Resources
Cybersecurity white papers, data sheets, webinars, videos and more
Resource Library
Blog
Show all
Scorecarder Spotlight: Emmy Chau
Our “Scorecarder Learning & Development Spotlight” series showcases our talented, driven employees, the incredible work they do, and their quest…
Scorecarder Spotlight
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
Domestic Sourcing Alone Won’t Secure America’s Defense Supply Chains
This month, the Administration signed an executive order that will force primes and subcontractors in the Defense Industrial Base to answer a question they have spent years avoiding: where does this actually come from? That’s the right question. It’s just not the whole question.
Case Studies
Show all
CEDIA
Cómo CEDIA transformó la ciberresiliencia del ecosistema académico ecuatoriano con SecurityScorecard
MRS Brazil
Depoimento da MRS sobre como a SecurityScorecard trouxe visibilidade independente à postura de segurança externa da empresa, elevando o score a 100% e tornando a gestão de risco cibernético um indicador estratégico acompanhado por executivos e áreas técnicas.
Solarig (SPN)
Cómo Solarig consolidó la supervisión continua de su huella digital y alcanzó una puntuación de 100 con SecurityScorecard.
Data Sheet
Show all
Unrivaled Global Telemetry for Proactive Defense and Threat Hunting
The TITAN AI Platform Corporate Overview
SecurityScorecard introduced an industry-first customer transformation model, Supply Chain Resilience Journey, designed to help organizations understand exactly where their TPRM program stands today and how to advance it. The journey maps four progressive stages: Basic Diligence, Periodic TPRM, Continuous TPRM, and Threat-Informed TPRM.
TITAN Watch: Foundational Visibility and a clear understanding risk in your vendor ecosystem
The TITAN Watch offering within SecurityScorecard’s TITAN AI platform helps organizations monitor risk in their extended supply chain and gain a clear understanding of their security posture.
Ebook
Show all
The Questionnaire Trap
Your TPRM program was designed to reduce risk – but bloated questionnaires, annual audit cycles, and vendor fatigue may be…
A Roadmap to Modern TPRM
Understanding the 4 Stages, the Gaps, and TPRM Priorities for Various Stakeholders Traditional Third-Party Risk Management (TPRM) programs, relying on…
Securing the Supply Chain: Building Cyber Resilience in the Modern Era
Traditional third-party risk management (TPRM) programs lack the continuous visibility and actionability required in today’s dynamic cyber threat environment. They…
Supply Chain Cyber Risk
Third-Party Risk Management
Infographic
Show all
The Total Economic Impact™ of the SecurityScorecard Platform
SecurityScorecard reduced third-party breaches by 75% – ROI of 176% in
Third-Party Incident Response Checklist
No matter the size, region, industry, or revenue, every organization needs a straightforward methodology for tracking supply chain risk indicators and building an incident timeline. \r\n\r\nThe SecurityScorecard MAX team created this checklist to ensure that your organization has a proactive plan in place to immediately respond to and mitigate supply chain incidents.
Supply Chain Cyber Risk
Third-Party Risk Management
Leading the Way – SecurityScorecard ratings are the best predictor of breach in the industry
Security ratings provide an objective and standardized way to assess the cybersecurity resilience of both small and large organizations.
Security Ratings
Learning Center
Show all
What is Zero Trust Architecture? 9 Steps to Implementation
Understanding what a Zero Trust Architecture is and how to implement one can help enhance security. Learn more on SecurityScorecard’s blog.
Attack Surface Management
Tech Center
What is a Cybersecurity Posture and How Can You Evaluate It?
Organizations across industries struggle to maintain robust security postures. While tremendous strides have been made in security technology, the fundamentals of establishing and maintaining a strong cybersecurity posture remain elusive for many organizations.
Tech Center
What is HIPAA Compliance? A Complete Guide
What is HIPAA compliance? Learn essential requirements, common violations, and best practices for healthcare data protection and security.
Tech Center
Podcasts
Show all
Why India Is Emerging as a Third-Party Breach Hotspot
SecurityScorecard experts analyzed why 52.6% of Indian vendors experienced at least one third-party breach in the past year in a recent webinar. India has become one of the most critical engines of the global digital economy and one of the most targeted.
How to Protect Yourself Against Holiday Scammers: Mike Centrella on Cybercrime Magazine Podcast
In Episode 1 of Cybercrime Magazine’s podcast series with SecurityScorecard, Head of Public Policy Mike Centrella joins podcast host Charlie Osborne and Eastman CISO Adam Keown to explore safe holiday shopping, avoiding scams, and how to build cyber resilience this season.
