Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Navigating the Evolving Supply Chain Threat Landscape

Webinars

Navigating the Evolving Supply Chain Threat Landscape
Learn more in this resource.
Cyber Threat Intelligence Update: New Claims of Attacks Against Israeli SCADA Systems

Research

Cyber Threat Intelligence Update: New Claims of Attacks Against Israeli SCADA Systems
Executive Summary SecurityScorecard’s ongoing collections from hacktivist channels involved in cyber activity provoked by the conflict in Gaza highlight the international scope of the conflict, with hacktivist groups in Indonesia and Malaysia claiming attacks against organizations in Israel and allied states. As in the other channels SecurityScorecard analyzed… Read More
Cyber Risk Intelligence: SecurityScorecard Analysis of Traffic Involving Storm-0558 IoCs

Research

Cyber Risk Intelligence: SecurityScorecard Analysis of Traffic Involving Storm-0558 IoCs
Executive Summary On July 11th, 2023, Microsoft disclosed that a threat actor had obtained a Microsoft private encryption key that allowed attackers to generate tokens enabling access to customers’ Exchange Online and Outlook[.]com accounts. Subsequent research found that the compromised key could have granted access to a wider… Read More
Optimizing Incident Response with Advanced Threat Intelligence

Blog

Optimizing Incident Response with Advanced Threat Intelligence
Here’s how modern threat intelligence tools can refine and improve an organization’s incident response strategies.
Cyber Threat Intelligence
Tech Center
日経XTECH: 「AI版GitHub」に「生成AI評価ツール」、活用支える技術基盤で新興勢に存在感

メディア掲載

日経XTECH: 「AI版GitHub」に「生成AI評価ツール」、活用支える技術基盤で新興勢に存在感
生成AI(人工知能)を支える技術基盤でスタートアップ勢の存在感が増している。オープンソースのAIモデルやデータを共有するプラットフォーム、既に数十万種類あるといわれるAIモデルから最適なものを選ぶ評価ツール──。こうした「縁の下の力持ち」の存在も、AI活用には欠かせない。様々な基盤を手掛ける6社の実力を見ていこう。
Japanese
EnterpriseZine: 2024年はサイバー攻撃者のAI活用でゼロデイ脆弱性増加か

メディア掲載

EnterpriseZine: 2024年はサイバー攻撃者のAI活用でゼロデイ脆弱性増加か
SecurityScorecardは、「2024年 サイバーセキュリティに関する予測」を発表した。
Japanese
C-Suite Liability and Cybersecurity: Strategies for Navigating a New Era of Enforcement

Ebook

C-Suite Liability and Cybersecurity: Strategies for Navigating a New Era of Enforcement
The role of the CISO was already a stressful one, with significant retention issues and burnout risk. In short, the personal and professional stakes for CISOs just got higher. A recent survey reveals that 62% of CISOs are concerned about being held personally\r\nliable for cyberattacks that occur on their watch.\r\n \r\nIn the following pages, we’ll explore strategies that CISOs and other C-Suite executives can use to boost their organizations’ cyber resilience while also protecting themselves from legal fallout.
Japan’s Nikkei 225 Index: The State of Cybersecurity in Japan

Research

Japan’s Nikkei 225 Index: The State of Cybersecurity in Japan
This research presents an analysis of the cybersecurity landscape of the Nikkei 225 index. Companies were ranked based on various factors, such as network security, potential malware exploits, and patching cadence.
Cyber Threat Intelligence
Security Ratings
TECH+: サプライチェーンに対するサイバー攻撃の現状と対策

メディア掲載

TECH+: サプライチェーンに対するサイバー攻撃の現状と対策
近年、サプライチェーンの脆弱性を突いたサイバー攻撃が増えている。これについては、世界中の政府が危機感を持っており、例えば、バイデン政権は国家サイバーセキュリティ戦略(National Cybersecurity Strategy)を発表した。本稿では、サプライチェーンに対するサイバー攻撃の現状と対策について説明する。
Japanese
日本経済新聞: 国内大企業のサイバー防衛、4割弱にリスク

メディア掲載

日本経済新聞: 国内大企業のサイバー防衛、4割弱にリスク
企業のサイバー防衛力の評価ツールを手掛ける米セキュリティ・スコアカード(SSC)日本法人は、日経平均を構成する225社のうち大手業種の企業に対する調査結果をまとめた。
Japanese
EnterpriseZine: 日経225の製造業と重要インフラに最低評価

