Product News

Find out about our new product features, the latest platform changes, and discover company announcements before anyone else.

Risk Management

Stay up to date on third-party risk management best practices and techniques, and learn about new regulations for third party risk.

Security Research

Keep up with research around the biggest data breaches, malware infections, IoT risks and all the latest news in cybersecurity.

The Security of Mobile Apps Starts and Ends With Developers

Third Party Development Adds to the App Security Dillema According to a story from Business Insider, mobile device users spend 86 percent of their time using mobile apps, as opposed to the mobile web. Businesses cite the rapid adoption of apps as a way to cut costs and increase productivity, but apps suffer from insecure … Continued

Third-Party Security Breaches Sign of Growing Vendor Risk Problem

Third-Party Security Breaches Sign of Growing Vendor Risk Problem

Third Party Breaches Continue to Remain in the Media The long term effects of data breaches that have originated via third parties have the attention of executive boards of directors, but the C-level may not be as keen on dealing with the problem as you might think. These long term effects include: legal action from customers, damage … Continued

Read More
Echoes of Target Breach In Recent CVS Photo Partner Hack

Echoes of Target Breach In Recent CVS Photo Partner Hack

PNI Digital Media Was A Third Party Entry Point Into Big Retail: CVS, Walmart, Possibly Others Update: PNI Digital media is facing multiple class action lawsuits, according to Law 360 and Class Actions Reporter. One suit is centered on CVS in the state of Georgia; the other suit is focused on Costco which was filed … Continued

Read More
The Problem With Corporate Email Addresses on Social Networks

The Problem With Corporate Email Addresses on Social Networks

SecurityScorecard Finds Grainger Susceptible to Social Engineering In a July 14 press release, the B2B industrial distributor, W.W. Grainger reported that it had experienced a security attack. The company stated in this press release that there was “no evidence there is any impact to customers, suppliers or employees because there is no indication that information … Continued

Read More
[Case Study] How To Operationalize Third Party Risk Management

[Case Study] How To Operationalize Third Party Risk Management

Harry’s Automates Vendor Risk Management Harry’s, an online retailer, was looking to solve the paradoxical challenge of having accurate, precise security information about partners, vendors, and suppliers whose networks they cannot access. Organization’s such as Harry’s cannot directly log in and access a partner’s network to readily view the security posture of that third party’s … Continued

Read More
U.S. Military Manufacturer Experiences Data Breach

U.S. Military Manufacturer Experiences Data Breach

Over 3,700 Customers’ PII, and Credit Card Information Breached Durham, North Carolina-based LC Industries has recently reported a security data breach, according to SC Magazine. The breach, which occurred in early June, affects a total of 3,754 customers, and affected 22 specific customers in New Hampshire, hence a public notification to the Department of Justice in the … Continued

Read More
Monthly News Roundup: Q2 Small Business Data Breaches

Monthly News Roundup: Q2 Small Business Data Breaches

Keep Track of SMB Security & Third Party Security Risks The big name brands may get all the security and data breach attention, but that does not mean that is where all of the data breaches and hacks are occurring. As we look closer at the entire security and risk management threat landscape and include small and … Continued

Read More
SecurityScorecard CRO Talks LastPass Hack in Business Insider

SecurityScorecard CRO Talks LastPass Hack in Business Insider

We Monitor Hacker Chatter in Our Platform Our Chief of Research, Alex Heid, was interviewed yesterday by Business Insider on the LastPass breach that the company announced earlier in the week. Heid told the business website that there is evidence that LastPass had been probed by a hacker over two years ago in September of 2013. … Continued

Read More
Healthcare Breach Shines Spotlight on Third Party Security Risks

Healthcare Breach Shines Spotlight on Third Party Security Risks

6 Reported Medical Centers, Hospitals in Indiana Have Patient Records Breached Update: According to the Department of Health and Human Services, this third party data breach from Medical Informatics Engineering and NoMoreClipboard has now affected a whopping total of 3.9 million individuals, making it the fourth largest breach in 2015, according to Data Breach Today. … Continued

Read More
The Current State of UK Bank Security

The Current State of UK Bank Security

SecurityScorecard Digs into the Grades of UK Banks A Freedom of Information request in the UK has revealed 791 data breaches occurred at most of the region’s major banks since the start of 2013 (with 585 of the incidents occurring in 2014).  The FOI request was spawned by Egress Software Technologies, an email encryption provider, that recently reported … Continued

Read More
UPDATE: Feds Breached Again, Lose 21.5 Million Records

UPDATE: Feds Breached Again, Lose 21.5 Million Records

SecurityScorecard Finds Federal Department Had Poor Security Hygiene, Especially in IP Reputation LATEST UPDATE: The number of people affected by the OPM breach is now over 21.5 million, according to The New York Times. UPDATE: BloombergBusiness reported the numbers of employee and contractor records stolen could now be up to 14 million. The news organization … Continued

Read More
The Calm Before the Mobile API Data Breach Storm

The Calm Before the Mobile API Data Breach Storm

Prediction: Mobile App Security Practices Will Become a Third Party Data Risk Mobile security may not be as easy to exploit as other established attack styles, but this latest news could change that for the worse. The Center for Advanced Security Research Darmstadt (CASED) in Germany has responsibly disclosed a cloud application security issue it discovered and published … Continued

Read More
CISOs: Pay Attention to the Cost of Lost Customers

CISOs: Pay Attention to the Cost of Lost Customers

If you haven’t downloaded the latest Ponemon Institute report on the cost of data breaches, well, you might want it… Is that a yawn? A groan from data theft marketing fatigue and breach boredom? We get it. Talking about the financial impact of data breaches isn’t nearly as cool as dissecting hacks (ahem, Adult Friend Finder and … Continued

Read More
Financials Cheer Target's Failed Settlement with MasterCard

Financials Cheer Target’s Failed Settlement with MasterCard

Third Party Breaches Can Have Long Term Impact on Cost Breaches happen in minutes. Lawsuits happen for years. The total costs of Target’s 2013 data breach of 40 million customer credit card numbers will continue to be an unknown for a whole lot longer than the giant retailer would likely want after financial institutions rejected a proposed settlement from Target with MasterCard … Continued

Read More
Third Party Risk in Business Units Is Festering

Third Party Risk in Business Units Is Festering

Vendor management offices, risk management programs, and security leaders are all being asked to manage third party risks buried in business units. They are all looking at it from their own unique, but disparate disciplines and points of view. The reason it is so difficult to discover risk is for one, simple reason: the volume … Continued

Read More