Resources

Research

Resource Library

Clear filters

Security Assessment of the Top 100 U.S. Gov’t Contractors

January 21, 2025

Security Assessment of the Top 100 U.S. Gov’t Contractors
Federal contractors are integral to supporting the operations of the U.S. government. However, as these contractors face evolving cyber threats, it’s critical to understand the vulnerabilities that could affect their ability to secure sensitive data and provide essential services. This report examines the security ratings and breach histories of the top 100 U.S. government contractors, uncovering significant gaps that could disrupt government functions and expose sensitive information. Key Findings: 58% of breaches were caused by third-party vulnerabilities, posing a direct threat to both contractors and the government. 35% of contractors had at least one publicly reported breach, with some experiencing multiple incidents, indicating a recurring security problem. Ransomware groups were responsible for 41.25% of breaches, and the frequency of attacks on third-party vendors (46.5%) is rising. 28% of contractors had malware infections or compromised devices, showing a need for stronger internal security measures. Defense and intelligence contractors had the highest security ratings, but technology and telecommunications contractors were among the lowest.   Download this report to learn more about the current landscape and discover practical steps that can be taken to enhance the security of the federal supply chain.
Operation 99: North Korea’s Cyber Assault on Software Developers

January 15, 2025

Operation 99: North Korea’s Cyber Assault on Software Developers
On January 9, the SecurityScorecard STRIKE team uncovered Operation 99, a cyberattack by the Lazarus Group, North Korea’s state-sponsored hacking unit.
STRIKE Team
Europe’s Top 100 Companies: Cybersecurity Threat Report

December 12, 2024

Europe’s Top 100 Companies: Cybersecurity Threat Report
This report analyzes the cybersecurity of the top 100 companies in the Europe by market capitalization. Through comprehensive analysis of their attack surface and reported breaches, SecurityScorecard data scientists uncovered several notable findings concerning third-party risk in Europe Key findings include: 98% of European companies experienced third-party breaches in the past year, highlighting widespread vulnerabilities. Only 26% of Europe’s top 100 companies achieved an A rating for cybersecurity resilience. 8% of companies reported direct breaches in the past year, illustrating significant gaps in internal defenses. Middle Eastern companies report significantly fewer breaches, with only 84% experiencing third-party breaches compared to Europe’s 98%. The Energy sector struggles most, with 75% of companies rated C or below, compared to the transport sector, where all companies scored B or higher. Download this report to understand the specific risks in Europe.
The Third-Party Cyber Risk Landscape of Japan

November 20, 2024

The Third-Party Cyber Risk Landscape of Japan
This comprehensive report provides a deep dive into third-party data breaches and third-party cyber risk in Japan. The goal is to provide third-party risk management (TPRM) teams inside and outside Japan with findings that can help them set clearer priorities for the vetting of vendors and other third parties. Key findings include: Japan still has a high third-party breach rate (41%): This percentage is somewhat lower than what the global third-party breaches report noted for Japan (48%), probably due to a larger sample size diluting this extreme outlier. 41% is still quite high. The Japanese industries with the most numerous or frequent third-party breaches include: Manufacturing, Automotive, and Construction (MAC); Technology, Media, and Telecommunications (TMT); and Retail & Hospitality (RH). MAC is a big part of the Japanese economy, whereas TMT and RH have more third-party breaches in particular. Third-party technology products and services are the top causes of Japan’s third-party breaches (58%): This finding fits global trends, but the percentage of Japan’s third-party breaches attributable to third-party technology is somewhat lower. Subsidiaries and acquisitions of Japanese companies, primarily overseas, are the other main cause of Japan’s third-party breaches (33%): This risk factor is not unique to Japan but seems to contribute to the country’s high rate of third-party breaches. Top threats to Japan include ransomware attacks and state-sponsored attacks from Chinese and North Korean groups. While state- sponsored attacks make up a smaller share compared to ransomware, they still account for a significant number of breaches:  Third-party attack vectors facilitate attacks on the often harder targets that state-sponsored groups pursue by finding weaknesses in their less secure supply chains.   Download this report to understand the specific risks in Japan.
The Middle East’s Top 100 Companies: Cybersecurity Threat Report

