Product News

Find out about our new product features, the latest platform changes, and discover company announcements before anyone else.

Risk Management

Stay up to date on third-party risk management best practices and techniques, and learn about new regulations for third party risk.

Security Research

Keep up with research around the biggest data breaches, malware infections, IoT risks and all the latest news in cybersecurity.

48 Hours After the Google Phishing Scam, Don’t Let Your Guard Down

  Several news outlets have reported on the Google Docs phishing scam, so we won’t rehash all the details here. The short version is: On Wednesday, one million Gmail accounts were hit with a Google Docs phishing scam. The way the scam worked was the target user received an email, likely from someone they knew, … Continued

3 Third-Party Risk Management Challenges of 2016 & How To Conquer Them

3 Third-Party Risk Management Challenges of 2016 & How To Conquer Them

  Since the massive Target data breach in December 2013, third-party risk stopped being an afterthought and started becoming one of the top priorities for CISOs and Risk Departments. As a response, Third-Party Risk Management (TPRM) underwent a transformation in early 2014, and has continued through 2016 to keep up with today’s modern risks. With … Continued

Read More
3 Security Approaches CISOs Must Embrace To Mitigate Third Party Risk

3 Security Approaches CISOs Must Embrace To Mitigate Third Party Risk

  Guest post by Sam Kassoumeh, COO and co-founder of SecurityScorecard. A seasoned cybersecurity professional, he has been the Head of Security and Compliance at Gilt and led Global Security at Federal-Mogul. Sam has over 10 years of experience leading security teams. In this guest blog post, Sam offers a critical perspective of how CISOs … Continued

Read More
Information Security and The Rio Games: Was Brazil Ready?

Information Security and The Rio Games: Was Brazil Ready?

  On Friday August 5th, the Rio Olympics kicked off and millions of eyes eagerly anticipated the start of the games. In the eyes of information security, a tentative breath was held to see if a major security incident would affect the opening ceremony or any subsequent events. Large sporting events are increasingly becoming an … Continued

Read More
New Technology Can Solve Your Vendor Risk Management Problems

New Technology Can Solve Your Vendor Risk Management Problems

  Vendor Risk Management (VRM) is stuck in tradition, leaving it far behind when it comes to the security risks and challenges of today. While organizations are using using more vendors and exposing themselves to higher risk, they’re largely still using periodic onsite assessments, questionnaires, and point-in-time penetration tests to assess their vendor’s risk. While … Continued

Read More
How Big Is the U.S. Government Cybersecurity Problem?

How Big Is the U.S. Government Cybersecurity Problem?

A look at recent data breaches and how the government is reacting. It seems like the US government is more and more often falling prey to hackers, whether it’s from nation-sponsored organizations or independent organizations. Two government data breaches made the list of Network World’s list of ‘Biggest data breaches of 2015’ citing an IRS … Continued

Read More
The Healthcare Industry Currently Faces A Growing Cyber Security Crisis

The Healthcare Industry Currently Faces A Growing Cyber Security Crisis

  Hospitals are where you go to get healthy, but they are increasingly becoming playgrounds for hackers, owing to weak cyber security measures. A couple of weeks ago, networks of the Hollywood Presbyterian Medical Center, a California-based hospital, were held hostage, reportedly to the tune of 9,000 bitcoin or over $3.6 million. This isn’t a … Continued

Read More
Automatic Vendor Detection - Do You Know Who Your Vendors Are?

Automatic Vendor Detection – Do You Know Who Your Vendors Are?

Sometimes your biggest security challenge is the vendors who are unknown to the risk management team. Traditionally, in order to determine vendors an enterprise is engaged with, it required working with procurement and surveying various departments and individuals. It’s a time-consuming process that is prone to errors, oversights, and doesn’t account for the many “shadow” … Continued

Read More
Hilton and Starwood Data Breaches Spotlight Retail Malware

Hilton and Starwood Data Breaches Spotlight Retail Malware

Point of Sale Malware at Retail Stores Inside Hilton & Starwood Hotels The last few weeks have seen several major hotel chains including Starwood Hotels and Hilton Hotels report data breaches targeting the credit card data used at retail outlets inside the hotels. In both cases, Point of Sale (PoS) malware was the attack culprit. … Continued

