Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Blog
What is a SOC 2 Compliance Checklist?
Use this SOC 2 compliance checklist to prepare for your audit, meet requirements, and maintain continuous compliance. Expert guidance for security leaders.
Blog
What Are Moltbot and Moltbook and What Happens When Agentic AI Assistants Scale Without Security
Moltbot AI assistants and their social media platform Moltbook have sparked AGI fears in recent days, but the real risk is access. Learn what Moltbook and Moltbot are (now OpenClaw and formerly known as Clawdbot), why it’s not artificial general intelligence (AGI), and how to reduce security exposure.
Blog
What Is Network Cloud Security?
Learn what network cloud security is, why traditional approaches fall short, and best practices for protecting your cloud infrastructure from security threats.
Blog
Odyssey 2026 Recap: Building Continuous Supply Chain Resilience in an Era of Persistent Threats
SecurityScorecard’s Odyssey 2026 customer conference in Miami brought CISOs together to examine continuous, threat-informed supply chain security and the shift from periodic assessments to real-time risk operations.
Blog
What Is Cyber Incident Response and Why It Matters
Learn what cyber incident response is, the steps in the incident response lifecycle, and how to build effective incident response teams and playbooks.
STRIKE
The Quiet Siege II
Explore a fictional depiction of a DDoS attack in The Quiet Siege Part II: Life, Interrupted. The scenario described does not represent a real attack, organization, or incident.
STRIKE
The Quiet Siege I
Explore a fictional depiction of a DDoS attack. The scenario described does not represent a real attack, organization, or incident.
STRIKE
Latin America as a Proving Ground: Cybercriminal Innovation and Escalation
The Conti ransomware group, active since late 2019, quickly became one of the most aggressive forces in the world of cybercrime. Known for “big game hunting” and its double-extortion model: stealing data before encrypting systems, Conti targeted major institutions in healthcare, education, and infrastructure.
Blog
Critical Update: What Security Leaders Need to Know Right Now About the Future of CISA and Threat Sharing
Discover how the expiration of the Cybersecurity Information Sharing Act (CISA 2015) disrupted threat intelligence, weakened national security, and widened AI-driven attack gaps. SecurityScorecard’s Mike Centrella and Dr. Aleksandr Yampolskiy explain what’s at stake as the January 2026 deadline nears amid a potential government shutdown.
Blog
What is a Parked Domain?
Learn what is a parked domain, why people park domains, and the security risks they create. Discover how to protect your attack surface from hidden threats.
Blog
Cyber Resilience in 2026: Why Supply Chains Are the New Front Line
The World Economic Forum’s Global Cybersecurity Outlook 2026 delivers a clear message for leaders across government and industry: cyber risk no longer lives inside the firewall.
Research
How to Prepare for Hong Kong’s Protection of Critical Infrastructure Bill in 2026
Hong Kong’s Protection of Critical Infrastructures Bill, effective January 1, 2026, introduces a comprehensive cybersecurity framework to safeguard essential services and strengthen national resilience. The legislation mandates operator-level accountability for both internal systems and external dependencies, including cloud platforms, managed services, and third-party vendors. Non-compliance carries severe financial penalties, emphasizing the need for structured governance and continuous oversight.
The whitepaper outlines:
Scope and Impact: Applies to critical sectors such as energy, finance, healthcare, transport, IT, communications, and government services.
Key Requirements: Formal risk assessments, documented mitigation actions, continuous monitoring, and demonstrable supplier oversight.
Compliance Challenges: Visibility into external risks, managing complex supply chains, and maintaining real-time control.
Strategic Recommendations: Conduct readiness assessments, implement continuous monitoring, strengthen supplier governance, and build auditable reporting frameworks.
Global Alignment: The Bill aligns with international standards such as the EU NIS2 Directive and Singapore’s Cybersecurity Act, signaling a global trend toward proactive cyber resilience.
By acting now, organizations can transform compliance obligations into an opportunity to enhance operational resilience and protect against evolving threats. The paper also highlights how SecurityScorecard’s platform enables continuous monitoring, AI-driven risk management, and structured reporting to meet these new regulatory expectations.
Contact us at marketing-apac@securityscorecard.io for further information or assistance.
Blog
What Is a Brute Force Attack and How to Prevent It
What is a brute force attack, how attackers use password cracking methods to gain access, and proven strategies to protect yourself.
Blog
What is SOX Compliance?
Discover how SOX compliance protects financial reporting through internal controls, audits, and cybersecurity measures for public companies.
Blog
What Is Data Leakage
Data leakage occurs when sensitive information escapes an organization’s control, whether due to employee mistakes, software vulnerabilities, or intentional theft.
Resources
Tens of thousands more ASUS routers pwned by suspected, evolving China operation
Learn more in this resource.
STRIKE News
Blog
What is API Security?
Learn what API security is, common vulnerabilities like broken authentication, and essential techniques to protect your APIs from evolving threats.
Resources
How to know if your Asus router is one of thousands hacked by China-state hackers
Learn more in this resource.
STRIKE News
Resources
Iranian hackers were more coordinated, aligned during Israel conflict than it seemed
Learn more in this resource.
STRIKE News
Blog
How Executive Order 14028 Is Strengthening Supply Chain Cybersecurity for the Public and Private Sector
Executive Order 14028 emphasizes Zero Trust, cloud adoption, and improved threat sharing across agencies and vendors. Learn how this EO reshapes supply chain defense and how SecurityScorecard supports continuous monitoring and risk intelligence.
Blog
SecurityScorecard Awards and Recognitions in 2025
SecurityScorecard is recognized as a leader in third-party risk management and supply chain security. Explore the awards and recognitions the company received in 2025 for supply chain cyber risk management, AI-driven security innovation, executive leadership, and third-party risk intelligence.