初创公司尽调
尽调报告 Cybersecurity / cyber risk ratings and TPRM Series E (private, unicorn) 2026-06-29

SecurityScorecard

网络风险评级与 TPRM 平台:品类开创者,仍挂着过时独角兽估值

SecurityScorecard 定义了网络风险评级品类,已有真实企业级规模和强战略位置;但 $1B 估值已停留五年,二级市场压缩到 $360–$470M,NRR 和毛利率仍未披露,因此在经济性验证前只能给出观察建议。

封面要素

Series E 轮后估值(2021) 01
1000 USD M [CO026, CV001]
直接企业客户 04
3300 customers+ [CO033, CU001]
被监测组织 05
12000000 organizations [CO007, CU003]
Fortune 100 渗透率 06
70 % of Fortune 100 [CO008, CU002]
渠道 ARR 增长(2025) 07
160 % YoY [CI005, CU011]
单 FTE ARR 改善 08
40 % YoY (Q3 2025) [CI018, CV012]

公司概况

SecurityScorecard 由 Dr. Aleksandr Yampolskiy 和 Sam Kassoumeh 于 2013 年创立,总部位于 New York City。公司开创了网络安全评级品类,现在销售更宽的 Supply Chain Detection and Response(SCDR)平台,覆盖持续外部评级、第三方风险管理工作流、攻击面管理、AI 驱动的问卷自动化(TITAN AI)以及托管安全服务(MAX)。公开证据支持这样一个判断:公司具备战略相关性,ARR 超过 $150M、自由现金流为正、拥有 3,300+ 企业客户,并深度进入 Fortune 100 和政府账户;但公开记录仍缺少经审计经营数据、NRR、毛利率和当前融资事件——二级市场定价也显示,估值较 2021 年 $1B 独角兽轮已明显压缩。

官网
securityscorecard.com
成立时间
2013-07-01
创始人
Dr. Aleksandr Yampolskiy, Sam Kassoumeh
创立地点
New York City, New York, USA
总部
New York, New York, USA (1140 Avenue of the Americas, 19th Floor)
产品
SecurityScorecard 平台为 12M+ 被监测组织提供持续的外部视角安全评级、供应商风险管理(TPRM)工作流、外部攻击面管理、TITAN AI 问卷自动化(将人工评估工作量降低 92%),以及由认证服务伙伴交付的 MAX 托管检测与响应。核心产品是一套获得专利的 A 到 F 评分引擎,覆盖十组风险因子,不需要安装代理,也不需要供应商参与。
客户
大型企业(53% 的评估者拥有 1,000+ 名员工)、金融服务公司(占 PeerSpot 会话 12%)、Fortune 100 和政府实体、网络保险公司以及私募股权机构。公司拥有 3,300+ 直接客户;在免费层监测宇宙中覆盖 70,000 个组织。
商业模式
安全评级和 TPRM 平台访问采用年度 SaaS 订阅;攻击面情报、网络风险量化和 AI 自动化作为附加模块;MAX 托管服务由合作伙伴交付,渠道 ARR 同比增长 160%;另有保险数据授权和联邦政府(FedRAMP Ready)合同。
阶段
Series E (private unicorn; no new primary round since March 2021)
融资情况
公司完成七轮融资,累计约 $293M,最终为 2021 年 3 月 $180M Series E,轮后估值 $1B。投资方包括 Silver Lake Waterman、Sequoia Capital、T. Rowe Price、GV、Evolution Equity Partners、Kayne Anderson Rudnick 等。截至 2026 年 6 月,公司未披露 IPO 计划或新一轮股权融资;已在 Series E 资本结构上运营 5 年以上。自由现金流为正的信号显示业务具备自我供血能力。
[CO001, CO002, CO006, CO011, CO012, CO013, CO024, CO026]

执行摘要

主要优势

  • SecurityScorecard 开创了安全评级品类,如今运营更宽的 SCDR 平台,覆盖评级、TPRM、攻击面管理、AI 驱动问卷自动化和托管服务,在 3,300+ 企业客户中拥有真实产品宽度和交叉销售空间。
  • 商业规模有分量,方向也正面:ARR 至少 $150M+、自由现金流为正、ARR / FTE 同比改善 40%、MAX 三位数增长、渠道 ARR 增长 160%、Fortune 100 渗透率 70%、收入连续 10+ 个季度增长。
  • NIS2、DORA、SEC 网络披露规则带来结构性监管顺风,把 TPRM 从可选工具推成合规要求,扩大可触达市场,也提高合规导向买家的切换成本。
  • FedRAMP Ready 和 StateRAMP 资质打开美国联邦与州政府采购市场;CISA 将其列为免费网络工具,又为企业转化增加了独特的非商业分发通道。

主要风险

  • 2021 年 3 月 Series E 的 $1B 估值已经过时五年;二级市场平台暗示企业价值仅 $360–$470M(折价 53–64%),没有新融资事件或财务披露就无法解释这道差距。
  • 毛利率、NRR、烧钱速度和过去 ARR 增速未公开披露,难以有信心承保;若没有高于 100% 的 NRR,扩张经济性无法验证。
  • Moody's 背书的 BitSight 在 Forrester Wave Q2 2026 中拿到最高战略评分,并在银行和保险中被定位为贴近信用评级的标准,对 SecurityScorecard 核心垂直行业构成持久竞争威胁。
  • 由外而内的评级方法天然容易出现误报、资产归属错误和供应商争议;竞争对手会在销售周期里利用这道天花板,监管也可能用强制准确性要求进一步收紧。
  • 关键人风险明显集中在 CEO Dr. Yampolskiy 身上:他是公司最主要的公众面孔、核心专利组合共同发明人,也是最显眼的商业资产。

未决问题

  • 按队列和层级拆分的 NRR —— 评估增长质量和承保扩张价值时最关键的缺失指标。
  • 按产品线拆分的毛利率(核心 SaaS、MAX 托管服务、TITAN AI),用于判断增长更快的托管服务层规模化后的利润率轨迹。
  • 截至 2026 年 6 月的当前 ARR —— $150M+ 数字已过时 8+ 个月,且披露场景是诉讼和解,而非独立财务发布。
  • 完全稀释股权结构、清算优先权、保护性条款,以及影响潜在投资人回报测算的任何二级市场交易细节。
  • 经审计财务报表、现金余额、债务计划和烧钱速度,用于验证自由现金流为正的说法,并评估当前增长率下的现金跑道。
  • 按职能拆分的准确员工数、销售生产率指标,以及每一美元销售和营销投入带来的新增 ARR,用于评估渠道组合变化后的销售效率。

目录

Chapter 01

01公司概览

1.1 身份、使命与平台

SecurityScorecard, Inc. 是一家私营网络安全公司,注册于 Delaware,总部位于 1140 Avenue of the Americas, 19th Floor, New York, NY 10036,并在 Texas 州 Austin 设有第二办公室,员工分布全球。公司由 Dr. Aleksandr Yampolskiy 和 Sam Kassoumeh 于 2013 年创立,并于 2014 年 7 月 17 日在 New York 正式注册(New York Department of State 文件编号 4607959)。公司仍为私营企业,凭 2021 年 3 月 Series E 轮后 $1B 估值保留独角兽身份。公司宣称的使命是改变组织理解、缓释并向董事会、员工和供应商沟通网络安全风险的方式,让世界更安全。 平台核心产品是一套获得专利的安全评级引擎,采集外部可观察信号——互联网扫描、DNS 健康度、IP 声誉、网络配置和端点观察——并汇总为横跨十组风险因子的 A 到 F 字母评分,不需要本地代理,也不需要供应商提交问卷。这种「由外向内」方法让 SecurityScorecard 可以在组织不知情或未同意的情况下,持续评级数百万个组织。以评级为基础,公司已扩展为更宽的 Supply Chain Detection and Response(SCDR)平台,覆盖供应商风险管理(TPRM)、外部攻击面管理、自我监测、董事会报告、网络保险承保、M&A 尽调、威胁情报,以及数字取证和事件响应。2026 年 3 月推出的 TITAN AI 进一步把平台延伸到 AI 加速问卷自动化和基于威胁的修复工作流。CISA 将 SecurityScorecard 认定为免费网络工具与服务;截至 2026 年 3 月,平台持续评级全球超过 1,200 万个组织。[CO001, CO002, CO003, CO004, CO005, CO006]

快照 KPI 与封面指标
指标数值 / 状态日期 / 期间置信度证据缺口
累计融资额$293MMar 2021(Series E 交割)2021 年以来未披露新增融资轮
投后估值$1B(独角兽)Mar 2021Series E 后未更新估值;很可能已经滞后
ARR / 收入运行率$150M+ ARROct 2025具体 ARR 和增长率未公开披露
付费客户3,300+Mar 2026未发布精确季度客户数
监控组织数12M+Jun 2026平台整体数字;不是付费客户数
Fortune 100 渗透率70%Mar 2026已由官方新闻稿确认
员工数~615–639(估算)2026无官方披露;仅为第三方聚合方估算
办公室 / 地理覆盖NYC(总部)、Austin TX;全球远程员工Jun 2026已由官方联系页面确认
最近一轮融资Series E($180M,Silver Lake 领投)Mar 2021未披露新融资轮或 IPO 计划
公司阶段私营独角兽(未宣布 IPO)Jun 2026未提交公开 IPO 文件或 S-1

估值基于 2021 年 3 月 Series E 投后估值;此后未公开披露更新估值。$150M+ ARR 来自 2025 年 10 月与 Safe Security 的联合新闻稿——这是公司在特定语境下的公告,不是经审计财务数据。员工数为第三方估算。所有置信度都反映公开证据质量。

[CO007, CO008, CO026, CO027, CO031, CO033]
FO002: SecurityScorecard 平台与价值链逻辑

外部信号如何进入评级引擎,驱动 SCDR 平台,服务企业用例,并产生商业与战略价值。

[CO003, CO004, CO005, CO007, CO008, CO010]

1.2 创始人、领导层与治理

SecurityScorecard 由 Dr. Aleksandr Yampolskiy 和 Sam Kassoumeh 共同创立,两人至今仍活跃在公司。Dr. Yampolskiy 拥有 Yale University 密码学博士学位(2006 年)以及 New York University 数学与计算机科学学士学位。创立 SecurityScorecard 之前,他曾任 Gilt Groupe CISO(将安全职能从服务 200 名员工扩展到 2,500 名员工)、Cinchcast/BlogTalkRadio CTO(扩展至 30M+ 月访问者),并在 Goldman Sachs 和 Oracle 担任工程与安全领导职务。他此前在 Gilt Groupe 担任 CISO、直接管理第三方供应商风险的经历,是 SecurityScorecard 核心用例的创立动机。2021 年,他获评 New York E&Y Entrepreneur of the Year,并被 Cyber Defense Magazine 评为 2021 年 CEO of the Year。联合创始人 Sam Kassoumeh 担任产品负责人,也是董事会成员;一家第三方数据库将其列为 COO,显示其公开头衔存在模糊性。 董事会治理包括关键投资方代表:Karim Faris(General Partner,GV / Google Ventures)、Joe De Pinho(Principal,Riverwood Capital)、Upal Basu(General Partner,NGP Capital)和 Richard Seewald(Managing Partner,Evolution Equity Partners)。IBM Fellow Emeritus Nick Donofrio 带来企业技术治理经验。Tanium CEO Dan Streetman 于 2026 年 1 月以独立董事身份加入董事会。关键人风险明显集中在 Dr. Yampolskiy 身上:他同时是 CEO、公开形象和核心技术共同发明人;公司未公开披露继任计划。官方公司材料未提供完整现任董事会名单、委员会任命和董事独立性披露,这对任何治理评估都是实质尽调缺口。[CO011, CO012, CO013, CO014, CO015, CO016]

领导层与创始人表
人员职务背景创始人-市场匹配 / 职能关键人物依赖
Dr. Aleksandr YampolskiyCEO 兼联合创始人Yale 密码学博士;Gilt Groupe CISO;BlogTalkRadio CTO;Goldman Sachs;Oracle;Microsoft有直接 CISO 经历;围绕自己亲身面对的供应商风险问题设计公司高——愿景、融资、公众品牌、核心 IP
Sam Kassoumeh联合创始人、产品负责人兼董事会成员共同创立 SecurityScorecard;在安全风险领域承担产品领导职责产品领域深度;早期市场定位中——产品方向和董事会连续性
Dan Streetman独立董事(自 2026 年 1 月起)Tanium CEO;TIBCO CEO;Allvue CEO;BMC;Salesforce;C3.ai;美国陆军军官企业软件扩张和安全相邻平台治理低——独立董事
Richard Seewald董事(Evolution Equity Partners)Evolution Equity Partners 管理合伙人;网络安全投资人Series E 主要支持者;网络安全行业专长低——投资方代表
Nick Donofrio董事(独立)IBM 荣休 Fellow;企业技术资深人士企业技术治理;品牌可信度低——独立董事

董事会构成根据多个第三方来源部分重建;官方未发布董事会名单。Kassoumeh 的确切头衔在不同来源之间有差异(产品负责人 vs. COO)。CFO 和 CTO 姓名因来源而异,可能反映近期领导层变动;2026 年搜索聚合方引用的现任 CFO 为 Chris Fritz。

[CO011, CO012, CO013, CO014, CO015, CO016]

1.3 融资历史与资本结构

SecurityScorecard 已披露的资本历史横跨从种子轮到 Series E 的七轮融资。最早可记录融资为 2014 年约 $2.2M 种子轮,随后是 2015 年 2 月 $13.7M Series A。公司之后完成 Series B(约 $20M,2016 年 6 月)和 Series C(约 $27.5M,2017 年 10 月),用于搭建评级平台和早期 go-to-market。2019 年 6 月约 $50M 的 Series D 资助国际扩张和产品邻接。决定性融资事件是 2021 年 3 月 18 日 Series E:$180M 优先股融资,将累计披露融资推高至 $290M 以上,并确立 $1B 轮后估值,使 SecurityScorecard 成为独角兽。J.P. Morgan Securities LLC 是 Series E 唯一配售代理。此后,公司未披露其他公开融资轮、IPO 计划、二级交易或债务融资。 Series E 新投资者包括 Silver Lake Waterman、T. Rowe Price Associates、Kayne Anderson Rudnick 和 Fitch Ventures(Fitch Group 子公司,显示一家竞争性评级业务的战略兴趣)。既有投资者也参与其中:Evolution Equity Partners、Accomplice、Riverwood Capital、Intel Capital、NGP Capital、AXA Venture Partners、GV(Google Ventures)和 Boldstart Ventures。PitchBook 与 Tracxn 报告,截至 2026 年累计融资约 $293M。投资人结构值得注意,既有财务投资方(Silver Lake、Sequoia、Riverwood),也有战略方(GV/Google、Intel Capital、Fitch Ventures、AXA Venture Partners),暗示退出预期多元。精确股权比例和清算优先权未公开披露。[CO021, CO022, CO023, CO024, CO025, CO026]

利益相关方或投资方图谱
投资方 / 利益相关方角色 / 投资层级控制权 / 经济重要性尽调要求
Sequoia CapitalSeries C 及后续轮次;列于官方公司页面主要机构投资方;SDNY 法院文件披露有董事会关联关系确认当前董事席位持有人和持股比例
Evolution Equity Partners(Richard Seewald,董事)Series D 和 E;Seewald 持有董事席位参与所有后期轮次;专注网络安全的 VC确认持股比例和退出论点一致性
Silver Lake WatermanSeries E 领投方($180M)领投最大一轮;关键经济利益相关方确认 Series E 后关系;是否存在清算优先条款
GV(Google Ventures;Karim Faris,董事)Series B 至 E;董事席位战略投资方;涉及 Google Alphabet 协同含义确认 Google 战略意图和数据访问协议
Riverwood Capital(Joe De Pinho,董事)Series D 和 E;董事席位偏 PE 的成长投资方;集中于企业软件评估买断收购与 IPO 偏好;优先条款
Intel CapitalSeries A 至 E战略企业投资方;半导体 / 终端协同评估 Intel Capital 合并后策略对持股的影响
NGP Capital (Upal Basu)早期轮次;董事席位Nokia 支持的 VC;聚焦电信和企业技术确认当前董事会代表
AXA Venture PartnersSeries E 参与方保险科技战略投资方;网络保险承保角度评估 AXA 商业合作或数据共享协议
Fitch Ventures(Fitch Group 子公司)Series E 新投资方与战略竞争相邻的投资方;Fitch 是信用评级业务评估来自竞争评级类别投资方的 IP 或方法论顾虑
Boldstart Ventures种子轮至 Series E早期专家型机构,所有轮次均维持头寸确认持续二级交易或额外持股调整

未披露确切持股比例和清算优先权。PitchBook 报告共有 29 家投资方;本表按轮次参与和董事会代表列出最重要投资方。考虑到 Fitch 自身也有评级业务,Fitch Ventures 参与值得治理审查。

[CO024, CO025, CO027, CO029, CO030]

1.4 规模、收入与客户版图

2021 年 Series E 之后,SecurityScorecard 规模显著扩张。公司 2023 年末拥有 2,600 个付费客户,70,000 个组织活跃使用平台。到 2026 年 3 月,其官方公司页面和 TITAN AI 新闻稿均确认直接客户组织超过 3,300 个,且 70% 的 Fortune 100 信任其数据。平台持续监测超过 1,200 万个组织——这一数字代表评级数据集的全球覆盖,而不是付费客户。SecurityScorecard 的 MAX 托管服务截至 2025 年 10 月以三位数速度增长;2020 年 Q4,公司报告国际经常性收入同比增长 61%,国际客户数同比增长 89%。2021 年 3 月 Series E 时,公司监测组织接近 200 万个。 收入披露仅限一个数据点:2025 年 10 月 SAFE-SSC 联合新闻稿称 SecurityScorecard 已超过 $150M ARR,MAX 以三位数速度增长。此后公司未公开披露 ARR 更新、毛利率或收入增长率。第三方聚合器估算 2026 年员工数为 615–639 人;Forbes Council 资料提到「超过 600 名员工」。官方员工数未发布。除 New York City 和 Texas 州 Austin 之外,地理存在主要依赖公司关于全球分布式员工队伍的表述。当前准确 ARR、毛利率和季度收入增长仍是私营公司指标。[CO031, CO032, CO033, CO034, CO035, CO036]

FO003: KPI 快照 — 融资、牵引与规模

截至 2026-06-29 运行日,SecurityScorecard 资本位置、收入信号和市场牵引的关键量化指标。

估值基于 2021 年 3 月 Series E(可能已过时 5 年以上)。$150M+ ARR 是联合新闻稿场景中的自报数字。 员工数为第三方估计。所有数字都应视为指示性,而非审计数字。

[CO027, CO026, CO031, CO033, CO035, CO036]

1.5 里程碑与战略轨迹

SecurityScorecard 的演进可分为三阶段:品类创建(2013–2019)、机构化规模与独角兽认证(2019–2022)、平台多元化与 AI 转型(2023 至今)。第一阶段,创始人搭建由外向内评级引擎,完成 Series D 前多轮融资,并在金融服务、保险和企业技术领域验证市场需求。第二阶段以 $180M Series E、收购 LIFARS(2022 年 2 月——增加 50+ 名 DFIR 员工和事件响应能力),以及公司跨过 200 万被监测组织为标志。2021 年 Q1 获 Forrester Wave Leader 认定,以及 2021 年 Gartner Peer Insights Customers' Choice,佐证了其评级市场领导者主张。 第三阶段由平台宽度和监管采用定义。2023 年,SecurityScorecard 收购 CVEDetails(漏洞数据库,350K+ 月用户)、推出 MAX 托管服务、成为首个集成生成式 AI 的安全评级平台,并获得 FedRAMP Ready 认定和 DHS CDM Program 批准——打开了有意义的政府收入渠道。与 Microsoft(Security Copilot)、AWS(Level 1 MSP)和 S&P Global(Supplier Risk Index)的战略合作扩大了分销。2025 年 9 月,公司收购 HyperComply 以自动化供应商问卷。2026 年 3 月 23 日 RSA Conference 上,TITAN AI 发布三层产品——TITAN Watch(持续监测)、TITAN Assess(AI 问卷自动化)和 TITAN Secure(基于威胁的修复)——声称可减少 95% 人工 TPRM 工作量,并让采用者供应链泄露减少 75%。2025 Global Third-Party Breach Report 基于 1,000 起已分析泄露,发现 2024 年数据泄露中 35.5% 与第三方有关(同比上升 6.5%),为平台价值主张提供市场背景。[CO039, CO040, CO041, CO042, CO043, CO044]

里程碑表
日期事件类型金额 / 状态参与方含义
2013公司在纽约市创立创立Yampolskiy、Kassoumeh网络安全评级品类形成
2014-07-17Delaware 公司在纽约注册为外州实体(Doc. 4607959)创立约 $2.2M 种子轮NY Department of State(纽约州务院)法律实体设立;最早的公开注册记录
2015-02-17Series A 融资融资$13.7M包括 NGP Capital 在内的多家 VC首笔机构资本;产品-市场验证
2016-06-23Series B 融资融资~$20MRiverwood Capital、GV 等成长资本;开始进入国际市场
2017-10-12Series C 融资融资~$27.5MNGP Capital、AXA VP 等平台扩展和企业销售体系搭建
2019-06-13Series D 融资融资~$50MSequoia Capital、Evolution Equity Partners 等后期增长;独角兽前规模
2021-03-18Series E 融资——独角兽里程碑融资$180M;$1B 估值Silver Lake Waterman(领投)、T. Rowe Price、Fitch Ventures、现有投资方达成独角兽状态;监控 200 万多家组织
2022-02-07收购 LIFARS(数字取证和事件响应)产品未披露50 多名 LIFARS 员工;CEO Ondrej Krehel 领导新的 DFIR 实践首家加入 DFIR 能力的评级公司;形成 360 度风险状态
2023收购 CVEDetails 漏洞数据库产品未披露CVEDetails 月用户 350K+威胁情报扩展;漏洞情报模块上线
2023推出 MAX 托管服务;集成生成式 AI(安全评级领域首创)产品SecurityScorecard 内部进入相邻市场;建立 AI 差异化
2023获得 FedRAMP Ready 认定;DHS CDM Program 批准;被 CISA 列入名单监管美国联邦政府打开政府采购渠道;提升公共部门可信度
2024-02-142023 年结束时拥有 2600 名客户和平台上 70,000 家组织规模公司新闻稿确认多产品客户扩张势头
2024-06-04对 Safe Security 提起商业秘密诉讼(1:24-cv-04240, S.D.N.Y.)负面指称损害 >$40MSafe Securities Inc.、Mary Polyakova;法官 Edgardo Ramos诉讼活跃;竞争对手冲突和潜在客户扰动
2025-09-15收购 HyperComply(AI 问卷自动化)产品未披露HyperComply 团队和 CEO Amar Chahal(成为 MAX 总经理)自动化供应商保证;供应链信任运营扩展
2025-10-17解决 Safe Security 诉讼;宣布研究合作;披露 $150M+ ARR负面庭外和解SecurityScorecard 和 Safe Security诉讼解除;ARR 里程碑作为解决公告的一部分披露
2026-01Dan Streetman(Tanium CEO)作为独立董事加入董事会治理Dan Streetman;董事会董事会能力获得企业软件运营者视角增强
2026-03-23在 San Francisco 的 RSA Conference 2026 发布 TITAN AI产品SecurityScorecard;RSA ConferenceAI 加速 TPRM 平台;重大产品代际转换

Series B、C、D 日期根据 PitchBook 和 Tracxn 数据库为近似值;金额由第三方报告,未获官方公司新闻稿确认。LIFARS 和 HyperComply 收购财务条款未披露。$150M+ ARR 数字披露于 SecurityScorecard 与 Safe Security 2025 年 10 月联合新闻稿,尚未独立审计。

[CO006, CO002, CO021, CO022, CO023, CO024]
FO001: SecurityScorecard 公司里程碑时间线

从创立到 2026 年 3 月 TITAN AI 发布的关键公司、资本、产品、监管和负面里程碑。

[CO006, CO021, CO023, CO024, CO026, CO042]

1.6 不利事件、诉讼与风险考量

SecurityScorecard 历史上最重大的不利事件,是 2024 年 6 月针对 Safe Security 和前员工 Mary Polyakova 的商业秘密诉讼(案号 1:24-cv-04240,S.D.N.Y.,Edgardo Ramos 法官主持)。SecurityScorecard 指控 Polyakova 作为在其销售组织任职四年的高级销售主管,在 2024 年 5 月加入 Safe Security 担任 VP of Central Sales 前,将「Master East List」和「CISO Prospect Lists」——价值超过 $40M 的机密客户和潜在客户数据——发送至个人账户。起诉书进一步指控 Safe Security 使用虚假账户和空壳域名访问 SecurityScorecard 平台以获取竞争情报,并通过对 SecurityScorecard 员工进行虚假招聘面试套取专有商业信息。SecurityScorecard 称,其已投入超过 $200M 建设客户和潜在客户基础。 诉讼期间,Safe Security CEO Saket Modi 公开反驳称,SecurityScorecard 及类似竞争对手「因业务表现不佳而裁撤团队的大量人员」。这一说法来自正在诉讼中的对方当事人,尚未被 WARN Act 备案、员工聚合器数据或 2024–2026 年独立新闻报道独立证实。SecurityScorecard 对此提出异议。两家公司于 2025 年 10 月解决纠纷,并宣布在网络风险管理方面开展共同研究合作,诉讼在审判前结束。截至本报告运行日,可访问公开记录中未发现其他重大诉讼、监管执法行动或制裁。[CO049, CO050, CO051, CO052, CO053, CO054]

1.7 图表

Chapter 02

02市场分析

2.1 市场边界、分类与相邻支出

SecurityScorecard 竞争的市场位于三个重叠软件品类的交叉处:网络风险评级(也称安全评级或网络风险评分)、第三方风险管理(TPRM)平台,以及外部攻击面管理(EASM)。评级品类的核心差异化在于「由外向内」的持续评分方法——把可观察互联网信号汇总为 A–F 字母等级,不需要本地代理或供应商参与——由此一次性自动覆盖数百万个组织。 纳入核心口径的支出,是用于监测外部网络安全态势和供应商 / 供应链风险的平台型企业软件订阅收入:安全评级数据源、TPRM 工作流软件、问卷自动化、持续供应商监测,以及 AI 辅助修复编排。紧密相邻预算包括:治理、风险与合规(GRC)软件(常承载 TPRM 工作流)、外部攻击面管理工具(在扫描侧既竞争又互补)、网络保险承保技术(用安全评级为保单定价),以及董事会级网络风险报告仪表盘。合计来看,这些相邻品类增加约 $23–35B 与 SecurityScorecard 平台范围重叠的软件支出。 核心 TAM 不包括内部网络安全产品(防火墙、端点检测、SIEM)、身份与访问管理,以及 Gartner 估算的 2026 年 $244B 全球信息安全大市场。安全评级的替代方案包括一次性渗透测试、临时问卷制项目(常基于 Excel)、由托管安全服务商处理供应商评估,以及内部安全团队做时间点审计。关键边界在于:SecurityScorecard 的由外向内持续评级模型替代周期性、劳动密集型评估——这是区别于传统 GRC 勾选框工具的独立价值主张,尽管随着大型 GRC 平台加入持续监测功能,这条边界正在变模糊。[CM001, CM002, CM003, CM004, CM005, CM006]

市场边界——网络风险评级、TPRM 与相邻类别
细分 / 类别纳入支出排除支出主要买家 / 付款方SecurityScorecard 相关性
安全评级(核心)面向持续外部评分的订阅 SaaS;供保险 / M&A 使用的评级 API本地部署代理;内部渗透测试人力;手工问卷CISO / 安全团队预算核心产品;与 BitSight 直接竞争
第三方风险管理(TPRM)供应商工作流软件、问卷自动化、VRM 门户、托管评估一次性渗透测试、纯人员服务、实体供应链审计CISO / GRC / 采购预算TITAN AI 平台扩张;与评级业务相邻
外部攻击面管理(EASM)外部扫描、资产发现、暴露验证工具内部 CSPM、云安全态势、网络访问控制CISO / 安全工程预算既竞争也互补;SSC 评级引擎提供相关信号
GRC 软件政策管理、审计工作流、风险登记册、合规报告法务 / 合同管理、纯 HR 合规工具、ERP 风险模块合规 / 风险官 / GRC 团队预算相邻需求;TPRM 买家常为 TPRM 工作流评估 GRC 平台
网络保险(技术驱动承保)以安全评级为输入的承保分析平台、网络风险量化纯保险保费、精算咨询服务保险 CTO / 承保 P&L衍生需求:保险公司授权使用 SSC 评级数据做承保
董事会 / 监管报告董事会仪表盘工具、SEC/DORA 报告自动化、高管网络风险记分卡通用企业报告、投资者关系软件CISO / 合规 / 董事会秘书SSC 董事会报告功能;监管要求推动采用提速

分析师报告对范围边界分歧很大;TPRM 与 GRC 品类高度重叠。 SecurityScorecard 在评级核心和 TPRM 上竞争;在 EASM 和 GRC 上处于相邻位置。

[CM001, CM002, CM003, CM004]

2.2 市场规模——多重视角与矛盾估算

分析机构对 2026 年全球 TPRM 软件市场的估算差异很大,取决于定义范围:Grand View Research 认为 2023 年基数为 $7.42B,到 2030 年以 15.7% CAGR 增至 $20.59B;SkyQuest 估算 2025 年为 $11.11B,到 2033 年以 16.4% 增至 $37.44B;Business Research Insights 将 2026 年市场规模定为 $10.36B,到 2035 年以 18.2% 增至 $45.98B。这个区间——2026 年点估约 $8–11B——反映出「TPRM」定义不同(纯软件 vs. 纳入托管服务)、地理范围不同,以及对 GRC、EASM 等相邻品类处理方式不同。 与 SecurityScorecard 评级引擎重叠的外部攻击面管理子板块,预计到 2026 年达到 $930.7M,CAGR 为 17.5%;更宽的攻击面管理市场(包括内部 ASM)估算将从 2024 年 $1.43B 增至 2032 年 $9.19B,CAGR 为 30.4%。GRC 软件为许多大型企业承载 TPRM 工作流,另有估算认为其 2026 年规模为 $23.32B,到 2031 年以 10.84% CAGR 增至 $39.01B。网络保险保费在 2025–2026 年约达 $15.3–19.6B,代表相邻需求池:保险公司越来越多要求把安全评级作为承保输入,为评级供应商创造派生需求信号。 自下而上构建 SecurityScorecard 的 SAM,需要剥离出 TPRM 的软件部分(按 Grand View Research 约占市场 59%)、北美和欧洲份额(合计约 70%),并排除 SME 自助服务之外的企业级部分。把这些过滤条件套到 $10–11B TPRM 总市场上,可服务可寻址市场约为 $4–7B。SecurityScorecard 报告的 $150M+ ARR 暗示其在该 SAM 中渗透率约 2–4%,符合早中期成长阶段。按质量政策要求,表 TM002 保留了相互矛盾的规模估算。[CM008, CM009, CM010, CM011, CM012, CM013]

TPRM 市场规模测算——多家分析机构视角(保留相互矛盾的估计)
发布方年份 / 期间地域市场价值CAGR范围 / 方法置信度局限
Grand View Research2023 基准;2030 预测全球$7.42B → $20.59B15.7%TPRM 软件 + 服务;云端和本地部署;覆盖所有垂直行业细节在付费墙后;定义比部分同业更窄
SkyQuest2025 基准;2033 预测全球$11.11B → $37.44B16.4%TPRM 软件和托管服务;定义较宽高位估计;未说明服务份额是否拆分
Business Research Insights2026 基准;2035 预测全球$10.36B → $45.98B18.2%TPRM 平台和服务;包括 AI 工具低–中同业组里增长估计最高;方法未披露
Research & Markets(2026 版)2025–2026 区间全球$8.09B–$9.34B (2025–2026)~15.6%TPRM 软件 + 服务;定义偏保守付费墙;公开方法有限
IONIX / Fortune Business Insights2024 基准;2032 预测全球EASM:到 2026 年 $930.7M;更宽口径 ASM:$1.43B→$9.19BEASM 17.5%;ASM 30.4%EASM 专项扫描;仅外部扫描仅覆盖 EASM;不是完整 TPRM 范围
Mordor Intelligence2025 基准;2031 预测全球GRC 软件:$21.04B→$23.32B (2026)→$39.01B (2031)10.84%仅 GRC 软件;包括政策、风险、审计;与 TPRM 相邻范围比 TPRM 更宽;不是直接的 TPRM 估计
Gallagher(Gallagher Re 数据库)2025F; 2026F全球网络保险保费:$16.9B (2025F)→$19.6B (2026F)同比约 16%总承保保费;代表相邻需求池相邻市场;不是 TPRM 软件;仅用于衍生需求测算

按范围不同,2026 年 TPRM 估计落在 $8–11B。服务与软件拆分、地域覆盖、是否纳入 AI 工具,是估计分化的主要来源。按质量政策保留相互矛盾的估计;不采用任何单一估计作为标准口径。

[CM008, CM009, CM010, CM011, CM012, CM013]
FM001: 可服务市场金字塔 — SecurityScorecard 的 TAM / SAM / SOM

展示 SecurityScorecard 可服务层级的示意性 TAM/SAM/SOM:顶部为总网络风险 / TPRM / GRC 邻近支出, 中间收窄到可服务的 TPRM 软件平台,底部则是 SSC 直接瞄准的、以评级为锚的纯平台细分。