November 20, 2024

The Middle East’s Top 100 Companies: Cybersecurity Threat Report
Download the Report Today!This report analyzes the cybersecurity of the top 100 companies in the Middle East by market capitalization. Through comprehensive analysis of their attack surface and reported breaches, SecurityScorecard data scientists uncovered several notable findings concerning third-party risk in the Middle EastKey findings include: Only 2% of Middle Eastern companies reported a direct breach in the past year, compared to 18% in Europe. 84% of Middle Eastern companies have a breach in their third-party ecosystem, significantly lower than Europe’s 98%. Telecommunications is the weakest sector, with 86% of companies rated C or lower. Utilities is the most secure sector, with no companies scoring a C rating or lower and no direct breaches. To learn more, download the report today.
Third-Party Breaches Are the Top Threat for the U.S. Energy Sector

October 23, 2024

Third-Party Breaches Are the Top Threat for the U.S. Energy Sector
This comprehensive report provides a deep dive into the cybersecurity posture of the U.S. energy sector. We’ve analyzed 250 top energy companies using SecurityScorecard metrics to identify vulnerabilities and potential threats. Key findings include: Third-Party Risks: A significant majority of breaches involve third-party vendors, highlighting the need for stronger supply chain security. Varying Security Levels: Different segments of the energy supply chain exhibit varying levels of cybersecurity preparedness. Data Breaches and Ransomware: Both data breaches and ransomware pose significant threats to the industry. Download this report to understand the specific risks facing your organization and develop effective strategies to mitigate third-party risks.
Supply Chain Cyber Risk
Third-Party Risk Management
Scandinavia’s Top 100 Companies: Cybersecurity Threat Report

September 24, 2024

Scandinavia’s Top 100 Companies: Cybersecurity Threat Report
This report analyzes the cybersecurity of the top 100 companies in Scandinavia by market capitalization. Through comprehensive analysis of their attack surface and reported breaches, SecurityScorecard data scientists uncovered several notable findings concerning third-party risk in Scandinavia Key findings include: 98% had a breach in their third-party ecosystem 98% had a breach in their fourth-party ecosystem too 100% of the Scandinavian companies with an A grade have not been breached in the last year (demonstrating the importance of having an A grade) 20% had a C rating or below 3% have suffered a direct breach in the last year Only 16% of the top 25 companies by market cap have a rating of C or below compare to 28% of the bottom 25 companies The Financial Services sector is the most robust with 100% of the companies in it scoring a B or higher compared to the Telecommunications sector in which 67% had a C rating or below   To learn more, download the report today.
Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk

August 5, 2024

Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk
Companies among the Forbes Global 2000 stand at the forefront of economic output and influence. With great economic power comes great vulnerability, particularly in the realm of third-party risk. In the complex landscape of third-party cyber risk in this report, no organization is too big to fail. This report aims to provide an in-depth analysis of these risks, offering insights to help Global 2000 companies and their suppliers bolster defenses and mitigate the impacts of third-party cyber threats.
The Cyber Risk Landscape of the Global Aviation Industry, 2024

July 31, 2024

The Cyber Risk Landscape of the Global Aviation Industry, 2024
Third-party cyber risk impacts all industries, but some industries are more vulnerable and severely affected due to the nature of their business and larger third-party networks. SecurityScorecard researchers analyzed cyber risk across the aviation industry, including airlines and the various types of vendors they rely on. To bolster cybersecurity across the aviation industry, this research aims to elevate the priority of cyber risk within the industry’s critical security and safety discourse. Key findings from the report include: The cybersecurity grade of the aviation industry How third-party breaches have impacted aviation companies How customers contribute to third-party risk
Third-Party Risk Management
An Analysis of the Cyber Security Ratings of the Top 150 Technology Vendors

July 24, 2024

An Analysis of the Cyber Security Ratings of the Top 150 Technology Vendors
Earlier this year, we collaborated with McKinsey to explore just how concentrated cyber risk is in our global economy. One of the key findings of that report: 150 companies account for 90% of the technology products and services across the global attack surface. In this report, we take a deeper dive into those 150 technology vendors. Our analysis includes: The % of customer relationships and products these 150 vendors comprise Common risk factors for which these vendors receive their lowest scores Signs of compromised machines — and types of compromise — in the past year   Security practitioners can use this report to support assessments and improvement of their organization’s security hygiene and that of their nth party vendors.
Report sulle minacce per la sicurezza informatica