メディア掲載

EnterpriseZine: 日経225の製造業と重要インフラに最低評価
SecurityScorecardは、日経225企業の業種別サイバーリスクレーティング調査に関する説明会を開催した。
Japanese
2025 Guide to Completing a Vendor Risk Management Questionnaire

Blog

2025 Guide to Completing a Vendor Risk Management Questionnaire
Vendor risk management is increasingly crucial in 2025 as enterprises integrate more cloud-based solutions into their IT ecosystems. With this shift comes greater compliance risks, making the verification of vendors’ security controls and regular security audits essential. Understanding and managing these risks effectively requires ongoing communication with… Read More
Tech Center
SecurityScorecard Threat Intelligence Reveals 90% of Energy Companies Experienced a Third-Party Breach

Press

SecurityScorecard Threat Intelligence Reveals 90% of Energy Companies Experienced a Third-Party Breach
New research from SecurityScorecard reveals 90% of the world’s leading energy companies experienced a third-party data breach in the past 12 months.
Cyber Risk Intelligence: Idaho National Laboratory Data Breach

Research

Cyber Risk Intelligence: Idaho National Laboratory Data Breach
On November 20, a spokesperson for Idaho National Laboratory (INL) confirmed that it had suffered a data breach. The confirmation followed the SiegedSec threat actor group’s circulation of claims that it had “accessed hundreds of thousands of user, employee and citizen data” on social media and hacking forums.
Public Sector
Energy Sector Cybersecurity Report: Navigating Third-Party Cyber Risk

Research

Energy Sector Cybersecurity Report: Navigating Third-Party Cyber Risk
SecurityScorecard threat researchers have identified that 90% of the world’s largest energy companies experienced a third party breach in the past 12 months. Fueling the global economy and daily life, reliance on the energy sector elevates it as a prime target for cyberattacks.
Cyber Threat Intelligence
SecurityScorecard Recognized as One to Watch in  Snowflake’s Inaugural Cybersecurity Report

Press

SecurityScorecard Recognized as One to Watch in Snowflake’s Inaugural Cybersecurity Report
SecurityScorecard has been recognized as one to watch in the Data Enrichment category in Snowflake’s inaugural cybersecurity report.
Cyber Risk Intelligence: Iran-Linked Attack on U.S. Water Treatment Facility

Research

Cyber Risk Intelligence: Iran-Linked Attack on U.S. Water Treatment Facility
On November 25, a U.S. municipal water authority confirmed that one of its booster stations had suffered an attack by a threat actor group known as CyberAv3ngers, which analysts believe acts in support of Iranian geopolitical interests.
Public Sector
日経ビジネス: あなたは何社知っている?新興勢が爆速成長 生成AIの旗手25選

メディア掲載

日経ビジネス: あなたは何社知っている?新興勢が爆速成長 生成AIの旗手25選
世界の新興投資が減速する中でも、生成AI(人工知能)だけは別世界。評価額10億ドル以上のユニコーンに爆速成長する新興企業が相次ぐ。本誌が厳選した、要注目の海外AIスタートアップ25社を紹介する。
Japanese
C-Suite Liability & Cybersecurity: Navigating a New Era of Enforcement

Blog

C-Suite Liability & Cybersecurity: Navigating a New Era of Enforcement
It’s well established that corporate directors have fiduciary “duties of care” to protect their companies against major risks and compliance failures. Only recently have courts clarified that these duties now extend to the C-Suite — CEOs, CISOs, GCs and other key executives now face personal liability for failing to safeguard their companies.
Executive Viewpoint
Decoding the Boardroom: A Fortune 500 CISO’s Guide to Winning Hearts and Budgets

Blog

Decoding the Boardroom: A Fortune 500 CISO’s Guide to Winning Hearts and Budgets
It’s imperative for CISOs to learn how to speak the language of their boards and stakeholders, oh by the way…it’s not cyber risk probability! Board members and business stakeholders prefer economic terminology over tech talk.
Executive Viewpoint
Security Ratings
Cyber Risk Intelligence: Exploitation of CVE-2023-47246

Research

Cyber Risk Intelligence: Exploitation of CVE-2023-47246
Executive Summary On November 8, SysAid disclosed that the Cl0p ransomware group had exploited a previously unknown vulnerability, now tracked as CVE-2023-47246, in SysAid’s on-premise IT Service Management (ITSM) software. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted SecurityScorecard’s Attack Surface Intelligence data and a… Read More