TAM 汇总 Mordor GRC($23B)+ BRI TPRM($10.4B)+ EASM($0.9B)并扣除重叠,不是单一来源数字。 SAM 套用 GVR 的 59% 软件占比、北美 + 欧洲合计 70%,并加上企业层级筛选。SOM 由 SSC 披露的 $150M+ ARR 除以估计 2–4% 渗透区间推断;三层都是估计值。

[CM008, CM009, CM013, CM014, CM015]
FM002: 2026 年 TPRM 市场规模 — 分析师估计区间(估计相互矛盾)

四组分析师对 2026 年全球 TPRM 市场规模的估计,以十亿美元计,显示不同范围定义带来的宽区间。 所有数字均为 $B USD。

所有数值均为十亿美元。GVR 2026 数值按 2023 年 $7.42B 基数、15.7% CAGR 复合三年估算。 SkyQuest 2025 数值作为 2026 低 / 高区间代理。未采用任何单一估计作为权威值;按照质量政策保留区间。

[CM008, CM009, CM010, CM011]

2.3 买方、用户与付款方分层

SecurityScorecard 的主要经济买方是 Chief Information Security Officer(CISO),其负责安全战略、供应商风险项目和董事会级网络风险报告。Panorays 2026 年对 200 名 CISO 的调查发现,85% 缺乏完整供应链可见性,62% 报告过去 12 个月监管压力增加,验证了问题紧迫性。不过,只有 22% 的 CISO 认为自己「完全准备好」应对不断演进的监管要求,这创造了一个庞大、动机明确但现有工具服务不足的可寻址买方群体。 用户画像通常是 CISO 组织内的 Third-Party Risk Manager 或供应商风险分析师,他们每天使用平台做供应商准入、持续监测和修复跟踪。付款方差异很大:在受监管行业(BFSI、医疗健康),TPRM 预算常从专门的 GRC 或合规预算中划出;在科技公司,支出来自安全工程预算;在中端市场公司,CISO 的自由裁量预算覆盖全部。 次级买方包括采购 / 供应商管理团队(控制供应商合同条款,并可能把安全评分要求嵌入 RFP)、网络保险承保人(用 SecurityScorecard 评级作为承保输入,为保单定价并设定条款——形成 B2B2B 需求链),以及董事会 / 审计委员会(消费风险仪表盘,并越来越要求把第三方风险指标纳入 SEC 和 NIS2 治理披露)。年收入 $1B+、拥有 500+ 供应商关系的大型企业是主要客群;Panorays 数据显示,只有 41% 的组织甚至会监测第四方供应商,说明中端市场仍有显著采用缺口。[CM018, CM019, CM020, CM021, CM022, CM023]

买方、用户与付款方分层图
细分群体买方角色用户角色付款方 / 预算归属关键采用触发点
企业 CISO / 安全团队CISO——经济买方和内部推动者安全分析师、TPRM 分析师IT / 安全自由支配预算供应商泄露事件;监管检查;董事会要求
第三方风险 / 供应商管理项目风险副总裁或 CISO 授权代表——审批人第三方风险经理、供应商关系经理GRC / 合规预算审计发现;监管要求(DORA、NIS2、SEC)
采购 / 寻源CPO 或采购负责人——共同审批人采购分析师、品类经理采购 / 运营预算供应商合同续签;供应链事件;新供应商准入要求
网络保险承保人首席承保官 / 精算团队使用评级 API 的承保人保险 P&L / 承保预算保单定价周期;赔付率恶化;监管要求
风险 / 合规 / 法务首席风险官 / 总法律顾问风险官、合规分析师、法务团队风险管理 / 合规预算NIS2 / DORA / SEC 治理披露;董事会审计委员会要求
董事会 / 审计委员会董事长 / 审计委员会主席——大型企业交易的最终审批人阅读仪表盘的董事会成员不是直接付款方;推动优先级SEC 10-K 披露要求;投资者 / 监管方压力

预算集中度随公司规模和行业差异很大。BFSI 和医疗健康机构常因监管要求设立专门 TPRM 预算; 科技和中端市场机构则用 CISO 自由支配预算支付 TPRM。

[CM018, CM019, CM020, CM021, CM022, CM023]
FM003: 买方细分地图 — TPRM 决策权与预算流

SecurityScorecard TPRM 平台五类主要买方细分的决策权和预算归属。

[CM018, CM019, CM020, CM021, CM022]

2.4 增长驱动——监管、威胁升级与 AI

2026 年,网络风险评级和 TPRM 市场最强的三项增长驱动是:(1)监管要求,(2)供应链威胁升级,(3)AI 驱动自动化扩大 ROI 论证。 监管方面:NIS2(EU)覆盖 18 个关键行业,要求到 2024 年 10 月完成转置;2026 年 1 月,EU Commission 提议有针对性修订,以减轻 28,700 家公司的合规负担。DORA(EU 金融韧性)于 2025 年 1 月生效,要求金融实体持续管理 ICT 第三方风险。SEC 2023 年 7 月 Cybersecurity Disclosure Rule 要求上市公司在四个工作日内报告重大事件,并在年度 10-K 文件中披露第三方风险管理治理——由此形成董事会级、可审计 TPRM 项目的需求。这三套框架共同直接要求或强烈激励安全评级所提供的持续供应商监测。 威胁方面:2025 年,第三方参与泄露的比例翻倍至全部泄露约 30%(Verizon DBIR);SecurityScorecard 自身 2025 年研究记录,2024 年泄露中 35.5% 与第三方有关。Black Kite 2026 年报告发现,每起供应商泄露现在平均会级联影响 5.28 个下游组织——为有记录以来最高——同时 41.4% 的勒索软件攻击现在通过第三方路径发起。全球供应链攻击成本在 2025 年估计达到 $60B。 AI 方面:TITAN AI 于 2026 年 3 月发布,声称可减少 95% 人工 TPRM 工作量,验证了自动化 ROI 逻辑。Gartner 预计 AI 放大的安全市场到 2029 年将达到 $160B,且到 2028 年 75%+ 企业将使用 AI 放大的网络安全产品。这既扩大了可寻址市场(AI 解锁此前无法配置 TPRM 团队的中端市场买方),也为较早把 AI 嵌入平台的供应商带来竞争优势。[CM025, CM026, CM027, CM028, CM029, CM030]

增长驱动因素与采用约束
因素方向时间对 SecurityScorecard 的影响尽调问题
NIS2 / DORA 监管要求(欧盟)驱动当前(2024–2025 生效)欧洲销售线索提速;欧盟总部企业因合规推动成交监测欧盟企业 ACV 增长;跟踪 2026 年 DORA 执法行动
SEC 网络披露规则(美国上市公司)驱动当前(2023 年 12 月生效)董事会层面需要可审计的 TPRM 证据;内部推动者从 CISO 扩大到审计委员会跟踪有多少 10-K 披露点名 TPRM 项目
第三方泄露升级(占泄露 30–35%)驱动当前且在加速制造紧迫事件,推动应急采购;提升 CISO 认知监测 SSC STRIKE 团队报告是否带来入站销售线索
网络保险承保集成驱动当前;增长中保险公司授权使用评级数据,形成衍生需求;若保险公司把 SSC 评分嵌入保单要求,保费上行空间更大在下一轮融资披露中确认保险公司授权收入的规模与增速
AI 驱动自动化(TITAN AI ROI)驱动近期(2026–2027)减少所需手工 TPRM 人力,扩大中端市场可服务范围;支撑溢价定价跟踪 TITAN AI 发布后中端市场客户数是否增长
大型厂商平台整合(Palo Alto、Microsoft、CrowdStrike)约束中期(2027+)捆绑威胁:大型厂商把 TPRM 功能免费加入现有企业协议评估 SSC 集成深度,对比 Prisma Cloud 和 Microsoft Defender 原生模块
预算周期性 / 安全预算削减约束阶段性TPRM 在监管最低要求之上属于自由支配支出;预算冻结会拉长销售周期确认 SSC 销售线索在 2026 年是否显示销售周期拉长
误报与数据质量担忧约束持续存在外部视角方法在共享主机、CDN 资产、弃用基础设施上容易误判,削弱 CISO 信心在客户访谈中衡量误报率和争议解决时间
企业交易中的采购摩擦约束持续存在评估周期跨多个季度;CISO 必须向采购和法务解释评级概念跟踪平均销售周期长度,理解法务审查瓶颈
品类教育缺口(71% 称问卷无法捕捉真实风险)约束与机会当前;正在改善买家不满现状,为评级打开机会;但也说明买家怀疑任何供应商解决该问题的能力跟踪 NPS 和续约率,作为 SSC 兑现 ROI 承诺能力的代理指标

驱动 / 约束的时间判断,基于监管生效日期和市场调研数据近似得出。影响列反映推断的战略相关性, 不是公司披露的指引。

[CM025, CM026, CM027, CM028, CM029, CM030]

2.5 采用约束、市场摩擦与不利信号

尽管增长顺风很强,网络风险评级和 TPRM 市场仍面对结构性采用约束。最常被提及的限制是数据质量和误报:安全评级依赖由外向内的被动扫描,可能误归属资产,或把已废弃基础设施标记为活跃漏洞。PeerSpot 买方评价指出,SecurityScorecard 在 IT Vendor Risk Management 中的 mindshare 在 2025 至 2026 年间从 11.1% 降至 5.7%,BitSight 从 10.8% 降至 5.8%——这更像是品类碎片化,而非领导者占优。66% 的 CISO 认为 GRC 工具「仅有一定效果」,反映的是整个 TPRM 品类的广泛买方不满,而不只是评级类工具的问题。 预算周期性是结构性约束:高于监管最低要求的企业安全预算具有自由裁量属性,ISC2 2024 年数据显示,37% 的组织遭遇安全预算削减,25% 经历网络安全裁员。平台整合带来替代风险:Palo Alto Networks、Microsoft 和 CrowdStrike 正在扩展 GRC 与风险管理能力,可能把 TPRM 功能吸收到既有企业协议中。Gartner 2026 年安全支出预测(总额 $244.2B,增长 13.3%)覆盖整个网络安全,TPRM 板块的增长必须与云安全(28.8% 增长)和端点安全等优先级更高的品类竞争预算。 采购摩擦是持续性约束:企业安全交易通常需要 CISO 赞助、法务 / 采购审查、供应商回应安全问卷,并经历跨季度评估周期。79% 的 CISO 缺少针对第三方泄露的正式事件响应计划(Panorays),说明市场仍处于教育和紧迫感建立阶段,许多组织已经意识到问题,但尚未为持续平台方案编列预算。网络保险市场转软(2025 年 Q4 全球保险定价约下降 7%)可能在近期削弱由保险驱动的安全改进紧迫性。[CM034, CM035, CM036, CM037, CM038, CM039]

FM004: TPRM 采用漏斗 — 企业买方旅程

示意性企业 TPRM 采用漏斗,从问题感知到全面生产部署,反映多阶段、多利益相关方的采购流程。

漏斗百分比是基于行业买方行为调查(Panorays 2026)和一般企业 SaaS 采用研究得出的示意估计。 不是 SecurityScorecard 特定转化数据;用途是展示 TPRM 采购中的结构性摩擦,而非 SSC 实际管线指标。

[CM019, CM023, CM036, CM037]

2.6 图表

Chapter 03

03竞争对手

3.1 竞争格局概览

SecurityScorecard 所处竞争场域拥挤且正在加剧,横跨三个不同板块:直接网络风险评级同行(BitSight、UpGuard、Mastercard RiskRecon、Black Kite、Panorays)、相邻 GRC 与工作流平台(OneTrust Vendorpedia、ProcessUnity/CyberGRX、ServiceNow VRM、Archer),以及包括自建项目和维持年度问卷流程在内的宏观替代方案。2026 Forrester Wave for Cybersecurity Risk Ratings 将 BitSight 和 Panorays 列为 Leaders,SecurityScorecard 未获该认定——这是企业买方会注意到的竞争差异化信号。与此同时,Gartner 发布首个 Magic Quadrant for TPRM Tools for Assurance Leaders(2026),在相邻 GRC 工作流品类中将 OneTrust、Diligent、Optro、Certa 和 Aravo 列为 Leaders。这些分析师位置反映市场分叉:以评级为中心的买方评估 BitSight vs. SecurityScorecard;以工作流为中心的买方评估通过 API 捆绑评级的 GRC 套件。Moody's 以 $250M 战略投资支持 BitSight,UpGuard 也在 2026 年 2 月完成 $75M Series C,所有主要直接竞争对手的资本化水平都在提高,产品投入和销售能力随之增强。AI 驱动自动化、监管压力和保险集成正在把赛道内每个竞争者推向相似能力组合,压缩差异化时间窗口。[CP001, CP002, CP007, CP022, CP036]

竞争对手画像表——直接与相邻竞争者
竞争对手品类规模 / 融资目标客群关键差异化相比 SSC 的主要短板
BitSight直接 / 评级$200M+ ARR;Moody's $250M 投资(2021)企业、保险、金融服务Forrester Wave 领导者,2026 Q2;350M+ 组织信号;保险细分 2026 H1 同比 +30%分析师认可更强;保险市场可能抢占份额;整合 Moody's 信用风险数据
UpGuard直接 / 评级累计融资 $120M+;2026 年 2 月 $75M C 轮中端市场、企业(50K+ 组织)G2 TPRM 第一(15 个季度);统一 CRPM;每日 100B+ 风险信号中端市场定价优势;问卷 + 评级工作流捆绑;部署更容易
Mastercard RiskRecon直接 / 评级Mastercard 支持;收入未公开披露金融服务、企业99.1% 资产验证率;Mastercard 全球威胁情报;2026 年集成 Cloudflare/Recorded Future垂直聚焦更窄;工作流模块少于 SSC
Black Kite直接 / 评级$22M B 轮(2021);约 3,000 客户中端市场、企业RSI 勒索软件指数;Open FAIR 财务量化;入门价约 $29K/yr规模更小;生态覆盖少于 SSC 或 BitSight;保险集成有限
Panorays直接 / 评级1,000+ 客户;Forrester Wave 领导者,2026 Q2企业、中端市场AI 驱动的智能体工作流;多层级供应链映射;问卷 + 评级一体化组织评级覆盖小于 SSC 或 BitSight;2026 年融资未公开披露
OneTrust VRM相邻 / GRC 平台私营;前几轮披露估值 $1B+企业 GRC / 合规Gartner MQ 2026 TPRM 领导者;AI 自动化;隐私 + TPRM 捆绑评级深度来自 API 集成,不是原生外部视角;总合同成本更高
ServiceNow VRM相邻 / 工作流上市公司(ServiceNow);大平台中的 VRM 模块大型企业 IT深度 ITSM 集成;统一风险与 IT 运营;工作流自动化强需要专门实施;捆绑会替代 SSC,而不是直接竞争

规模指标结合公司披露和第三方估计数字。BitSight $200M+ ARR 来自公司新闻稿(2025);UpGuard $75M C 轮来自公司新闻稿(2026 年 2 月)。ServiceNow 数字指整家公司,不仅是 VRM 模块。RiskRecon 和 Panorays 的 2026 年收入与客户数未公开披露。

[CP001, CP002, CP007, CP011, CP015, CP018]
FP001: 竞争定位图 — 评级广度 vs. 工作流集成深度

SecurityScorecard 与七个主要竞争对手在评级覆盖广度(规模、受评级组织、全球足迹)和工作流集成深度 (问卷自动化、GRC 连接、AI agent)上的序数定位。位置是基于公开证据的方向性分析师判断。

X 轴(1–10):有证据支撑的评级广度和组织足迹序数估计。Y 轴(1–10):有证据支撑的工作流深度、 问卷自动化和 GRC 集成强度序数估计。分数来自截至 2026-06-29 审阅的公开产品页、新闻稿和评论站点, 是方向性估计,不是审计指标。象限标签:右上 = 宽 + 深;右下 = 宽 + 浅;左上 = 窄 + 深;左下 = 窄 + 浅。

[CP001, CP003, CP007, CP010, CP018, CP020]

3.2 直接竞争对手画像

BitSight 是 SecurityScorecard 最主要的直接竞争对手。依托 Moody's $250 million 战略投资,BitSight 到 2025 年 ARR 已超过 $200 million,并通过 Moody's 集成在全球评级超过 350 million 个组织的信号。其保险板块在 2026 年 H1 同比增长 30%,巩固了其在保险公司和金融服务机构中作为首选评级提供商的地位。Forrester Wave Q2 2026 给 BitSight 在 11 个标准类别中最高分,是所有被评供应商中最多的。在 Gartner Peer Insights 上,BitSight 得分 4.6/5(264 条评价),SecurityScorecard 为 4.4/5(278 条评价),差距不大但在企业评估周期中具有方向性意义。BitSight 与 Moody's 的合作也让其获得信用风险数据集成,形成 SecurityScorecard 当前无法复制的跨资产风险视图。 UpGuard 于 2026 年 2 月完成 $75 million Series C(Springcoast Partners 领投,累计融资超过 $120 million),并连续 15 个季度在 G2 上占据 No. 1 TPRM 位置。平台每天处理超过 100 billion 个风险信号,服务 90 多个国家的 50,000+ 个组织,面向中端市场和企业买方,提供统一的 Cyber Risk Posture Management 方法,在一个 AI 驱动系统下结合供应商风险、泄露监测和合规。UpGuard 是在中端市场替代 SecurityScorecard 的领先挑战者,主要靠易用性和总拥有成本竞争,而不是评级覆盖宽度。 Mastercard RiskRecon 声称资产验证率为 99.1%,并通过 Mastercard 全球威胁情报集成、AI 辅助深度资产发现,以及 2026 年包含 Cloudflare 和 Recorded Future 的合作伙伴生态来增强攻击面监测。其在受监管金融服务垂直最强,Mastercard 品牌信任能加速采购批准。 Black Kite 在 2021 年 Series B 融资 $22 million,全球服务约 3,000 个企业客户。其 Ransomware Susceptibility Index(RSI)和 Open FAIR 财务量化能力,让其在寻求业务语境化风险指标的买方中形成差异化,尤其适合以美元计量的风险量化。中端市场价格约从每年 $29,000 起,对价格敏感买方而言比 SecurityScorecard 更易进入。 Panorays 是 Forrester Wave Q2 2026 Leader,全球服务超过 1,000 个客户,差异化在于 AI 驱动的 agentic 工作流、实时多层供应链映射,以及单一用户体验中的问卷加评级集成。其 2026 年对 200 名美国安全领导者的 CISO 调查发现,85% 缺乏完整第三方威胁可见性,只有 41% 会监测 Tier-1 供应商之外的层级;Panorays 正是用 nth-tier 映射能力瞄准这一市场痛点。[CP001, CP002, CP003, CP004, CP005, CP006]

功能 / 能力矩阵——SecurityScorecard 与直接竞争对手
能力SecurityScorecardBitSightUpGuardRiskReconBlack KitePanorays
外部视角持续评级是——12M+ 组织被主动评级是——通过 Moody's 获得 350M+ 组织信号是——每日 100B+ 风险信号是——99.1% 验证准确率是——RSI + 字母等级评级是——多层级持续覆盖
AI 问卷自动化是——TITAN AI + HyperComply(声称减少 92% 工作量)部分——已有功能是——原生 AI 自动化部分——Whistic AI 合作无公开 AI 问卷功能是——智能体 AI 工作流
N 层供应链映射部分——TITAN AI 供应链声明部分——不是主要差异化部分——供应商发现功能是——主要差异化
财务风险量化否——仅外部视角是——Open FAIR 模型部分
网络保险集成是——Aon、Willis 合作是——Moody's、主要承保商无公开保险集成部分——Mastercard 生态无公开集成无公开集成
2026 年分析师认可未被列为 Forrester Wave 领导者Forrester Wave 领导者,2026 Q2G2 第一(15 个季度)Gartner Predicts 引用;Mastercard 支持无主要 Wave 入选Forrester Wave 领导者,2026 Q2
原生 GRC 工作流部分——MAX 问卷平台否——以评级为中心是——一体化工作流部分——轻量工作流是——一体化 Q&A + 评级

能力评估基于 2026-06-29 抓取的公开产品页面、新闻稿和第三方评价。'部分' 表示覆盖有限或依赖合作伙伴。 所有供应商 AI 声明均由公司自行提出,尚未独立基准验证。'否' 表示未找到该能力的公开证据,不代表确认不存在。

[CP002, CP009, CP010, CP012, CP016, CP020]
定价与包装对比
供应商定价模式入门价格(公开数据)企业成本(指示性)定价透明度买方影响
SecurityScorecard按模块计费的 SaaS;定制企业合同未公开列价估计在 $50K–$500K+ 区间不透明——需要定制谈判预算不确定;增加中端市场摩擦;模块加购推高 TCO
BitSight按模块计费;多年期企业许可未公开列价估计 $50K–$300K+不透明——定制谈判分析深度和保险公司接受度支撑溢价;多年期折扣
UpGuard分层 SaaS;CRPM 平台打包基础档位起价约 $5,999/年企业版估计 $20K–$100K部分透明——官网列出档位更容易进入中端市场;透明入门价降低评估摩擦
Black Kite年度订阅;按供应商数量分层中端市场典型约 $29,000(公开参考)大型组合 $50K–$200K+部分透明——评论中引用中端市场价格入门价可负担;成本随供应商数量上升;Open FAIR 量化增加价值
PanoraysSaaS 平台;按供应商数量和模块分层未公开列价;需演示估计 $30K–$150K不透明——销售接触后报价价值主张嵌入工作流;缺少透明公开锚点
OneTrust VRM更大 GRC 平台合同中的 VRM 模块非独立销售;打包进 GRC 合同完整 GRC 平台 $100K–$500K+不透明——大型平台企业谈判买方若已有 OneTrust GRC 合同,存在替代风险;没有独立 VRM SKU

所有价格区间都是市场估算区间或公开引用的数据点。SecurityScorecard、BitSight、Panorays 和 OneTrust 都不公布标价;这些数字是作者基于公开评论数据和社区报告区间给出的分析估算。Black Kite 的 $29K 数字来自公开评论网站。UpGuard 入门价来自公开引用档位。企业区间会因供应商数量、模块范围和合同期限而大幅波动。

[CP017, CP035, CP038, CP040]
FP002: 功能广度 / 能力地图 — 竞争对手覆盖评估

SecurityScorecard 与五个直接竞争对手在七个购买标准维度上的能力覆盖。 评估来自截至 2026-06-29 的公开产品证据。

所有能力评估都是分析师基于公开产品页、新闻稿和第三方评论作出的判断;“部分”表示能力有限或依赖合作伙伴。 未独立审计。AI 声明来自供应商自述。

[CP002, CP012, CP016, CP028, CP031, CP033]

3.3 相邻与工作流替代品

除直接评级同行外,SecurityScorecard 还面临来自 GRC 和工作流平台的竞争。这些平台通过原生模块或 API 集成嵌入评级功能,实际上在更大的企业软件合同内替代独立评级产品。OneTrust 在首个 Gartner Magic Quadrant for TPRM Tools for Assurance Leaders(2026)中被评为 Leader,在 Gartner Peer Insights 上得分 8.4/10,推荐意愿为 78%。在隐私相邻和合规驱动项目中,GRC 与 TPRM 常被整合进单一供应商合同,OneTrust 在此竞争力强。 ServiceNow VRM 瞄准有深度 ITSM 集成需求的大型企业。虽然实施通常需要专业咨询,但其装机基础规模创造了捆绑风险——当 TPRM 被吸收到既有 ServiceNow 合同时,独立评级层就不再必要。ProcessUnity 的 CyberGRX 与 ServiceNow 集成,把众包第三方风险情报送入既有 ServiceNow 工作流,让采购团队无需单独评级工具即可访问经过同行验证的风险数据。Interos 聚焦 nth-tier 供应链可见性和供应商关系映射,瞄准供应链情报用例,而非传统由外向内评级方法。 Recorded Future 和 Google Mandiant 在威胁情报上竞争,与以安全运营为中心项目中的 EASM 和评级数据发生重叠。RSA Archer、MetricStream 等既有厂商服务成熟 GRC 项目,这些项目可能通过集成嵌入评级。所有这些平台都构成 SecurityScorecard 的管线威胁,尤其当买方已经标准化在大型企业软件栈上、只需要边际评级能力时。Gartner TPRM MQ 将五家 GRC 品类供应商列为 Leaders,而没有传统评级供应商入列,说明工作流层可能随时间商品化评级层,并把预算从独立产品拉走。[CP021, CP022, CP023, CP024, CP025, CP026]

3.4 SecurityScorecard 的差异化与护城河

SecurityScorecard 的主要竞争优势是组织规模、保险生态集成、产品宽度和数据网络效应。其由外向内评级引擎持续评级超过 1,200 万个组织——在可比活跃监测范围内,目前没有直接竞争对手匹配这一覆盖足迹。2026 年 3 月发布的 TITAN AI 平台声称可将供应链泄露减少 75%,并把供应商参与度提高 9 倍,自动化超过 95% 的 TPRM 人工任务,包括问卷、证据收集、修复规划和报告生成。2025 年 9 月收购 HyperComply 进一步强化这一点,增加 AI 驱动问卷自动化能力,可将人工工作量降低 92%,并把问卷响应时间加快 70% 以上。这些主张均由供应商提出,尚未经过独立基准验证。 保险生态集成创造有意义的转换成本。Aon 合作(2026 年 3 月)把 SecurityScorecard 的由外向内评级与 Aon 的 CyQu 网络保险平台集成,使承保可基于持续更新的评级数据动态进行。2025 年 4 月 Willis 合作将 Willis 指定为 SecurityScorecard 官方保险经纪商,把产品嵌入全球最大保险经纪网络之一。结合 CVEDetails、MAX 问卷平台和统一 TITAN AI agent 层,SecurityScorecard 正在搭建具备复合转换成本的多产品栈。买方若把 SecurityScorecard 评级嵌入承保工作流、供应链准入和监管披露报告,更换摩擦很高。数据网络效应——1,200 万+ 被评级组织意味着每个新客户都能受益于宽覆盖,同时贡献信号数据、提升所有参与者的准确性——是一条架构型护城河,后来者需要多年才能复制。[CP028, CP029, CP030, CP031, CP032, CP033]

FP003: 护城河 / 就绪度 KPI — SecurityScorecard 竞争耐久性摘要

截至 2026 年 6 月,用六项竞争耐久性指标衡量 SecurityScorecard 的市场位置,同时标出相对竞品的强项与缺口。

[CP028, CP031, CP032, CP037, CP029, CP009]

3.5 竞争弱点与不利信号

尽管具备规模优势,SecurityScorecard 仍有可记录的竞争脆弱点。最根本的是,其只采用由外向内方法,因外部资产归属错误或内部补偿性控制对外部扫描器不可见而被批评会产生误报。竞争对手撰写的分析和独立评价记录了扫描器把资产错误归属给其他组织的案例,导致供应商分数下降,只能通过争议流程申诉。竞争性风险管理平台 FortifyData 明确将这一归因限制列为客户可能偏好补充问卷或内部人信息平台的原因。SecurityScorecard 声称误报率低于 1%,并提供快速争议解决流程(通常 72 小时内),但该指标由公司自行声称,未独立验证。 在 Forrester Wave Q2 2026 for Cybersecurity Risk Ratings 中,SecurityScorecard 未获得 Leader 认定,而 BitSight 和 Panorays 获得了。这会在分析师认可影响企业采购短名单的竞争销售周期中,造成声誉定位缺口。尤其在保险垂直,BitSight 2026 年 H1 保险板块同比增长 30%,说明其正在相对所有同行(包括 SecurityScorecard)取得份额。定价不透明——企业合同按模块定制谈判,完整平台没有公开标价——给中端市场买方带来预算不确定性,也是独立评价中的反复主题。SAFE Security 法律纠纷(商业秘密诉讼,截至报告日状态部分未决)带来品牌风险,因为方法论可信度会在竞争评估中成为销售异议。[CP034, CP035, CP036, CP037, CP038, CP041]

护城河耐久性与竞争风险登记表
护城河主张主要威胁严重性缓释 / 证据尽调问题
12M+ 组织评级的网络效应BitSight 借 Moody's 扩展至 350M+ 组织信号;UpGuard 每日处理 100B+ 信号SSC 的 12M 主动监控覆盖广度对比 BitSight 的被动信号覆盖;口径可能不同澄清 SSC 对「已评级组织」的定义,并比较主动监控占比
保险生态护城河(Aon、Willis)BitSight 保险板块 2026 年上半年同比 +30%;保险公司可能在承保中把 BitSight 标准化Aon CyQu 集成和 Willis 官方经纪商身份形成工作流锁定;同时拉动双向需求链获取保险相邻 SSC 账户的客户留存率;核验 Aon/Willis 合同排他性
TITAN AI 自动化护城河UpGuard 和 Panorays 提供可比的 AI 问卷自动化;所有供应商主张都未经验证收购 HyperComply 带来专有问卷数据;TITAN 品牌具备先发优势委托独立基准测试,比较 TITAN AI、UpGuard 和 Panorays 的自动化速度与准确率
未进入 Forrester Wave 领导者档买方会使用 Forrester 短名单;没有领导者标签时,SSC 必须靠具体用例价值自证Forrester 报告提到 SSC,但未列为领导者;Gartner TPRM MQ 只覆盖相邻工作流市场跟踪未来分析师排名;优先安排分析师简报并提升 Forrester 评分
Outside-in 方法容易产生误报如果归因错误频繁,买方可能转向增强型平台(问卷 + outside-in 的混合方案)争议处理流程加上声称低于 1% 的 FP 率;HyperComply 问卷层补充 inside-out 数据视角向 SSC 索取实际误报率、争议量和资产归因准确率数据

严重性评级是作者基于截至 2026-06-29 的公开证据作出的分析判断。高 = 有证据支持、近期可信的替代或份额流失风险;中 = 风险有意义但可管理,证据不完整。所有严重性评估都应在尽调中结合 SSC 管理层数据重新审视。

[CP003, CP005, CP028, CP029, CP031, CP034]

3.6 按买方分层与地理划分的赢 / 输动态

SecurityScorecard 最稳定的胜场在大型企业账户:这些客户把广泛供应链供应商覆盖、监管可辩护性(SEC 10-K、NIS2、DORA 披露)和保险集成作为主要购买标准。管理全球供应链中数千家供应商的企业 CISO——需要评分被保险公司和审计师接受的评级提供商——构成 SecurityScorecard 最清晰的胜利画像。Aon 和 Willis 集成形成下游渠道拉力:当保险公司用 SecurityScorecard 数据报价网络保险时,被保险组织自然有动力采用平台,主动改善评分并跟踪修复。 失败集中在中端市场账户,以及集成工作流、部署易用性和总拥有成本压过评级宽度的交易中。UpGuard 赢下中端市场交易,买方想要价格更易接受的问卷加评级捆绑体验。Panorays 在 AI 驱动供应链映射和多层可见性是主要差异化时胜出。BitSight 在金融服务和保险中获胜,其 Moody's 支持的统计方法被视为保险风险建模的行业标准。地理差异化很难从公开来源验证;SecurityScorecard 的多语言平台(包括 2026 年韩语支持)和全球评级足迹显示其正在积极国际扩张,但按地区划分的收入集中度未公开披露。在包含分析师评分卡的采购评估中,Forrester Q2 2026 将 BitSight 和 Panorays 评为 Leaders,可能改变企业短名单,迫使 SecurityScorecard 依靠独特用例强项而非分析师同等地位来防守。大型套件捆绑的出现是额外结构性风险:如果企业标准化采用 OneTrust 或 ServiceNow,合同内评级模块会替代独立 SecurityScorecard 订阅需求。[CP039, CP040, CP041, CP042, CP043]

3.7 图表

Chapter 04

04财务

4.1 收入模式与 ARR 轨迹

SecurityScorecard 披露的收入历史很少,但方向上向好。第三方 SaaS 数据库估计,ARR 从 2021 年约 $71M 增至 2022 年 $88.5M(约同比增长 25%)、2023 年 $106M(约同比增长 20%),并在 2024 年初达到 $144.3M(约同比增长 36%)——隐含四年 CAGR 约 27%。公司唯一披露的数字,是 2025 年 10 月与 Safe Security 共同发布的商业秘密诉讼和解新闻稿中宣布 ARR 超过 $150M。没有独立投资者公告、业绩电话会或经审计申报文件确认该数字,可审计性受限。截至 2026 年 6 月,公司没有再发布公开 ARR 更新,数据新鲜度缺口在扩大。 公司的经常性收入模式,以安全评级、第三方风险监控和供应链检测能力的年度 SaaS 订阅为核心。这些订阅带来可预测 ARR,续约动态符合企业安全软件常态——但准确 NRR 和总流失率未公开。收入确认遵循标准 SaaS 合同确认方式;公司未披露递延收入复杂性或按用量计费异常。按 3,300 多家企业客户和超过 $150M ARR 计算,隐含平均合同额约为每客户每年 $45,000——与企业 TPRM 定价基准一致。 [CI001, CI002, CI003, CI031, CI032, CI033]

