Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    SecurityScorecard Detects, Rates Security of Third-Party Suppliers

    Written by

    Sean Michael Kerner
    Published February 11, 2016
    Share
    Facebook
    Twitter
    Linkedin

      Modern enterprises face a lot of different types of threats, including security risks and vulnerabilities in the third-party vendor technologies they use. It’s a challenge that Aleksandr Yampolskiy, CEO and co-founder of SecurityScorecard, is tackling head on with his company’s new Automated Vendor Detection (AVD) capability that can identify and rate the security of vendors used by an organization.

      Yampolskiy, who holds a Ph.D. in cryptography from Yale University and has worked at big names in IT including Microsoft, Oracle and Goldman Sachs, started SecurityScorecard in 2013 after realizing that he could build a company to address the challenge of multivendor risk.

      “The question that kept me awake at night was, I had a good grasp of security at my own company but when it came to my vendors, partners and suppliers, I was left in the dark if they were as diligent as I was to protect my data,” Yampolskiy told eWEEK.

      SecurityScorecard, which employs approximately 60 people and is headquartered in New York City, in March 2015 raised $12.5 million in a Series A round of funding led by Sequoia Capital. What SecurityScorecard does is monitor millions of signals and terabytes of data from all over the Internet from every company in the world. The scorecard then rates the security of companies as observable from outside of the organization, according to Yampolskiy.

      The new piece of the SecurityScorecard platform that is now launching is the ability to automatically discover the vendors that an organization is using. Yampolskiy said that most organizations face an unknown downstream risk when doing business today, as they don’t always know all of the suppliers that their own vendors might be using.

      For example, an organization may be doing business with a partner that is using Dropbox to store their files, Slack for communication and GitHub to store source code. If any one of those vendors (Dropbox, Slack or GitHub in this example) experiences a hack, then there is a risk to the original partner with which the organization is working.

      “So we have built and patented a technology that can automatically discover a list of partners that a company might be using without the need for that company to first tell us who they are,” he said. “We’re looking at various traces of information that could indicate to us that a particular third-party service is being used by a company.”

      SecurityScorecard uses multiple techniques to gather data that informs the Automated Vendor Detection engine, Yampolskiy said. The collected data is then passed to SecurityScorecard’s machine learning algorithms to help improve accuracy and reduce the risks of false positives. SecurityScorecard makes use of proprietary crawler and scraping technologies as well as some open-source tools, including Elasticsearch, he added. The Elasticsearch technology is based on Apache Lucene and provides search engine capabilities.

      Looking forward, Yampolskiy said that SecurityScorecard is continuing to expand it capabilities and is building various analytics modules for cyber-insurance.

      “We’re doubling down on new ways to gather intelligence and reconnaissance,” he said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.