June 28, 2024

Report sulle minacce per la sicurezza informatica
Questo studio presenta un’analisi del panorama della sicurezza informatica delle 100 maggiori aziende italiane per capitalizzazione di mercato.Le aziende sono state classificate in base a vari fattori, come la sicurezza della rete, le potenziali infezioni da malware e le patch. I punti salienti includono: Il 95% ha subito una violazione nel proprio ecosistema di terze parti Il 100% con un grado A non è stato superato nell’ultimo anno Più grande non significa necessariamente una migliore sicurezza informatica Il 41% delle aziende ha un rating C o inferiore L’80% delle telecomunicazioni e dell’IT hanno un rating C o inferiore. Potete scaricare il rapporto completo qui.
The Cyber Risk Landscape of the U.S. Healthcare Industry

June 18, 2024

The Cyber Risk Landscape of the U.S. Healthcare Industry
This report presents an in-depth analysis of cybersecurity hygiene and risks in the U.S. healthcare industry The massive payment disruptions for U.S. healthcare providers resulting from the February 2024 BlackCat ransomware attack was an extreme, yet highly illustrative, example of the third-party risks stemming from high interdependence among healthcare organizations. This report aims to help healthcare organizations and their partners reduce such risks, by examining: The security ratings of healthcare organizations to identify those areas in which they score lowest Specific issues with the most negative impact on ratings Recent healthcare breaches, including ransomware attacks
Healthcare
The United Kingdom Top 100 Companies: Cybersecurity Threat Report

May 28, 2024

The United Kingdom Top 100 Companies: Cybersecurity Threat Report
This report analyzes the cybersecurity of the top 100 companies in the United Kingdom by market capitalization. Through comprehensive analysis of their attack surface and reported breaches, SecurityScorecard data scientists uncovered several notable findings concerning third-party risk in the UK Key findings include: 97% had a breach in their third-party ecosystem 97% had a breach in their fourth-party ecosystem 85% of the UK companies with an A grade have not been breached in the last year 24% of companies have a C rating or below Only 12% experienced a direct breach in the last year   To learn more, download the report today.
Deutschlands Top 100 Unternehmen: Bericht zu Cybersicherheitsbedrohungen

May 15, 2024

Deutschlands Top 100 Unternehmen: Bericht zu Cybersicherheitsbedrohungen
SecurityScorecard veröffentlichte eine umfassende Analyse der Cybersicherheitslandschaft der 100 größten Unternehmen in Deutschland. Unter Verwendung des weltweit größten proprietären Risiko- und Bedrohungsdatensatzes analysierte SecurityScorecard Cybersicherheitsverstöße in den 100 größten Unternehmen Deutschlands. Hauptergebnisse: 94% der Unternehmen hatten einen Verstoß in ihrem Drittanbieter-Ökosystem 44% der Top 25 Unternehmen haben einen Scorewert von C oder niedriger 57% des Kommunikationssektors hatten eine Bewertung von C oder niedriger 34% der Unternehmen haben eine Bewertung von C oder niedriger Nur 65% der Top 100 Unternehmen in Deutschland haben eine Bewertung von A oder B
Concentrated Cyber Risk in a Global Economy

May 2, 2024

Concentrated Cyber Risk in a Global Economy
With knowledge contributions from McKinsey & Company, this threat research uncovers an extreme concentration of cyber risk that poses serious threats to national security and global economies. The research also details a surge in adversaries exploiting third-party vulnerabilities to maximize the stealth, speed, and impact of supply chain cyberattacks. Other key findings include: 150 companies account for 90% of the technology products and services across the global attack surface. 41% of those companies had evidence of at least one compromised device in the past year. 11% had evidence of a ransomware infection in the past year. 62% of the global external attack surface is concentrated in the products and services of just 15 companies. The top 15 third parties have below-average cybersecurity risk ratings – indicating a higher likelihood of breach. Learn more about concentrated cyber risk and how to boost your organization’s resilience.
Supply Chain Cyber Risk
A Quantitative Analysis of the Security Ratings of the S&P 500