收入流——机制、状态与尽调问题
收入流机制定价单位当前状态收入质量尽调问题
核心 SaaS 评级 / TPRM安全评级平台和第三方风险监控的年度订阅按席位或按被监控实体;分层(Business / Enterprise)活跃;ARR 主要来源;3,300+ 企业客户高 – 经常性、合同化、多年期按档位拆分的毛利率、NRR、总流失率
MAX 托管服务(渠道)合作伙伴用 SSC 平台交付托管 TPRM 服务;2025 年渠道 ARR 同比 +160%收入分成或直接 MAX 订阅;定制合同增长最快的产品;三位数增长;600+ 合作伙伴中高 – 增长快,但服务交付成本结构未披露托管服务对比 SaaS 的毛利率;合作伙伴经济性;抽成率
TITAN AI 问卷自动化AI 驱动供应商评估和问卷自动化;2025 年 9 月收购 HyperComply 后加速Enterprise/MAX 加购项或独立销售(价格未公开)活跃;HyperComply 集成进行中;定价未披露中 – 战略加购项;收入贡献未量化定价模型(加购还是打包)、收购成本、年化贡献
保险承保与经纪为网络保险承保提供数据许可和评分服务;经纪商用 SSC 数据生成报价数据许可费或按报价计收;合同条款未披露活跃;合作伙伴包括 WTW;多篇新闻稿提及中 – 若按合同计费则具备经常性;市场在增长收入规模、利润率、与保险合作伙伴的排他安排
政府 / 公共部门向美国和加拿大政府机构交付 FedRAMP 评级 SaaS;DHS CDM 批准产品企业订阅(政府采购渠道)活跃;FedRAMP Ready 认定;DHS CDM APL 列名中高 – 粘性经常性收入;由合规驱动联邦 ARR 占总 ARR 比例;采购渠道条款;续约率

收入流状态来自官方新闻稿和产品页的观察或推断。各收入流规模未公开披露。收入质量评估是作者基于合同类型和增长信号作出的判断。

[CI007, CI008, CI009, CI011, CI035]
FI003: 财务估算区间 — 有来源支撑边界的关键指标

基于第三方数据、公司披露和行业基准,估算关键财务指标区间。区间较宽,反映私有公司不透明带来的显著不确定性。多数指标没有 SecurityScorecard 披露值。

所有区间均为基于第三方数据聚合器、行业基准和公司新闻稿的估算或推断。SecurityScorecard 未公布增长率、毛利率或详细财务。所有区间仅作方向性参考;未经独立验证,不应放入财务模型。

[CI001, CI002, CI003, CI031, CI037]

4.2 产品收入结构与新兴增长流

SecurityScorecard 的收入结构横跨四条可观察路径:(1)来自安全评级和 TPRM 平台访问的核心 SaaS 订阅收入,占 ARR 大头;(2)MAX 托管服务,通过认证服务伙伴交付,是高速增长层;(3)TITAN AI 问卷自动化收入,受 2025 年 9 月收购 HyperComply 推动;(4)通过与 WTW 的合作及扩大的经纪商关系带来的保险承保和数据授权收入。 MAX 托管服务是最突出的增长信号。截至 2025 年中,该产品同比增长 370%,并推动最近一个季度实现三位数增长。渠道 ARR——经合作伙伴生态流入的收入——2025 年同比增长 160%,伙伴主导的 pipeline 同比增加 126%。公司拥有 600 多家合作伙伴,并在 2025 年新增 35 家,渠道正成为结构性重要的分销机制。HyperComply 收购把问卷自动化纳入产品能力;该能力是作为独立附加模块定价,还是打包进企业层级,尚未公开披露。保险承保用例在新闻材料中反复出现,并由 WTW 及其他经纪商关系支撑,代表一条新兴数据变现渠道,但其对总 ARR 的贡献未量化。国际收入在增长——2020 年 Q4 国际经常性收入同比增长 61%,国际客户数同比增长 89%——但公司没有发布近期地域收入拆分。 [CI004, CI005, CI006, CI007, CI008, CI009]

FI001: 收入模型桥 — 从客户活动到收入流

估算 SecurityScorecard $150M+ ARR(2025 年 10 月确认下限)在四条已观察收入流中的构成。拆分基于增长信号和新闻稿披露估算;公司未披露分部收入。

所有分部数值均为作者估算,依据包括 MAX 三位数增长信号、2025 年渠道 ARR 增长 160% 以及新闻稿表述。SecurityScorecard 未按产品或分部披露收入。$150M 总额是公司在 2025 年 10 月确认的下限;实际收入结构可能与这些估算有重大差异。

[CI007, CI008, CI009, CI011, CI041]

4.3 定价架构与合同经济性

SecurityScorecard 采用分层定价,但入门层以上并不透明。Free 层提供自评访问。Business 计划覆盖最多五个外部实体的监控,按第三方采购数据估计,每年约 $15,000–$25,000。Enterprise 计划覆盖自定义数量的受监控 scorecards,并提供高级告警、合规框架和专属客户成功经理;定价仅为 “Contact Sales”,第三方基准显示典型企业合同为每年 $50,000–$100,000+。MAX 层增加托管服务、修复支持和入侵检测,完全定制定价;有意义部署的年费估计在 $100,000+。 多个附加模块(Cyber Risk Quantification、Attack Surface Intelligence API、Automatic Vendor Detection)位于基础 Enterprise 订阅之外,可能显著推高合同总额。采购数据库引用的按用户定价基准约为小规模部署 $20,000/user/year,大型组织则非线性扩展。公司提供多年期折扣,但没有系统披露。2025 年 10 月新闻稿中的 SecurityScorecard 竞争替换胜单涉及“six-figure”合同,确认最大型企业交易明显高于 $100K 的隐含 ACV 下限。定价不透明给买方和分析师都带来不确定性;第三方定价分析师指出,“Contact Sales”模式“likely targets larger enterprises”,且入门成本高于部分竞争对手。 [CI012, CI013, CI014, CI015, CI016, CI033]

定价与变现架构
档位 / 模块标价区间合同基础关键能力来源置信度
Free$0/year无合同;自助服务仅自评 scorecard;14 天 Business 试用;20 次搜索查询高(来自产品页观察)
Business$15,000–$25,000/year(估算)年度最多监控 5 家公司;每日告警;基础 API;Slack/JIRA 集成中(Vendr/PricingNow 基准)
Enterprise$50,000–$100,000+/year(估算)年度,可选多年期定制被监控 scorecard;主动告警;合规框架;专属 CSM中(采购基准;Contact Sales 模式)
MAX$100,000+/year(估算)年度;定制托管服务;合作伙伴交付整改;泄露检测与响应;零日支持低(推断;无公开价格)
加购项(CRQ、EASM API、AVD)未知;定制定价叠加在 Enterprise/MAX 之上的模块Cyber Risk Quantification(网络风险量化);Attack Surface Intelligence API(攻击面情报 API);Automatic Vendor Detection(自动供应商发现)低(加购项存在已确认;价格未披露)

所有价格数字都是来自 Vendr、PricingNow 和 ToolRadar 的第三方基准估算;SecurityScorecard 不公布 Free 档以上的标价。实际合同成交额可能有重大差异。加购项价格没有公开信息。

[CI012, CI013, CI014, CI015, CI016]

4.4 成本结构与资本效率

SecurityScorecard 不披露毛利率、COGS、运营费用或 EBITDA。第三方员工数聚合机构把公司放在 501–1,000 人区间,LeadIQ 报告为“501–1,000 employees”,Forbes Council 简介称“over 600 employees”。按超过 $150M ARR 和约 580–620 名员工计算,隐含人均 ARR 约 $250,000–$260,000——与安全领域高效率 SaaS 运营商一致。 2025 年 10 月新闻稿披露了两个关键财务效率信号:该季度自由现金流为正,且 ARR / 全职员工同比改善 40%。若这些信号准确,意味着收入增长快于员工增长,公司正在接近或已经跨过现金中性运营模式。公司还在 2025 年新增三名高管(CFO Chris Fritz、CRO Peter Jantzen、CMO Claire Trimble),说明即使在提效周期中,公司仍继续投入商业化领导团队。 核心 SaaS 评级平台的毛利率未披露。可比 SaaS 网络安全评级公司的行业基准显示,受可扩展云交付模式和有限单客户增量成本支撑,毛利率约在 75–85%。不过,MAX 托管服务可能毛利率更低,因为它涉及人工交付的修复、合作伙伴服务成本组件和托管响应流程。随着 MAX 增速快于核心订阅,混合毛利率轨迹可能面临轻微压缩——这一风险无法用现有公开数据量化。 [CI017, CI018, CI019, CI020, CI021, CI022]

单位经济性——关键指标、置信度与尽调路径
指标估计值置信度重要性尽调问题
隐含平均合同价值(ACV)约 $45,000/年(推断)核心收入驱动因素;反映交易规模分布和销售效率按档位和客群拆分的实际 ACV;ASP 随时间的趋势
毛利率(核心 SaaS)75–85%(行业基准)决定增长转化为现金和长期盈利的能力经审计的分客群 COGS;SaaS 与托管服务毛利率拆分
毛利率(MAX 托管服务)40–60%(推断)很低MAX 增长最快;综合毛利率取决于托管服务成本结构合作伙伴服务成本经济性;每个托管客户的直接交付成本
净收入留存(NRR)未披露SaaS 健康度关键指标;缺少 NRR 无法判断增长质量按 cohort 和档位拆分的 NRR;扩张与收缩拆分
每 FTE ARR约 $250,000–$260,000/年(推断)低-中运营效率代理指标;公司披露同比改善 40%按职能拆分的准确员工数;直销生产率指标
竞争胜率70%(公司声称)反映相对 BitSight 和 Black Kite 的市场位置独立赢单 / 输单数据;竞争机会集合的定义
CAC 与回本期未披露衡量增长的资本效率;私营公司未披露销售和营销支出;每 1 美元 S&M 产生的新 ARR;按客群拆分的回本期
客户生命周期价值(LTV)未披露计算 LTV:CAC 比率所需;没有流失数据无法计算按客户客群拆分的 LTV/CAC;客户 logo 留存率

所有估计值都基于有限第三方数据或可比 SaaS 网络安全平台的行业基准推断。SecurityScorecard 不披露任何单位经济性指标。置信度反映作者对估算可靠性的评估。

[CI021, CI022, CI033, CI034, CI044]
FI002: 单位经济桥 — 从潜在客户到毛利

示意企业潜在客户识别、年度订阅、MAX 向上销售到估算毛利贡献的流转。节点数值基于定价基准和行业可比公司估算;SecurityScorecard 未披露单位经济。

约 $45K 的 ACV 来自 $150M ARR 除以 3,300 名客户,是混合平均值;实际 ACV 从约 $15K(Business 档)到 $500K+(最大型企业)不等。公司未披露毛利率;核心 SaaS 78–85%、MAX 40–60% 是行业基准。

[CI012, CI014, CI033, CI044, CI010]

4.5 资本充足性与融资姿态

SecurityScorecard 从 2013 年到 2021 年 3 月 Series E 共完成七轮股权融资,累计约 $293M;Series E 投后估值为 $1B。自 2021 年 3 月以来,公司未公开宣布新的股权融资——也就是说,公司已依靠 Series E 资本栈运营超过五年。因此,$1B 估值已经滞后五年以上,且反映的是与当下条件明显不同的 Series E 市场环境。公司没有公开确认债务融资、授信额度或二级流动性事件。 2025 年 10 月的自由现金流为正信号显示,SecurityScorecard 可能没有以显著速度烧钱;在五年没有新融资的背景下,这一点很重要。它意味着:(a)公司已达到或接近现金口径经营盈亏平衡;(b)Series E 留存现金仍足以支持运营;或(c)两者兼有。没有资产负债表披露,任何假设都无法确认。ARR/FTE 效率改善 40% 强化了资本效率叙事,但绝对现金头寸仍未知。高管案例研究提到 IPO 准备度,但截至 2026 年 6 月,公司没有披露 S-1 文件、投行聘任公告或明确 IPO 时间表。 按超过 $150M ARR 运行率和 2026 年私营 SaaS 网络安全公司常见的 7–10x ARR 倍数计算,企业价值约为 $1.05–$1.5B,大致包住 2021 年估值。这说明相对于当前 ARR,滞后估值既不显著便宜也不显著昂贵——但没有当前融资事件,无法验证。 [CI023, CI024, CI025, CI038, CI043]

资本充足性评估
项目状态证据质量
股权融资总额2013–2021 年七轮合计 $293MSSC 投资者页面;Pitchbook;Tracxn;LeadIQ
最近一轮股权融资2021 年 3 月 Series E,融资 $180M,投后估值 $1BSecurityScorecard 官方披露;投资者档案
估值$1B(2021 年 3 月);此后未披露更新估值Bitscale 引用 $1.04B;Pitchbook 档案;无新一轮融资中(已过时 5+ 年)
债务 / 信贷额度未有公开确认无新闻稿或备案;媒体搜索未发现 SSC 专属信贷安排低(缺少证据)
月度烧钱率未披露;按 2025 年 10 月 FCF 信号,方向上接近现金中性2025 年 10 月新闻稿:「正自由现金流」低(仅方向性)
资金 runway没有现金头寸和烧钱率,无法可靠估算正 FCF 信号暗示运营可自我维持;距 Series E 已 5 年很低(推断)
IPO 信号高管案例研究提到 IPO 准备;截至 2026 年 6 月无活跃 S-1 或备案ChristianTimbers 案例研究;未发现 SEC 备案

资本充足性数据主要来自公开披露的融资历史和公司新闻稿。烧钱率、现金头寸和 runway 未公开披露。5+ 年没有新融资,再加上正 FCF 信号,与运营自我维持一致,但没有财务报表无法确认。

[CI023, CI024, CI025, CI038]
FI004: 资本强度图 — 各阶段累计股权融资

SecurityScorecard 从 2013 年到 2021 年 3 月 Series E 的七轮融资累计股权融资额。自 2021 年 3 月以来,公司未公开宣布新的股权融资。瀑布图展示了支撑平台开发、销售和国际扩张的资本栈。

只有 Series E($180M,2021 年 3 月)金额由官方新闻稿确认。更早轮次金额基于第三方聚合器数据(Pitchbook、Tracxn、Bitscale)估算。全轮次总融资额确认约为 $292–$293M。

[CI023, CI024, CI025, CI038, CI043]

4.6 财务质量评估与尽调缺口

SecurityScorecard 可观察的财务画像,符合一家增长中、资本效率提升的 SaaS 公司:ARR 超过 $150M、自由现金流为正、ARR/FTE 改善 40%、MAX 三位数增长、收入连续 10 多个季度增长。这些信号对 TPRM 市场中的私营公司很有意义。但完整财务承销所需的几乎所有指标仍未公开或未经验证。 2024 年 6 月 Safe Security CEO 的负面信号——称 SecurityScorecard “laying off significant portions of their teams because of the poor performance of their business”——发生在诉讼进行期间,代表带有动机的竞争对手表述。随后 2025 年 10 月新闻稿披露自由现金流为正和创纪录季度表现,直接反驳了这种说法。不过,最初 $150M ARR 披露的诉讼语境(出现在诉讼和解公告,而非独立财务新闻稿中)会招致审视,也降低了独立可验证性。外部视角安全评估方法也因潜在误报和深度有限受到批评,长期可能削弱定价权和企业客户追加销售能力。 关键尽调阻塞项包括:按产品线拆分的毛利率(核心 SaaS vs. MAX vs. TITAN AI)、净收入留存、从 $150M 底线起算的过去 ARR 增速、准确员工构成及各职能生产率、现金和债务头寸、新兴收入流(保险数据、问卷自动化)的贡献毛利率。截至 2026 年 6 月,公开来源无法获得这些信息。 [CI026, CI027, CI028, CI029, CI030, CI034]

公开财务缺口——缺失指标与尽调路径
缺失指标对判断的影响精确尽调路径优先级
按产品线拆分的毛利率无法评估盈利轨迹或 MAX 毛利率压缩风险索取经审计 P&L 或管理账;披露分部 COGS阻断
净收入留存(NRR)无法判断收入质量、扩张效率或流失风险索取按档位拆分的 cohort NRR;扩张 ARR 对比收缩 ARR 拆分阻断
2025 年 10 月以来的 ARR 增速新鲜度缺口;截至 2026 年 6 月,$150M ARR 已过时 8+ 个月索取当前 ARR;对比 2025 年 Q4 和 2026 年 Q1 内部报告阻断
现金与债务状况没有资产负债表数据,无法评估 runway 或资本充足性索取经审计或管理层资产负债表;截至 2026 年 6 月的资金 / 现金头寸阻断
CAC、回本期和 LTV无法评估销售效率或长期单位经济性索取 S&M 支出;按 cohort 拆分的新 ARR;cohort 回本分析重大
按地域拆分的收入无法评估国际增长质量或货币 / 集中度风险索取按地域拆分的 ARR;按地区拆分的增速;最大国家敞口重大
MAX 收入占总 ARR 比例无法判断 $150M+ ARR 中托管服务与 SaaS 各占多少索取产品线 ARR;按收入类型拆分的综合毛利率重大
客户集中度没有前 10 大客户敞口,无法评估收入集中风险索取前 10 大客户 ARR 贡献;续约状态;通知期重大
按职能拆分的员工数和趋势没有职能员工数,无法评估销售效率或成本结构索取按职能拆分的员工数;招聘计划;员工成本拆分次要

优先级评级反映作者对财务承销影响的评估。「阻断」表示缺少该指标会在没有额外披露时阻止投资决策;「重大」表示该缺口影响判断,但若有定性替代依据,可能不阻止决策。

[CI026, CI029, CI036, CI042]

4.7 图表

Chapter 05

05产品与技术

5.1 外部视角评分方法与数据引擎

SecurityScorecard 的基础产品,是其外部视角安全评级引擎——一种非侵入式、持续评估组织互联网暴露基础设施的方法,不需要安装 agent 或供应商配合。该引擎把每个发现的安全问题归入十个风险因子组之一:Network Security、DNS Health、Patching Cadence、Endpoint Security、IP Reputation、Application Security、Cubit Score、Hacker Chatter、Information Leak 和 Social Engineering。每类问题都有 High、Medium 或 Low 严重程度;这些严重程度权重直接塑造每个因子的 0 到 100 分,以及整体数字分数,并映射为 A 到 F 的字母等级,类似网络安全领域的信用评级。 Scoring 3.0 于 2024 年 4 月 9 日发布,此前在 2023 年 9 月预览;它替代了旧方法。旧方法的总分只是十个因子分数的加权平均。3.0 下,因子仍保留数字分数,但在整体计算中不再各自带权重;整体分数改为直接反映所有发现的安全问题及其严重程度影响。该变化提高了入侵相关性信号:F 级组织(分数 ≤60)遭遇入侵的可能性现在是 A 级(90–100)组织的 13.8 倍,而旧模型下为 7.7 倍。SecurityScorecard 数据科学团队评估了 15,000 多起历史入侵事件,以验证这种相关性映射。 评分算法通过对数尺度做规模归一化,确保规模差异很大的组织可以公平比较,避免小组织仅因 IP 较少、潜在发现较少而显得人为更安全。算法为每类问题计算经规模调整的“z-scores”后,再进行季度校准,以平滑统计波动。因子分和总分每日重新校准,确保低分数波动:如果组织的数字足迹和问题数量保持稳定,分数就会日复一日保持不变。[CE001, CE002, CE003, CE004, CE005, CE006]

工作流与用例表——SecurityScorecard 客户场景
用户 / 买方当前工作流痛点SecurityScorecard 方案可衡量收益局限
企业 CISO / 第三方风险团队靠人工表格跟踪供应商风险;周期性做时点评估TITAN Watch + Assess:连续自动监控,AI 问卷分流人工问卷工作量减少 95%;实时风险告警黑箱评分让供应商难以解释;可能出现归因错误
供应商 / 第三方安全团队为多个客户反复回答同一批安全问卷RespondAI(HyperComply):靠知识库自动生成回复完成速度快 70%;人工工作量减少 92%收购后集成仍在稳定(2025 年 9 月)
网络保险公司 / 承保人靠静态问卷和时点审计人工承保连续评级 API;姿态变化告警;网络保险集成缩短承保周期;提供动态风险定价信号只有由外向内信号;不评估内部控制
美国政府机构供应链监管缺少标准化供应商风险评分FedRAMP/StateRAMP Ready 平台;列入 DHS CDM APL 的 ASI;CISA 免费工具为关键基础设施提供标准化 A–F 评级;TSA 蓝图仅为 FedRAMP Ready(非 Authorized);完整 ATO 仍待机构赞助
M&A 尽调团队评估目标公司安全状况耗时且依赖人工任意域名即时 SecurityScorecard 评级;历史趋势;问题明细快速给出尽调量化基线;可向董事会汇报的字母评级仅由外向内;不评估内部 IT 环境或代码质量

用例来自 SecurityScorecard 官方产品页、客户证言(McDonald's、未具名医疗公司)以及政府合作公告。除非引用来源已独立佐证,收益主张均为公司表述。

[CE001, CE004, CE033, CE036, CE037]
FE002: 客户工作流 — 供应商风险发现与整改流程

展示企业安全团队如何借助 SecurityScorecard TITAN AI 平台,从初始供应商发现一路推进到持续风险监控、自动化评估、协同整改和合规报告。

工作流来自 SecurityScorecard 官方产品描述;实际步骤顺序和自动化深度取决于客户档位(自助服务还是 TITAN MAX 托管服务)和集成配置。

[CE010, CE011, CE012, CE014, CE015]

5.2 产品模块与平台生态

SecurityScorecard 的商业产品,已经从独立评级产品演进为 TITAN AI 旗下的多模块平台;TITAN AI 于 2026 年 3 月 23 日在 RSA Conference 宣布。TITAN AI 包含三层:TITAN Watch 对供应商生态提供常开、持续可见性——自动发现第三方和第四方关系,并实时浮现外部可观察暴露。TITAN Assess 端到端自动化问卷管理,使用 AI agent 验证回答、排序风险,并更快完成供应商评估;公司声称可减少 95% 人工工作量,并把供应商参与率提高 9 倍。TITAN Secure 加入威胁情报驱动的修复,把实时网络威胁情报(CTI)接入分诊工作流,使企业和供应商在识别关键暴露的第一时间协调修复。 除自助式 TITAN 层级外,SecurityScorecard 还提供 TITAN MAX——一种通过认证伙伴特许模式交付的托管服务,公司于 2024 年 1 月推出。MAX 运营 Vendor Risk Operations Center(VROC),由风险管理、威胁狩猎和事件响应从业者组成。它采用与 NIST 对齐的方法,并承诺问卷审核速度提高 26 倍、问题修复率提高 2 倍、注册组织的供应链入侵减少 75%。MAX 已在 AWS Marketplace 上架,并于 2025 年 5 月加入 CrowdStrike Marketplace,扩大渠道触达,同时不需要 SecurityScorecard 直接销售介入。 2025 年 9 月收购 HyperComply 后,平台新增 AI 驱动的问卷自动化。HyperComply 的专有 RespondAI 技术可将人工问卷工作减少 92%,并把问卷处理速度提高 70%;它构建集中式合规知识库,存储经验证答案以便复用。HyperComply 功能整合始于 2025 年末,目标是为 GDPR、DORA 和 NIS2 合规提供持续、自动化的供应商保障。[CE010, CE011, CE012, CE013, CE014, CE015]

产品模块与资产矩阵——SecurityScorecard 平台
模块 / 产品主要用户状态 / 成熟度关键差异化尽调缺口
TITAN WatchCISO、风险团队GA(2026 年 3 月)持续发现第三 / 第四方;自动供应商识别第 N 方覆盖深度仍在成熟
TITAN Assess风险分析师、供应商经理GA(2026 年 3 月)AI 自动化 95% 问卷工作流;供应商参与度 9×缺少证据文档的 AI 解析(Forrester 批评)
TITAN Secure安全运营、供应商经理GA(2026 年 3 月)CTI 集成分诊;协作式整改工作流效果未经独立审计验证
TITAN MAX(托管服务)缺少内部 TPRM 人员的组织GA(2024 年 1 月);已进入 AWS 与 CrowdStrike MarketplaceVROC 将问卷审核提速 26×;合作伙伴加盟模式合作伙伴质量不一;价格未公开
Attack Surface Intelligence(ASI)威胁情报团队、政府机构GA;DHS CDM APL 批准CVE/CPE 映射;威胁行为者关联;CDM 列名尚未 FedRAMP Authorized(仅 Ready)
HyperComply / RespondAIGRC 团队、销售 / 收入团队集成进行中(来自 2025 年 9 月收购)人工工作减少 92%;问卷周期加快 70%独立业绩记录有限;平台集成尚未完成
Developer API & Marketplace安全工程师、合作伙伴GA;100+ 认证集成开放 REST API;代码示例;CrowdStrike、ServiceNow、OneTrust 应用SDK 成熟度不足;未发布 API 可用性 SLA
网络保险集成保险公司、承保人生产环境(多承运商)承保实时使用评级;姿态变化触发告警未披露与各保险公司的合同条款

状态日期来自公司官方新闻稿和产品页公布的 GA 时间线;尽调缺口来自公开记录中的 Forrester 批评、客户评论和本分析。所有模块均未公开定价。

[CE010, CE011, CE012, CE013, CE014, CE015]
产品路线图与发布时间线
日期 / 阶段功能 / 里程碑状态含义来源
Jan 2024MAX 托管服务发布GA;合作伙伴特许经营模式;AWS Marketplace打开托管服务收入线;McDonald's 是早期客户之一BusinessWire 2024 年 1 月
Sep 2023 / Apr 9 2024Scoring 3.0 预览并 GA 发布自 2024 年 4 月 9 日起 GA;永久替代 2.x 评分泄露相关性收紧;F 级风险为 A 级的 13.8×SecurityScorecard 帮助中心
Sep 15 2025HyperComply 收购完成集成推进中;功能在 2025 年末至 2026 年陆续上线增加 RespondAI 问卷自动化;扩展 GDPR/DORA 合规支持SSC 新闻稿;BetaKit
Feb 10 2025取得 StateRAMP Ready 认定;FedRAMP 再次确认认定处于有效状态将政府可服务市场扩至州 / 地方机构SSC 2025 年 2 月新闻稿
Mar 23 2026TITAN AI 在 RSA Conference 2026 发布GA;三层架构(Watch/Assess/Secure)+ Supply Chain Resilience Journey平台重新发布,以 AI 加速 TPRM 为核心;确立竞争定位SSC 2026 年 3 月新闻稿

所有日期均来自 SecurityScorecard 官方新闻稿和公司帮助中心文档。HyperComply 集成时间线(2025 年末至 2026 年)为公司表述的估计,不是合同保证交付日期。

[CE002, CE011, CE013, CE017, CE032]

5.3 技术架构与数据基础设施

SecurityScorecard 的数据管线始于一套自研专有全球互联网扫描框架,覆盖整个 IPv4 地址空间——超过 39 亿个可路由 IP——并以 10 天为周期扫描 1,400 多个端口。云资产所有权变化更快,因此每天扫描多次。扫描器收集 IP 地址暴露数据,以及服务、产品、操作系统、库的指纹,包括版本号、Common Platform Enumeration(CPE)ID、CVE Version 2 ID 和 Nmap 脚本输出。原始信号还由横跨三大洲的传感器网络补充,再加上公司称为全球最大之一的 sinkhole 和 honeypot 网络——每天捕获超过 20 亿次恶意软件 DNS 请求。商业和开源威胁情报 feed 补齐了信号摄取层。 归因是运营上最关键、也最容易出错的一步:SecurityScorecard 必须把收集到的信号与特定组织的数字足迹关联起来。归因引擎依赖 DNS 查询、BGP 路由数据和其他可靠映射来源。组织可以主动认领并反驳其 scorecard 中的资产,以提高归因准确性。Scoring 3.0 引擎按问题类型使用修改后的 z-score 计算,把每个组织与超过 1,200 万个已评级实体组成的参照群体比较,并使用上述对数归一化。SecurityScorecard 使用机器学习算法提高发现准确性,并提供针对勒索软件变种和零日漏洞等新兴威胁的洞察。 AI 能力通过 TITAN AI 引擎和 HyperComply RespondAI 集成嵌入平台各处。TITAN AI 平台被描述为一个“operational clearinghouse”,通过共享数据层连接企业和供应商——把评级引擎的外部视角攻击者遥测与评估的内部视角风险信息合并,产出预测性、高保真信号。公司宣称风险归因准确率 99.9%,反驳率接近零,但该说法未经独立审计。[CE019, CE020, CE021, CE022, CE023, CE024]

技术与运营架构——关键组件、作用和风险
层级 / 组件作用关键依赖风险
IPv4 互联网扫描器每 10 天扫描 3.9B 个可路由 IP,覆盖 1,400+ 端口;云资产每天多次扫描自研专有扫描基础设施大型云服务商若屏蔽扫描器,可能形成盲区
DNS Sinkhole 与蜜罐网络每天检测 2B+ 次恶意软件 DNS 请求;补强 IP 声誉和黑客聊天信号覆盖三大洲的传感器网络Sinkhole 覆盖受地域限制;主动型攻击者可能绕过
归因引擎借助 DNS 查询、BGP 路由和数字足迹声明,把信号映射到组织可靠的公开 DNS/BGP 数据;用户声明资产归属归因错误仍会存在;误归因会拉低合法组织评分
Scoring 3.0 引擎按问题类型计算 z-score;套用规模归一化、校准和泄露惩罚15,000+ 条历史泄露数据集,用于相关性验证算法专有;未发布评分逻辑的独立审计
AI / ML 层TITAN AI 引擎编排风险信号融合、问卷自动化(RespondAI)和预测分析HyperComply RespondAI;专有 LLM/ML 模型AI 主张(99.9% 归因准确率)未获独立验证
API 与交付层REST API 位于 securityscorecard.readme.io;100+ 市场集成;GitHub SDK合作伙伴集成(CrowdStrike、ServiceNow、OneTrust、Archer)API 未发布正常运行时间 SLA;没有处于活跃 OSS 维护的开放 SDK

架构细节来自官方帮助中心文档、SecurityScorecard 开发者中心和 Forrester Wave 2024 报道。内部架构细节(云基础设施提供商、数据中心覆盖)未公开披露。

[CE019, CE020, CE021, CE022, CE023, CE024]
FE001: SecurityScorecard 平台架构 — 技术栈

从原始互联网信号采集到 AI 编排的 TPRM 交付,平台分为四层,展示 SecurityScorecard 平台每一层的技术组件。

[CE019, CE020, CE021, CE001, CE010]

5.4 集成生态、API 平台与开发者界面

SecurityScorecard 在 securityscorecard.readme.io 提供 RESTful API,采用 token 认证,支持六类主要集成模式:企业网络风险管理、第三方风险管理、工作流管理、网络保险承保、合规跟踪和攻击面管理。API 调用接收一个 domain 加一个 API token,返回 scorecard 等级、因子分、问题清单、历史发现、事件、合规映射和第三方供应链数据。代码样例覆盖 Shell、Ruby、Python、PHP 等语言。API keys 不会过期,必须安全存放在应用 secrets 中,不能放在客户端代码里。 Integrate360° Marketplace 承载 100 多个认证伙伴集成,包括 CrowdStrike Falcon、ServiceNow、Archer、OneTrust 和 ProcessUnity,使客户无需定制工程就能把 SecurityScorecard 数据路由进既有 GRC、工单和 SIEM 工作流。MAX 于 2025 年 5 月在 CrowdStrike Marketplace 支持直接购买,让 CrowdStrike Falcon 客户为安全运营增加持续供应链风险监控。Microsoft 365 Copilot 连接器目录列出 SecurityScorecard 连接器;平台还通过 AWS Marketplace 上架和云资产扫描能力集成进 AWS 环境。 SecurityScorecard 的 GitHub 组织(github.com/securityscorecard)有 63 个公开仓库,包括设计系统 React 组件库(TypeScript、Apache-2.0 license、13 stars)、SSC-Threat-Intel-IoCs(与技术博客文章相关的公开 IoC 数据,75 stars)、aws-big-data-blog Java 项目(623 stars),以及 grpc-python-microservice-template 和 consul-template 等基础设施工具。另一个 SSCDeveloperCommunity 组织承载 hackathon 和社区集成项目。开发者活动显示工程组织活跃,但公开仓库主要是内部工具和样例代码,而非对外维护的开源项目。[CE025, CE026, CE027, CE028, CE029, CE030]

FE003: 关键依赖图 — SecurityScorecard 平台依赖与下游集成

用有向图呈现 SecurityScorecard 的关键上游数据输入和下游平台集成,显示该平台在更广泛网络安全生态中的数据枢纽位置。

[CE025, CE026, CE027, CE028, CE029, CE031]

5.5 合规姿态、政府认证与信任控制

SecurityScorecard 已建立有意义的政府和受监管行业合规姿态。2023 年 10 月,公司为其 Third-Party Cyber Risk Management Platform(包括 Attack Surface Intelligence)获得 FedRAMP Ready designation,跻身不到 450 个拥有 FedRAMP designation 的云产品之列。2025 年 2 月,公司重申 FedRAMP Ready 状态,并额外获得 StateRAMP Ready designation,扩大到州和地方政府机构采购资格。这两个 designation 表明公司已完成严格联邦安全控制下的合规测试,但尚未获得完整 FedRAMP Authorization to Operate(ATO),后者需要特定联邦机构赞助并审查。 SecurityScorecard 的 Attack Surface Intelligence 产品还单独获批进入 Department of Homeland Security(DHS)Continuous Diagnostics and Mitigation(CDM)Program Approved Products List(APL),使联邦机构可以直接使用该产品。CISA 在 2022 年把 SecurityScorecard 纳入 Free Cybersecurity Services and Tools 目录;SecurityScorecard 还参与 CISA Joint Cyber Defense Collaborative(JCDC),共享威胁情报,保护公共和私营关键基础设施。公司与 Transportation Security Administration(TSA)Surface Operations Cybersecurity Assurance Division 建有活跃合作,监控关键基础设施伙伴;白宫称其为行业风险管理机构的“game-changing”蓝图。 在数据质量和信任方面,SecurityScorecard 发布了争议解决流程,客户和非客户都可使用。存在争议的发现会被标记,直到解决;公司承诺 24 小时内响应,并在争议验证后 72 小时内完成分数调整。公司称误报率低于 1%,靠严格内部验证、资产认领 / 反驳工具,以及用于数据佐证的合作关系实现。[CE031, CE032, CE033, CE034, CE035, CE036]

