SecurityScorecard

SecurityScorecard AI-powered, threat-informed third-party risk management. Continuous visibility and predictive intelligence to secure global supply chains.

SecurityScorecard leads the way in Supply Chain Detection and Response, empowering organizations to swiftly manage and mitigate critical third-party risks.

🔐 Insider threats don’t always start on the inside.For National Insider Threat Awareness Month, The IT Nerd featured Sec...
09/03/2026

🔐 Insider threats don’t always start on the inside.

For National Insider Threat Awareness Month, The IT Nerd featured SecurityScorecard’s Mike Centrella, Head of Public Policy, on how the definition of an “insider” is changing.

Today, organizations face more than the traditional risk of an employee misusing sensitive information.

Outsiders can obtain legitimate access. Contractors can be compromised or recruited. Identities can be stolen. And trusted employees can become avenues for external threat actors.

As Mike explains, a valid account can’t automatically mean a trusted user — and trust can’t be treated as permanent.

As workforces increasingly span employees, contractors, remote workers, and external partners, organizations need to continuously understand who has access, what they can access, and when activity starts to deviate from what’s expected.

👉 Read Mike’s full perspective in The IT Nerd: https://itnerd.blog/2026/09/01/today-starts-national-insider-threat-awareness-month/

SecurityScorecard's CEO and Co-Founder Dr. Aleksandr Yampolskiy explains why roughly 90% of the internet runs on softwar...
09/02/2026

SecurityScorecard's CEO and Co-Founder Dr. Aleksandr Yampolskiy explains why roughly 90% of the internet runs on software built by a small handful of companies, and what happens when one of them stumbles.

He calls it "the digital butterfly effect": a single vulnerability that can ground flights, take hospitals offline, and lock you out of your own accounts, all at once.

🎤 Watch the full TEDx talk: https://www.youtube.com/watch?v=KNmHaPfuPjw

What resonated most with you? Drop a comment below. 👇

AI can speed up a vendor assessment but of course, a human-in-the-loop approach is critical.SecurityScorecard's eBook dr...
09/02/2026

AI can speed up a vendor assessment but of course, a human-in-the-loop approach is critical.

SecurityScorecard's eBook draws on candid insights from experienced risk management practitioners to show how the best TPRM teams use a documentation-first model that cuts assessment time without sacrificing rigor, and where AI belongs in that process versus where it doesn't.

📄 A documentation-first approach that speeds up review without cutting corners
🤖 Where AI acts as a force multiplier, and where human judgment still belongs
⚡ How to move from calendar-driven audits to reviews triggered by real risk events

👉 Get the eBook and see exactly where AI should (and shouldn't) drive your assessment process: https://securityscorecard.com/resources/ebook/the-questionnaire-trap/?utm_campaign=&utm_content=&utm_medium=social&utm_source=facebook

Four AI models broke out of testing environments in less than three weeks.In a new byline for Unite.AI, SecurityScorecar...
09/01/2026

Four AI models broke out of testing environments in less than three weeks.

In a new byline for Unite.AI, SecurityScorecard CEO and Co-Founder Dr. Aleksandr Yampolskiy explains why security leaders should see these incidents as more than AI safety stories. They’re third-party risk stories.

One number stands out: of the roughly 17,600 attacker actions Hugging Face recovered from its logs, most failed.

The agent was blocked. It hit dead ends. It tried again. And again. Failure cost almost nothing.

That changes the economics of cybersecurity — and raises the stakes for organizations whose attack surface now extends across interconnected vendors, infrastructure, and technology dependencies.

As Alex writes, we can’t answer machine-speed attacks with human-speed triage.

👉 Read his full perspective in Unite.AI: https://www.unite.ai/ai-sandbox-escapes-third-party-cybersecurity-risk/

09/01/2026

A vendor answers your questionnaire. Their answers may not match what's actually happening on their network. Someone has to catch that gap.

TITAN Watch's Questionnaire Gap Analysis Agent does it automatically, comparing vendor-reported answers against real-world scan data and flagging discrepancies your team would otherwise have to identify manually.

In this installment of SecurityScorecard's Demo Tuesday series, see the Questionnaire Gap Analysis Agent in action.

📺 Watch the demo below

👉 See how much faster it gets to catch questionnaire discrepancies before they become blind spots: https://securityscorecard.com/resources/?resource_tag=demo-tuesdays&utm_campaign=&utm_content=&utm_medium=social&utm_source=facebook

Cisco Talos just confirmed something SecurityScorecard's STRIKE team suspected: LapDogs never actually stopped.STRIKE pi...
09/01/2026

Cisco Talos just confirmed something SecurityScorecard's STRIKE team suspected: LapDogs never actually stopped.

STRIKE pivoted off a new certificate detail in Talos' report and identified three previously undisclosed servers tied to UAT-7810's ORB network, first exposed by SecurityScorecard in 2025.