Read More
An Analysis of the Pearson VUE Data Breach

An Analysis of the Pearson VUE Data Breach

Cisco Shuts Down Cert Tracker After Pearson Breach A third party technology examination company, Pearson VUE, was recently a victim of a malware attack that has exposed personal user data and passwords, according to Network Computing. Pearson VUE is one of the largest handlers of technology exams for companies and organizations that test individuals for … Continued

Read More
The Holiday Shopping Season's Retail Security Reality

The Holiday Shopping Season’s Retail Security Reality

Ranking Retail Security: Web Applications & Legacy Systems Are Weak Black Friday and Cyber Monday are almost here. Earlier this week, we released our 2015 Retail & eCommerce Security Report that examines a variety of security risk trends and problem areas within the top and bottom 10% of retail companies which represent roughly 200 retail … Continued

Read More
Tips for Vetting the Security of Cloud Service Providers

Tips for Vetting the Security of Cloud Service Providers

How to Vet Cloud Vendors and Make Sure CSPs Are Used Securely A modern enterprise uses the cloud and cloud service providers (CSP), period. Your employees might use DropBox or OneDrive to access work data remotely. You might communicate with your vendors mostly through a portal that accepts invoices and generates work orders. At the top … Continued

Read More
New Research Calls Out Today's Vendor Risk Challenges

New Research Calls Out Today’s Vendor Risk Challenges

New ESG Report: “Intelligence-driven Vendor and Supplier Security Risk Management” A recent study conducted by Enterprise Strategy Group (ESG), an IT research and strategy firm based in Milford, MA, looks at the issue of third party supplier and partner security in depth. The new report discusses approaches to today’s vendor risk management challenges and emerging technology solutions … Continued

Read More
SecurityScorecard Honored to Be a Part of the SINET 16 Showcase

SecurityScorecard Honored to Be a Part of the SINET 16 Showcase

SecurityScorecard Wins Coveted Innovation Award SecurityScorecard was recently named a top 16 winner from SINET, the Security Innovation Network. SINET chose SecurityScorecard as one of the winners out of over a hundred security companies. SecurityScorecard is one of the youngest companies on the winning roster. Our CEO and Co-founder, Dr. Aleksandr Yampolskiy, is presenting today … Continued

Read More
How Shadow IT Complicates Vendor Risk Management

How Shadow IT Complicates Vendor Risk Management

Third Party Dangers in Shadow IT The shadow information technology (IT) services provided by unknown third-party vendors introduce multiple risks. Any time data is moved to a vendor or accessed outside the corporate network by a third- or fourth-party, the risk of loss increases. Companies have, in one sense, lost control of IT. A Forbes article reported … Continued

Read More
Third Parties a Major Culprit in Healthcare Breaches

Third Parties a Major Culprit in Healthcare Breaches

Healthcare Breaches Cannot Be Ignored There have been two notable healthcare breaches in the last month: Upstate New York healthcare provider, Excellus Blue Cross Blue Shield, recently reported over 10 million patients’ records were breached. Systema Software, a Larskpur, California-based third party claims software provider, had data of 1.5 million customer claims data exposed on … Continued

Read More
Use Vendor Risk Management Templates to Establish a Baseline

Use Vendor Risk Management Templates to Establish a Baseline

Level the Vendor Risk Playing Field With Templates Two facts have radically transformed vendor risk management and the need for template use in just the past few years:   There’s increased awareness that vendors are often the weak links that allow data breaches to occur; Federal regulators are increasingly vocal about the need for aggressive … Continued

Read More
How Strong Is Your Vendor Management Program?

How Strong Is Your Vendor Management Program?

Vendor Management: You Need a Strategy Like the game of chess, vendor management requires understanding all the moves of all the pieces of vendors themselves. The more vendors differ in what and how they supply your company, the more challenging your vendor management (VM) program will be. Vendor management processes for companies with minimal vendor diversity … Continued

Read More
A Closer Look at Experian’s Scorecard

A Closer Look at Experian’s Scorecard

T-Mobile & Experian: The Fallout From Big Brand Breaches Update: Class-action lawsuits for Experian are increasing, according to The Hill. Experian, who released half-year financials yesterday, was quoted as saying: “It is currently not possible to predict the scope and effect on the Group of these various regulatory and government investigations and legal actions, including their timing … Continued

Read More