信任、质量与合规控制
控制 / 认证状态范围缺口 / 注意事项
FedRAMP Ready2023 年 10 月取得;2025 年 2 月再次确认第三方网络风险管理平台,含 Attack Surface Intelligence尚未取得 FedRAMP Authorized(ATO);需要联邦机构赞助
StateRAMP Ready2025 年 2 月取得州和地方政府云采购仅为 Ready 认定;未确认州级 ATO
DHS CDM 批准产品清单已获批准(Attack Surface Intelligence)联邦机构 CDM 项目采购范围限于 ASI 模块;未确认整个平台取得 CDM 批准
CISA 免费工具目录自 2022 年起列入;JCDC 参与方面向任意组织的免费评分卡;聚焦关键基础设施免费层功能集少于付费平台
误报率公司声称:<1%覆盖 12M+ 家已评级组织的评级发现比例未经独立审计;Forrester 指出,2024 年加大投入前曾有历史误报担忧
争议处理24 小时响应;经验证争议 72 小时内调整评分面向客户和非客户开放复杂归因争议可能耗时更久;没有具约束力的外部仲裁

合规认定来自 SecurityScorecard 官方新闻稿(2023 年 10 月和 2025 年 2 月)。误报率为公司声称,来源为 MSP Today 文章。争议处理时限来自 MSP Today 对 SSC 透明度能力的报道。

[CE031, CE032, CE033, CE034, CE035, CE037]

5.6 方法局限、批评与产品风险

SecurityScorecard 评分使用专有算法,详细组件级证据和因子交互逻辑未公开发布,限制了独立审计和可复现性。被评分组织通常无法准确追踪是哪些数据点或信号组合导致某项发现,这会让希望先核验准确性再采取行动的 CISO 受挫。Forrester 2024 年 cybersecurity risk ratings Wave 指出具体平台缺口:SecurityScorecard 缺少用于评估上传证据文件(SOC 2 报告、政策 PDF)的 AI 解析工具;当同一资产同时以 IP 地址和主机名上报时,平台在防止重复发现方面也存在挑战。Bitsight 在 2024 Wave 的战略得分上超过 SecurityScorecard,尽管 SecurityScorecard 仍保住当前产品实力第一的位置。 外部视角扫描模型存在结构性局限,除非部署 agent,否则无法解决。一名经验证 AWS Marketplace 客户指出,SecurityScorecard 只监控面向公众互联网的资产,不监控内部(非互联网暴露)设备;这意味着内部网络风险——横向移动路径、不可路由主机漏洞、终端合规——落在产品覆盖模型之外。归因错误也持续存在:组织偶尔会因并不拥有的 IP 地址、domain 或资产而被评分,导致等级被不公平拉低。虽然争议机制存在,复杂争议的解决过程可能需要数周,在此期间,错误分数会影响客户、保险公司和监管机构作出的第三方决策。 与 TITAN AI 相关的 AI 能力说法——包括风险归因准确率 99.9%、入侵减少 75%、供应商参与提升 9 倍——都是公司自行声称,缺少独立验证。HyperComply 集成始于 2025 年末,平台统一仍在完成中;组合产品的生产记录有限。FedRAMP Ready(但未 Authorized)状态可能拖慢政府机构采用,直到获得完整 ATO 赞助。这些缺口合在一起,围绕评分透明度、AI 证据质量和政府市场时点,构成重大的尽调问题。[CE038, CE039, CE040, CE041, CE042]

FE004: 产品成熟度与能力评估 — 模块级分析

基于官方产品文档、Forrester 批评、客户评价和分析师评论,评估 SecurityScorecard 六个核心产品能力领域的成熟度、差异化和尽调缺口。

成熟度评估是分析师基于公开产品证据作出的判断,证据包括 SSC 新闻稿、官方产品页面、Forrester Wave 2024 报道和客户评价。尽调缺口反映已记录的批评和未解问题。

[CE038, CE039, CE040, CE041, CE042]

5.7 图表

Chapter 06

06客户

6.1 客户群分层与理想客户画像

截至 2026 年 2 月,SecurityScorecard 付费客户超过 3,300 家,较 2024 年初约 2,600 家明显增加——两年增长约 27%。平台声称的理想客户,是受监管行业的企业 CISO 或 TPRM 经理;这些人需要持续监控复杂供应商生态,又不能投入大型内部团队做人工评估。中型市场和企业账户中,买方、用户和付款方大体合一:CISO 或 VP of Security 通常推动采购,采购或风险负责人批准预算,TPRM 分析师日常使用平台。在网络保险场景下,还会出现额外付款方——Aon 等保险公司的承保人把 SecurityScorecard 分数作为 CyQu 网络风险平台的一部分,使保险买方成为间接客户群,并推动希望获得有利承保条款的被评级组织产生需求。 垂直集中度偏向金融服务(占全部 PeerSpot 研究会话的 12%),其次是科技、医疗、政府和私募股权。大型企业(超过 1,000 名员工)占评估 SecurityScorecard 的 PeerSpot 研究者的 53%,凸显平台根基在企业市场,而非 SMB 市场。2024 年末新增的 $400/month starter tier 试图提高 SMB 可及性,但 $15,000/year 的入门付费层和超过 $100,000/year 的企业套餐,使产品明确面向拥有专门安全预算的中大型组织。地域上,客户群集中在北美;通过 Macnica 分销网络,公司在日本取得有意义进展,并通过 KPMG Canada、Crowe LLP、Uniqus Consultech 和 P3 Group 等 MAX Service Delivery Partners 拓展 APAC、欧洲和中东足迹。National Defense ISAC(ND-ISAC)向其国防行业成员组织提供 SecurityScorecard 企业许可,确认其已渗透美国国家安全供应链。[CU001, CU002, CU003, CU004, CU005, CU006]

客户分层——买方 / 用户 / 付款方、垂直行业、规模和战略价值
分层主要买方 / 付款方主要用户关键用例规模指标战略价值证据质量
金融服务(银行、资产管理机构)CISO / 风险委员会TPRM 分析师供应商监控、监管合规、网络尽调PeerSpot 研究会话的 12%高——监管压力和供应链风险要求推动粘性采用中(基于评论)
网络保险(承运商、经纪商)承保负责人 / Aon CyQu风险分析师 / 精算师承保数据、保单定价、被保险风险姿态Aon 集成覆盖 120+ 个国家高——嵌入保险工作流,形成结构性需求高(Aon 新闻稿、insurance-canada.ca)
大型企业(Fortune 100/1000)CISO / CPOTPRM 经理、SOC 分析师第三方连续监控、泄露通知、M&A 尽调渗透 70% 的 Fortune 100;PeerSpot 研究者中 53% 为企业很高——平台嵌入多个安全工作流高(官方、BusinessWire)
政府 / 公共部门机构 CIO / 采购安全运营团队供应链风险、CISA 工具采用、FedRAMP 合规数百家公共部门组织;ND-ISAC 合作高——FedRAMP/StateRAMP Ready 支撑正式采购中(官方发布)
医疗健康CISO / 合规官TPRM 分析师面向 PHI 持有者的供应商风险、第三方合规Children's Hospital MN 案例研究;更广的客户组合中——监管强、采购复杂低(公开案例有限)
私募股权投资组合 CTO / GP网络安全总监(投资组合层面)M&A 网络尽调、投资组合监控、相对顾问降本Verdane 案例研究;100+ 家投资组合公司中——按交易复用的用例,且可节省成本中(官方案例研究)

分层规模指标来自已发布客户数量、PeerSpot 研究会话占比和具名案例研究。未公开按垂直行业拆分的收入区间数据。

[CU001, CU002, CU004, CU005, CU006, CU007]

6.2 采用轨迹与市场渗透

SecurityScorecard 的商业轨迹显示,公司已从利基安全评级提供商转为多产品平台,直接渠道和伙伴渠道共同复合增长。收入从 2022 年 $88.5M 增至 2024 年初 $144.3M(约同比增长 36%),客户数在 2024 年初增至 2,600,并在 2026 年 2 月突破 3,300。MAX 托管服务于 2024 年 1 月推出,成为增速最快的产品,截至 2025 年中报告同比三位数增长。SCORE Partner Program 的渠道 ARR 在 2025 年同比增长 160%,伙伴主导的 pipeline 同比增加 126%——说明间接销售如今已与直接企业销售并列,成为主要增长机制。 在付费客户之外,平台拥有 1,200 万个持续评级实体的“monitored universe”,并提供免费层(任何组织都可免费查看自己的 scorecard),形成庞大的漏斗顶部认知面。FeaturedCustomers 收录 56 条 testimonials、55 个 case studies,以及 Winter 2026 Market Leader designation;来自 3,007 个 references 的综合评分为 4.8/5——显示跨行业客户参与度广且加深。平台还在 2025 年 2 月获得 FedRAMP Ready 和 StateRAMP Ready designations,打开美国联邦和州政府采购的正式资格;该高价值细分合同周期长、留存特征强。从 2021 年到 2026 年,受监控实体数量从约 1,168 万(2021 年 10 月)增至超过 1,200 万,表明新客户进入正在推动受监控宇宙温和但稳定扩张。[CU010, CU011, CU012, CU013, CU014, CU015]

客户增长与采用轨迹——关键指标、日期、来源和含义
指标数值 / 区间参考日期来源置信度含义
付费客户数~2,6002024 年初Christian & Timbers CRO 案例研究衡量 2024–2026 年增长的基线
付费客户数3,300+2026 年 2 月BusinessWire / Aon 新闻稿约两年内客户增长 ~27%
Fortune 100 渗透率70%2026 年 2 月SecurityScorecard 官方(why 页面、BusinessWire)在 Fortune 100 顶层接近饱和
监控实体宇宙12 million+2026SecurityScorecard 官方认知触达面远超付费客户数
渠道 ARR 增长(YoY)160%2025 全年BusinessWire MAX 生态新闻稿中(公司表述)合作伙伴渠道现为主要增长引擎
合作伙伴带来的 pipeline 增长(YoY)126%2025 全年BusinessWire MAX 生态新闻稿中(公司表述)间接销售速度超过直销
收入(全年)$88.5M2022Christian & Timbers CRO 案例研究收入轨迹基线
收入(年化)$144.3M2024 年初Christian & Timbers CRO 案例研究~36% YoY 增长;此后增长率未披露
FeaturedCustomers 推荐3,007 条评分;4.8/52026 年冬季FeaturedCustomers Market Leader 认定客户群内互动深度广
NRR / GRR未披露截至 2026 年 6 月无公开来源低(缺口)重大尽调缺口;无法建模由留存驱动的增长

Christian & Timbers 的收入数字由第三方根据 CRO 招聘案例研究和公开信号重建,属于估计值。客户数量为公司表述且未经审计。NRR/GRR 完全未披露。

[CU009, CU010, CU011, CU012, CU013, CU014]
FU002: SecurityScorecard 采用漏斗 — 从监控宇宙到付费客户

展示 SecurityScorecard 从 1,200 万实体监控宇宙到付费客户群的陡峭漏斗,突出免费档转化机会,以及漏斗顶部的 Fortune 100 市场饱和度。

漏斗数值混合了公司披露数字(监控实体、付费客户、Fortune 100 %)和较早公开的免费 / 认知用户数字;70K 组织数字可能反映历史累计注册,而非活跃免费用户。MAX 客户数未披露。

[CU001, CU002, CU003, CU009, CU033]

6.3 具名客户证据与生产部署质量

SecurityScorecard 公开可见的具名客户库,覆盖五类不同客户原型的生产级部署:国际公共部门机构、全球消费品牌、欧洲私募股权、媒体代理商和网络保险集成商。United Nations International Computing Centre(UNICC)提供最高质量证据:一份四页案例研究,具名高级管理员 Alejandro Bustos,记录覆盖 80 多个 UN agencies 的部署、一个通过自动告警解决的具体 DNS 事件用例,以及网络安全运营节省 70-75% 时间的数字。The Hershey Company 案例研究中,Phil Addison(Manager of Third-Party Cyber Risk Management)确认对完整第三方版图实现 100% 网络可见性——包括未通过问卷评估的供应商——并接入事件响应、漏洞管理和 M&A 尽调工作流。两个案例都验证的是生产状态,而非试点部署。 Verdane 这家欧洲成长股权机构展示了私募股权用例:SecurityScorecard 在不部署外部顾问的情况下,为 100 多家公司提供组合范围网络尽调,使精简的内部网络安全能力得以落地。Horizon Media 获得 “A” 安全评级,并在面向客户的销售沟通中把 SecurityScorecard 用作外部信任信号——这是一个有记录的用例,平台在其中成为被评级组织的获客工具。Aon 集成则是保险行业层面的机构级证据:Aon 把 SecurityScorecard 的外部视角能力嵌入 CyQu 承保平台,使 SecurityScorecard 数据成为 Aon 客户在 120 多个国家网络保险流程中的标准输入。 这些案例的参考质量很强:全部具名,多数包含具体运营指标,且全部确认生产部署。不过,客户库覆盖的垂直相对狭窄——UN 体系以外的医疗、零售和政府机构在公开案例研究中代表性不足,给这些细分留下证据缺口。[CU016, CU017, CU018, CU019, CU020, CU021]

具名客户证明表
客户分层 / 垂直行业部署 / 用例生产环境 / 试点有记录的结果证据局限
UNICC(联合国国际计算中心)国际公共部门自我监控 + 面向 80+ 个 UN 伙伴机构的 TPRM;攻击面管理生产环境(具名管理员,视频 + PDF 案例研究)网络安全运营节省 70–75% 时间;DNS 事件通过自动告警解决公司托管的案例研究;SSC 托管削弱独立性
The Hershey Company消费品 / Fortune 500覆盖完整第三方版图的 TPRM;泄露通知集成;M&A 尽调生产环境(具名经理 Phil Addison;视频 + 网页案例研究)100% 供应商网络可见性;接入 SOC、漏洞管理、M&A 工作流公司托管的案例研究;单一具名联系人;无独立验证
Verdane(欧洲 PE 公司)私募股权(100+ 家投资组合公司)对潜在投资做网络尽调;连续监控投资组合生产环境(具名网络安全总监 Thomas Baasnes;PDF 案例研究)降低外部顾问成本;为投资组合网络 KPI 建立蓝图SSC 发布的案例研究;2024 年材料
Horizon Media媒体与广告代理自我监控;客户信任沟通;供应商风险监控生产环境(具名 CISO Richard Arenaro;8 页 PDF 案例研究)取得 “A” 评级;在业务拓展中作为面向客户的信任差异点案例研究为 2022 年材料;部署状态的新鲜度不确定
Aon(保险集成)网络保险 / 专业服务由外向内风险数据嵌入 Aon CyQu 承保平台生产合作(2026 年 2 月 4 日通过 Aon media room 公布)Aon 客户在 120+ 个国家的网络承保中,将 SecurityScorecard 数据作为基线输入合作伙伴层面的证明;没有来自 Aon 客户群的具名终端客户结果
Macnica(日本分销)渠道 / 分销(日本企业市场)自 2021 年起担任 SecurityScorecard 在日本的一线分销商;Partner of the Year Japan 2025生产环境(获奖公告;自 2021 年起分销)Macnica 提到客户续约率高;日本企业供应链中的 SSC 客户基础扩大间接证据;Macnica 自身客户身份未公开具名

表格只覆盖已验证的具名部署。SecurityScorecard 在 FeaturedCustomers(2026 年冬季)有 55 份已发布案例研究和 56 条证言,但公开聚合视图中多数未标注公司名称。更广泛的 3,300+ 客户基础无法从公开来源逐一列举。

[CU016, CU017, CU018, CU019, CU020, CU021]
FU003: 客户证明证据质量矩阵 — 评估与部署深度

从四个证据质量维度为每个具名客户证明打分,用来区分高质量生产证据和仅有 logo 或未经验证的说法;这提供了不同于 TU003 部署细节表的观察角度。

证据质量评级是基于具名联系人、案例研究深度、资料年份和独立性作出的定性评估。客户结果指标无法得到独立验证。

[CU016, CU017, CU018, CU019, CU020, CU021]

6.4 留存信号、满意度评分与工作流深度

SecurityScorecard 不公开披露净收入留存、总收入留存或 cohort 层面流失数据——这对任何经常性收入估值承销都是重大缺口。不过,来自公开评价平台的代理信号持续偏正面。Gartner Peer Insights 基于 278 条 reviews 给平台 4.4/5 分,其中 62% 为五星;Service and Support 为 4.7/5,Evaluation and Contracting 为 4.6/5——这些分数使 SecurityScorecard 位于 Gartner Third-Party Risk Management 市场 reviews 的上游梯队。SoftwareReviews 来自 18 名 verified users 的数据显示,plan-to-renew intent 为 100%,likeliness to recommend 为 92%。TrustRadius 基于七条 verified reviews 给产品 9/10。这些信号合起来表明活跃企业客户的总留存较高,尽管它们无法替代正式 NRR 披露。 工作流深度是关键留存驱动:The Hershey Company 案例研究显示,单人 TPRM 团队使用 SecurityScorecard 实现 100% 供应商版图覆盖,同时还与事件响应、SOC 分诊、漏洞管理、暴露管理和 M&A 尽调管线集成。这种多工作流嵌入形成转换成本,保护续约。UNICC 报告网络安全运营节省 70-75% 时间。PeerSpot 用户强调,持续监控、自动告警、入侵通知集成和 IP reputation scanning 是产生最高回报的功能。平台把人工问卷工作量减少 92%(公司对 TITAN AI 的说法),并接入 CrowdStrike、AWS、BlinkOps 和 90 多个生态伙伴,进一步加深客户围绕 SecurityScorecard 数据构建相邻安全运营后的工作流锁定。[CU022, CU023, CU024, CU025, CU026, CU027]

留存与满意度信号——评论平台评分和代理指标
平台评级 / 分数评论数量提到的关键优势提到的关键弱点置信度尽调要求
Gartner Peer Insights4.4/5(62% 五星;Service & Support 4.7/5)278 条评论评估与签约体验;支持响应速度大规模集成复杂度细节有限高(Gartner 是一线独立分析机构)在供应商尽调会上获取 NRR / 续约率数据
G24.3/591+ 条评价易用;暗网监测;Power BI API 集成企业收购后偶发误报中(第三方评价;Wayback 2025 年 11 月快照)确认当前评分版本和评价量
PeerSpot8.2/10多次经验证访谈持续监测;自动告警;泄露通知定价(中档 $1,000/月);初始设置复杂;误报中(独立同行访谈平台)向 CSM 索取流失率和 ARR 扩张数据
SoftwareReviews7.7/10 综合评分;92% 推荐意愿;100% 计划续约18 条评价可信;提升生产力;持续改进较小组织会觉得成本相对价值偏高中(独立 B2B 分析平台)用实际续约合同数据验证计划续约率
TrustRadius9/107 条经验证评价清晰、可执行的概览;部署简单;供应商管理容易评价数量较少,限制统计显著性中(经验证 B2B 评价平台)补充更多企业细分市场评价
FeaturedCustomers3,007 个参考评分给出的 4.8/5 综合评分56 条证言;55 个案例研究案例研究覆盖面广;2026 年冬季市场领导者认定证言由 SecurityScorecard 筛选整理低-中(公司筛选整理的客户参考库)与未审核评价平台交叉核对

所有评分反映截至 2026 年 Q1-Q2 独立或半独立平台的数据。SecurityScorecard 完全未披露 NRR 和 GRR;计划续约分数只能作为代理指标。SoftwareReviews 的 100% 计划续约率基于 18 条评价,应谨慎解读。

[CU022, CU023, CU024, CU025, CU026, CU027]
负面发现与方法论批评——来源、主张、严重性和缓释因素
问题类别发现来源和立场严重性SSC 缓释措施 / 回应
AI 能力缺口Forrester Wave 2026 年 4 月给 SSC 的 AI 能力和客户 AI 采用度打 1/5 分,低于 Black Kite(5/5)等同行Black Kite 竞争对比引用 Forrester;负面高——Forrester 属一线分析机构;1/5 直接冲撞 TITAN AI 定位SSC 于 2026 年 3 月推出 TITAN AI;Forrester 评估截止日前,平台成熟度可能尚未被纳入
评分不透明 / 黑箱Black Kite 将 SSC 算法透明度描述为“中等”,称其对数据来源和计算逻辑的可见性有限Black Kite 竞争对手页面;负面(存在竞争对手偏见)中——削弱企业对争议解决的信任;帮助竞争对手定位SSC 发布方法论深度文档,并允许评分争议在 72 小时承诺内解决
误报归因错误收购后的 IP 错配会让子公司漏洞拖低收购方评分;G2 和 AuditXYZ 均指出该问题G2 评价者;AuditXYZ 评价;负面 / 中性中——企业续约中的反复摩擦;影响 M&A 使用场景SSC 的争议门户允许组织标记并移除错误归因发现;声称 24 小时内回应
中端市场 / SMB 定价摩擦中档定价被指 $1,000/月,难以负担;2024 年末新增 $400/月入门档,但功能受限PeerSpot 评价;中性-负面低-中——限制企业级以下 TAM 扩张;不是核心客户集中度风险已推出 $400/月入门档;免费层仅供自评
服务质量回落Capterra 和 PeerSpot 评价者称,部分长期客户获得的个性化支持减少、响应更慢SoftwareReviews / Capterra 评价;中性-负面低——Capterra 客服评分 3.8/5;Gartner 支持评分 4.7/5 显示问题并非普遍Gartner Peer Insights 支持评分(4.7/5)显示企业级客户获得的服务质量更高

负面发现来自独立评价平台和一个竞争对手对比页面。竞争对手来源的主张(Black Kite)天然带有偏见;Forrester 引用由 Black Kite 使用,但 Forrester Wave 报告本身是独立一手来源。SSC 缓释措施为公司口径。

[CU036, CU037, CU038, CU039, CU040, CU041]

6.5 伙伴生态、扩张驱动与集中度风险

SecurityScorecard 的落地扩张动作,靠两套机制相互强化。第一是产品追加销售:客户从自我监控(免费层或基础付费)开始,可以逐步增加供应商监控组合、问卷自动化(TITAN Assess)、威胁情报驱动 TPRM(TITAN Secure),最终迁移到 MAX 托管服务——每次迁移都代表有意义的 ARR 增量。第二是渠道杠杆:SCORE Partner Program 和 MAX Service Delivery 框架允许 MSSP、咨询公司(KPMG Canada、Crowe LLP)和技术集成商把 SecurityScorecard 打包进托管安全产品,在不消耗 SecurityScorecard 直接销售产能的情况下,把新的企业 logo 拉入客户基数。600 多家全球伙伴和 2025 年渠道 ARR 增长 160%,确认间接销售如今是更快增长的向量。 与 Aon 的保险行业集成,是一项独特的结构性扩张驱动:使用 CyQu 的 Aon 客户会收到 SecurityScorecard 数据作为基线评估——这形成了一条间接 pipeline,让组织在成为直接客户之前就接触产品。类似地,SecurityScorecard 被列为 CISA 免费工具,会在美国政府和关键基础设施运营方中推动认知和试用,后续可能转化为付费企业订阅。Macnica 的日本分销合作展示了地域集中风险缓释:这家单一高绩效本地分销商赢得 2025 年 Partner of the Year Japan,目前掌握了一个企业采购要求复杂市场中的主要 go-to-market。 客户层面的集中度风险存在但不尖锐:没有单一具名客户主导已披露收入。渠道集中度风险更实质——如果 MAX 伙伴生态或 Aon 集成受扰,主要增长向量可能显著受损。渠道 ARR 快速加速也意味着,随着更多收入通过伙伴关系流转,直接企业留存数据会越来越难观察。[CU029, CU030, CU031, CU032, CU034, CU035]

扩张与集中度风险——驱动因素、风险、影响和尽调路径
扩张驱动因素 / 集中度风险类型机制 / 证据影响 / 严重性尽调路径
通过产品追加销售落地扩张扩张驱动因素客户从免费层或基础监测起步;再沿 TITAN Watch → Assess → Secure → MAX 升级高——每个层级都意味着有意义的 ARR 增量;形成自然追加销售漏斗索取各层级平均合同价值和追加销售转化率
MAX 服务交付合作伙伴渠道扩张驱动因素600+ 全球合作伙伴;渠道 ARR 增长 160%;管道增长 126%(2025)高——增长最快的收入向量;不用增加直销人头也能扩大触达索取渠道 ARR 占总 ARR 比例;渠道流失率
Aon CyQu 保险集成扩张驱动因素 / 集中度风险Aon 将 SSC 数据嵌入覆盖 120+ 个国家的承保平台;形成间接管道高——机构型管道;但单一合作伙伴依赖带来集中度风险了解与 Aon 的合同排他性、收入分成和续约条款
免费层获客漏斗顶端扩张驱动因素任何组织都可免费查看自己的评分;推动认知、试用和付费转化中——漏斗很宽,但付费转化率未披露索取免费转付费转化率和转化耗时数据
Macnica 日本分销商集中度风险日本市场唯一一级分销商;2025 年年度合作伙伴中——日本市场增长高度依赖一个合作伙伴关系了解日本备用分销方案和直销能力
头部客户收入集中集中度风险没有公开数据披露前 10/20 大客户收入占比未知——无法评估 Herfindahl-Hirschman 指数或头部客户流失风险在尽调会议中索取前 10 大客户收入集中度和续约条款

扩张驱动指标来自公司新闻稿,未经独立审计。集中度风险严重性为基于现有渠道结构数据的定性判断。

[CU011, CU012, CU013, CU029, CU030, CU031]
FU001: SecurityScorecard 客户旅程 — 入口与扩张路径

从初始发现到多模块扩张,映射客户旅程,说明免费档、合作伙伴渠道和保险集成如何形成多条并行获客路径,并最终汇聚到企业 ARR。

旅程阶段根据产品文档、案例研究和定价数据重构;各阶段转化率未公开披露。

[CU004, CU009, CU033, CU034, CU015]

6.6 负面证据与采用摩擦

独立评价平台和直接竞争对手暴露出四类采用摩擦,限制 SecurityScorecard 的扩张和留存潜力。第一是方法不透明:直接竞争对手 Black Kite 形容 SecurityScorecard 评分透明度“moderate”,且有“black box”元素——相较 Black Kite 与标准对齐的开放方法,对底层数据来源和计算逻辑的可见性有限。在 2026 年 4 月 Forrester Wave for Cybersecurity Risk Ratings Platforms 中,SecurityScorecard 在 AI capabilities 和 customer AI adoption 上只得 1/5,低于 Black Kite 等同行(同类得分 5/5)。考虑到 SecurityScorecard 于 2026 年 3 月推出 TITAN AI,这一 Forrester 发现尤其重要,说明评估时平台 AI 能力尚未成熟到足以获得顶级评分。 第二个摩擦点是误报归因:G2 和 AuditXYZ 评论者都提到,企业收购后,SecurityScorecard 曾错误地把漏洞归因给某组织——收购方分数可能被尚未运营整合的子公司问题拖低。解决这类争议需要被评级组织提交反证,把举证责任转移到客户身上。第三是定价摩擦:PeerSpot 评论者指出,$1,000/month 的中档定价对小型组织负担不起,即使最近推出的 $400/month starter tier 也有限制。一些南美和欧洲客户还面临额外税费和电汇附加费,实际抬高成本。第四是服务质量回落:Capterra 评论者指出,组织调整后,一些长期客户感到个性化服务减少、支持响应变慢。这些问题会在续约谈判中形成真实摩擦,尤其影响没有专属企业成功经理的客户。[CU036, CU037, CU038, CU039, CU040, CU041]

6.7 图表

Chapter 07

07风险

7.1 方法不透明、误报与外部视角上限

SecurityScorecard 的核心竞争资产——外部视角评级引擎——同时也是最大的结构性负债。平台完全依赖外部可见信号(开放端口、DNS 健康、IP 声誉、证书异常、暗网暴露),因此无法评估任何互联网不可见的补偿性控制:补偿性防火墙、网络分段、应用层防护、内部治理状态,都在模型视野之外。这会制造一类已有充分记录的误报:云服务商共享 IP 段、临时开发环境、管理正确但外部看来不常见的 TLS 设置等合法配置,会被打成漏洞,引发供应商摩擦和争议升级。 PeerSpot 和 AuditXYZ 评论(2026 年 6 月更新)中的独立用户研究显示,误报仍是从业者最常见的不满之一:「定价需要改进,尤其在巴西;考虑到 SaaS 模式,整体定价预期可以更低」与「把无关公司的漏洞关联起来会产生不准确」以及修复建议没有区分根因和噪声的抱怨并存。Netcraft 2024 年行业分析发现,33% 的公司因为团队在排查误报而延迟响应真实网络攻击,说明自动评分工具误报率过高会带来系统性成本。SecurityScorecard 的 IPv4 扫描周期为 10 天,而 UpGuard 为 24 小时;这留下时间缺口,新出现的漏洞可能在期间未被发现,也成为竞争对手在销售对话中使用的事实差异。纯「外部视角」设计还催生了不对称的争议市场:低评级公司有强烈商业动机去质疑发现;如果争议获得监管牵引或具备法律可诉性,SecurityScorecard 的核心产品变现模式将面临生存级挑战。同行评论反复指出评分透明度和分数变化解释薄弱,进一步削弱买家对方法论的信心。[CR001, CR002, CR003, CR004, CR005, CR034]

FR001: SecurityScorecard 风险热力图 — 可能性 vs. 影响

按可能性(行)和影响(列)分布已识别风险,单元格列出每个严重程度桶中的主导风险。评估基于截至 2026 年 6 月的公开证据。

可能性和影响由分析师基于公开来源估算;内部风险数据不可得。高可能性风险反映已记录事件或结构性特征,而非概率建模。

[CR001, CR002, CR006, CR007, CR030, CR036]

7.2 竞争替代与平台打包风险

SecurityScorecard 所在的第三方风险管理(TPRM)市场越来越拥挤。ServiceNow、OneTrust、Microsoft 等平台打包方,正把原生风险评级和供应商风险工作流嵌入大型企业账户已经部署的 GRC 技术栈。买家一旦标准化在这些平台上,独立点状方案的增量价值就更难证明,尤其在 SecurityScorecard 报告定价下(基础层级起价约 $15,000–$16,500/年;企业组合超过 $100,000/年)。Moody's Corporation 带来显著侵蚀风险:它曾在 2017 年作为 Series C 投资方支持 SecurityScorecard,之后却收购 BitSight,形成结构性冲突——昔日战略支持者如今出资并整合一个直接竞争对手,进入信用分析、保险承保和监管工作流,而 Moody's 品牌本身就有内嵌可信度。 PeerSpot 2026 年 6 月 IT Vendor Risk Management 对比显示,SecurityScorecard 心智份额降至 5.7%(上一年为 11.1%),BitSight 同期也降至 5.8%(上一年为 10.8%),说明两家传统龙头都在向新进入者和打包平台流失份额。UpGuard 以更快的 24 小时扫描周期和一体化 TPRM 套件定位为直接替代品,并在 G2 用户情绪中排名第一。Forrester 在 2026 年将 BitSight 认定为 Wave Leader,而 SecurityScorecard 未被列为 Forrester Leader,这制造了认知差距,企业采购团队会在竞争评估中使用该差距。ServiceNow 和 OneTrust 越来越像供应商风险数据的编排层,由它们选择哪些评级引擎作为插件嵌入,而不是把评级引擎视为战略伙伴;随着时间推移,这会压缩 SecurityScorecard 的定价权和切换成本护城河。[CR006, CR007, CR008, CR009, CR010, CR038]

合作伙伴和依赖风险登记表(按严重性排序)
依赖项交易对手角色集中度失效场景严重性缓释措施剩余风险暴露
网络保险渠道合作Aon plc将 SSC 评级集成进 CyQu 承保平台(2026 年 2 月)高——单一最大具名保险经纪合作伙伴Aon 转向 Moody's/BitSight 获取评级数据;SSC 失去保险承保转介流量在 Aon 之外分散合作伙伴;扩展直接保险公司关系若 Aon 转向,保险渠道收入面临风险;集中度风险当前存在且在扩大
云基础设施AWS / GCP(未确认)承载扫描基础设施和平台交付高——假设依赖超大规模云厂商云服务商宕机同时中断 3,300+ 客户的监测未知;未公开披露 DR 或多云架构系统性宕机风险未披露,外部无法验证
Moody's 投资者关系Moody's Corporation曾为 Series C 投资方(2017);现拥有竞争对手 BitSight中——利益冲突,不是运营依赖Moody's 将信用风险分析和保险客户导向 BitSight,削弱 SSC 在金融服务业的渗透在定价和包装上降低与信用风险分析的重叠仍在持续;Moody's 在金融服务业的公信力放大 BitSight 的竞争定位
CISA 政府认可美国 Cybersecurity and Infrastructure Security Agency免费网络工具和服务认可能带动政府部门需求中——单一政府机构,但属于建议而非合同DHS/CISA 政策变化将 SSC 移出名单或背书竞争对手保持政府互动;扩展进入欧盟监管框架存在一定政策集中度风险,但 CISA 认可目前是差异化因素

集中度评估是分析师基于公开公告做出的判断;未披露按合作伙伴拆分的内部收入。Aon 合作于 2026 年 2 月宣布;未分享规模或收入数字。AWS/GCP 依赖根据行业常态推断;未在 SSC 公开文件中确认。

[CR007, CR032, CR033]