The operators have also released three new tools, LONGLEASH, DOGLEASH, and JARLEASH, aimed at managing and extending compromised routers long-term.

🔍 Three new IPs, with active windows and ports, that defenders should check against their own traffic

🌐 Why home routers remain one of the most exposed and least-monitored device categories

🛰️ What continued investment after public exposure reveals about how well-resourced actors actually operate

👉 Read the full findings and get the new indicators: https://securityscorecard.com/resources/strike/lapdogs-is-back-inside-uat-7810s-expanding-orb-network-and-its-new-servers/?utm_campaign=&utm_content=&utm_medium=social&utm_source=facebook

📚 What does it take to get an “A” in cybersecurity from your Board of Directors?Join SecurityScorecard CEO and Co-Founde...
08/31/2026

📚 What does it take to get an “A” in cybersecurity from your Board of Directors?

Join SecurityScorecard CEO and Co-Founder Dr. Aleksandr Yampolskiy at Books in Cyber on September 8 for a spotlight on his book, The Perfect Scorecard: Getting An 'A' in Cybersecurity From Your Board of Directors.

When Alex wrote The Perfect Scorecard, the idea was simple: you can’t manage cyber risk if you can’t measure it.

That thinking helped shape SecurityScorecard’s journey — from giving organizations a way to understand cyber risk to TITAN AI, which brings continuous threat intelligence and AI-powered action into how organizations manage risk across their supply chains.

At Books in Cyber, Alex will revisit the ideas behind the book and how the cybersecurity landscape and the way leaders need to measure, communicate, and act on risk has evolved.

💻 The event is virtual and free to attend. Tune in live and hear from Alex alongside cybersecurity authors and leaders from across the industry.

📅 September 8
⏰ Alex’s Book Spotlight: 1:50-2:10 PM ET
🎥 Virtual & free

👉 Register to join: https://booksincyber.com/

"You're expected to hit the ground running on day one, but you're never expected to do it alone. I’ve been struck by how...
08/31/2026

"You're expected to hit the ground running on day one, but you're never expected to do it alone. I’ve been struck by how proactive everyone is about offering support, feedback, and advice."

That's Riché Zamor's take after his first week as VP of Product Operations & AI Innovation at SecurityScorecard.

He's already collaborating directly with customers and thinking through what an AI operating system across product, engineering, and design actually looks like at scale.

👉 Read Riché's full spotlight and what drew him to SecurityScorecard: https://securityscorecard.com/blog/new-hire-spotlight-riche-zamor/?utm_campaign=&utm_content=&utm_medium=social&utm_source=facebook

Every SecurityScorecard release adds something new and we want to make sure that you're aware of the exciting new update...
08/31/2026

Every SecurityScorecard release adds something new and we want to make sure that you're aware of the exciting new updates that we have!

Join Kelsey Leon, Product Marketing Manager, and Luke Tremont, Solutions Architect at SecurityScorecard, for Pulse Check: Tips & Tricks for What's New at SecurityScorecard. This month, they're walking through recent platform updates to optimize your TPRM workflow and showing exactly how to put each one to work with real use cases.

🗓️ Register today: https://www.brighttalk.com/webcast/19566/674333?bt_tok=%7B%7Blead.Id%7D%7D&utm_source=SecurityScorecard&utm_medium=brighttalk&utm_campaign=674333
📅 September 9, 2026 | 12 p.m. EDT

⚙️ Custom fields that actually match how you assess risk
🧵 Auditable, in-platform threads instead of buried email chains
📄 AI Document Analysis that cuts hours out of manual questionnaire review
🚨 Visibility into Alleged Breaches across your vendor ecosystem

The US just disrupted infrastructure allegedly run by a China-based firm with clients including China's Ministry of Stat...
08/29/2026

The US just disrupted infrastructure allegedly run by a China-based firm with clients including China's Ministry of State Security and its military.

The platforms let attackers infect thousands of routers and other devices, then route attacks through them to hide the true source.

SecurityScorecard's Richard Hummel, VP of Threat Intelligence, spoke with Al Jazeera about what this takedown actually disrupts: "When an intrusion appears to come from a device down the street from the target instead of from overseas, it buys the operator time and makes attribution slow. Taking two platforms of that size offline costs the operators real capability they were using every day."

👉 Read the full story on Al Jazeera: https://www.aljazeera.com/news/2026/8/26/us-says-chinese-linked-hackers-attacked-nasa-senate-and-govt-agencies

Address

1140 Avenue Of The Americas/19th Floor
New York, NY
10036

Opening Hours

Monday 8:30am - 7pm
Tuesday 8:30am - 7pm
Wednesday 8:30am - 7pm
Thursday 8:30am - 7pm
Friday 8:30am - 7pm

Telephone

(800) 682-1707

Alerts

Be the first to know and let us send you an email when SecurityScorecard posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to SecurityScorecard:

Shortcuts

Share