April 3, 2024

A Quantitative Analysis of the Security Ratings of the S&P 500
Download the Report   New cybersecurity regulations from the SEC require publicly traded companies to disclose “material” cyber incidents within four days. But many companies, policymakers, and shareholders still lack key insights into the current threat landscape. Against this backdrop, SecurityScorecard’s threat researchers analyzed the security ratings of the members of the S&P 500 U.S. stock market index. Key findings from the report include: 21% of S&P 500 companies reported breaches in 2023 25% of these breaches impacted Financial Services and Insurance companies 52% of companies had Exposed Personal Information The average Social Engineering risk grade for the S&P 500 is an “F”   To find out more, download the 2024 SecurityScorecard S&P 500 Cyber Threat Report.
Security Ratings
The Cybersecurity of France’s Top 100 Companies

March 26, 2024

The Cybersecurity of France’s Top 100 Companies
Liberté, égalité, cybersécurité : La cybersécurité des 100 plus grandes entreprises françaises Cette étude présente une analyse du paysage de la cybersécurité des 100 plus grandes entreprises françaises (en termes de capitalisation boursière). Les entreprises ont été classées en fonction de divers facteurs, tels que la sécurité du réseau, les infections potentielles par des logiciels malveillants et l’application des correctifs. Vous pouvez télécharger le rapport complet ici.
Security Ratings
Supply Chain Cyber Risk
CISO Playbook: Third-Party Cyber Incident Response

March 13, 2024

CISO Playbook: Third-Party Cyber Incident Response
With 98% of companies exposed to risks via third-party vendors, understanding and operationalizing an effective third-party cyber incident response is more critical than ever. In this playbook, we’ll cover how you can Streamline your response efforts Communicate effectively during crises, and Transform insights from past incidents into fortified defenses for your digital ecosystem   Delve into actionable steps and best practices, ensuring your response plan is not just a protocol but a robust shield against the escalating threats in the digital landscape.
Services
Supply Chain Cyber Risk
CISO Playbook: Third-Party Cyber Incident Response

March 13, 2024

CISO Playbook: Third-Party Cyber Incident Response
With 98% of companies exposed to risks via third-party vendors, understanding and operationalizing an effective third-party cyber incident response is more critical than ever. In this playbook, we’ll cover how you can Streamline your response efforts Communicate effectively during crises, and Transform insights from past incidents into fortified defenses for your digital ecosystem   Delve into actionable steps and best practices, ensuring your response plan is not just a protocol but a robust shield against the escalating threats in the digital landscape.
Services
Supply Chain Cyber Risk
A technical analysis of the APT28’s backdoor called OCEANMAP

March 5, 2024

A technical analysis of the APT28’s backdoor called OCEANMAP
A technical analysis of the APT28’s backdoor called OCEANMAP   Late last year, the Computer Emergency Response Team of Ukraine (CERT-UA) released an advisory that reported cyberattacks targeting state organizations attributed to the Russian espionage group APT28, aka Fancy Bear/Sofacy. The advisory listed the use of a new backdoor named “OCEANMAP.” Download this whitepaper to explore a technical analysis of APT28’s tactics, techniques, and procedures.
Cyber Threat Intelligence
Enterprise Cyber Risk
Supply Chain Cyber Risk
Global Third-Party Cybersecurity Breach Report

February 28, 2024

Global Third-Party Cybersecurity Breach Report
An in-depth analysis of the most significant third-party cyber risks and incidents in 2023. Covering adversary activity in 2023, this report is the first to use SecurityScorecard’s new BreachDetails threat intelligence solution. With BreachDetails, SecurityScorecard increased the level of breach data coverage by 50% compared to other breach notice providers by using AI to analyze news articles, ransomware notifications, and international sources. Key findings: 75% of third-party breaches targeted the software and technology supply chain 64% of third-party breaches linked to C10p cybercrime group 61% of third-party breaches attributed to MOVEit (CVE-2023-34362)
Services
Supply Chain Cyber Risk