7.3 产品执行风险与 TITAN AI 验证缺口

SecurityScorecard 在 RSA Conference 2026(2026 年 3 月 23 日)发布 TITAN AI,提出了激进的性能主张:风险归因准确率 99.9%、反驳率接近零、手工 TPRM 工作量最多降低 95%、供应商互动提升 9 倍、供应链泄露最多减少 75%。这些都是公司发布的营销主张,没有公开独立审计、同行评审方法论或长期结果研究。第三方验证缺位很关键,因为这些主张构成定价溢价和管线加速的主要依据;如果企业买家将其纳入正式评估,SecurityScorecard 可能无法在竞争性比测中证明这些数字,从而暴露商业和声誉风险。 TITAN AI 分为三层:TITAN Watch(持续可视性)、TITAN Assess(AI 驱动的问卷自动化)、TITAN Secure(威胁情报驱动的修复)。每一层都对应一种能力,而 Safe Security 的自主 TPRM 平台、UpGuard 的原生评估工作流等竞争对手也声称能提供类似能力。与 Safe Security 达成和解后的合作(2025 年 10 月宣布)降低了短期诉讼成本,但也认可了 Safe Security 是有能力的市场参与者,可能加速其增长,并在 AI 层制造更长期的竞争威胁。LIFARS DFIR 收购(2022 年 2 月)带来 50 多名员工并扩展了专业服务能力;整合风险——文化契合、服务一致性、DFIR 工具协调——仍然存在,但公司没有公开披露已经解决。考虑到私营公司的披露状态,收购整合质量仍是一个未确认的尽调项。[CR011, CR012, CR013, CR014, CR015]

7.4 法律、治理与声誉风险

公开记录中识别到 SecurityScorecard 唯一仍活跃过的诉讼,是 2024 年在美国纽约南区联邦地区法院对 Safe Security(Safe Securities, Inc.)和 Mary Polyakova 提起的商业秘密诉讼(案号 1:24-cv-04240),指控违反 DTSA、违反终端用户协议和不正当竞争。双方于 2025 年 10 月和解,并宣布建立合作研究伙伴关系,消除了即时诉讼成本,但也确立了一个法律先例:在涉及离职员工的争议中,客户名单数据和商业秘密高度敏感。截至 2026 年 6 月,通过 GDPR 执法跟踪器和行业数据库,未发现 SecurityScorecard 遭遇 GDPR 监管制裁、FTC 执法行动或 SEC 披露失败。 治理结构将战略、产品和声誉资本高度集中在 Dr. Aleksandr Yampolskiy 身上;他自 2013 年起担任 CEO 兼联合创始人。Yampolskiy 拥有 Yale 密码学博士学位,曾任 Gilt Groupe CISO,并在 Goldman Sachs 和 Oracle 担任安全领导岗位。如果他被免职、失去履职能力或离职,企业销售关系、伙伴谈判(如 Aon、CISA 认可)和产品愿景连续性很可能受损。未发现公开披露的继任计划或正式 CEO 备份治理政策。公司是私营企业,未提交 SEC 文件,也未公开董事会委员会披露,外部无法验证独立治理监督。非正式 LinkedIn 背书带来轻微声誉风险:第三方曾引用 Yampolskiy 的社交媒体互动,作为与 SecurityScorecard 存在「战略伙伴关系」的验证,但双方并无正式商业协议,形成潜在误导陈述敞口。[CR016, CR017, CR019, CR020, CR021, CR022]

监管 / 法律风险登记表
规则 / 案件司法辖区状态(2026 年 6 月)可能性严重性缓释措施剩余风险暴露尽调路径
Safe Security 商业秘密诉讼(SDNY 1:24-cv-04240)美国——SDNY2025 年 10 月已和解已发生高(历史)已和解;同意研究合作先例:商业秘密可被争议;未来员工跳槽可能重演该模式审查雇佣协议、IP 转让条款和非招揽范围
EU AI Act——风险评级系统作为高风险 AI欧盟2026 年生效(分阶段)法律合规审查正在进行(未确认);合规页面引用 DORA/NIS2 准备情况监管罚款最高 €35M 或全球营业额 7%;受监管 EU 实体可能挑战评分确认 EU AI Act 分类评估和评级引擎符合性文件
GDPR——外部观测数据的数据处理者 / 控制者义务欧盟 / EEA / 英国无处罚(据 GDPR tracker 2026 年 6 月)合规页面引用 GDPR 准备情况和 72 小时事件通知支持若扫描数据收集或泄露通知做法遭挑战,可能触发执法行动索取 DPA、数据主体权利流程和扫描数据法律依据文件
SEC 网络披露规则(Item 106 / 8-K 重大事件)美国未发现问题公司帮助客户满足披露要求;自身 SEC 义务有限(私营)若推进 IPO,将适用 10-K/8-K 网络披露标准;准备缺口未知确认内部网络治理文件是否达到上市公司标准
UK Cyber Security and Resilience Bill——第三方风险义务英国待颁布(2026)合规页面提及英国法案是 SSC 支持客户应对的框架新供应链报告要求可能带来客户需求,也可能施加义务跟踪 UK 议会进展;评估 SSC 英国实体是否面临新的报告责任

各行按严重性排序。诉讼行反映截至 2025 年 10 月公告时的和解状态;未来争议的底层先例风险仍在。将 SSC 评级引擎归类为 EU AI Act 下的高风险 AI 是尽调判断,并非已确认的监管认定。2026 年 6 月 GDPR tracker 搜索未返回 SSC 条目。缓释成熟度仅基于公开合规页面披露,未经独立验证。

[CR016, CR017, CR019, CR023]
人员和执行风险登记表(按严重性排序)
角色 / 职能依赖或缺口可能性严重性缓释措施尽调路径
Aleksandr Yampolskiy——CEO 与联合创始人愿景、企业销售关系、合作伙伴协议和品牌身份集中在单一个人身上,且未披露继任计划低(无离任信号)致命董事会强,且有投资方代表;Dan Streetman(Tanium CEO)于 2026 年 1 月加入索取董事会治理政策、继任计划,以及授予 COO/CRO/CPO 的权限范围
Sam Kassoumeh——联合创始人,产品负责人产品战略共同依赖;若离任,核心团队会失去第二位创始时期工程师留任董事会成员和产品负责人;持续参与已确认确认产品职能的合同留任条款和继任安排
TITAN AI 工程团队交付风险:公司称可减少 90-95% 手工 TPRM 工作量,但尚未验证;若 TITAN AI 交付不足,管道可能停滞RSA 2026 分阶段推出;预计与锚定客户开展试点项目索取 TITAN AI 试点案例研究、客户验收测试结果和生产环境客户参考名单
LIFARS DFIR 领导层(Ondrej Krehel)DFIR 业务整合取决于留住被收购领导层;若其离任,专业服务差异化会被掏空Krehel 被明确留任,收购后继续领导 DFIR 业务(2022)确认 Krehel 当前雇佣状态,以及 DFIR 业务是否达到收入目标

可能性截至 2026 年 6 月按公开信号评估;没有内幕信息。严重性评级反映离任或交付不足带来的业务影响。缓释成熟度仅反映公开可观察的治理和留任信号。

[CR021, CR022, CR015, CR011]

7.5 财务、估值与市场周期风险

SecurityScorecard 最后一次确认的一级融资,是 2021 年 3 月以投后 $1B 估值完成 $180M Series E。此后五年多内,没有公开后续融资轮、宣布 IPO 或披露二级交易。Premier Alternatives 二级市场数据(2026 年 6 月访问)显示隐含估值约 $359.5M,较 2021 年一级轮价格折价约 64%,说明私募市场估值明显压缩,也符合 2022–2026 年后期 SaaS 独角兽整体重估。公司在公开沟通中称 ARR 超过 $150M(见 2025 年 10 月 Safe Security 和解新闻稿),但毛利率、经营现金流、烧钱率和 ARR 增长率都未披露;任何投资者若要评估盈利路径,或判断是否有理由重新估回 $1B 独角兽水平,都会面对重大信息缺口。 收入集中风险存在于产品和渠道两个层面:公司收入过度绑定网络保险承保用例(通过 Aon、Willis 以及截至 2026 年宣布的承保方伙伴关系)和追随网络监管扩张的企业 TPRM 强制要求。Munich Re 2026 年 Cyber Insurance 报告指出,超过三分之二的大型组织在过去 12 个月内至少经历过一次第三方网络安全事件——这是顺风;但报告也指出,网络保险市场周期可能快速转向,再保险容量约束或灾难性系统事件(例如大型云服务商宕机引发大规模索赔)可能压缩承保意愿,直接减少对 SecurityScorecard 保险相关评级用例的需求。五年融资空窗提高了未来 12–24 个月内被迫退出事件(IPO、收购或 down round)的概率,而二级市场价格已经暗示部分持有人将该场景计入价格。[CR026, CR027, CR028, CR029, CR030, CR031]

缓释和否决标准表
风险可监测触发项阈值 / 事件行动含义
方法论争议升级正式评分争议提交量,以及针对评级的监管挑战任一司法辖区就评分准确性发布具有约束力的法律标准;或争议 / 客户比超过 5%投资逻辑破裂:评级变成责任场景;退出,或只围绕问卷 + AI 层重组
竞争对手降价压制BitSight、UpGuard 或平台捆绑方(ServiceNow、OneTrust)宣布定价调整,将评级免费嵌入SSC 同一季度在 2+ 个重大竞争评估中输给免费捆绑方案提高 IPO/退出时间表紧迫性;加速平台差异化,或承认评级已商品化
融资缺口 / 退出失败到 2027 年 Q4 仍无新一轮主要融资、IPO 申报或收购公告二级市场估值跌破 $250M,或宣布投资方推动的重组重大恶化信号;提高组合对冲;直接追问烧钱率和现金跑道
关键人物离任CEO、联合创始人或 CRO 公开宣布离开 SecurityScorecardYampolskiy 或 Kassoumeh 宣布离任或长期休假列入观察;评估继任者厚度;重新评估企业销售管道耐久性
网络保险市场收缩Munich Re、Swiss Re 或 Lloyd's 市场数据显示网络保费规模同比下降 >15%,或承保能力实质收紧两家或更多 Tier-1 网络保险合作伙伴降低承保决策对 SSC 评分的依赖收入模型受压信号;用例暴露多元化对维持 ARR 变得关键

阈值是投资者监测的示例触发点;并非基于管理层披露指标。所有触发项都应每季度按更新后的公开数据跟踪。行动含义面向投资者,不是给 SecurityScorecard 管理层的运营建议。

[CR030, CR031, CR033, CR037]
FR002: 风险传导图 — 结构性风险如何流向估值

有向图展示截至 2026 年 6 月,SecurityScorecard 的主要风险向量如何通过中间影响层层传导,最终落到财务和估值后果。

[CR001, CR013, CR021, CR027, CR030, CR037]

7.6 运营、依赖与保险渠道风险

SecurityScorecard 自身基础设施构成元系统性风险:平台持续监控 1200 多万家公司的外部攻击面,并为 3300 多家企业客户持有敏感第三方风险评估数据,其中包括 70% 以上的 Fortune 100;一旦 SecurityScorecard 自身系统被成功攻破,就会成为一阶供应链事件,带来灾难性的声誉和监管后果。SecurityScorecard 2025 Global Third-Party Breach Report 发现,2024 年所有泄露中 35.5% 与第三方有关,41.4% 的勒索软件攻击从第三方开始——这正是 SecurityScorecard 所定位防御的威胁向量。因此,公司本身会成为高能见度目标,外界也预期其内部安全状态达到从业者级别。 2026 年 2 月宣布的 Aon 合作,将保险渠道收入和推荐流集中到单一经纪关系中;如果 Aon 风险偏好变化、Aon 扩展自有原生风险评分能力,或 Aon 与竞争对手(BitSight/Moody's)合作,SecurityScorecard 的保险渠道收入可能大幅收缩。云基础设施集中在主要 hyperscaler(AWS/GCP)上,形成平台依赖风险——云服务商层面的故障可能同时中断整个客户群的持续监控。2026 年未发现 SecurityScorecard 有已确认的 WARN Act 申报、大规模裁员公告或公开重组行动,说明近期运营稳定;但员工数估计为 600–640 人(低于上一年估算),可能反映静默流失,而非正式重组。客户支持质量是已被指出的运营风险:PeerSpot 评论记录显示,响应时间需要改善,尤其是非企业层级客户;这会在中端市场制造流失风险。[CR018, CR024, CR032, CR035, CR036]

运营和安全风险登记表(按严重性排序)
失效模式可能性严重性缓释成熟度剩余风险暴露未解决缺口
SSC 平台自身基础设施泄露 / 供应链攻击致命未知(私营;无审计披露)灾难性:3,300+ 家企业客户和 12M+ 个被监测组织同时暴露未发现公开 SOC 2 Type II 报告或第三方红队披露
大规模误报评分引发供应商争议和流失高(有记录)部分——争议门户存在;评分争议流程已发布与被评分供应商的摩擦持续;方法论可能遭监管挑战未发布独立误报率研究;争议规模未披露
并购或共享云 IP 后资产错配低——用户称收购后不准确仍在持续错误归因资产会让评分虚高或虚低;若评分用于保险决策,可能带来监管或合同责任未公开描述针对 M&A 资产重新归因的系统性审计或对账流程
10 天 IPv4 扫描周期缺口,相比竞争对手 24 小时覆盖高(结构性)低——架构内生限制;没有公开加速路线图新暴露漏洞最多 10 天不会被发现;相对 UpGuard 处于竞争劣势需要架构调整;没有确认的产品路线图项目来补上缺口
云基础设施集中(依赖 AWS / GCP)未知——未公开披露多云或 DR 架构主云服务商同时宕机会中断所有客户监测业务连续性和灾难恢复文件未公开

可能性和严重性为分析师基于公开证据的判断;并非基于内部风险登记表。缓释成熟度只按现有公开证据做定性评级。剩余风险暴露反映缓释失效时的最坏情形。

[CR001, CR002, CR003, CR005, CR036]
FR003: 依赖图 — 关键基础设施、合作伙伴与治理依赖

有向图映射 SecurityScorecard 的关键运营和治理依赖;一旦这些依赖中断,平台交付、收入或战略定位都会受到重大损害。

[CR021, CR025, CR032]

7.7 图表

Chapter 08

08估值

8.1 融资历史与当前估值背景

SecurityScorecard 于 2021 年 3 月完成 $180M Series E 融资,投后估值约 $1B,并由此进入独角兽行列。自 2013 年以来,公司六轮股权融资合计约 $293M,背后投资方包括 Silver Lake、Sequoia Capital、GV(Google Ventures)、Evolution Equity Partners、Riverwood Capital、NGP Capital 和 Intel Capital。2021 年 3 月后,公司没有公开宣布新的一级股权融资;截至本报告日期,$1B 估值已经滞后五年。 二级市场平台提供了唯一可观察的当前定价信号。Premier Alternatives(2026 年 6 月)给出的市场隐含估值为 $359.5M,约 210M 股流通,每股价格约 $1.66,52 周跌幅为 13%。Hiive 平台同样显示 $1.66/股;Notice.co 显示 $2.20/股。这些信号合在一起,意味着二级市场企业价值为 $360–$470M,较上一轮 $1B 价格折价 53–64%。私营公司股票的二级市场价格通常较内在价值存在 20–40% 流动性折价,也可能反映股权结构复杂、多轮清算优先权造成的优先权悬压,或市场对退出时间和路径的担忧。即便如此,被压缩的二级定价仍是一个不能忽视的重大负面信号。 公司没有披露 IPO 计划、S-1 申报时间表或战略出售流程。更广泛的独角兽群体面对比 2021 年更紧的退出窗口:网络安全 IPO 市场直到 2025 年 9 月才随 Netskope 以 $707M ARR(10.3x)和 $7.3B 首秀重新打开;Google/Wiz 以 $32B、约 32–45x ARR 的收购为云原生安全给出了高水位,但这一溢价属于 ARR $1B 的差异化高速增长资产,不属于整体 ARR CAGR 20% 的 TPRM/评级提供商。 [CV001, CV002, CV003, CV004, CV005, CV006]

建议摘要
维度评估含义
建议跟踪在投入资本前,监测 NRR/利润率披露或战略退出信号
信心市场位置证据充分;没有 NRR/利润率,估值无法按所需精度确认
风险评级信息不透明、上一轮融资已过 5 年、市场拥挤、二级市场估值压缩,带来实质下行风险
估值立场公允(基准情景)/ 偏紧(官方 $1B vs. 二级市场约 $360M)$1B 对应 6.7x ARR,基本贴合行业中位数;二级市场对应 2.4x ARR —— 差距很大且尚未解释
目标持有期24–36 个月(需要退出催化剂)IPO 或战略 M&A 都要求指标披露,并且退出窗口配合

估值立场是双重的:官方 $1B 轮次价格大体匹配 10–25% 增长私有网络安全 SaaS 的 6–8x ARR 区间, 但截至 2026 年 6 月,二级市场平台给出的股价比轮次价格低 53–64%。这是一处尚未解决的分歧, 入场前必须查清。

[CV001, CV025, CV035]
FV004: 投资 KPI 评分卡

面向 IC 的七维评分(0–10),反映证据质量和投资吸引力。评分仅反映当前公开证据状态。

分数(0–10)是分析师团队基于证据质量和行业基准作出的定性评估。财务透明度得分 2/10,因为在 $150M+ ARR 规模下,公司未披露任何毛利率、NRR 或现金消耗率。估值吸引力得分 4/10,因为 $1B 融资轮价格处在可辩护的基准情景区间,但二级市场显示估值明显压缩。

[CV031, CV033, CV034, CV035]

8.2 ARR 锚点与已披露运营指标

SecurityScorecard 唯一公开披露的收入数字,是 2025 年 10 月创纪录季度新闻稿中的「$150M+ ARR」。第三方收入聚合方 Latka 估计 2024 全年 ARR 为 $144.3M,预计 2026 年 ARR 约 $153.4M。ARR 轨迹——从 2021 年 $71M 到 2022 年 $88.5M、2023 年 $106M、2025 年 10 月 $150M+——意味着四年 CAGR 约 21%。2025 年渠道 ARR 同比增长 160%(伙伴计划),但这是从较小基数扩张而来,并不必然说明公司整体 ARR 增速加快。 公司报告 2025 年 10 月季度自由现金流为正,且每名全职员工 ARR 提升 40%,说明效率有实质改善。但成熟买家需要的关键价值驱动指标——毛利率、净收入留存(NRR)、月度烧钱率、CAC 回收期和 logo 流失——完全没有披露。没有 NRR,就无法扎实承销收入质量:110%+ NRR 意味着按美元计的留存引擎,足以支撑溢价倍数;90% NRR 则意味着重大流失风险,并压缩适用倍数。可比 SaaS 网络安全龙头(Palo Alto 平台客户约 120% NRR;CrowdStrike NRR 强劲;SentinelOne FY27 Q1 非 GAAP 毛利率 77%、非 GAAP 经营利润率 4%)显示,披露透明度在这一 ARR 规模上已是基本预期。SecurityScorecard 在 $150M+ ARR 规模下仍如此不透明,本身就是投资风险。 2021 年 Series E 给 SecurityScorecard 的估值约为远期 ARR 的 14x(融资时 trailing ARR 为 $71M)。如今 $1B 名义估值相当于基于 $150M ARR 的约 6.7x,五年间隐含倍数明显压缩,即便名义价格未变。压缩部分反映 2022 年回调后 SaaS 倍数的市场重估;在 2021 年高点,高增长 SaaS 的远期收入倍数为 20–40x。投资者真正要问的是:在不透明和增速背景下,今天隐含的 6.7x ARR 是便宜、合理,还是仍然太高。 [CV009, CV010, CV011, CV012, CV013, CV014]

8.3 可比估值框架

根据 Multiples.vc 和 Windsor Drake,截至 2026 年 6 月,上市网络安全公司行业中位数为 7.8x EV/NTM 收入,分化很大:CrowdStrike 约 27x(平台龙头,$5.25B ARR,增长 24%),Palo Alto Networks 约 18x(平台 / NGS ARR $8B),Tenable 为 3.3x(漏洞管理,$1B 收入,增长较慢)。TPRM 和风险评级厂商作为一个类别,更接近 Tenable 端,因为产品范围更窄、服务成分更重;但 SecurityScorecard 的纯 SaaS 评级引擎和保险网络,可能支撑其相较点状方案厂商有适度溢价。 私营网络安全 SaaS 在所有增长区间的 ARR 中位数倍数为 15.2x(Windsor Drake),但这一数字掩盖了极端分层:ARR 增速 10–30% 的公司中位数为 6.1x ARR,30–50% 为 9.8x,50% 以上的高速增长公司为 15.2x。SecurityScorecard 自 2021 年以来整体 ARR CAGR 约 21%,落在 10–30% 增长区间,对应私募市场中位数倍数约 6x–8x ARR,或 $900M–$1.2B 企业价值。 最直接可比的私营交易,是 Veeam 以 $1.725B 收购 Securiti AI,后者 ARR 约 $150M,隐含约 11x ARR——这是一笔针对成立六年的 AI 原生数据安全平台的 11x 收入交易。ServiceNow 以约 23x ARR 收购 Armis,后者 ARR $340M、同比增长 50%——这是增长高得多的资产。BitSight 2021 年一轮 $2.4B 估值约为 12x ARR(基于 $200M+ ARR)。$32B Wiz/Google 交易按 32–45x ARR 计,是真正的离群值(云原生、$1B ARR、预计 2026 年增长 40%+),不应作为 TPRM 厂商可比分析的锚。 综合上市中位数(7.8x)、私营增长区间基准(10–30% 增长对应 6–10x)和交易可比(Securiti AI 11x、BitSight 战略轮 12x),SecurityScorecard 在 $150M ARR 下可辩护的基准估值区间为 $900M–$1.2B;若战略收购方支付溢价,可能达到 $1.5–2.0B。$1B 名义估值舒适地落在该区间内,但并不显然便宜。 [CV016, CV017, CV018, CV019, CV020, CV021]

可比估值表
可比对象类别ARR / 收入企业价值 / 倍数与 SSC 的相关性关键限制
BitSight(2021 轮)网络风险评级 / TPRM~$200M+ ARR(估计)$2.4B / ~12x ARR(Moody's 投资)最接近的直接可比对象 —— 同一类别、客户相似2021 年定价;Moody's 战略溢价抬高倍数;BitSight 为 $200M+ ARR,SSC 为 $150M
Securiti AI(Veeam 收购,2025)数据安全 / DSPM~$150M ARR$1.725B / 约 11x ARR与 SSC ARR 规模相同;AI 原生产品溢价类别不同(数据安全,不是 TPRM / 评级);与 Veeam 备份业务的战略契合也不同
Armis(ServiceNow 收购,2026)OT/IoT 安全~$340M ARR,50% 同比增长$7.75B / 约 23x ARR显示网络安全资产的平台级战略溢价上限增长和 ARR 规模高得多;OT/IoT 细分不同于 TPRM;50% 增长 vs. SSC 约 21% CAGR
Netskope(IPO,2025 年 9 月)SASE / 云安全$707M ARR,33% 同比增长$7.3B / 约 10.3x ARR证明当前公开市场仍愿意在 IPO 中接纳网络安全 SaaS类别不同(SASE vs. TPRM);ARR 大得多;上市估值低于 2021 年 $7.5B 私有估值
Google / Wiz(收购,2026)云原生应用安全(CNAPP)~$1B ARR,预计增长 40%+$32B / 约 32x ARR网络安全战略 M&A 溢价的高水位极端离群值;云原生架构、超大规模云厂商的战略必需性;不适用于 TPRM
SentinelOne(公开市场,FY27 Q1)AI 端点 / XDR$1.163B ARR,23% 同比增长~$10B 市值 / ~8–10x ARRAI 融合型网络安全 SaaS 在中双位数 ARR 增长下的公开市场参照端点 / XDR 类别竞争动态不同;SSC 规模小得多
Tenable(公开市场,LTM 2026)漏洞管理~$1B 收入$3B EV / 3.3x EV/收入显示盈利但低增长网络安全 SaaS 的底部倍数成熟、盈利、风险类别不同;SSC 未披露盈利能力指标
UpGuard(Series C,2026 年 2 月)TPRM / 供应商风险未披露$75M Series C(估值未披露)直接 TPRM 竞争对手可比;显示 VC 对该类别仍有兴趣估值未公开披露;规模小于 SSC

所有倍数都是引用来源给出的时点估计;私有公司的 ARR 数字来自第三方估计或轮次时披露指标。 战略买家倍数包含控制权和协同溢价,金融投资者不能直接套用。Wiz/Google 交易只作为上限参考。

[CV016, CV017, CV018, CV019, CV020, CV021]
FV003: 分情景估值与回报区间

在 $150–175M ARR 下,三种情景各自的企业价值低高区间,来自私募市场基准和可比交易。

区间单位为百万美元。熊市假设为 $150M ARR × 3–5x;基准假设为 $150–165M ARR × 6–8x;牛市假设为 $165–175M ARR × 10–15x。战略溢价尾部(23x)不纳入,因为它不能代表财务投资人的进入倍数。2021 年披露的 $1B 估值落在基准情景顶部。

[CV025, CV026, CV027, CV028]

8.4 牛市、基准与熊市情景

牛市情景建立在三个条件上:TITAN AI 到 2027 年推动可衡量的 ARR 年增速超过 30%;保险驱动收入流能够量化,并获得单独的战略资产溢价;财务或战略收购方(保险承保方、信用评级公司或大型 GRC/风险平台)愿意为 TPRM 加保险分析组合支付 10–15x ARR 倍数。若基于预计 $175M ARR 给 15x ARR,企业价值将达到约 $2.25B,较 2021 年 $1B 锚点回报 125%。这一情景依赖毛利率披露确认 75%+,且 NRR 为 110%+。 基准情景假设总 ARR 继续增长 15–20%,没有战略收购方支付溢价,且 2027–2028 年公开网络安全 IPO 市场中,TPRM/风险评级厂商交易区间为 6–8x ARR。若基于 $165M(2027 年中预计 ARR)给 7x ARR,企业价值约 $1.15B,大致符合上一轮 $1B 价格,并较当前二级市场水平提供温和上行。考虑到缺乏已披露指标提供的下行保护,基准情景不是强烈买入信号。 熊市情景由毛利率或 NRR 披露触发:毛利率低于 70%(与服务占比较重的 MAX 模式一致),且 NRR 低于 100%(客户流失受到 BitSight/UpGuard 竞争挤压)。在该情景下,适用倍数为 3–5x ARR,对应 $450–$750M 企业价值——低于上一轮 $1B 价格,并构成实质 down round。二级市场 $360M 隐含估值可能已经在为该情景的不对称尾部定价,清算优先权在六轮融资中累积形成的股权结构悬压可能进一步放大该尾部。 [CV025, CV026, CV027, CV028, CV029, CV030]

牛市、基准与熊市情景分析
情景关键假设在约 $150–175M ARR 下的隐含 EV情景关键风险概率信号
牛市TITAN AI 推动 ARR 同比增速升至 30%+;毛利率 ≥75%;NRR ≥115%;战略买家 (保险 / 评级巨头)支付 12–15x ARR 溢价;2027–2028 年退出$1.8B–$2.6B(基于 $150–175M ARR 的 12–15x ARR)AI 牵引未经验证;战略买家未必出现;Wiz 先例不能直接套用到 TPRM中低(20–25%)
基准ARR 同比增长 15–20%;毛利率 70–75%;NRR 100–110%;2027–2028 年以 6–8x ARR IPO 或出售给 PE 支持买家; 无战略溢价$900M–$1.4B(基于 $150–175M ARR 的 6–8x ARR)依赖尚未披露的毛利率确认;公开市场对 TPRM SaaS 的胃口不明中(45–50%)
熊市披露后发现毛利率低于 70%、NRR 低于 100%;BitSight/UpGuard 竞争压力加速客户流失;退出推迟到 2029 年之后; 可能 down round$450M–$750M(基于 $150M ARR 的 3–5x ARR)约 $360M 的二级市场价格可能已经在反映这条尾部;股权结构优先权会放大稀释中低(25–30%)

ARR 情景以 2025 年 10 月的 $150M 为锚,并推演 2027 年中达到 $165–175M。倍数来自 Windsor Drake 私有网络安全基准和可比 TPRM / 网络评级交易。概率信号是定性判断,不是模型输出。

[CV025, CV026, CV027, CV028, CV029, CV030]
FV002: ARR 倍数估值敏感性

在 $150M ARR 下,从二级市场隐含倍数(2.4x)到战略收购方溢价倍数(23x),测算隐含企业价值。可比公司锚定关键参考点。

柱形表示在精确 $150M ARR 下的隐含 EV,单位为百万美元。实际 ARR 为 $150M+(精度未披露)。战略可比倍数(11x、12x、23x)包含控制权和协同溢价;适用于财务投资人的倍数为 3–10x。23x Armis 可比仅作背景展示;SecurityScorecard 的品类和增长画像不支持这一水平。

[CV016, CV018, CV019, CV021, CV026, CV027]

8.5 投资论点、反论点与否决条件

投资论点建立在 SecurityScorecard 在结构性增长市场中的品类领导力上。TPRM 已不再可选:NIS2、DORA、SEC 网络披露规则和供应链勒索软件频率,已经把安全评级从可自由裁量工具变成董事会层面的强制要求。SecurityScorecard 评级覆盖 1200 万多家组织、渗透 70% 的 Fortune 100,并深度嵌入保险承保(Aon、Willis 等),构成新进入者难以复制的数据和关系护城河。RSA 2026 发布的 TITAN AI 以及 HyperComply 收购,补上了问卷自动化缺口,并可能扩大每个账户的总合同价值。 反论点同样有证据支撑。TPRM 领域有 200 多个竞争对手;Forrester Wave 2026 年 Q2 将 BitSight 评为 Leader,而 SecurityScorecard 未进入最高排名,说明最高价值企业交易中存在竞争侵蚀。外部视角评级方法持续受到误报批评,削弱买家信心并制造流失风险。收入不透明让外界无法验证毛利质量、NRR,也无法判断增长来自扩张(值得高倍数)还是新 logo(值得低倍数)。$1B 估值已经滞后五年,之后没有新的价格发现;二级市场已下移 50–64%,意味着投资者正在为退出不确定性定价。 论点失效条件包括:确认 NRR 低于 100%,披露毛利率低于 70%,或新一级融资低于 $900M 定价(即相对 2021 年 $1B 锚点的 down round)。任一条件出现,都会把建议从 TRACK 结构性转向 AVOID。 [CV031, CV032, CV033, CV034, CV035, CV036]

论点与反论点
轴线论据什么会改变判断
论点 1类别开创者,已评级 12M+ 组织,覆盖 70% 的 Fortune 100,并深度接入保险承保流程,数据与关系护城河更耐久用客户流失验证市场份额是否被侵蚀:Forrester Wave 未进入领导者阵营之后的流失,或 BitSight/UpGuard 的净赢单
论点 2TITAN AI 与 MAX 托管服务启动 NRR 扩张引擎,可能把增长推到 25% 以上,并支撑 8–10x ARR 倍数TITAN AI 的独立客户采用指标;托管服务毛利率验证
论点 3NIS2、DORA、SEC 网络披露等结构性监管顺风,要求企业规模化采用 TPRM,且没有替代品TPRM 要求获得监管豁免,或被整合进买方已拥有的 GRC 平台
反论点 1Forrester Wave 2026 年 Q2 未将 SecurityScorecard 列为顶级领导者;BitSight(Moody's 支持,$200M+ ARR) 处在战略溢价位置,威胁最大客户替换 SSCSecurityScorecard 在连续重大 Forrester/Gartner 评估中获得第一梯队认可
反论点 2毛利率、NRR、烧钱速度完全未披露;没有详细单位经济学,正自由现金流信号不足以支撑溢价倍数完整财务披露确认毛利率 75%+、NRR 110%+,且经营利润为正
反论点 3$1B 估值已停留 5 年;二级市场暗示 $360M–$470M 隐含 EV(折价 53–64%),说明退出风险和潜在 down round 暴露都不小新一轮一级股权融资定价不低于 $1B,或 M&A 公告确认战略溢价

论点主要来自公司发布的新闻稿(官方)和市场分析来源;反论点来自竞争情报和二级市场定价数据。 双方都缺少完整财务验证。

[CV031, CV032, CV033, CV034, CV035, CV036]
论点失效与终止触发器
触发器阈值或事件对论点的传导行动含义
NRR 低于 100%任何已披露或可信推断的净收入留存低于 100%表明客户流失压过扩张;收入质量坍塌;所有溢价倍数失效下调至 AVOID;将 EV 底部修正为 3–4x ARR($450–600M)
毛利率低于 70%任何规模下披露毛利率低于 70%MAX 托管服务交付成本超过 SaaS 常态;公司被重新定价为技术赋能服务套用服务倍数(4–7x EBITDA vs 6–10x ARR);EV 压缩 30–50%
Down round 或平轮一级股权融资 post-money 估值低于 $900M确认二级市场信号;清算优先权重置;早期投资者受损触发投资者治理复核;重新评估股权价值分配的 cap-table waterfall
BitSight 被大型保险公司或评级机构平台化收购Moody's、S&P、Verisk 或大型再保险公司收购 BitSight,或进一步将 BitSight 整合为独家网络评级标准抹去 SSC 在保险承保中的差异化;核心评级可服务市场收缩下调至 AVOID;SSC 的战略可选性被大幅折价
单一客户或合作伙伴收入集中度披露超过 20%披露或推断某客户或合作伙伴贡献 >20% ARR集中风险不符合 SaaS 溢价;客户流失风险变成灾难性任何股权购买或 LP 承诺前,要求客户集中度契约

触发器按对投资论点的重要性排序。NRR 和毛利率最可操作,因为它们是管理层可控且可披露的事实。 竞争触发器(BitSight 收购)由外部驱动,需要快速重新评估。

