilience Scorecard
Learn more in this resource.
Cyber Threat Intelligence
Public Sector
Case Studies
Horiens Risk Advisors
We are able to measure, equalize, and improve in an intelligent way, always supporting our clients.
Cyber Insurance
Case Studies
Horiens Risk Advisors
We are able to measure, equalize, and improve in an intelligent way, always supporting our clients.
Cyber Insurance
Blog
SecurityScorecard Returns to the World Economic Forum’s Annual Meeting: Our Top 5 Insights
Last week, SecurityScorecard was invited back to participate in the World Economic Forum’s Annual Meeting in Davos, Switzerland. It was a tremendous honor and, once again, we were the only security ratings company present (and one of the few cybersecurity companies). \r\n
Executive Viewpoint
Blog
The Evolution of CISOs and Security Ratings
Just like security ratings, the role of the CISO continues to evolve and they’ve had to become more strategic at prioritizing threats and vulnerabilities, especially in the wake of the SEC charges against SolarWinds and their CISO for defrauding investors.
Executive Viewpoint
Security Ratings
Blog
Leveraging Collaboration and Transparency: How CISOs Can Comply With New SEC Regulations
As we kick off 2024, CISOs at public companies will certainly be thinking of new regulations from the U.S. Securities and Exchange Commission (SEC) on security incident reporting, effective December 15, 2023. The new regulations demand unprecedented transparency and collaboration from CISOs. Open communication with the C-Suite and third-party partners will be a critical tool for maintaining compliance with the SEC’s new rules.\r\n
Services
Blog
Introducing SecurityScorecard MAX
Introducing SecurityScorecard MAX: Elevate your supply chain cyber risk management with our comprehensive, AI-driven solution. MAX combines expert insights and advanced technology to identify, prioritize, and resolve critical vulnerabilities in your vendor ecosystem. Protect your enterprise from emerging threats and ensure operational efficiency with MAX’s fully managed service, tailored for both Fortune 500 companies and growing businesses. Discover how MAX transforms cybersecurity strategy, offering collective defense and proactive services like penetration testing. Take your supply chain cyber risk to the MAX with SecurityScorecard.
Cyber Threat Intelligence
Services
Blog
Introducing SecurityScorecard MAX
Introducing SecurityScorecard MAX: Elevate your supply chain cyber risk management with our comprehensive, AI-driven solution. MAX combines expert insights and advanced technology to identify, prioritize, and resolve critical vulnerabilities in your vendor ecosystem. Protect your enterprise from emerging threats and ensure operational efficiency with MAX’s fully managed service, tailored for both Fortune 500 companies and growing businesses. Discover how MAX transforms cybersecurity strategy, offering collective defense and proactive services like penetration testing. Take your supply chain cyber risk to the MAX with SecurityScorecard.
Cyber Threat Intelligence
Services
Press
SecurityScorecard Launches MAX to Redefine the Supply Chain Cyber Risk Management Market
New managed services offering from SecurityScorecard is winning over customers, driving record revenue with its simplicity and outcomes-focused approach.
Professional Services
Services
Webinars
A CISO’s Guide to Demystifying Cyber Risk for the Board
Learn more in this resource.
Research
Ransomware Attack on Vendor Managing U.S. Government Records
Executive Summary On January 3, CyberScoop reported a cyberattack resulting from an earlier service interruption affecting a vendor that manages records for U.S. county governments. As of January 10, some counties’ records remain inaccessible due to the incident. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external data sources to investigate the incident and identified a possible
Public Sector
Research
BlackCat Ransomware Group Claims Attack on Healthcare Service Provider
Executive Summary On January 17, the BlackCat ransomware group added an entry for an electronic health record (EHR) vendor to its extortion site., Bbut, as of January 21, the vendor’s entry no longer appeared there. Following the claim, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team investigated the incident. By pairing its exclusive access to
Cyber Threat Intelligence
Research
Avoslocker Ransomware Group Targets U.S University
Executive Summary On May 1, the Avoslocker ransomware group claimed responsibility for an attack against a small U.S. university. Shortly after news of the incident surfaced, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external sources to collect and analyze intelligence about the attack. These sources yielded findings that enabled STRIKE Team researchers to
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence
Research
Avoslocker Ransomware Group Targets U.S University
Executive Summary On May 1, the Avoslocker ransomware group claimed responsibility for an attack against a small U.S. university. Shortly after news of the incident surfaced, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external sources to collect and analyze intelligence about the attack. These sources yielded findings that enabled STRIKE Team researchers to
Attack Surface Management
Cyber Insurance
Cyber Threat Intelligence
Research
Investigation of North Korea-Linked Indicators of Compromise (IOCs)
Executive Summary On February 9, CISA published a #StopRansomware alert regarding ransomware attacks against healthcare and public health organizations they attribute to threat actors acting on behalf of the North Korean state. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external data sources to enrich the indicators of compromise (IoCs) in the alert. Researchers
Cyber Threat Intelligence
Research
Newly-identified Vulnerability Affecting All Versions of Outlook for Windows
Executive Summary On March 14, Microsoft released a security update for a newly-identified vulnerability affecting all versions of Outlook for Windows. Current reports indicate that the vulnerability is under active exploitation by a threat actor group the cybersecurity community believes is acting on behalf of the GRU, Russia’s military intelligence agency. Shortly after the vulnerability’s
Cyber Threat Intelligence
Research
New Intrusion Campaign Targeting Users of Popular Business Communication Software
Executive Summary On March 29, cybersecurity vendors announced that a new intrusion campaign had targeted users of business communication software company 3CX’s desktop client through a supply-chain attack. Initial reports have attributed the activity to the threat actor group tracked as Labyrinth Chollima, which is believed to conduct espionage on behalf of the North Korean government. Shortly after warnings
Cyber Threat Intelligence
Research
Investigations of Lazarus Group Indicators of Compromise Reveals Suspicious Traffic Involving State Government IP Addresses
Executive Summary In early February, analysts attributed a new intrusion affecting a healthcare research organization to the Lazarus Group, a well-established threat actor believed to act on behalf of the government of the Democratic People’s Republic of Korea (DPRK). In an effort to enrich the Indicators of Compromise (IoCs) provided in the original report, the SecurityScorecard Threat Research,
Cyber Threat Intelligence