Report
Show all
SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot
SecurityScorecard researchers used Driftnet’s internet-scale discovery capabilities to analyze the network footprint of a small U.S. municipal utility provider that…
STRIKE Alert
STRIKE News
Close Encounters in the Insurance Sector
Cyber Insurance
Reduce Cyber Risk with the Predictive Power of Security Ratings
The Marsh McLennan Global Cyber Risk Analytics Center and SecurityScorecard have come together to study how cybersecurity ratings correlate with reduced cyber insurance risk.
Cyber Insurance
Research
Show all
Catch Me If You Can: Inside the Anonymization-for-Hire Network
In this briefing, Wade Lance VP, Product Marketing & Sales Enablement walks through STRIKE’s newest report Catch Me If You…
STRIKE Alert
STRIKE News
Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire
Blocklists, geolocation, and ASN reputation all share one assumption: that an IP tells you who’s behind it. CanOworms is built…
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead,…
STRIKE Alert
STRIKE News
Research Reports
Show all
2025 Supply Chain Cybersecurity Trends: Why Visibility Is the Next Competitive Advantage
A handful of technology giants now control the infrastructure that powers the global economy. Traditional cybersecurity threats target individual companies,…
Supply Chain Cyber Risk
Third-Party Risk Management
北朝鮮による世界規模のデータ窃取攻撃
北朝鮮のサイバー攻撃「Operation Phantom Circuit」の全貌を解明 最新レポートでは、北朝鮮のハッカー集団「Lazarus」による世界規模のサイバー攻撃の手口を詳細に分析。 サプライチェーン攻撃を通じて正規ソフトウェアにバックドアを仕込み、企業や開発者の機密データを巧妙に奪取する手法が明らかになりました。 233件以上の被害が確認された本攻撃の詳細や、サプライチェーンセキュリティを強化するための対策をレポートでご紹介。レポートの完全版をダウンロードして、詳細なデータと分析をご覧ください。
Japanese
日本におけるサードパーティサイバーリスクの現状
近年、日本におけるサードパーティを介したサイバー攻撃の割合は、世界平均を大幅に上回っています。本レポートでは、2024年春に発表されたグローバルサードパーティ侵害レポートの分析を基に、日本特有のリスク要因を詳しく調査しました。 このレポートでは以下のポイントを中心に解説しています。 日本でのサードパーティ攻撃経路による侵害の特性と原因 各業界におけるサードパーティリスクの分布 国家支援型攻撃グループの動向と日本における影響 リスク管理を強化するための具体的な推奨事項 製造、自動車、テクノロジー業界など、日本の主要産業における課題を明らかにし、サイバーリスク管理の向上に役立つ洞察を提供します。 レポートの完全版をダウンロードして、詳細なデータと分析をご覧ください。
Japanese
Resources
Show all
Insurance Authority of Hong Kong
How the Insurance Authority of Hong Kong Strengthened Cyber Visibility and Risk Posture with SecurityScorecard
Tens of thousands more ASUS routers pwned by suspected, evolving China operation
STRIKE News
How to know if your Asus router is one of thousands hacked by China-state hackers
STRIKE News
Tribune
Show allVideo
Show all
Unlock the Hidden Power of DriftNet’s Summary Page
A Driftnet tip for threat hunters: how the summary page reveals co-hosted domains and certs that hint at what an IP is really being used for.
Demo Tuesdays
Mastering Driftnet: Power-Filtering Strategies for Threat Hunters
See how Driftnet’s Add Filter and Add to Query options let you narrow, exclude, or reset artifact searches without losing your original results.
Demo Tuesdays
Hunting LapDogs: Threat Research with Driftnet
See how STRIKE’s threat intel team uses DriftNet to pivot on certificate fingerprints and uncover new LapDogs ORB network indicators.
Demo Tuesdays
Webinars
Show allWhite Papers
Show all
Meeting BNM RMiT 2025: A Guide to Third-Party & Supply Chain Cyber Risk Requirements
On 28 November 2025, Bank Negara Malaysia issued one of the most significant overhauls to Malaysian financial sector cybersecurity regulation…
TPRM: De la gestion statique au pilotage en temps réel
Moderniser la gestion des risques tiers grâce à l’IA et à la Threat Intelligence Pendant des décennies, la gestion des…
TITAN MAX Service
TITAN MAX inserts technology and expertise at every stage of the vendor lifecycle to drive TPRM outcomes.