[CV035, CV036, CV041, CV042]
FV001: 建议逻辑流

从市场规模、运营证明、竞争风险和估值信号,推导到 TRACK 建议的链条。

[CV031, CV035, CV036]

8.6 退出准备度与最终尽调要求

截至 2026 年 6 月,SecurityScorecard 没有宣布 IPO 计划,而网络安全 IPO 门槛很高:Netskope 需要 $707M ARR、33% 增长和 118% NRR,才支撑 $7.3B 首秀。以 $150M ARR、NRR 和盈利能力未披露的状态,仅凭已披露指标,SecurityScorecard 尚未准备好进入公开市场。M&A 退出是更可能的近期流动性路径,潜在战略买家包括信用风险数据在位者(Moody's、S&P、Verisk)、大型 GRC/风险平台厂商(ServiceNow、SAP)、托管安全服务收购方,或对 TPRM 品类进行整合的私募股权基金。 最关键的尽调优先事项是 NRR、毛利率和烧钱率披露;没有这些,任何溢价倍数都站不住。次级优先事项包括股权结构透明度(优先权结构、反稀释条款、加权平均退出收益分配)以及把保险承保收入作为独立资产并量化其自身战略溢价。 最终尽调要求见表 TV006。若 NRR 和毛利披露不能给出令人满意的回应,建议仍应为 TRACK 而非 BUY;没有一手证据,投资者不应把牛市情景结果计入价格。 [CV037, CV038, CV039, CV040]

最终尽调清单
主题缺失证据重要性负责人或尽调路径
净收入留存按 cohort 和细分披露毛收入留存与净收入留存(整体、企业、保险、托管服务)NRR 是 SaaS 估值最重要的驱动项;没有 NRR,适用倍数范围会从 3x 到 15x ARR —— 太宽,无法承销管理层 data room 请求;与客户扩张交易公告交叉核对
毛利率披露混合毛利率及细分毛利率(SaaS 评级、MAX 托管服务、保险 API)如果托管服务毛利率只有 40–50%,混合毛利率可能低于 70% SaaS 门槛;这会触发 30–50% 的倍数折价管理层 data room;对标可比 MSSP 与 SaaS 混合型公司
股权结构与优先权栈完全稀释股数、期权池、优先清算瀑布、各轮反稀释条款二级市场交易的是普通股;6 轮融资累积的优先权悬挂,可能意味着在 $900M–$1.2B 出售时,普通股拿到的价值显著低于名义 EV直接向公司索取;按多个退出价格情景穿透优先权栈建模
保险收入贡献网络保险承保 API 和保费分析合作的量化收入保险承保 ARR 在出售给评级既有厂商(Moody's、Verisk)时有结构性溢价;不量化,这项战略资产就按零定价管理层披露,或审查渠道伙伴收入协议
按细分划分的 ARR 增速过去 8 个季度按产品线披露季度 ARR 增长(核心评级、MAX、HyperComply、国际)渠道 ARR 同比增长 160%,但总 ARR CAGR 约 21%;必须确认哪些细分带来持久增长,哪些增长集中在合作伙伴,才能预测 2027–2028 年收入管理层 data room;用 CrowdStrike 与 WTW marketplace 报告中引用的 SSC 渠道指标交叉验证

尽调清单按估值影响排序。没有 NRR 和毛利率,牛市论点无法验证,建议不应从 TRACK 上调至 BUY。 股权结构和保险收入量化是次级事项,但对交易结构和战略溢价建模仍然重要。

[CV037, CV038, CV039, CV040, CV043]

8.7 图表

免责声明

本报告仅供尽调和信息参考,不构成投资、法律、会计或税务建议。报告完全基于截至 2026-06-29 可获得的公开信息。SecurityScorecard 是一家私营公司;多项财务和所有权指标仍为估算值,或在公开来源之间存在争议,任何投资决策前都应独立核实。文中引用的 $1B 估值对应 2021 年 3 月 Series E 轮投后估值,未必代表当前公允市场价值。二级市场价格仅具指示意义,可能反映流动性折价、股权结构和信息不对称,而非企业基本价值。

