Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Research
Third-Party Data Breaches in the Energy Sector
Learn more in this resource.
Research
School District Attack Illustrates Ongoing Threat of Ransomware to Public Education
Interested in reading the report later? Download it. Download Now Executive Summary After a large U.S. school district recently announced that it had suffered a ransomware attack, SecurityScorecard consulted in-house data and strategic partnership sources to enrich the public reporting on the incident. Many of… Read More
Public Sector
Research
A detailed analysis of the Menorah malware used by APT34
Executive summary Menorah malware was used by the APT34 group, which targeted organizations in the Middle East and was discovered by Trend Micro in August this year. The malware creates a mutex to ensure that only one copy is running at a single time. It extracts the hostname and… Read More
Research
Cyber Risk Intelligence Update: Hacktivist Involvement in Israel-Hamas War Reflects Possible Shift in Threat Actor Focus
The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team has continued its monitoring of threat actors involved in the war between Israel and Hamas and has integrated this monitoring into its ongoing deep and dark web (DDW) collections. Key takeaways Analysis of these collections appears, as of… Read More
Research
A Deep Dive Into ALPHV/BlackCat Ransomware
Executive summary ALPHV/BlackCat is the first widely known ransomware written in Rust. The malware must run with an access token consisting of a 32-byte value (–access-token parameter), and other parameters can be specified. The ransomware comes with an encrypted configuration that contains a list of services/processes to be stopped,… Read More
STRIKE Team
Research
Brute Force Attempts May Have Preceded Ransomware Attack on School District
Executive Summary: Vice Society Ransomware Group Attack Following reports that an attack by the Vice Society ransomware group was responsible for disrupting a US school district’s operations, SecurityScorecard researchers reviewed available data from internal sources and strategic partnerships. SecurityScorecard’s platform revealed that the school district suffered from issues that our… Read More
Public Sector
STRIKE Team
Blog
What Is Cybersecurity Risk and How Do You Manage It in 2025?
Explore what cybersecurity risk means in 2025 and how organizations can effectively assess, mitigate, and monitor cyber threats across their digital and third-party ecosystems
Tech Center
Blog
2025 Third-Party Vendor Risk Management in the Financial Industry
With an established third-party risk management program, financial organizations are better able to identify and address vendor cyber risk. Learn more.
Tech Center
Blog
What is Cyber Attack Insurance? Best Practices for Protection
Cyber attack insurance is increasingly essential to protect your organization from cyber threats and their consequences. Learn more.
Cyber Insurance
Executive Viewpoint
Tech Center
Blog
What is Cyber Attack Insurance? Best Practices for Protection
Cyber attack insurance is increasingly essential to protect your organization from cyber threats and their consequences. Learn more.
Cyber Insurance
Executive Viewpoint
Tech Center
メディア掲載
ZDNET: 2024年のサイバーセキュリティ予測–AI、クラウド、CISOの変化など
サイバーセキュリティ各社が2024年のセキュリティ動向を予想している。2023年にブームとなったAIやクラウドなどのテクノロジートレンド、また、社会情勢や企業・組織の体制を踏まえた興味深い示唆が目立つ。各社の予想を主要なトピックスで紹介する。
Japanese
Blog
The Most Important Security Metrics to Maintain Compliance: Best Practices for Prioritizing Cyber Resilience
Security metrics are a great way to ensure your organization is meeting industry standards. Here are a few key performance indicators to track for maintaining compliance.
Security Ratings
Tech Center
Blog
What is a Cybersecurity Assessment?
A cybersecurity assessment helps security teams determine whether or not an organization is properly prepared to protect its assets against a range of threats. Learn more.
Tech Center
Blog
20 Cybersecurity Metrics & KPIs to Track in 2025
Explore the top cybersecurity metrics for 2025. Learn how to measure risk, performance, and vendor exposure across your organization and supply chain.\r\n
Security Ratings
Tech Center
Blog
How to Perform A Cybersecurity Risk Analysis in 2024
Identify, manage, and safeguard data, and assets that could be vulnerable to a cyberattack. Learn how to perform a cyber security risk analysis.
Tech Center
Press
エネルギー業界に関するサイバーリスク調査レポートを発表:90%がサードパーティによるデータ侵害を経験
Learn more in this resource.
Japanese
Blog
In-Depth Review: How SecurityScorecard Stacks Up Against UpGuard in 2024
In the dynamic world of cybersecurity, choosing the right platform can be pivotal for an organization’s digital safety. As we delve into 2024, two major players, SecurityScorecard and UpGuard, continue to make waves. This in-depth review compares these two companies and highlights how SecurityScorecard’s offerings often outshine those of… Read More
Security Ratings
Press
2024年 サイバーセキュリティに関する予測を発表
Learn more in this resource.
Japanese
Blog
Applying the Churchill Knowledge Audit to Cybersecurity: The Importance of Security Ratings
As a CISO, I am frequently pitched by companies promising to transform or revolutionize my job. I shrug off most pitches because they don’t add any value to what I’m doing. But every once in a while, an organization comes along that offers something new.
Executive Viewpoint
Webinars
The New Normal for CISOs, Security Ratings, and Cyber Warfare
Learn more in this resource.
メディア掲載
サイバーセキュリティ総研: セキュリティVSハッカー AIによる攻防激化と大規模な情報流出が懸念
セキュリティ企業のSecurityScorecardは、2024年のサイバーセキュリティに関する予測を発表した。
Japanese