Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

SecurityScorecard Appoints Tenable Co-Founder as Senior Advisor

Press

SecurityScorecard Appoints Tenable Co-Founder as Senior Advisor
SecurityScorecard today announced the appointment of Renaud Deraison, Co-Founder of Tenable and a pioneer of vulnerability management, as Senior Advisor and Chairman of its Corporate Advisory Board.
Introducing the Cyber Resilience Scorecard: SecurityScorecard Finds Global Cyber Risk and GDP Closely Linked

Blog

Introducing the Cyber Resilience Scorecard: SecurityScorecard Finds Global Cyber Risk and GDP Closely Linked
SecurityScorecard has published the first Cyber Resilience Scorecard, offering leaders and decision-makers a comprehensive and global view of global cyber risk. SecurityScorecard identified a strong correlation between a country’s cyber risk exposure and GDP, which underscores that a nation’s economic prosperity is deeply intertwined with its ability to navigate the complex landscape of cyber threats.
Cyber Threat Intelligence
Davos 2024: Global Cyber Risk and GDP Closely Linked, New SecurityScorecard Research Reveals

Press

Davos 2024: Global Cyber Risk and GDP Closely Linked, New SecurityScorecard Research Reveals
SecurityScorecard, a global leader in Security Ratings, released the world’s first Cyber Resilience Scorecard at the World Economic Forum Annual Meeting. The Cyber Resilience Scorecard provides an unprecedented view of global cybersecurity risk, arming leaders with data-driven insights to safeguard the world’s economies.
Cyber Conflict And The Erosion Of Trust: Introducing the Cyber Resilience Scorecard

Research

Cyber Conflict And The Erosion Of Trust: Introducing the Cyber Resilience Scorecard
Our report explores the intricate dynamics between cyber threats, economic resilience, and the vital component of societal trust.
Cyber Threat Intelligence
Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days

Research

Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has identified new infrastructure that appears to be linked to the threat actor group tracked as Volt Typhoon. Volt Typhoon is a state-sponsored group based in China that typically focuses on espionage and information gathering. Approximately 30% of the Cisco RV320/325 devices observed by SecurityScorecard in a 37-day period may have been compromised by Volt Typhoon.
Cyber Threat Intelligence
Evolve from Risk Management to Risk Intelligence

Ebook

Evolve from Risk Management to Risk Intelligence
Proven Strategies to Drive a Risk Intelligence Program in Your Organization
DORA and Cyber Risk: A New Framework for Third-Party Risk in the European Union

White Papers

DORA and Cyber Risk: A New Framework for Third-Party Risk in the European Union
DORA is an effort to build resilience within the financial service sector by requiring financial services organizations to establish and monitor networks of trust amongst themselves and their ICT vendors. However, trust requires verification through monitoring and transparency.
Attack Surface Management
Cyber Threat Intelligence
DORA
SecurityScorecard Validation Assessment Summary

Research

SecurityScorecard Validation Assessment Summary
Online found SecurityScorecard’s footprinting to be very accurate. Over the course of testing Online evaluated SecurityScorecard’s data for a total of 13 unique, unrelated, and randomly selected domains and found SecurityScorecard’s attribution process to have an accuracy of 95%. The accuracy for positively attributing IP Addresses was found to be 94% while for DNS Records it was found to be 100%.
Threat Intelligence Research: Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days

Blog

Threat Intelligence Research: Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has been investigating covert infrastructure linked to Volt Typhoon, a state-sponsored threat actor group believed to act on behalf of the People’s Republic of China. The group conducts multiple types of cyberattacks, but its use of compromised small office and home office (SOHO) equipment such as routers and firewalls is a recurring theme.
Cyber Threat Intelligence
Canadian Centre for Cyber Security and SecurityScorecard Establish Partnership to Strengthen Cyber Resilience and Secure Critical Infrastructure

Press

Canadian Centre for Cyber Security and SecurityScorecard Establish Partnership to Strengthen Cyber Resilience and Secure Critical Infrastructure
Cyber Centre pioneers real-time visibility of national critical infrastructure using nationwide implementation of security ratings, credit scores of the digital world.
North Korean State-Sponsored Cyber Attack: Unveiling the Intricacies of Threat Actor Group Andariel

Research

North Korean State-Sponsored Cyber Attack: Unveiling the Intricacies of Threat Actor Group Andariel
This SecurityScorecard threat research sheds light on a significant cyber attack attributed to North Koreans tate-sponsored actors known as Andariel, emphasizing the critical role that South Korea plays both as a target and a source of infrastructure for these threat actors.
Cyber Threat Intelligence
Vendor Risk Management vs Third Party Risk Management vs Enterprise Risk Management: What’s the Difference?