证据索引

结论
编号陈述可信度来源
CO001 SecurityScorecard, Inc. is a privately held cybersecurity company headquartered at 1140 Avenue of the Americas, 19th Floor, New York, NY 10036, with a secondary office in Austin, Texas. SO001, SO020, SO018
CO002 The legal entity SecurityScorecard, Inc. was incorporated in Delaware (Foreign Formation Date July 1, 2013) and registered as a foreign corporation in New York on July 17, 2014, under document number 4607959 per the New York Department of State Division of Corporations. SO018, SO001
CO003 SecurityScorecard's current core business is Supply Chain Detection and Response (SCDR), which connects continuous external security ratings with threat intelligence and TPRM workflows to help organizations defend against supply chain attacks. SO001, SO024
CO004 The company's ratings engine uses externally observable signals — internet scanning, DNS health, IP reputation, network configuration, and endpoint observations — to assign A-to-F letter scores across ten risk factor groups without requiring agents, questionnaires, or active participation from rated entities. SO001, SO009
CO005 SecurityScorecard's platform covers vendor risk management (TPRM), external attack surface management, self-monitoring, board reporting, cyber insurance underwriting, M&A due diligence, threat intelligence, supply chain detection and response, and digital forensics and incident response. SO001, SO009
CO006 SecurityScorecard was founded in 2013 by Dr. Aleksandr Yampolskiy and Sam Kassoumeh; the company positions itself as the originator of the cybersecurity security ratings category. SO001, SO002
CO007 As of the March 2026 TITAN AI press release, SecurityScorecard continuously monitors and rates more than 12 million organizations globally. SO001, SO024
CO008 SecurityScorecard serves over 3,300 direct customer organizations and is trusted by 70% of the Fortune 100 as of March 2026, per its official company page and TITAN AI press release. SO001, SO024
CO009 SecurityScorecard's principal office is at 1140 Avenue of the Americas, 19th Floor, New York, NY 10036; a second office is located at 2105 E Martin Luther King Jr Blvd, Austin, TX 78702; the company also operates a globally distributed workforce. SO020, SO018
CO010 SecurityScorecard is recognized by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as a free cyber tool and service, and is listed on the CISA approved tools list. SO009, SO024
CO011 Dr. Aleksandr Yampolskiy, CEO and co-founder, holds a Ph.D. in Cryptography from Yale University (awarded 2006) and a B.A. in Mathematics and Computer Science from New York University. SO011, SO014
CO012 Prior to founding SecurityScorecard, Yampolskiy served as CISO at Gilt Groupe, CTO at Cinchcast/BlogTalkRadio (scaling to 30M+ monthly visitors), and held engineering and security leadership roles at Goldman Sachs and Oracle. SO011, SO014
CO013 Sam Kassoumeh is SecurityScorecard's co-founder and serves as Head of Product and a board member; third-party databases list his title as COO, reflecting ambiguity in public disclosures. SO001, SO019
CO014 SecurityScorecard's board of directors includes investor representatives from GV (Karim Faris), Riverwood Capital (Joe De Pinho), NGP Capital (Upal Basu), and Evolution Equity Partners (Richard Seewald). SO013, SO015
CO015 Dan Streetman, CEO of Tanium, joined SecurityScorecard's board of directors as an independent director as of January 2026, per the Christian & Timbers executive placement announcement. SO012
CO016 Nick Donofrio, IBM Fellow Emeritus, serves on SecurityScorecard's board of directors, providing enterprise technology and governance expertise. SO013
CO017 Dr. Yampolskiy was named E&Y Entrepreneur of the Year 2021 in New York and Cyber Defense Magazine's CEO of the Year 2021. SO014
CO018 A full current board roster, committee assignments, and director independence disclosures are not publicly available via official SecurityScorecard company materials as of the run date. SO013, SO019
CO019 Yampolskiy's founding motivation was the direct experience of managing vendor risk as CISO at Gilt Groupe, where vendor data sharing created security risk outside his control. SO011
CO020 Key-person risk is meaningfully concentrated in Dr. Yampolskiy, who is CEO, primary public face, and co-inventor of the core technology; no succession plan has been publicly disclosed. SO013, SO019
CO021 SecurityScorecard's earliest documented funding includes a seed round of approximately $2.2M in 2014 and a $13.7M Series A in February 2015. SO015, SO013
CO022 The company raised a Series B of approximately $20M in June 2016 and a Series C of approximately $27.5M in October 2017. SO015, SO013
CO023 SecurityScorecard raised a Series D of approximately $50M in June 2019, funding international expansion and product adjacencies. SO015, SO013
CO024 SecurityScorecard completed a $180M Series E preferred stock financing round on March 18, 2021, bringing total disclosed funding to more than $290M. SO002, SO021
CO025 New Series E investors included Silver Lake Waterman, T. Rowe Price Associates, Kayne Anderson Rudnick, and Fitch Ventures; existing investors Evolution Equity Partners, Accomplice, Riverwood Capital, Intel Capital, NGP Capital, AXA Venture Partners, GV (Google Ventures), and Boldstart also participated. SO002, SO021
CO026 The Series E valued SecurityScorecard at $1 billion (post-money), establishing the company as a unicorn as of March 2021. SO002, SO015
CO027 Total capital raised as of 2026 is approximately $293M per PitchBook and Tracxn; no additional public funding rounds have been disclosed since the March 2021 Series E. SO015, SO013
CO028 J.P. Morgan Securities LLC served as the sole placement agent for the March 2021 Series E financing round. SO002, SO021
CO029 Key current investors listed on the official company page include Sequoia Capital, Evolution Equity Partners, Silver Lake Partners, GV (Google Ventures), Riverwood Capital, NGP Capital, Intel Capital, AXA Venture Partners, Boldstart Ventures, Two Sigma Ventures, and Moody's. SO001, SO024
CO030 No IPO, secondary transaction, debt facility, credit facility, or valuation update has been publicly disclosed by SecurityScorecard since the March 2021 Series E as of the run date. SO015, SO013
CO031 SecurityScorecard disclosed that it had exceeded $150M in ARR as of October 2025, in the context of announcing the resolution of its lawsuit with Safe Security; this is the only public ARR disclosure available. SO007
CO032 SecurityScorecard closed 2023 with 2,600 paying customers and 70,000 organizations using the platform, per its February 2024 business momentum press release. SO009
CO033 By March 2026, SecurityScorecard's official company page and TITAN AI press release both confirmed over 3,300 direct customer organizations, growing from 2,600 at the close of 2023. SO001, SO024
CO034 Third-party aggregator estimates for SecurityScorecard's 2026 headcount range from approximately 615 to 639 employees; the Forbes Council profile cited "over 600 employees" as an official-adjacent figure. SO013, SO014
CO035 SecurityScorecard's MAX managed services offering was growing at triple-digit rates as of October 2025 per the SAFE-SSC joint resolution press release. SO007
CO036 The company had approximately 2 million monitored organizations at the March 2021 Series E; by 2026 this had grown to 12 million+, indicating approximately 6x growth in platform coverage over five years. SO002, SO001
CO037 In Q4 2020, SecurityScorecard's total international recurring revenue grew over 61% YoY, and international customer count grew 89% YoY, demonstrating global expansion velocity at Series E time. SO002
CO038 Exact current ARR beyond the $150M+ October 2025 disclosure, gross margin, net revenue retention, and quarterly revenue growth rates are not publicly available; these remain private company metrics. SO007, SO015
CO039 SecurityScorecard achieved FedRAMP Ready designation in 2023 and was approved for the Department of Homeland Security Continuous Diagnostics and Mitigation Program Approved Product List in the same year. SO009
CO040 SecurityScorecard acquired CVEDetails, a vulnerability database with 350,000+ monthly users, in 2023 and subsequently launched a Vulnerability Intelligence module and CVE impact scores. SO009
CO041 SecurityScorecard launched MAX managed services in 2023 and became the first security ratings platform to integrate generative AI for natural language query capabilities in the same year. SO009
CO042 SecurityScorecard acquired LIFARS, a digital forensics and incident response firm, on February 7, 2022, adding 50+ LIFARS employees and CEO Ondrej Krehel as head of a new DFIR practice within SecurityScorecard's Professional Services group. SO004, SO023
CO043 SecurityScorecard acquired HyperComply, an AI-powered security questionnaire automation and compliance management platform, in September 2025; HyperComply's CEO Amar Chahal joined SecurityScorecard as General Manager of MAX. SO010, SO023
CO044 TITAN AI, SecurityScorecard's AI-accelerated TPRM platform, was launched at RSA Conference 2026 in San Francisco on March 23, 2026, comprising three product tiers — TITAN Watch, TITAN Assess, and TITAN Secure. SO024, SO008
CO045 TITAN AI claims to reduce manual TPRM effort by up to 95%, achieve 9x higher vendor engagement, and deliver 99.9% accurate risk attribution with a near-zero refute rate per SecurityScorecard's product claims. SO024
CO046 In 2023, SecurityScorecard partnered with Microsoft (Security Copilot Partner Private Preview), achieved AWS Level 1 Managed Service Provider status as the first SaaS provider in the Business Continuity and Ransomware Readiness category, and launched the S&P Supplier Risk Index with S&P Global. SO009
CO047 SecurityScorecard was named to Fast Company's Most Innovative Companies list and Inc. Magazine's fastest-growing private companies in America in 2023, and joined the World Economic Forum Global Innovators Community. SO009
CO048 SecurityScorecard's 2025 Global Third-Party Breach Report, based on analysis of 1,000 breaches by its STRIKE Threat Intelligence Unit, found that 35.5% of all data breaches in 2024 were third-party related, a 6.5 percentage point increase from 2023. SO016, SO022, SO025
CO049 On June 4, 2024, SecurityScorecard filed a civil trade secret lawsuit (case 1:24-cv-04240, S.D.N.Y., Judge Edgardo Ramos) against Safe Security, Inc. and former employee Mary Polyakova, alleging misappropriation of confidential customer and prospect lists worth more than $40M. SO017, SO006
CO050 Safe Security's CEO Saket Modi publicly claimed during the litigation that SecurityScorecard and comparable competitors were "laying off significant portions of their teams because of the poor performance of their business," a statement SecurityScorecard disputed. SO006, SO005
CO051 The lawsuit alleged that Polyakova emailed the 'Master East List' and 'CISO Prospect Lists' to her personal email account before joining Safe Security, and that Safe Security also accessed SecurityScorecard's platform via fake accounts for competitive intelligence. SO006, SO005
CO052 SecurityScorecard and Safe Security resolved their legal dispute in October 2025, announcing a mutual research collaboration in cybersecurity risk management and ending the litigation before trial. SO007
CO053 SecurityScorecard disclosed in its lawsuit complaint that it had invested more than $200M in developing its customer and prospect base, underscoring the commercial significance of the allegedly stolen data. SO006, SO002
CO054 No WARN Act filings, independent news reports, or workforce aggregator data confirm material layoffs at SecurityScorecard for 2024-2026; the sole layoff allegation originated from Safe Security's CEO in the context of active litigation and was disputed by SecurityScorecard. SO006, SO005, SO013
CM001 SecurityScorecard competes at the intersection of cyber risk ratings, third-party risk management (TPRM) platforms, and external attack surface management (EASM). SM005, SM011
CM002 The status quo substitutes for security ratings include one-time penetration tests, Excel-based questionnaire programs, and ad hoc manual vendor assessments by internal security teams. SM010, SM005
CM003 Adjacent software budget pools for TPRM include GRC software ($23B+ in 2026), EASM ($0.9B in 2026), and cyber insurance underwriting technology (derived from ~$19.6B in global premiums). SM014, SM003, SM021
CM004 Gartner estimates global information security spending will reach $244.2 billion in 2026, representing 13.3% growth over the prior year. SM012, SM019
CM005 The TPRM/security ratings segment is a small but fast-growing fraction of the total $244B infosec market, concentrated in enterprise software subscription revenue. SM001, SM012
CM006 Cyber insurance underwriters use SecurityScorecard security ratings as underwriting inputs to price policies and set coverage terms, creating a B2B2B derived demand channel. SM007, SM009
CM007 GRC software platforms increasingly embed TPRM continuous monitoring features, blurring the boundary between GRC vendors and pure-play security ratings platforms. SM014, SM010
CM008 Grand View Research estimates the global TPRM market at $7.42B in 2023, projecting growth to $20.59B by 2030 at a 15.7% CAGR. SM001
CM009 SkyQuest estimates the global TPRM market at $11.11B in 2025, scaling to $37.44B by 2033 at a 16.4% CAGR. SM013
CM010 Business Research Insights places the 2026 TPRM market at $10.36B scaling to $45.98B by 2035 at an 18.2% CAGR—the highest growth estimate among reviewed analyst sources. SM015
CM011 Research & Markets puts the 2026 TPRM market at $8.09–$9.34B, representing the lowest point in the analyst range due to narrower scope definition. SM016
CM012 The external attack surface management (EASM) market is projected to reach $930.7 million by 2026 at a 17.5% annual growth rate. SM003, SM023
CM013 The broader attack surface management market (including internal ASM) is estimated to grow from $1.43B in 2024 to $9.19B by 2032 at a 30.4% CAGR. SM023, SM003
CM014 GRC software market is estimated at $21.04B in 2025, growing to $23.32B in 2026 and $39.01B by 2031 at a 10.84% CAGR. SM014
CM015 Applying Grand View Research's 59% software share, ~70% North America and Europe combined, and enterprise-tier filter yields a serviceable addressable market of approximately $4–7B for TPRM platforms. SM001, SM013
CM016 North America dominates the global TPRM market with 38–44% revenue share, with the U.S. expected to grow at 13.6% CAGR from 2024 to 2030. SM001, SM013
CM017 BFSI is consistently the largest industry vertical for TPRM adoption, driven by regulatory requirements and high volume of third-party relationships. SM001, SM014
CM018 The CISO is the primary economic buyer and champion for enterprise TPRM platforms, owning vendor risk strategy and board-level cyber risk reporting responsibilities. SM005, SM010
CM019 A 2026 Panorays survey of 200 CISOs found that 85% lack full supply chain visibility across their entire vendor ecosystem. SM010, SM024
CM020 Only 41% of CISOs monitor fourth-party vendors, and just 13% track nth-party vendors, indicating a large adoption gap in comprehensive supply chain risk coverage. SM010
CM021 Cyber insurance underwriters constitute a B2B2B demand channel for SecurityScorecard: insurers license security ratings data as underwriting inputs to price policies and set coverage terms. SM007, SM009
CM022 Procurement and vendor management teams are secondary buyers who embed security scoring requirements into RFPs and vendor contracts, creating additional demand from procurement-driven onboarding workflows. SM005, SM010
CM023 62% of CISOs surveyed by Panorays in 2026 reported increased regulatory pressure over the prior 12 months, and only 22% feel fully prepared to meet evolving requirements. SM010
CM024 79% of CISOs admit they have limited or no formal incident response plan for third-party breaches, indicating the market is still in an education and urgency-building phase. SM010
CM025 NIS2 covers 18 critical EU sectors, required transposition by October 2024, and in January 2026 the European Commission proposed targeted amendments to ease compliance for 28,700 companies. SM018, SM010
CM026 The EU Digital Operational Resilience Act (DORA) became effective in January 2025 and mandates continuous ICT third-party risk management for financial entities across the EU. SM018, SM010
CM027 The SEC Cybersecurity Disclosure Rule (effective December 2023) requires public companies to report material cyber incidents within four business days and disclose TPRM governance in annual 10-K filings. SM017, SM012
CM028 The combination of NIS2, DORA, and the SEC Disclosure Rule simultaneously mandates continuous vendor risk monitoring, making compliance-driven demand the strongest single accelerator for the TPRM market in 2026. SM017, SM018, SM010
CM029 Third-party involvement in data breaches doubled to approximately 30% of all breaches in 2025 according to the Verizon Data Breach Investigations Report, cited as the largest single-year jump recorded. SM020, SM007
CM030 SecurityScorecard's 2025 Global Third-Party Breach Report found that 35.5% of all breaches in 2024 were third-party related, with 41.4% of ransomware attacks originating through third-party access vectors. SM006
CM031 Black Kite's 2026 Third-Party Breach Report found that each vendor breach now cascades to an average of 5.28 downstream organizations—the highest multiplier ever recorded—and 433 million people were publicly impacted by third-party breach events in 2025. SM008, SM025
CM032 Global supply chain attack costs reached an estimated $60B in 2025 and are projected to reach $138B by 2031. SM020
CM033 SecurityScorecard's TITAN AI platform (launched March 2026) claims 95% reduction in manual TPRM effort and 75% fewer supply chain breaches for adopting organizations. SM005
CM034 SecurityScorecard's mindshare in IT Vendor Risk Management declined from 11.1% to 5.7% between 2025 and 2026 on PeerSpot, and BitSight's declined from 10.8% to 5.8%, indicating category fragmentation. SM011
CM035 66% of CISOs say GRC platforms are only 'somewhat effective' at reflecting real risk, and 71% say traditional vendor questionnaires fail to capture real risk. SM010
CM036 ISC2's 2024 Cybersecurity Workforce Study found 37% of organizations faced security budget cuts and 25% experienced cybersecurity layoffs, indicating episodic budget cyclicality as a TPRM adoption constraint. SM012
CM037 Gartner's 2026 security forecast projects cloud security growing at 28.8%—significantly faster than the TPRM segment—meaning TPRM budget must compete with higher-urgency categories for security spend. SM012, SM019
CM038 Platform consolidation by Palo Alto Networks, Microsoft, and CrowdStrike, which are adding risk management features to existing enterprise agreements, creates a medium-term displacement risk for standalone TPRM vendors. SM005, SM012
CM039 Global cyber insurance pricing fell approximately 7% in Q4 2025 and the market transitioned to a buyer-friendly phase, potentially reducing insurance-driven urgency for security improvement. SM007
CM040 Outside-in security ratings methodology is susceptible to false positives from shared hosting, CDN assets, and deprecated infrastructure, reducing CISO confidence in scores without additional context. SM011, SM010
CM041 Healthcare is projected to be the fastest-growing TPRM vertical with a 14.15% CAGR through 2031, driven by HIPAA compliance requirements and high volume of third-party medical device and billing vendors. SM014
CM042 Asia-Pacific is projected to be the fastest-growing TPRM geography at a 15.1% CAGR through 2031, while North America remains the largest market at 38–44% share. SM014, SM001
CP001 BitSight surpassed $200 million in annual recurring revenue as of 2025, making it the best-capitalized pure-play cyber risk ratings competitor to SecurityScorecard. SP001, SP002
CP002 BitSight was named a Leader in the Forrester Wave for Cybersecurity Risk Ratings Platforms Q2 2026, achieving the highest possible scores across 11 criteria — more than any other evaluated vendor. SP001, SP013
CP003 BitSight and Moody's jointly provide cyber risk signals on over 350 million organizations globally, giving BitSight a claims-coverage scale approximately 29 times larger than SecurityScorecard's 12 million actively rated organizations. SP001, SP021
CP004 Moody's invested $250 million in BitSight in 2021 as a strategic partner, integrating BitSight's cybersecurity ratings with Moody's credit-risk data and making BitSight the primary cyber risk data provider across Moody's client base. SP021, SP024
CP005 BitSight's insurance business segment grew 30% year-over-year in the first half of fiscal year 2026, extending its market leadership in the cyber insurance vertical. SP024, SP002
CP006 BitSight scores 4.6 out of 5 on Gartner Peer Insights (264 reviews) versus SecurityScorecard's 4.4 out of 5 (278 reviews), a narrow but directionally meaningful user-satisfaction gap. SP013, SP010
CP007 UpGuard raised $75 million in a Series C funding round in February 2026 led by Springcoast Partners, bringing total capital raised to over $120 million. SP003, SP028
CP008 UpGuard's platform processes over 100 billion risk signals daily and serves more than 50,000 organizations in over 90 countries as of early 2026. SP003, SP028
CP009 UpGuard has held the top position for Third-Party and Supplier Risk Management on G2 for 15 consecutive quarters as of 2026. SP003, SP011
CP010 UpGuard's Cyber Risk Posture Management platform unifies vendor risk, breach monitoring, and compliance under one AI-driven system, differentiating it from single-function outside-in ratings tools. SP028, SP011
CP011 Mastercard RiskRecon claims a 99.1% asset validation accuracy rate and the lowest false-positive rate among leading TPRM platforms, independently verified by Mastercard's internal standards. SP012, SP027
CP012 RiskRecon uses AI-assisted machine learning for deep asset discovery and integrates with Mastercard's global threat intelligence network, giving it access to transaction-level fraud signal data unavailable to pure-play ratings vendors. SP012, SP022
CP013 Mastercard RiskRecon announced partnership integrations with Cloudflare and Recorded Future in early 2026 to enhance attack surface monitoring and remediation capabilities, expanding its threat intelligence ecosystem. SP027, SP022
CP014 RiskRecon is strongest in regulated financial services verticals where Mastercard's brand trust accelerates procurement approval, and it is the preferred choice among banking and financial-sector buyers seeking outside-in ratings. SP012, SP013
CP015 Black Kite serves approximately 3,000 enterprise customers globally and raised $22 million in a Series B round in October 2021; no additional funding rounds have been publicly disclosed as of June 2026. SP025, SP026
CP016 Black Kite's Ransomware Susceptibility Index (RSI) and Open FAIR financial quantification model differentiate it from competitors by expressing cyber risk in dollar-value business impact terms rather than letter grades or raw scores. SP026, SP025
CP017 Black Kite's mid-market subscription pricing is approximately $29,000 annually for a typical deployment, making it more affordable than SecurityScorecard for price-sensitive buyers. SP026, SP008
CP018 Panorays serves over 1,000 customers globally and was named a Leader in the Forrester Wave for Cybersecurity Risk Ratings Platforms Q2 2026, citing its ambitious roadmap and strong agentic AI features. SP009, SP015
CP019 Panorays' 2026 CISO survey of 200 US-based security leaders found 85% lack full third-party threat visibility and only 41% monitor risk beyond their Tier-1 suppliers, highlighting the multi-tier monitoring gap that Panorays specifically targets. SP015, SP009
CP020 Panorays differentiates through AI-driven agentic workflows, real-time multi-tier supply chain mapping, and a unified questionnaire-plus-ratings interface, making it a strong competitor for buyers who need integrated risk management beyond outside-in scoring. SP009, SP008
CP021 Shadow AI risk — undisclosed or unmanaged AI embedded in third-party tools — is an emerging supply chain threat that only 22% of CISOs have formally vetted, representing a market pain point that both Panorays and SecurityScorecard's TITAN AI platform are beginning to address. SP015, SP009
CP022 OneTrust was named a Leader in the inaugural Gartner Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders (2026), one of five vendors in the Leaders category, primarily for AI-driven automation and always-on monitoring. SP006, SP013
CP023 ProcessUnity's CyberGRX integration with ServiceNow enables enterprise buyers to access crowd-sourced third-party risk intelligence — the world's largest risk exchange — directly within existing ServiceNow vendor workflows. SP014, SP008
CP024 ServiceNow VRM targets large enterprises with complex IT environments and a preference for unified ITSM and GRC operations; its implementation typically requires specialized consulting and is poorly suited to standalone TPRM deployments. SP008, SP020
CP025 Interos focuses on nth-tier supply chain visibility and vendor relationship mapping, competing on the supply chain intelligence use case rather than traditional outside-in security ratings methodology. SP008
CP026 OneTrust's VRM module scores 8.4 out of 10 on Gartner Peer Insights with a 78% willingness-to-recommend rate among IT VRM buyers as of 2026. SP006, SP020
CP027 GRC workflow vendors (OneTrust, Archer, ServiceNow) can subsume ratings functionality through native modules or API integrations, and the Gartner TPRM MQ 2026 naming five GRC-category Leaders with no traditional ratings vendor signals a potential long-term commoditization of standalone ratings. SP008, SP013
CP028 SecurityScorecard continuously rates over 12 million organizations worldwide, making it the broadest active-monitoring ratings platform in the sector by that metric. SP016, SP018
CP029 SecurityScorecard's TITAN AI platform claims up to a 75% reduction in supply-chain breaches and 9x higher vendor engagement compared to traditional manual TPRM approaches, automating more than 95% of assessment tasks. SP004, SP018
CP030 The September 2025 acquisition of HyperComply adds AI-powered questionnaire automation to SecurityScorecard's platform, reducing manual vendor assessment effort by 92% and accelerating questionnaire response times by over 70%. SP005, SP016
CP031 SecurityScorecard's Aon partnership (March 2026) integrates SSC's outside-in ratings with Aon's CyQu cyber insurance platform, enabling dynamic underwriting based on continuously updated ratings data. SP007, SP019
CP032 SecurityScorecard's April 2025 Willis partnership designated Willis as its official insurance broker, creating embedded distribution into one of the largest global brokerage networks and incentivizing insurance clients to adopt SSC for proactive score management. SP017, SP007
CP033 SecurityScorecard's unified stack — CVEDetails, HyperComply, MAX questionnaire platform, and TITAN AI agent layer — creates a multi-product ecosystem that increases switching costs for customers embedded across multiple product surfaces. SP016, SP018
CP034 SecurityScorecard's outside-in-only methodology is criticized for producing false positives when external asset attribution is incorrect or when compensating controls are invisible to external scanners, creating score-reduction disputes for affected vendors. SP023, SP010
CP035 Independent reviews note SecurityScorecard requires deeper remediation guidance tooling and more customizable GRC workflow integration to match best-in-class alternatives at the workflow automation layer. SP010, SP013
CP036 The cyber risk ratings and TPRM market is converging toward AI-driven automated assessments, with every major vendor investing in questionnaire automation and continuous monitoring, compressing the window of product differentiation. SP008, SP013
CP037 SecurityScorecard was not designated a Leader in the Forrester Wave Q2 2026 for Cybersecurity Risk Ratings Platforms; BitSight and Panorays received the Leader designation, a competitive positioning gap in enterprise procurement cycles. SP001, SP013
CP038 SecurityScorecard does not publicly disclose platform pricing; enterprise contracts are custom-negotiated and module-based, creating budgetary uncertainty for mid-market buyers and a recurring criticism in independent product reviews. SP010, SP011
CP039 SecurityScorecard wins most reliably in large enterprise accounts where broad supply-chain coverage, regulatory defensibility, and insurance integration are the primary buying criteria for the CISO and GRC team. SP010, SP011
CP040 SecurityScorecard loses mid-market deals primarily on price sensitivity, ease of use, and desire for bundled questionnaire-plus-ratings workflows — use cases where UpGuard and Panorays have competitive advantage. SP011, SP010
CP041 BitSight's 30% year-over-year insurance segment growth in H1 2026 is an adverse signal suggesting BitSight has gained share over SecurityScorecard and other peers in the cyber insurance vertical. SP024, SP002
CP042 All major competitors' AI automation claims — including SecurityScorecard's TITAN AI, UpGuard's CRPM, and Panorays' agentic AI — are vendor-asserted and have not been independently benchmarked as of June 2026, making differentiation on AI features difficult to validate. SP004, SP027
CP043 Incumbent GRC platform vendors (ServiceNow, Archer) and large consulting-integrated players (Aon, WTW) represent both partnership opportunities and bundling threats to SecurityScorecard, depending on whether the integration deepens SSC's channel or subsidizes a substitute product. SP007, SP014
CI001 SecurityScorecard exceeded $150M ARR as of October 2025, per a joint press release with Safe Security. SI001, SI005, SI007
CI002 Third-party revenue aggregators (Latka) estimate SecurityScorecard's 2024 ARR at approximately $144.3M. SI002, SI011
CI003 SecurityScorecard's ARR grew from $71M in 2021 to $88.5M in 2022 (~25% YoY), to $106M in 2023 (~20% YoY), and to approximately $144.3M in early 2024 (~36% YoY), based on third-party aggregator data. SI002, SI006, SI011
CI004 MAX managed services grew at 370% year-over-year as of mid-2025 and achieved triple-digit growth in Q3 2025. SI001, SI007, SI020
CI005 SecurityScorecard's channel ARR grew 160% year-over-year in 2025 driven by the MAX Service Delivery Partner Program. SI003, SI012, SI013
CI006 SecurityScorecard's partner-led pipeline grew 126% year-over-year in 2025, reflecting global demand for MAX managed services. SI003, SI012
CI007 SecurityScorecard's core revenue stream is an annual SaaS subscription for security ratings and third-party risk monitoring, representing the majority of total ARR. SI001, SI008, SI014
CI008 SecurityScorecard's MAX offering delivers managed third-party risk services through certified service partners, representing a distinct and rapidly growing revenue stream layered on top of platform subscriptions. SI001, SI003
CI009 SecurityScorecard's revenue mix includes (a) core SaaS ratings/TPRM subscriptions, (b) MAX managed services through the channel, (c) AI-powered questionnaire automation (TITAN AI, via HyperComply), and (d) insurance underwriting data and analytics; relative contributions are not publicly disclosed. SI001, SI008, SI014
CI010 The TITAN AI questionnaire automation platform reduces manual vendor assessment workload by 92% and processes questionnaires up to 18x faster than manual methods, per SecurityScorecard's official product page. SI014
CI011 SecurityScorecard powers global cyber insurance underwriting and brokering, enabling insurers and brokers to generate faster, more accurate quotes; partners include WTW and expanding insurer relationships. SI001, SI003
CI012 SecurityScorecard offers four observable pricing tiers: Free (self-assessment only), Business (~$15K–$25K/year, up to 5 monitored entities), Enterprise (custom, typically $50K–$100K+/year), and MAX (custom managed services, $100K+/year). SI016, SI017, SI019, SI004
CI013 Enterprise and MAX pricing is not publicly disclosed; all tiers above Business require contacting sales for a custom quote, making independent pricing verification difficult. SI016, SI004, SI017
CI014 Third-party procurement data (Vendr, PricingNow) shows a median SecurityScorecard contract value of approximately $23,619/year, with enterprise deployments typically at $50K–$100K+. SI004, SI019
CI015 SecurityScorecard's per-user pricing benchmark is approximately $20,000/user/year for small deployments, scaling to approximately $2M/year for 100-user enterprise deployments. SI019
CI016 SecurityScorecard's Enterprise plan includes add-on costs for Cyber Risk Quantification, Attack Surface Intelligence API, and Automatic Vendor Detection modules that are not included in the base subscription. SI016, SI004
CI017 SecurityScorecard reported positive free cash flow for the quarter ending October 2025, per its official press release. SI001, SI007
CI018 SecurityScorecard achieved a 40% improvement in ARR per full-time employee year-over-year in the period surrounding the October 2025 record quarter. SI001, SI007
CI019 Third-party headcount aggregators place SecurityScorecard in the 501–1,000 employee range as of early 2026, with LeadIQ listing '501–1,000 employees.' SI015, SI018
CI020 SecurityScorecard hired a new CFO (Chris Fritz, formerly of Tenable), a new CRO (Peter Jantzen, formerly of RSA Security), and a new CMO (Claire Trimble, formerly of Synack) in 2025, indicating continued executive investment. SI001, SI007
CI021 Gross margin for SecurityScorecard's core SaaS platform is not publicly disclosed; comparable SaaS cybersecurity rating platforms typically report gross margins in the 75–85% range. SI021
CI022 MAX managed services likely carries lower gross margins than the core SaaS subscription due to partner cost-of-service, remediation delivery, and human-in-the-loop components; estimated at 40–60% based on managed services benchmarks. SI021
CI023 SecurityScorecard raised approximately $293M in equity across seven rounds from 2013 through the March 2021 Series E at a $1B post-money valuation. SI022, SI018, SI002
CI024 No new equity funding round has been publicly announced for SecurityScorecard since the March 2021 Series E; the company has operated on the same capital stack for over five years as of June 2026. SI002, SI022, SI023
CI025 SecurityScorecard's monthly burn rate and exact cash position are not publicly disclosed; the positive free cash flow signal from October 2025 suggests the company is not burning cash at a material rate. SI001, SI021
CI026 Monthly burn rate, exact cash position, and runway cannot be reliably estimated for SecurityScorecard without direct access to balance sheet data or investor disclosures.
CI027 In June 2024, Safe Security CEO Saket Modi publicly alleged that SecurityScorecard was "laying off significant portions of their teams because of the poor performance of their business." SI009
CI028 SecurityScorecard's October 2025 record-quarter press release—reporting positive free cash flow and 40% ARR/FTE improvement—directly contradicts the Safe Security CEO's June 2024 allegation of poor business performance, though the allegation was made during active litigation and the response came after the suit's resolution. SI001, SI009
CI029 SecurityScorecard has not publicly disclosed quarterly or annual ARR growth rates, gross margin, NRR, or burn rate; the $150M+ ARR figure from October 2025 is the only publicly available revenue metric as of June 2026. SI001, SI009, SI013
CI030 A third-party statistical estimate (Latka) places SecurityScorecard's 2026 revenue at approximately $153.4M, implying roughly 6% growth from the $150M+ floor; this is a modeled estimate and should not be treated as a company-disclosed figure. SI002
CI031 From $71M ARR in 2021 to $150M+ in October 2025, SecurityScorecard grew approximately 111% cumulatively over ~4.5 years, implying a CAGR of roughly 21–27% depending on timing assumptions. SI002, SI001
CI032 SecurityScorecard served over 3,300 direct enterprise customer organizations as of February 2026, including 70% of the Fortune 100. SI003, SI013
CI033 At $150M ARR and 3,300 enterprise customers, SecurityScorecard's implied average contract value (ACV) is approximately $45,000/year—consistent with mid-market enterprise TPRM pricing benchmarks. SI001, SI003, SI019
CI034 SecurityScorecard claimed a 70% win rate in known competitive opportunities as of October 2025; no independent win-loss data is available to corroborate this figure. SI001, SI007
CI035 SecurityScorecard generates revenue from the U.S. and Canadian government sectors via FedRAMP Ready designation and DHS Continuous Diagnostics and Mitigation Approved Product List inclusion. SI008
CI036 The $150M ARR disclosure appeared in a joint press release resolving a trade secret lawsuit rather than in a standalone investor or financial communication, reducing its independent auditability and raising the question of whether the figure served dual purposes (commercial and legal signaling). SI005, SI009
CI037 SecurityScorecard's estimated ARR CAGR of ~21–27% from 2021 to 2025 is broadly consistent with high-growth SaaS companies but not exceptional relative to leading public cybersecurity peers at similar scale. SI002, SI011, SI021
CI038 SecurityScorecard reported more than 10 consecutive quarters of revenue growth through 2025, without disclosing any new equity raise since March 2021—consistent with self-sustaining operations. SI020, SI008
CI039 External-only security assessment methodology has faced industry criticism for potential false positives and incomplete coverage of internal controls, which could limit enterprise upsell penetration over time. SI017, SI009
CI040 SecurityScorecard acquired HyperComply in September 2025 to add AI-powered questionnaire automation; the acquisition price is not publicly disclosed. SI001, SI020
CI041 SecurityScorecard drove multiple six-figure competitive displacement deals in Q3 2025, including wins over BitSight and Black Kite in restaurant, logistics, and healthcare verticals. SI001, SI007
CI042 The cyber insurance underwriting revenue stream—while referenced in multiple press releases—has no publicly quantified contribution to total ARR, making it an emerging but uncharted revenue source. SI003, SI011
CI043 At $150M ARR and a 7–10x ARR multiple typical for comparable private SaaS cybersecurity companies in 2026, SecurityScorecard's implied enterprise value of ~$1.05–$1.5B roughly brackets the stale $1B Series E valuation. SI021, SI022
CI044 At ~$150M ARR and approximately 580–620 employees, SecurityScorecard's implied ARR per FTE is approximately $250,000–$260,000—broadly consistent with efficient enterprise SaaS operating benchmarks. SI015, SI001, SI002
CI045 The Safe Security trade secret lawsuit (SDNY Case 1:24-cv-04240) alleged that SecurityScorecard's customer and prospect database was worth more than $40M, reflecting the asset-intensive nature of its enterprise sales motion. SI024, SI009
CE001 SecurityScorecard's scoring methodology categorizes every discovered security issue into one of ten risk factor groups: Network Security, DNS Health, Patching Cadence, Endpoint Security, IP Reputation, Application Security, Cubit Score, Hacker Chatter, Information Leak, and Social Engineering. SE001, SE020
CE002 SecurityScorecard launched Scoring 3.0 on April 9, 2024, with a preview made available from September 13, 2023, replacing the prior model in which the overall score was a weighted average of the ten factor scores. SE002, SE018
CE003 Under Scoring 3.0, the ten factor groups retain numeric scores between 0 and 100 but no longer carry individual weights in the overall score computation; individual issue types continue to carry severity-based weights reflecting their breach correlation. SE001, SE002
CE004 Under Scoring 3.0, an organization with an F grade (score ≤60) is 13.8× more likely to sustain a breach than an A-grade (90–100) organization, compared to 7.7× under the prior scoring 2.x methodology. SE001, SE002
CE005 SecurityScorecard's scoring algorithm is recalibrated on a quarterly schedule, with factor and total scores updated daily; SecurityScorecard's data science team assessed over 15,000 historical breaches to validate the breach-correlation mapping. SE001, SE002
CE006 SecurityScorecard applies size normalization via a logarithmic scale, comparing each organization against peers of similar digital footprint size, to avoid unfairly penalizing small organizations with fewer total IPs than large enterprises. SE001, SE002
CE007 SecurityScorecard's global internet scanning framework covers more than 3.9 billion routable IPv4 addresses every 10 days across more than 1,400 ports; cloud assets are scanned multiple times daily. SE001, SE020
CE008 SecurityScorecard operates one of the world's largest malware DNS sinkholes, detecting more than 2 billion daily malware DNS requests, complemented by a three-continent honeypot sensor network and commercial threat intelligence feeds. SE020, SE019
CE009 SecurityScorecard's scoring engine rates more than 12 million organizations globally, using a modified z-score approach per issue type that normalizes findings against this reference population. SE001, SE020
CE010 TITAN AI, announced at RSA Conference 2026 on March 23, 2026, is SecurityScorecard's AI-accelerated TPRM platform comprising three product tiers: TITAN Watch (continuous visibility), TITAN Assess (intelligent automation), and TITAN Secure (threat-informed remediation). SE019, SE022
CE011 TITAN Assess automates questionnaire management end-to-end with a claimed 95% reduction in manual effort and a 9× improvement in vendor engagement rates compared to traditional processes. SE019, SE022
CE012 TITAN Watch automatically discovers third- and fourth-party vendor relationships and provides always-on continuous visibility into externally observable exposures across an organization's extended vendor ecosystem. SE019, SE020
CE013 TITAN MAX is a managed supply chain cyber risk service launched in January 2024, delivered via a certified partner franchise model, that operates a Vendor Risk Operations Center (VROC) aligned to NIST methodology. SE007, SE013
CE014 TITAN MAX became available for direct purchase in the CrowdStrike Marketplace in May 2025 and is listed in the AWS Marketplace, enabling CrowdStrike Falcon and AWS customers to add supply chain risk monitoring. SE012, SE011
CE015 TITAN MAX claims 26× faster questionnaire reviews and 2× higher issue remediation rates compared to baseline TPRM program performance, according to SecurityScorecard's official product page. SE013, SE007
CE016 SecurityScorecard acquired LIFARS, a cybersecurity services firm, in 2022 to build the technical and operational expertise underlying the MAX managed service franchise model. SE007, SE023
CE017 SecurityScorecard acquired HyperComply on September 15, 2025 to add AI-powered questionnaire automation to its platform; the HyperComply team, including co-founders Amar Chahal and Cody Wright, joined SecurityScorecard. SE006, SE017
CE018 HyperComply's RespondAI technology reduces manual questionnaire workload by 92% and accelerates questionnaire processing by 70% using AI-driven response generation backed by human verification. SE005, SE006
CE019 SecurityScorecard's scanning framework collects IP addresses, exposed port mappings, service fingerprints including version numbers, CPE IDs, CVE Version 2 IDs, and Nmap script output from all internet-facing assets in its scan scope. SE001, SE020
CE020 The attribution engine associates signals with organizations using DNS lookups and other reliable sources; organizations can actively improve attribution accuracy by claiming or refuting assets in their SecurityScorecard portal. SE001, SE010
CE021 SecurityScorecard applies machine-learning algorithms to improve the quality and accuracy of security findings, including identification of malware strains, ransomware characterization, and zero-day vulnerability detection. SE001, SE008
CE022 TITAN AI's data model ingests, normalizes, and connects risk signals across millions of organizations, merging outside-in adversary telemetry with inside-out third-party data to produce "predictive, high-fidelity signals." SE019, SE020
CE023 SecurityScorecard claims 99.9% accurate risk attribution with a near-zero refute rate for TITAN AI findings, according to the March 2026 TITAN AI press release. SE019, SE022
CE024 HyperComply's platform integration into SecurityScorecard began in late 2025 with the goal of establishing continuous, automated trust operations across the enterprise supply chain by 2026. SE006, SE017
CE025 SecurityScorecard provides a REST API at securityscorecard.readme.io with token-based authentication, supporting portfolio monitoring, scorecard grades, factor scores, issue lists, historical findings, and supply chain data. SE010, SE015
CE026 SecurityScorecard's API supports six primary use cases: enterprise cyber risk management, third-party risk management, workflow management, cyber insurance underwriting, compliance tracking, and attack surface management. SE015, SE010
CE027 SecurityScorecard's Integrate360° Marketplace hosts over 100 certified partner integrations including CrowdStrike Falcon, ServiceNow, Archer, OneTrust, and ProcessUnity. SE015, SE023
CE028 SecurityScorecard's GitHub organization (github.com/securityscorecard) hosts 63 public repositories as of June 2026, including the TypeScript design-system (13 stars, Apache-2.0), SSC-Threat-Intel-IoCs (75 stars), and aws-big-data-blog (623 stars). SE009, SE010
CE029 SecurityScorecard MAX became available for purchase in the CrowdStrike Marketplace in May 2025, listed alongside the CrowdStrike Falcon AI-native cybersecurity platform to enable unified supply chain risk monitoring. SE012, SE013
CE030 SecurityScorecard's developer hub provides API code samples in Shell, Ruby, Python, PHP, and other languages, and offers a "Try it" function that lets developers validate API calls directly in the documentation. SE010, SE015
CE031 SecurityScorecard achieved FedRAMP Ready designation in October 2023 for its Third-Party Cyber Risk Management Platform including Attack Surface Intelligence, joining fewer than 450 cloud-based products with FedRAMP designation. SE003, SE004
CE032 SecurityScorecard reaffirmed FedRAMP Ready status and additionally achieved StateRAMP Ready designation on February 10, 2025, enabling state and local government agency procurement. SE016, SE004
CE033 SecurityScorecard's Attack Surface Intelligence product is approved on the DHS Continuous Diagnostics and Mitigation (CDM) Program Approved Products List (APL), enabling federal agencies to procure it for critical threat monitoring. SE003, SE004
CE034 CISA incorporated SecurityScorecard into its catalog of Free Cybersecurity Services and Tools in 2022, and SecurityScorecard participates in the CISA Joint Cyber Defense Collaborative (JCDC). SE003, SE016
CE035 SecurityScorecard partners with the TSA Surface Operations Cybersecurity Assurance Division to provide cyber vulnerability monitoring and security ratings for critical infrastructure partners, a model the White House described as "game-changing." SE003, SE004
CE036 SecurityScorecard claims a false positive rate below 1% for its ratings findings, achieved through rigorous internal validation, asset claiming/refutation tools, and data partnership corroboration. SE014, SE008
CE037 SecurityScorecard's dispute resolution process provides a response within 24 hours and finalizes score adjustments within 72 hours for validated disputes, and the process is accessible to non-customers as well as customers. SE014, SE003
CE038 Forrester's 2024 cybersecurity risk ratings Wave criticized SecurityScorecard for lacking AI-parsing tools to assess uploaded evidence documents (e.g., SOC 2 reports, policy PDFs) and for challenges preventing duplicate findings when the same asset is reported via both an IP address and a hostname. SE008
CE039 SecurityScorecard's outside-in methodology does not cover internal (non-internet-facing) devices or applications, a structural limitation confirmed by a verified AWS Marketplace customer review. SE011, SE008
CE040 SecurityScorecard's scoring algorithm is proprietary and not publicly audited; organizations subjected to its ratings cannot independently trace exactly which signals or algorithm logic caused a specific finding or score. SE008, SE014
CE041 Bitsight surpassed SecurityScorecard on Forrester's strategy dimension in the 2024 Wave evaluation, while SecurityScorecard retained the top position for current offering strength in the same assessment. SE008
CE042 TITAN AI's performance claims — including 99.9% attribution accuracy, 75% fewer supply-chain breaches, and 95% manual-effort reduction — are company-asserted at launch (March 2026) without independent third-party validation. SE019, SE022
CU001 SecurityScorecard is trusted by over 3,300 organizations globally as of February 2026. SU001, SU007, SU009
CU002 SecurityScorecard is used by 70% of the Fortune 100 as of February 2026. SU001, SU007
CU003 The SecurityScorecard platform continuously monitors over 12 million entities worldwide. SU001, SU007
CU004 Primary buyers are enterprise CISOs, TPRM managers, procurement, and risk leaders; primary payers also include cyber insurance underwriters who receive SecurityScorecard data as part of Aon's CyQu platform. SU001, SU008, SU012
CU005 SecurityScorecard's customer base spans financial services, insurance, healthcare, government, private equity, and technology verticals. SU012, SU013, SU018
CU006 Large enterprises with more than 1,000 employees constitute 53% of PeerSpot researchers evaluating SecurityScorecard. SU012
CU007 Financial services firms account for 12% of all PeerSpot research sessions for SecurityScorecard, the largest single vertical represented. SU012
CU008 The National Defense ISAC (ND-ISAC) offers SecurityScorecard enterprise licenses to its defense-sector member organizations as a free 60-day enterprise benefit. SU020
CU009 SecurityScorecard grew its paying customer base from approximately 2,600 in early 2024 to over 3,300 by February 2026, approximately 27% growth in two years. SU007, SU022
CU010 SecurityScorecard revenue grew from $88.5M in 2022 to $144.3M in early 2024, approximately 36% YoY, with the customer base expanding to 2,600 by early 2024. SU022
CU011 Channel ARR across the SCORE Partner Program grew 160% year-over-year in 2025, driven by MAX-powered managed service adoption. SU007, SU021
CU012 Partner-led pipeline increased 126% year-over-year in 2025, reflecting strong enterprise demand delivered through SecurityScorecard's global partner network. SU007
CU013 SecurityScorecard added 35 new MAX Service Delivery Partners in 2025, bringing the total global partner count to over 600, including KPMG Canada, Crowe LLP, Uniqus Consultech, and P3 Group. SU007, SU021
CU014 FeaturedCustomers published 56 testimonials and 55 case studies for SecurityScorecard as of Winter 2026, with a composite 4.8/5 rating across 3,007 reference ratings, earning a Market Leader designation. SU023
CU015 SecurityScorecard achieved FedRAMP Ready and StateRAMP Ready designations in February 2025, formally enabling U.S. federal and state government procurement for its Supply Chain Detection and Response (SCDR) product. SU019, SU024
CU016 UNICC deploys SecurityScorecard in production for self-monitoring and TPRM across 80+ UN partner agencies, achieving 70–75% time savings in cybersecurity operations. SU002, SU003
CU017 The Hershey Company uses SecurityScorecard in production to gain cyber insights on 100% of third parties in its risk management process, including integration into SOC breach notification, vulnerability management, and M&A due diligence workflows. SU004
CU018 Verdane, a European private equity firm managing 100+ portfolio companies, uses SecurityScorecard for cyber due diligence on prospective investments and continuous portfolio monitoring, reducing reliance on external consultants. SU005
