Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
メディア掲載
EnterpriseZine: 2024年はサイバー攻撃者のAI活用でゼロデイ脆弱性増加か
SecurityScorecardは、「2024年 サイバーセキュリティに関する予測」を発表した。
Japanese
Ebook
C-Suite Liability and Cybersecurity: Strategies for Navigating a New Era of Enforcement
The role of the CISO was already a stressful one, with significant retention issues and burnout risk. In short, the personal and professional stakes for CISOs just got higher. A recent survey reveals that 62% of CISOs are concerned about being held personally\r\nliable for cyberattacks that occur on their watch.\r\n \r\nIn the following pages, we’ll explore strategies that CISOs and other C-Suite executives can use to boost their organizations’ cyber resilience while also protecting themselves from legal fallout.
Research
Japan’s Nikkei 225 Index: The State of Cybersecurity in Japan
The Nikkei 225 Cyber Threat Landscape
Companies were ranked based on various factors, such as network security, potential malware exploits, and patching cadence. To measure cyber risk, SecurityScorecard delivers standardized “A to F” letter grades that measure and validate organizations’ security posture and supply chains in real time. Validation of SecurityScorecard scores using statistical analysis demonstrates that companies with an F rating have a 13.8x greater likelihood of a data breach than companies with an A.
To download the full report, please submit your information.
Cyber Threat Intelligence
Security Ratings
メディア掲載
TECH+: サプライチェーンに対するサイバー攻撃の現状と対策
近年、サプライチェーンの脆弱性を突いたサイバー攻撃が増えている。これについては、世界中の政府が危機感を持っており、例えば、バイデン政権は国家サイバーセキュリティ戦略(National Cybersecurity Strategy)を発表した。本稿では、サプライチェーンに対するサイバー攻撃の現状と対策について説明する。
Japanese
メディア掲載
日本経済新聞: 国内大企業のサイバー防衛、4割弱にリスク
企業のサイバー防衛力の評価ツールを手掛ける米セキュリティ・スコアカード(SSC)日本法人は、日経平均を構成する225社のうち大手業種の企業に対する調査結果をまとめた。
Japanese
メディア掲載
EnterpriseZine: 日経225の製造業と重要インフラに最低評価
SecurityScorecardは、日経225企業の業種別サイバーリスクレーティング調査に関する説明会を開催した。
Japanese
Blog
2025 Guide to Completing a Vendor Risk Management Questionnaire
Vendor risk management is increasingly crucial in 2025 as enterprises integrate more cloud-based solutions into their IT ecosystems. With this shift comes greater compliance risks, making the verification of vendors’ security controls and regular security audits essential. Understanding and managing these risks effectively requires ongoing communication with third—and fourth-party vendors. Utilizing a vendor risk management
Tech Center
Press
SecurityScorecard Threat Intelligence Reveals 90% of Energy Companies Experienced a Third-Party Breach
New research from SecurityScorecard reveals 90% of the world’s leading energy companies experienced a third-party data breach in the past 12 months.
Research
Cyber Risk Intelligence: Idaho National Laboratory Data Breach
On November 20, a spokesperson for Idaho National Laboratory (INL) confirmed that it had suffered a data breach. The confirmation followed the SiegedSec threat actor group’s circulation of claims that it had “accessed hundreds of thousands of user, employee and citizen data” on social media and hacking forums.
Public Sector
Research
Energy Sector Cybersecurity Report: Navigating Third-Party Cyber Risk
SecurityScorecard Threat Research
SecurityScorecard threat researchers have identified that 90% of the world’s largest energy companies experienced a third party breach in the past 12 months.
Fueling the global economy and daily life, reliance on the energy sector elevates it as a prime target for cyberattacks. Amid economic and political uncertainties, concerns about safeguarding this vital sector intensifies. Attacks on energy not only result in financial losses and disruptions but also ripple through manufacturing, healthcare, and transportation sectors.
Download the full report by submitting the form.
Cyber Threat Intelligence
Press
SecurityScorecard Recognized as One to Watch in Snowflake’s Inaugural Cybersecurity Report
SecurityScorecard has been recognized as one to watch in the Data Enrichment category in Snowflake’s inaugural cybersecurity report.
Research
Cyber Risk Intelligence: Iran-Linked Attack on U.S. Water Treatment Facility
On November 25, a U.S. municipal water authority confirmed that one of its booster stations had suffered an attack by a threat actor group known as CyberAv3ngers, which analysts believe acts in support of Iranian geopolitical interests.
Public Sector
メディア掲載
日経ビジネス: あなたは何社知っている?新興勢が爆速成長 生成AIの旗手25選
世界の新興投資が減速する中でも、生成AI(人工知能)だけは別世界。評価額10億ドル以上のユニコーンに爆速成長する新興企業が相次ぐ。本誌が厳選した、要注目の海外AIスタートアップ25社を紹介する。
Japanese
Blog
C-Suite Liability & Cybersecurity: Navigating a New Era of Enforcement
It’s well established that corporate directors have fiduciary “duties of care” to protect their companies against major risks and compliance failures. Only recently have courts clarified that these duties now extend to the C-Suite — CEOs, CISOs, GCs and other key executives now face personal liability for failing to safeguard their companies.
Executive Viewpoint
Blog
Decoding the Boardroom: A Fortune 500 CISO’s Guide to Winning Hearts and Budgets
It’s imperative for CISOs to learn how to speak the language of their boards and stakeholders, oh by the way…it’s not cyber risk probability! Board members and business stakeholders prefer economic terminology over tech talk.
Executive Viewpoint
Security Ratings
Research
Cyber Risk Intelligence: Exploitation of CVE-2023-47246
Executive Summary On November 8, SysAid disclosed that the Cl0p ransomware group had exploited a previously unknown vulnerability, now tracked as CVE-2023-47246, in SysAid’s on-premise IT Service Management (ITSM) software. The SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted SecurityScorecard’s Attack Surface Intelligence data and a partner’s network flow (NetFlow) data to identify
Webinars
Evolving with Threats: a 360 dive into continuous cyber risk assessment
Learn more in this resource.
Press
SecurityScorecard Joins Microsoft Security Copilot Partner Private Preview
SecurityScorecard today announced its participation in the Microsoft Security Copilot Partner Private Preview. SecurityScorecard was selected based on its proven experience with Microsoft Security technologies, willingness to explore and provide feedback on cutting-edge functionality, and close relationship with Microsoft.
Case Studies
Maximus
SecurityScorecard allows my team members to be more efficient.
Press
SecurityScorecard Adds Fortune 500 CISO Jim Routh to Cybersecurity Advisory Board
SecurityScorecard today announced the appointment of Jim Routh, a distinguished CISO and security leader with over 30 years of experience at Fortune 500 companies, as Senior Advisor and Chairman of its Cybersecurity Advisory Board.
Blog
What are Tabletop Exercises?
One of the best ways to prepare your organization for a security incident and reduce the cost of a breach is by putting your incident response plan to the test with tabletop exercises. Here we’ll explore the objectives of tabletop exercises and how they can improve your organization’s security posture.
Services
Tech Center