Blog

Vendor Risk Management vs Third Party Risk Management vs Enterprise Risk Management: What’s the Difference?
Third-Party, Vendor, and Enterprise Risk Management are often used interchangeably, but they are not always the same. Learn which is right for your business.
Tech Center
SecurityScorecard and Industry Leaders Deliver Industry-Specific Security Ratings for Telecommunications, Internet Service Providers, and Cloud Providers

Press

SecurityScorecard and Industry Leaders Deliver Industry-Specific Security Ratings for Telecommunications, Internet Service Providers, and Cloud Providers
SecurityScorecard today announced the industry’s first security ratings developed exclusively for telecommunications, internet service providers, and cloud providers. Through close collaboration with industry leaders, SecurityScorecard sets a new standard for cybersecurity across these critical sectors.
Security Ratings
7 Incident Response Metrics and How to Use Them

Blog

7 Incident Response Metrics and How to Use Them
A robust incident response plan provides quantitative data. Check out these seven incident response metrics and how to use them.
Tech Center
業界大手企業と共同で通信事業者、インターネットサービスプロバイダー、クラウドプロバイダー向けの業種別セキュリティレーティングを提供

Press

業界大手企業と共同で通信事業者、インターネットサービスプロバイダー、クラウドプロバイダー向けの業種別セキュリティレーティングを提供
Learn more in this resource.
Japanese
SecurityScorecard 10 Risk Factors Explained

Blog

SecurityScorecard 10 Risk Factors Explained
Trust begins with transparency. Check out SecurityScorecard’s ten risk factors, which are explained in an easy-to-understand manner that enables business and IT leaders to create meaningful conversations around cybersecurity risk and compliance.
Tech Center
Introducing Security Ratings for Telecommunications, Internet Service Providers, and Cloud Providers: Collaborating on enhancements with industry leaders

Blog

Introducing Security Ratings for Telecommunications, Internet Service Providers, and Cloud Providers: Collaborating on enhancements with industry leaders
Telecommunications, Internet Service Providers, and Cloud Providers are some of the most critical sectors on the planet. But they are also prime targets for nation-state attacks and other threat actor groups. And their reliance on vast networks of third-party vendors, partners, and service providers creates a need for a comprehensive cybersecurity approach tailored specifically to the sector.
Security Ratings
Security Ratings: A New Horizon

White Papers

Security Ratings: A New Horizon
Unveiling a new Security Ratings methodology for Telecommunications, Internet Service Providers, and Cloud Providers
Attack Surface Management
Cyber Threat Intelligence
Enterprise Cyber Risk
SecurityScorecard Reinforces Commitment to Free Security Ratings for All Organizations

Press

SecurityScorecard Reinforces Commitment to Free Security Ratings for All Organizations
SecurityScorecard today unveiled new capabilities to strengthen cybersecurity trust and transparency across the digital ecosystem. Building on a decade-long commitment to providing free security ratings for all organizations, SecurityScorecard innovations advance the industry’s most transparent, trusted, and accurate security ratings.
Security Ratings
8 Types of Vendor Risks That Are Important to Monitor in 2025

Blog

8 Types of Vendor Risks That Are Important to Monitor in 2025
Discover how to manage vendor risk by understanding and monitoring various threats, ensuring your business stays secure from third-party vulnerabilities.
Tech Center
The Increase in Ransomware Attacks on Local Governments

Research

The Increase in Ransomware Attacks on Local Governments
What makes organizations in the public sector vulnerable to ransomware?
Public Sector
STRIKE Team