CU019 Horizon Media achieved an "A" SecurityScorecard rating and uses the platform daily for self-monitoring and as a client trust differentiator in business development conversations. SU006
CU020 Aon integrated SecurityScorecard's outside-in risk capabilities into its CyQu cyber underwriting platform, announced February 4, 2026, giving Aon clients in 120+ countries continuous external risk assessment as part of the insurance underwriting process. SU008, SU009, SU025
CU021 Macnica, SecurityScorecard's primary Japanese first-tier distributor since 2021, received the Partner of the Year Japan award for 2025, citing high customer renewal rates as a key performance factor. SU017
CU022 Gartner Peer Insights rates SecurityScorecard 4.4 out of 5 from 278 reviews, with 62% five-star ratings, Service and Support at 4.7/5, and Evaluation and Contracting at 4.6/5 as of 2026. SU010, SU011
CU023 G2 rates SecurityScorecard 4.3 out of 5 from over 91 reviews as of 2025–2026. SU011
CU024 PeerSpot users give SecurityScorecard an average rating of 8.2 out of 10 across multiple verified interview-based reviews. SU012
CU025 SoftwareReviews scores SecurityScorecard Security Ratings 7.7 out of 10, with 92% likeliness to recommend and 100% plan-to-renew intent from 18 verified reviews. SU013
CU026 TrustRadius rates SecurityScorecard 9 out of 10 from seven verified reviews, with users emphasizing ease of setup and vendor portfolio management. SU014
CU027 SecurityScorecard does not publicly disclose net revenue retention, gross revenue retention, or cohort-level churn data as of June 2026.
CU028 The Hershey Company's TPRM function is operated by a single person using SecurityScorecard, demonstrating the platform's operational leverage for under-resourced security teams. SU004
CU029 SecurityScorecard delivered 160% year-over-year ARR growth across its channel program in 2025 through the SCORE Partner Program. SU007, SU021
CU030 New MAX Service Delivery partners in 2025 include KPMG Canada, Crowe LLP, Uniqus Consultech, and P3 Group, expanding managed TPRM coverage across APAC, North America, Europe, and the Middle East. SU007
CU031 SecurityScorecard's technology ecosystem partners added in 2025 include CrowdStrike Marketplace, BlinkOps, AWS, and WTW (Willis Towers Watson), extending distribution and intelligence-sharing. SU007
CU032 SecurityScorecard established its Japanese subsidiary, SecurityScorecard Co., Ltd., in Tokyo in June 2021 to serve the Japanese enterprise supply chain security market through reseller and alliance partners. SU018, SU026
CU033 SecurityScorecard offers a permanent free tier that delivers four features at no cost: a domain scorecard, questionnaire response, pre-built dashboards, and basic report creation — functioning as a top-of-funnel acquisition channel. SU001
CU034 SecurityScorecard is listed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as a free cybersecurity tool and service available to critical infrastructure organizations. SU007, SU019
CU035 Former Maryland Governor Larry Hogan joined SecurityScorecard's advisory board in February 2026, reinforcing the company's public-sector go-to-market positioning. SU024
CU036 Black Kite, a direct competitor, characterizes SecurityScorecard's scoring methodology as having "moderate" data transparency with "black box" elements and limited visibility into underlying data sources and calculation logic. SU016
CU037 In the April 2026 Forrester Wave for Cybersecurity Risk Ratings Platforms, SecurityScorecard scored 1 out of 5 on AI capabilities and customer AI adoption, below peers such as Black Kite which scored 5 out of 5. SU016
CU038 AuditXYZ (2026) notes that SecurityScorecard's external-only assessment cannot capture the full picture of an organization's security posture, and false positives create friction with vendors who dispute their scores. SU015
CU039 G2 reviewers cite instances where SecurityScorecard incorrectly attributes vulnerabilities after a corporate acquisition, causing an acquirer's score to drop due to unintegrated subsidiary infrastructure. SU011, SU012
CU040 PeerSpot reviewers note that the $1,000/month mid-tier pricing exceeds the budget of smaller organizations; a $400/month starter tier was added to address this, but it has feature limitations. SU012, SU015
CU041 SoftwareReviews data reflects some customer service quality concerns, with Capterra users reporting reduced personalized support and slower responsiveness following organizational changes — though Gartner Peer Insights Service and Support score of 4.7/5 suggests enterprise-tier customers experience higher service quality. SU013, SU010
CR001 SecurityScorecard's ratings engine is exclusively outside-in, relying on externally observable signals such as open ports, DNS health, certificate anomalies, and IP reputation; internal compensating controls, network segmentation, and application-layer security postures that are not internet-visible are structurally excluded from the score. SR010, SR011
CR002 Multiple PeerSpot user reviews updated through June 2026 document false positives as a top practitioner complaint, citing instances where acquired-company vulnerabilities were misattributed to the scored organization's score, creating wrong risk data. SR003, SR021
CR003 Vendors frequently dispute SecurityScorecard scores citing misattributed assets, cloud-provider shared IP configurations, and ephemeral misconfigurations not under the vendor's direct control. SR010, SR003
CR004 SelectHub's 2026 review of SecurityScorecard identifies score accuracy as a con, noting that false positives can lead to inaccurate risk assessments and user frustration. SR021, SR003
CR005 SecurityScorecard performs a full non-intrusive scan of the IPv4 address space in a 10-day cycle, compared to UpGuard's 24-hour scan cycle, a factual competitive gap that competitors use in sales conversations. SR011, SR010
CR006 BitSight, backed by Moody's following its acquisition, was positioned as a Visionary in the Gartner 2026 Magic Quadrant and maintains a higher mindshare (5.8%) than SecurityScorecard (5.7%) as of June 2026 per PeerSpot IVRM category data. SR018, SR019
CR007 Moody's Corporation was a Series C investor in SecurityScorecard (October 2017) and subsequently acquired BitSight, creating a former-backer-turned-competitor dynamic that gives Moody's financial-services credibility to a direct rival. SR008, SR019
CR008 ServiceNow, OneTrust, and Microsoft are embedding native third-party risk and vendor risk workflow capabilities into GRC suites already deployed at enterprise accounts, reducing the marginal value of standalone point solutions like SecurityScorecard for buyers who are already on those platforms. SR019, SR018
CR009 UpGuard positions itself as an all-in-one TPRM alternative to SecurityScorecard with a faster 24-hour scan cycle and is rated No. 1 in G2 user sentiment in the IT Vendor Risk Management category as of 2026. SR011, SR018
CR010 SecurityScorecard's enterprise pricing reportedly starts at approximately $15,000–$16,500 per year for basic monitoring tiers, with large portfolio deployments exceeding $100,000 per year, which AuditXYZ identifies as a pricing concern for mid-market buyers. SR010, SR021
CR011 SecurityScorecard launched TITAN AI at RSA Conference 2026 on March 23, 2026, claiming 99.9% accurate risk attribution with a near-zero refute rate, up to 95% reduction in manual TPRM effort, 9x higher vendor engagement, and up to 75% fewer supply-chain breaches. SR002, SR005
CR012 TITAN AI is organized into three tiers — TITAN Watch (continuous visibility), TITAN Assess (AI-driven questionnaire automation reducing manual work by over 90%), and TITAN Secure (threat-informed remediation workflows) — according to SecurityScorecard's official March 2026 product launch announcement. SR002, SR016
CR013 The TITAN AI performance claims of 99.9% accuracy, 75% breach reduction, and 95% manual-effort reduction are company-issued marketing figures with no published independent third-party audit, peer-reviewed methodology, or longitudinal outcome study available as of June 2026.
CR014 TITAN AI was introduced alongside a Supply Chain Resilience Journey maturity model mapping four stages from Basic Diligence to Threat-Informed TPRM, positioning SecurityScorecard as meeting customers at their current program maturity level. SR002, SR005
CR015 SecurityScorecard acquired LIFARS (digital forensics and incident response) in February 2022, adding more than 50 employees with LIFARS CEO Ondrej Krehel leading the new DFIR practice; integration risks include cultural alignment, service consistency, technology harmonization, and customer retention. SR006
CR016 SecurityScorecard filed suit in 2024 against Safe Securities, Inc. and Mary Polyakova in the U.S. District Court for the Southern District of New York (Case No. 1:24-cv-04240), alleging trade secret misappropriation under the Defend Trade Secrets Act, breach of end-user agreements, and unfair competition. SR001, SR005
CR017 SecurityScorecard and Safe Security publicly announced settlement of their legal dispute in October 2025 and agreed to a collaborative research partnership, resolving the litigation without a judgment. SR001, SR005
CR018 PeerSpot reviews updated through June 2026 document that SecurityScorecard's technical support response times need improvement, particularly for non-enterprise tier customers, creating churn risk in the mid-market segment. SR003, SR021
CR019 No GDPR regulatory sanctions, FTC enforcement actions, SEC disclosure penalties, or other regulatory actions against SecurityScorecard itself appear in public enforcement databases, regulatory filings, or industry reports as of June 2026. SR022, SR025
CR020 A third-party account (The Rob Rockefeller S.C.) publicly described CEO Yampolskiy's LinkedIn repost of a Davos 2026 update as validation of a "strategic partnership," illustrating reputational risk from informal social media engagement being mischaracterized as formal commercial relationships. SR013, SR017
CR021 Dr. Aleksandr Yampolskiy has served as CEO and Co-Founder of SecurityScorecard since its founding in 2013, and is the primary public face, product vision driver, and enterprise relationship holder; he holds a PhD in Cryptography from Yale University. SR013, SR017
CR022 Yampolskiy's prior executive experience includes CISO at Gilt Groupe (managing security across 200–2,500 employees), CTO at BlogTalkRadio, and security leadership roles at Goldman Sachs and Oracle. SR013, SR017
CR023 SecurityScorecard is a private company with no SEC filings, no publicly disclosed financial statements, no board committee disclosures, and no publicly available governance policy documentation, making independent governance assessment impossible from external sources. SR020, SR008
CR024 SecurityScorecard does not appear in 2026 WARN Act filing trackers or major layoff announcement databases, including Intellizence's 2025-26 Layoff Dataset, indicating no publicly disclosed mass layoff or restructuring event as of June 2026. SR023
CR025 SecurityScorecard's board of directors includes investor representatives from Evolution Equity Partners, Silver Lake Partners, Sequoia Capital, Google Ventures, and Riverwood Capital, and added Tanium CEO Dan Streetman as an independent director in January 2026. SR020, SR017
CR026 SecurityScorecard's most recent primary fundraising was a $180M Series E in March 2021 that set a $1B post-money valuation; total disclosed funding across seven rounds is approximately $292M. SR008, SR017
CR027 Secondary-market data from Premier Alternatives (accessed June 2026) implies a SecurityScorecard valuation of approximately $359.5M — a decline of roughly 64% from the $1B primary-round valuation — with the share price showing a 52-week decline of approximately 13%. SR009, SR024
CR028 SecurityScorecard has raised approximately $292M total across seven funding rounds (seed through Series E) from investors including T. Rowe Price, Kayne Anderson Rudnick, Evolution Equity Partners, Sequoia Capital, Google Ventures, Riverwood Capital, and Moody's. SR008
CR029 SecurityScorecard exceeded $150M ARR as stated in the October 2025 Safe Security settlement press release, which cited this figure in SecurityScorecard's company boilerplate; no gross margin, growth rate, or profitability data accompanies this disclosure. SR001, SR002
CR030 More than five years have elapsed since SecurityScorecard's last primary fundraising round (March 2021), increasing the probability of a forced exit event — IPO, acquisition, or bridge financing — within the next 12-24 months, a scenario that secondary-market pricing already implies. SR008, SR009
CR031 Munich Re's 2026 Cyber Insurance report finds that more than two-thirds of large organisations experienced at least one third-party cybersecurity incident in the past 12 months, validating SecurityScorecard's market tailwind but also confirming that supply-chain attacks are the primary systemic risk driver for the cyber-insurance market that SSC's insurance-linked revenue depends on. SR007
CR032 Aon announced a collaboration with SecurityScorecard in February 2026 to integrate SecurityScorecard's external risk assessment data into Aon's CyQu underwriting platform, creating a single named insurance broker as a concentrated channel dependency. SR004, SR012
CR033 SecurityScorecard's revenue is materially tied to cyber insurance underwriting and enterprise TPRM mandates; a contraction in cyber insurance market capacity or underwriting appetite — as could occur following catastrophic systemic events — would directly reduce demand for its ratings use cases. SR007, SR004
CR034 SecurityScorecard's outside-in-only model structurally excludes internal compensating controls from scoring; this is an architectural ceiling that cannot be resolved by AI or product enhancements without changing the data-collection model itself. SR010, SR011
CR035 SecurityScorecard's 2025 Global Third-Party Breach Report analyzed 1,000 breaches and found 35.5% were third-party related and 41.4% of ransomware attacks start through third parties, placing SecurityScorecard itself as a high-value target for nation-state or criminal actors seeking access to its entire customer base. SR015, SR007
CR036 SecurityScorecard monitors over 12 million companies globally and serves 3,300+ enterprise customers including 70%+ of the Fortune 100; if SecurityScorecard's own infrastructure were breached, the incident would constitute a first-order supply-chain event with systemic implications. SR015, SR002
CR037 Scored vendors with low SecurityScorecard grades have strong commercial incentives to dispute findings to protect their insurance premiums, customer relationships, and regulatory standing, creating an adversarial dynamic that could escalate into legal challenges if a binding legal accuracy standard is imposed. SR010, SR003
CR038 SecurityScorecard's mindshare in the IT Vendor Risk Management category declined from 11.1% to 5.7% year-over-year as of June 2026 per PeerSpot data, suggesting market fragmentation and share erosion beyond just the BitSight rivalry. SR018, SR019
CR039 G2 (91 verified reviews, 4.3/5.0 overall rating), TrustRadius, and SoftwareFinder (11 reviews, 4.5/5.0) collectively corroborate recurring user friction around English-only reporting, limited dark-web coverage, pricing-per-organization tokenization, and the inability to dispute false positives without a formal remediation request — all operationally consistent with the methodology opacity and outside-in limitation risks documented across this chapter. SR026, SR027, SR028
CR040 No SecurityScorecard C-suite departure or publicly announced executive leadership change was identified in available 2026 sources; Aleksandr Yampolskiy retained his CEO role and represented the company publicly at RSA Conference 2026, reinforcing key-person concentration without evidence of succession-depth expansion into a co-CEO, president, or named heir-apparent structure. SR002, SR013, SR017
CR041 SecurityScorecard's own research library and threat-intelligence outputs depend on continuous ingestion of data from the same 12M+ organization monitoring footprint that clients rely upon; a compromise of SSC's data collection or scoring infrastructure could propagate corrupted risk assessments across the entire client base simultaneously, creating a systemic single-point-of-failure analogous to the SolarWinds supply-chain attack vector for cyber-risk intelligence rather than software updates. SR015, SR029
CV001 SecurityScorecard raised $180M in its Series E funding round in March 2021, achieving a post-money valuation of approximately $1B. SV001, SV016
CV002 SecurityScorecard has raised approximately $293M in total equity across six rounds since 2013, backed by Silver Lake, Sequoia Capital, GV, Evolution Equity Partners, Riverwood Capital, NGP Capital, and Intel Capital. SV001, SV010, SV016
CV003 No new primary equity funding round has been publicly announced for SecurityScorecard since the March 2021 Series E, making the $1B valuation anchor five years stale as of June 2026. SV010, SV016
CV004 Premier Alternatives (June 2026) reports SecurityScorecard's market-implied enterprise value at $359.5M, with approximately 210M shares outstanding and a per-share price of $1.66, representing a 13% 52-week decline. SV002, SV017
CV005 Secondary market platforms Hiive and Notice.co show SecurityScorecard per-share prices of $1.66 and $2.20, respectively, as of June 2026, implying an enterprise value range of approximately $350–$470M. SV017, SV018
CV006 The secondary market implied enterprise value of $360–$470M represents a 53–64% discount to the March 2021 $1B round price, constituting an adverse pricing signal for investors. SV002, SV017, SV018
CV007 The March 2021 Series E valued SecurityScorecard at approximately 14x forward ARR (against $71M trailing ARR at time of round), a level consistent with peak 2021 SaaS multiples of 20–40x forward revenue. SV001, SV010
CV008 The $1B stated SecurityScorecard valuation at $150M ARR implies approximately 6.7x ARR, representing significant multiple compression from the 14x ARR multiple implied at the time of the 2021 round. SV001, SV010, SV011
CV009 SecurityScorecard exceeded $150M ARR as of October 2025, per its official record-quarter press release; Latka estimates $144.3M for full-year 2024 and approximately $153.4M for 2026. SV011, SV010
CV010 SecurityScorecard's ARR trajectory from $71M (2021) to $88.5M (2022), $106M (2023), and $150M+ (October 2025) implies an approximately 21% four-year CAGR, placing it in the 10–30% growth band for private SaaS valuation benchmarking. SV010, SV011
CV011 SecurityScorecard's channel ARR grew 160% year-over-year in 2025 driven by the SCORE Partner Program expansion and MAX Service Delivery Partner adoption, though this channel growth rate exceeds overall company ARR growth rate. SV012
CV012 SecurityScorecard reported positive free cash flow and a 40% improvement in ARR per FTE for the quarter ending October 2025, but gross margin, NRR, burn rate, and CAC payback remain entirely undisclosed. SV011
CV013 Without disclosed NRR, gross margin, and burn rate, the applicable ARR multiple range for SecurityScorecard spans 3–15x — too wide to support a specific price commitment. SV019, SV022
CV014 At $150M ARR and approximately 600 employees, SecurityScorecard's implied ARR per FTE of approximately $250K is consistent with high-efficiency SaaS companies, but the 40% YoY improvement in this ratio is presented without a base-year anchor. SV011, SV015
CV015 SentinelOne's Q1 FY27 results show 77% non-GAAP gross margin and 4% non-GAAP operating margin at $1.163B ARR growing 23%, establishing a public-market benchmark for AI-integrated cybersecurity SaaS at higher ARR scale. SV021
CV016 The public cybersecurity sector median EV/NTM revenue multiple is 7.8x as of June 2026, with CrowdStrike at ~27x (platform leader), Palo Alto at ~18x, and Tenable at 3.3x (vulnerability management, slower growth). SV003, SV004, SV005, SV027
CV017 BitSight's 2021 Moody's investment valued it at $2.4B, implying approximately 12x ARR on an estimated $200M+ ARR, providing the most direct comparable for SecurityScorecard as a pure-play cyber risk ratings leader. SV006, SV026
CV018 Veeam's $1.725B acquisition of Securiti AI in Q4 2025 implied approximately 11x ARR on $150M ARR, making it the closest directly comparable transaction to SecurityScorecard by ARR scale and deal type. SV003, SV027
CV019 ServiceNow paid approximately 23x ARR for Armis in 2026 at $340M ARR growing 50% year-over-year, reflecting a strategic premium for an OT/IoT security platform with high growth and platform-synergy fit. SV027
CV020 Netskope's September 2025 IPO priced at $7.3B on $707M ARR (10.3x ARR), but debuted below its 2021 $7.5B private-round valuation, demonstrating that even high-growth cyber SaaS can face flat-to-negative multiple realization versus peak private marks. SV009, SV030
CV021 Google's $32B acquisition of Wiz at ~32x ARR (on ~$1B ARR, 40%+ projected 2026 growth) is the cybersecurity M&A high-water mark for cloud-native security and is not transferable to a TPRM/risk-ratings valuation context. SV007, SV008, SV020
CV022 Windsor Drake's private cybersecurity SaaS benchmarks place companies at 10–30% ARR growth at a 6.1x median ARR multiple, and those at 30–50% ARR growth at a 9.8x median, making SecurityScorecard's overall CAGR of ~21% most consistent with the 6–8x range. SV003, SV022
CV023 Private SaaS businesses typically transact at a 30–50% discount to comparable public market multiples due to liquidity, scale, concentration, and the absence of audited financials (Windsor Drake, Acquiry). SV019, SV022
CV024 UpGuard's February 2026 Series C raised $75M at an undisclosed valuation, confirming continued investor appetite for TPRM/cyber-risk management platforms but providing no direct multiple anchor for SecurityScorecard. SV013
CV025 The bull-case scenario for SecurityScorecard (12–15x ARR on $165–175M projected ARR) implies an enterprise value of $1.8B–$2.6B, requiring TITAN AI ARR acceleration to 30%+ YoY, confirmed high gross margins, and a strategic acquirer premium. SV003, SV019, SV027
CV026 The base-case scenario for SecurityScorecard (6–8x ARR on $150–165M ARR) implies an enterprise value of $900M–$1.32B, broadly consistent with the $1B stated round price and the private cybersecurity benchmark for 10–25% ARR growth companies. SV003, SV022, SV019
CV027 The bear-case scenario for SecurityScorecard (3–5x ARR on $150M ARR) implies an enterprise value of $450–$750M, triggered by disclosure of sub-70% gross margin and sub-100% NRR, which would reclassify the company as a tech-enabled services provider. SV019, SV022, SV003
CV028 The secondary market implied enterprise value of ~$360M may be pricing in a combination of liquidity discount, cap-table preference overhang from six rounds, and a tail probability of the bear-case scenario with sub-4x ARR. SV002, SV017, SV022
CV029 Windsor Drake notes that Series B/C companies that raised at inflated 2021 valuations are facing flat or down rounds unless they have grown into their valuation, with structured rounds maintaining face-value while providing investor downside protection. SV003
CV030 SecurityScorecard's overall ARR CAGR of approximately 21% since 2021 is insufficient to have grown into a 14x ARR multiple from the 2021 round; the company would need to trade at 6–8x ARR today to maintain consistent multiple-to-growth alignment. SV001, SV010, SV003
CV031 SecurityScorecard's investment thesis rests on category-pioneer status, 12M+ rated organizations, 70% Fortune 100 penetration, and deep insurance-underwriting integrations that constitute a data and relationship moat difficult for new entrants to replicate. SV011, SV012, SV015
CV032 Structural regulatory tailwinds — NIS2, DORA, the SEC cyber-disclosure rule — convert TPRM from a discretionary tool to a board-level compliance mandate, expanding SecurityScorecard's addressable market independent of technology cycle. SV027, SV003
CV033 The Forrester Wave for Cybersecurity Risk Ratings Platforms Q2 2026 ranked BitSight as a Leader with the highest strategy and current offering scores; SecurityScorecard did not receive a top-Leader designation, indicating competitive differentiation risk at the highest-value enterprise accounts. SV016, SV015
CV034 The outside-in ratings methodology faces persistent industry criticism for false positives and incomplete asset discovery, creating churn risk particularly in verticals with complex network architectures where external scanning cannot capture full exposure. SV015, SV016
CV035 The combination of a five-year stale primary valuation ($1B March 2021), secondary market compression to $360M–$470M, undisclosed NRR and gross margin, and Forrester non-Leader positioning constitutes a materially adverse valuation signal warranting a TRACK rather than BUY recommendation. SV002, SV003, SV017
CV036 Moody's strategic investment in BitSight at $2.4B in 2021 established a precedent for credit-ratings incumbents paying strategic premiums for cyber-risk ratings platforms; however, this premium benefited BitSight's investors, not SecurityScorecard's, and no equivalent strategic acquisition has been announced for SecurityScorecard. SV006, SV026
CV037 SecurityScorecard has not announced IPO plans, S-1 filing timelines, or confirmed M&A processes as of June 2026, leaving the exit path unclear and the investment hold period indeterminate. SV025, SV016
CV038 An IPO at SecurityScorecard's current disclosed metrics ($150M+ ARR, positive FCF, no NRR or gross margin) would not meet the transparency bar set by Netskope's 2025 IPO ($707M ARR, disclosed 33% growth, 118% NRR, full S-1 financial disclosure). SV009, SV030, SV011
CV039 The most plausible M&A acquirers for SecurityScorecard include credit-risk data incumbents (Moody's, S&P, Verisk), large GRC/risk platform vendors (ServiceNow, SAP), or private equity consolidators of the TPRM category. SV006, SV014, SV023
CV040 Without NRR and gross margin disclosure, the applicable ARR multiple range for SecurityScorecard spans 3x (bear, managed-services reclassification) to 15x (bull, strategic acquirer with insurance-premium analytics), making precise entry pricing impossible to defend. SV019, SV003
CV041 A disclosed NRR below 100% would constitute a thesis-break trigger, compressing SecurityScorecard's applicable ARR multiple to the 3–4x range and implying enterprise value of $450–$600M — below the $1B 2021 round price. SV019, SV022
CV042 A Moody's, S&P, or Verisk acquisition of BitSight as an exclusive embedded cyber-ratings standard would materially reduce SecurityScorecard's insurance-underwriting differentiation and addressable market, threatening the strategic-premium premium thesis. SV006, SV026
CV043 The upgrade from TRACK to BUY requires three simultaneous conditions: NRR confirmed at 110%+, gross margin confirmed at 70%+, and either an IPO filing or a credible strategic M&A process at base-case-or-higher valuation. SV003, SV019, SV022
来源
编号出版方标题引文
SO001 SecurityScorecard Company — SecurityScorecard SecurityScorecard is the global leader in supply chain detection and response and the only service with millions of organizations continuously rated. Trusted by 3,300+ organizations including 70% of the Fortune 100.
SO002 SecurityScorecard SecurityScorecard Raises $180 Million in Series E Financing Round to Make Security Ratings Mainstream SecurityScorecard has completed a $180 million Series E preferred stock financing round. This round brings SecurityScorecard's total funding to more than $290 million.
SO003 SecurityScorecard Leadership — SecurityScorecard
SO004 SecurityScorecard SecurityScorecard Acquires LIFARS; Empowers Organizations with a Complete View of Cyber Risk SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response.
SO005 The Cyber Express SecurityScorecard Files Suit Against Safe Security SafeSecurity CEO Saket Modi, refuting the allegations, said that his company's competitors like SecurityScorecard were laying off many of its employees because of its poor business and this is resorting to legal retribution.
SO006 BankInfoSecurity / Information Security Media Group SecurityScorecard Accuses Vendor of Stealing Trade Secrets Safe Security CEO Saket Modi said: "Most of our competitors, including Security Scorecard, are laying off significant portions of their teams because of the poor performance of their business."
SO007 Safe Security SAFE and SecurityScorecard Resolve Legal Dispute and Announce Research Collaboration SecurityScorecard has exceeded $150M ARR, with MAX offering growing at unprecedented triple-digit rates.
SO008 SiliconAngle SecurityScorecard debuts TITAN AI to reduce supply chain breaches and streamline vendor risk workflows
SO009 SecurityScorecard SecurityScorecard Continues Leadership of the Security Ratings Market — New Solutions Drive Massive Growth Leading Into 2024 SecurityScorecard closed the year with 2,600 customers — representing 70% of the Fortune 1000 — and 70,000 organizations using the platform.
SO010 BusinessWire / SecurityScorecard SecurityScorecard Acquires HyperComply to Bring AI-Powered Automation to Supply Chain Risk Management
SO011 NGP Capital A rare glimpse into the mind of cryptographer and CEO of SecurityScorecard, Aleksandr Yampolskiy Aleksandr started SecurityScorecard in the beginning of 2014 with the idea that it must be possible to reduce the security posture of a company to a grade.
SO012 Christian & Timbers Dan Streetman Joins SecurityScorecard Board of Directors
SO013 Tracxn SecurityScorecard — 2026 Company Profile & Team
SO014 Forbes Technology Council Aleksandr Yampolskiy — Co-Founder and Chief Executive Officer, SecurityScorecard SecurityScorecard is now one of the world's most trusted cybersecurity brands, with tens of thousands of customers — including half of the Fortune 100 and nine of the top 10 U.S. banks — and over 600 employees.
SO015 PitchBook SecurityScorecard Company Profile 2024 — Valuation, Funding & Investors
SO016 Dark Reading SecurityScorecard Report Reveals Surge in Vendor-Driven Attacks
SO017 UniCourt SecurityScorecard, Inc. v. Safe Securities, Inc. et al — Case 1:24-cv-04240 (S.D.N.Y.) On 06/04/2024 SecurityScorecard, Inc. filed a Civil lawsuit against Safe Securities, Inc. and Mary Polyakova in U.S. District Court, New York Southern District. Case status: Open (as of last update).
SO018 BizProfile / New York Department of State Securityscorecard, Inc. — New York State Filing Information Securityscorecard, Inc. officially filed on July 17, 2014; Document Number 4607959; Foreign Formation Date 07/01/2013; Jurisdiction: Delaware; Status: Active.
SO019 Craft.co SecurityScorecard CEO and Key Executive Team
SO020 SecurityScorecard Contact Us — SecurityScorecard SecurityScorecard Headquarters: 1140 Avenue of the Americas, 19th Floor, New York, NY, 10036. SecurityScorecard Austin, Texas: 2105 E Martin Luther King Jr Blvd, Austin, TX, 78702.
SO021 AXA Venture Partners SecurityScorecard Raises $180M — AVP Portfolio Announcement
SO022 Infosecurity Magazine SecurityScorecard Observes Surge in Third-Party Breaches
SO023 Mergr SecurityScorecard Acquires LIFARS — M&A Transaction Record
SO024 SecurityScorecard SecurityScorecard Unveils TITAN AI — A New Era of Threat-Informed Third-Party Risk Management Trusted by over 3,300 organizations, including 70% of the Fortune 100, and recognized as a trusted resource by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
SO025 The HIPAA Journal More Than One-Third of Data Breaches Due to Third-Party Supplier Compromises
SM001 Grand View Research Third-party Risk Management Market Size Report, 2024-2030 The global third-party risk management market size was estimated at USD 7.42 billion in 2023 and is projected to reach USD 20.59 billion by 2030, growing at a CAGR of 15.7% from 2024 to 2030.
SM002 Polaris Market Research Third-Party Risk Management Market Trend & Global Analysis 2034
SM003 IONIX EASM Market Trends 2026: IONIX External Exposure Management The External Attack Surface Management market is projected to reach $930.7 million by 2026, growing at 17.5% annually.
SM004 Beinsure Media 2026 Outlook for Global Cyber Insurance Segment Global cyber insurance premiums rose 7% in 2025 to $15.3 bn, with projections showing average annual growth above 10% through 2030.
SM005 SecurityScorecard RSAC 2026 Recap: What Did RSAC 2026 Reveal About the Future of TPRM? SecurityScorecard's TITAN AI Sets the Pace
SM006 SecurityScorecard SecurityScorecard 2025 Global Third-Party Breach Report Reveals Surge in Vendor-Driven Attacks 35.5% of all breaches in 2024 were third-party related.
SM007 CRC Group 2026 Cyber + Technology State of the Market at a Glance Third-party involvement in breaches has doubled, increasing from approximately 15% in earlier periods to roughly 30% more recently.
SM008 Black Kite 2026 Third-Party Breach Report | Black Kite Supply Chain Risk Data For every single vendor breached, an average of 5.28 downstream companies were publicly compromised—the highest level observed to date.
SM009 Gallagher (AJG) 2026 Cyber Insurance Market Outlook Most forecasts for future growth agree that the 2025 market size of $16 to $20 billion could reasonably scale to $30 to $50 billion by 2030.
SM010 Panorays 200 CISOs Reveal the Truth About Third-Party Cyber Risk 85% of CISOs surveyed admitted they do not have full visibility across their entire supply chain.
SM011 PeerSpot Bitsight vs SecurityScorecard (2026) — IT Vendor Risk Management Comparison The mindshare of SecurityScorecard is 5.7%, down from 11.1% compared to the previous year.
SM012 Software Strategies Blog Top 6 cybersecurity trends from Gartner's 2026 Security Forecast Gartner's 4Q25 forecast shows the three major security segments all growing at double-digit constant currency rates in 2026.
SM013 SkyQuest Technology Third-Party Risk Management Market Growth Opportunities and Industry Analysis Global Third-Party Risk Management Market size was valued at USD 9.54 Billion in 2024 and is poised to grow from USD 11.11 Billion in 2025 to USD 37.44 Billion by 2033.
SM014 Mordor Intelligence GRC Software Market Size, Share & 2031 Growth Trends Report The GRC Software market size was valued at USD 21.04 billion in 2025 and estimated to grow from USD 23.32 billion in 2026 to reach USD 39.01 billion by 2031, at a CAGR of 10.84%.
SM015 Business Research Insights Third-Party Risk Management Market | Hit to $45.98 Bn (2026–2035) Starting at USD 10.36 Billion in 2026, the global Third-Party Risk Management Market is set to witness notable growth.
SM016 Research and Markets Third-party Risk Management Market Report 2026
SM017 U.S. Securities and Exchange Commission Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure — Small Entity Compliance Guide Item 1.05 requires disclosure of the following information regarding a material cybersecurity incident... The filing must be made within four business days of the registrant determining that a cybersecurity incident is material.
SM018 European Commission — Digital Strategy NIS2 Directive: securing network and information systems The directive mandates that each Member State adopt a national cybersecurity strategy, which includes policies for supply chain security, vulnerability management, and cybersecurity education and awareness.
SM019 BitSight (citing Gartner research) Gartner Predicts 2026: Prioritizing Cyber Resilience By 2028, 50% of CISOs will be asked to own disaster recovery, in addition to incident response, reflecting a broader organizational focus on cyber resilience.
SM020 AppSec Santa Supply Chain Attack Statistics 2026: 65+ Key Facts & Data
SM021 Gallagher Re (via Gallagher PDF) Gallagher Re Cyber Industry Database — Global Market Estimates 2016–2026
SM022 SecurityScorecard 2026 Supply Chain Cybersecurity Trends Report
SM023 IONIX (citing Fortune Business Insights) EASM Market — Broader ASM Market Size: $1.43B (2024) to $9.19B (2032)
SM024 Panorays (citing Verizon DBIR 2025) 200 CISOs Reveal the Truth About Third-Party Cyber Risk — Verizon DBIR reference
SM025 Black Kite (citing global vendor ecosystem) 2026 Third-Party Breach Report — Elite 50 vendor analysis
SP001 BitSight Bitsight Named a Leader in Cybersecurity Risk Ratings, Praised By Customers for the Utility of its Data Bitsight achieved the highest possible scores across 11 criteria, more than any other vendor evaluated in the Forrester Wave.
SP002 PRNewswire (BitSight) Bitsight Surpasses $200 Million in ARR, Accelerating Leadership in Cyber Risk Intelligence Bitsight surpasses $200 million in ARR, accelerating leadership in cyber risk intelligence.
SP003 UpGuard UpGuard Raises $75M in Series C Funding to Accelerate Market Leadership in Cyber Risk Posture Management UpGuard raises $75M in Series C funding, bringing total raised to over $120 million.
SP004 Security Boulevard SecurityScorecard Debuts TITAN AI to Automate Third-Party Risk Management Workflows SecurityScorecard's TITAN AI automates 95%+ of manual TPRM tasks.
SP005 Help Net Security SecurityScorecard acquires HyperComply to automate vendor security reviews SecurityScorecard acquires HyperComply, which reduces manual questionnaire effort by up to 92%.
SP006 OneTrust OneTrust Recognized in Gartner's First TPRM Report — Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders 2026 OneTrust named a Leader in the inaugural Gartner Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders 2026.
SP007 Insurance-Canada.ca Aon Advances Cyber Risk Capabilities With SecurityScorecard Aon partners with SecurityScorecard to integrate SSC outside-in ratings with the CyQu cyber insurance platform.
SP008 Security Boulevard 5 Enterprise Vendor Risk Management Solutions: 2026 TPRM Platforms Comparison
SP009 Panorays Supply Chain Risk Management: A Strategic Guide for Modern Resilience
SP010 AuditXYZ SecurityScorecard Review 2026: Pricing, Features, and Verdict SecurityScorecard needs deeper remediation guidance and more customizable reporting to match best-in-class alternatives.
SP011 ShieldRisk.ai UpGuard vs SecurityScorecard: Which Rating Wins in 2026?
SP012 RiskRecon (Mastercard) Manage Cyber Security Risks | Risk Management — RiskRecon by Mastercard
SP013 Gartner Peer Insights Bitsight vs SecurityScorecard 2026 | Gartner Peer Insights BitSight 4.6/5 (264 reviews) vs SecurityScorecard 4.4/5 (278 reviews) on Gartner Peer Insights for TPRM.
SP014 ProcessUnity CyberGRX Integrates with ServiceNow to Streamline Third-Party Cyber Risk Programs
SP015 Cyber Insurance News Third Party Blind Spots: 85% Of CISOs Lack Visibility — Panorays 2026 CISO Survey 85% of security leaders lack visibility into third-party threats; only 41% monitor beyond Tier-1 suppliers.
SP016 SecurityScorecard Support SecurityScorecard 2026 Feature Releases
SP017 SecurityScorecard SecurityScorecard Announces Strategic Partnership with Willis Willis designated SecurityScorecard's official insurance broker in strategic partnership.
SP018 SecurityScorecard Supply Chain Cybersecurity Platform — SecurityScorecard TITAN AI
SP019 SecurityScorecard Cyber Insurance Risk Assessment | SecurityScorecard
SP020 Gartner Peer Insights Best IT Vendor Risk Management Solutions Reviews 2026
SP021 BitSight Bitsight vs. SecurityScorecard: Feature Comparison, Reviews and Analyst Rankings BitSight's statistical correlation with real-world breaches is supported by independent studies, while SecurityScorecard focuses on compliance and reporting.
SP022 Mastercard Cybersecurity Risks and Third-Party Risk Management | Mastercard
SP023 FortifyData How Does SecurityScorecard Work? A Detailed Breakdown SecurityScorecard's reliance on external data cannot provide a full picture of actual risk; false positives occur when external asset attribution is incorrect.
SP024 Cyber Insurance News Cyber Insurance Technology and Services Growing Faster than Premiums — BitSight Results Raise Question BitSight's insurance business grew by 30% in the first half of fiscal year 2026.
SP025 PRNewswire (Black Kite) Black Kite's 2026 Wholesale and Retail Report Reveals Over 70% of Major Retailers Have Exposed Credentials
SP026 Black Kite Third-Party Risk Management (TPRM) Solutions | Black Kite
SP027 RiskRecon Blog (Mastercard) Gartner Predicts 2026 — Third-Party Cybersecurity Risk Management Evolves for the AI Era
SP028 UpGuard The Number 1 Cyber Risk Posture Management Platform | UpGuard
SI001 SecurityScorecard SecurityScorecard Achieves Record Quarter, Extending Market Leadership Through AI Innovation SecurityScorecard delivers strong growth balanced with profitability, including positive free cash flow and 40% improvement in ARR per FTE.
SI002 Latka Database SecurityScorecard Revenue 2024: $144.3M Est. ARR
SI003 SecurityScorecard SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide SecurityScorecard delivered 160% year-over-year ARR growth across its channel program in 2025, driven by continued expansion of the SCORE Partner Program.
SI004 Vendr SecurityScorecard Software Pricing & Plans 2026: See Your Cost
SI005 Safe Security SAFE and SecurityScorecard Resolve Legal Dispute and Announce Research Collaboration SecurityScorecard has exceeded $150M ARR, with MAX offering growing at unprecedented triple-digit rates.
SI006 Christian & Timbers SecurityScorecard Boosts Revenue 36% with New CRO Hire Early 2024: Revenue hit $144.3M (+36% YoY); customer base expanded to 2,600; MAX managed services became fastest-growing product.
SI007 BusinessWire SecurityScorecard Achieves Record Quarter, Extending Market Leadership Through AI Innovation Triple-digit growth in MAX, the company's flagship SCDR solution, marks the strongest quarterly performance in company history.
SI008 SecurityScorecard SecurityScorecard Continues Leadership of the Security Ratings Market, New Solutions Drive Massive Growth Leading Into 2024 SecurityScorecard closed the year with 2,600 customers — representing 70% of the Fortune 1000 — and 70,000 organizations using the platform.
SI009 BankInfoSecurity (ISMG) SecurityScorecard Accuses Vendor of Stealing Trade Secrets Most of our competitors, including Security Scorecard, are laying off significant portions of their teams because of the poor performance of their business.
SI010 IncFact Annual Report on Securityscorecard's Revenue, Growth, SWOT Analysis & Competitor Intelligence
SI011 FounderPath SecurityScorecard Growth Playbook: 7 Strategies That Scaled to $140M ARR
SI012 Yahoo Finance SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide
SI013 TMCNet SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide
SI014 SecurityScorecard Security Questionnaire Automation — TITAN AI for Vendor Assessments Complete complex security questionnaires up to 18X faster than manual methods using generative AI and human review.
SI015 LeadIQ SecurityScorecard Employee Directory, Headcount & Staff
SI016 ToolRadar SecurityScorecard Pricing 2026: Plans, Hidden Costs & Cheaper Alternatives SecurityScorecard's pricing structure, with only a Free tier and subsequent 'Contact Sales' options, makes it difficult to assess fairness.
SI017 AuditXYZ SecurityScorecard Review 2026: Pricing, Features, and Verdict Ratings accuracy has faced criticism. External-only assessment cannot capture the full picture of an organization's security posture, and false positives or misleading ratings can create friction with vendors.
SI018 Bitscale SecurityScorecard Company Directory — Revenue, Headcount, Tech Stack
SI019 PricingNow SecurityScorecard Pricing 2026: Real Costs, Fees & What Others Paid
SI020 Christian & Timbers How SecurityScorecard Hit Triple-Digit MAX Growth and 160% Channel ARR with Strategic Board Director Placement SecurityScorecard delivered 160% year-over-year ARR growth across the channel program; 126% increase in partner-led pipeline.
SI021 FE International How to Value a Cybersecurity Business in 2026
SI022 PitchBook SecurityScorecard 2026 Company Profile: Valuation, Funding & Investors
SI023 Tracxn SecurityScorecard 2026 Company Profile — Tracxn
SI024 Justia Federal Court Records SecurityScorecard, Inc. v. Safe Securities, Inc. et al — Case 1:24-cv-04240 SDNY
SI025 SiliconAngle SecurityScorecard debuts TITAN AI to reduce supply chain breaches and streamline vendor risk workflows
SE001 SecurityScorecard Help Center How SecurityScorecard calculates your scores "We scan the entire IPv4 web space, more than 3.9 billion routable IP addresses, every 10 days across more than 1,400 ports."
SE002 SecurityScorecard Help Center Prepare for Scoring 3.0 "On April 9, 2024, SecurityScorecard introduced Scoring 3.0, an updated methodology that tightens the correlation of scores to breach likelihood."
SE003 SecurityScorecard SecurityScorecard Achieves FedRAMP® 'Ready' Designation "SecurityScorecard's core ratings platform, including Attack Surface Intelligence, is now approved with an initial 'Ready' status for FedRAMP."
SE004 BusinessWire SecurityScorecard Achieves FedRAMP® Ready Designation to Enable U.S. Federal Agencies "SecurityScorecard U.S. Public Sector business continues to see strong momentum with 96% year-over-year growth."
SE005 SecurityScorecard SecurityScorecard Acquires HyperComply "HyperComply's technology reduces this work by 92%."
SE006 SecurityScorecard SecurityScorecard Acquires HyperComply to Bring AI-Powered Automation to Supply Chain Risk Management "HyperComply's AI-powered platform automates security questionnaire responses … Its proprietary 'RespondAI' technology … ensures questionnaire accuracy while dramatically reducing the workload for both suppliers and their customers by 92%."
SE007 BusinessWire SecurityScorecard Launches MAX to Redefine the Supply Chain Cyber Risk Management Market "SecurityScorecard MAX™, a new partner-focused managed service … the fastest-growing offering in SecurityScorecard's lineup."
SE008 BankInfoSecurity / Information Security Media Group Bitsight, SecurityScorecard, Panorays Lead Risk Ratings Tech "Forrester chided SecurityScorecard for lacking AI-parsing tools to assess uploaded evidence documents and challenges with preventing duplicate findings when a scanned IP and hostname report the same asset."
SE009 SecurityScorecard (GitHub) SecurityScorecard GitHub Organization "SecurityScorecard has 63 repositories available."
SE010 SecurityScorecard Developer Hub Get started with your integration "We use API keys to authenticate requests … API keys do not expire and are almost as powerful as passwords so be sure to keep them secure."
SE011 AWS Marketplace / Verified Customer AWS Marketplace: MAX Managed Service — Customer Review "If SecurityScorecard could also help their customers internally by developing their tool or feature so that customer devices that are not only public-facing can be monitored, it would be more beneficial."
SE012 BusinessWire SecurityScorecard MAX Now Available for Purchase in CrowdStrike Marketplace "SecurityScorecard MAX … is now available for purchase in the CrowdStrike Marketplace."
SE013 SecurityScorecard TITAN MAX | Managed Security & Third-Party Risk Services "TITAN MAX delivers the visibility and actionability essential for governing your entire ecosystem … 26x faster questionnaire reviews … 2x higher issue remediation rates."
SE014 MSP Today SecurityScorecard Reinforces Cybersecurity Trust and Transparency "SecurityScorecard's dedication to eliminating false positives … has achieved a false positive rate below 1%. … Organizations receive a response within 24 hours, with score adjustments finalized within 72 hours."
SE015 SecurityScorecard 6 Ways To Use SecurityScorecard APIs and Integrations "With over 100 certified partner integrations, customers can access the largest ecosystem of cyber risk ratings."
SE016 SecurityScorecard SecurityScorecard Reaffirms FedRAMP and Achieves StateRAMP Ready Status "SecurityScorecard announced today that it has achieved State Risk and Authorization Management (StateRAMP®) Ready status and again achieved Federal Risk and Authorization Management Program (FedRAMP®) Ready designation."
SE017 BetaKit Ex-Vidyard employees sell Toronto's HyperComply to SecurityScorecard "The entire HyperComply team joined SecurityScorecard after the deal closed … HyperComply last raised a seed round in early 2022 … bringing its total external funding to $10 million USD."
SE018 Forcerta SecurityScorecard Scoring Algorithm 3.0 Version Announced
SE019 SecurityScorecard SecurityScorecard Unveils TITAN AI: A New Era of Threat-Informed Third-Party Risk Management "TITAN AI replaces the reactive, manual grind of third-party risk management (TPRM) programs with AI-acceleration."
SE020 SecurityScorecard Supply Chain Cybersecurity Platform | SecurityScorecard Titan AI "The platform scans 100% of the internet daily, including active IPv6 space … We operate the world's largest malware DNS sinkhole, detecting 2B+ daily requests."
SE021 SecurityScorecard Vendor Questionnaire Automation | SecurityScorecard
SE022 Security Boulevard SecurityScorecard Debuts TITAN AI to Automate Third-Party Risk Management Workflows "SecurityScorecard claims the approach can reduce manual effort by up to 95%, while improving vendor response rates and reducing supply-chain incidents."
SE023 SecurityScorecard SecurityScorecard Continues Leadership of the Security Ratings Market
SE024 SecurityScorecard Help Center SecurityScorecard 2026 feature releases
SE025 BusinessWire SecurityScorecard Acquires HyperComply to Bring AI-Powered Automation to Supply Chain Risk Management
SU001 SecurityScorecard Why SecurityScorecard | Data, Experts, and Proven Results
SU002 SecurityScorecard UNICC Customer Case Study Page Before working with SecurityScorecard, we had a bandage over our eyes. We couldn't see. So then, when we started working with them, it's like this bandage was removed.
SU003 SecurityScorecard SecurityScorecard Improves UNICC's Cyber Hygiene — PDF Case Study Automation only in terms of dos and alerts created is making you love to be in front of your desktop — seventy, seventy-five percent of my time, regarding the work that they do with the platform.
SU004 SecurityScorecard The Hershey Company Customer Case Study SecurityScorecard has absolutely helped us mature our third-party risk management program. We now get some level of cyber insight for 100% of the third parties that come through our risk management process.
SU005 SecurityScorecard Verdane Private Equity Case Study — Building a Robust Cybersecurity Posture SecurityScorecard's solution has been very well received by our portfolio companies and has encouraged many of them to implement a key performance indicator around their cybersecurity posture.
SU006 SecurityScorecard Horizon Media Customer Case Study We were looking to drive the point home to our clients that we have a robust, transparent information security program and that we take safeguarding their data very serious. We consider SecurityScorecard a key piece of our strategy to gain customer trust.
SU007 BusinessWire (SecurityScorecard press release) SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide Trusted by over 3,300 organizations, including 70% of the Fortune 100, and recognized as a trusted resource by the U.S. Cybersecurity & Infrastructure Security Agency (CISA).
SU008 Aon plc Aon Advances Cyber Risk Capabilities With SecurityScorecard Integrating SecurityScorecard into our cyber offerings underscores Aon's commitment to helping clients make better decisions about their cyber risk. By combining SecurityScorecard's external findings with the insights from CyQu and our consulting team, we're deepening visibility into clients' cyber risk posture.
SU009 Insurance-Canada.ca Aon Advances Cyber Risk Capabilities With SecurityScorecard
SU010 Gartner Peer Insights SecurityScorecard Reviews, Ratings & Features 2026 — Third-Party Risk Management 4.4/5 rating from 278 reviews; Service & Support 4.7/5; Evaluation & Contracting 4.6/5; 62% five-star ratings.
SU011 G2 SecurityScorecard Reviews 2026 — Details, Pricing & Features We do still occasionally see some false positives related to the baked-in risk of vendors with whom we have no leverage.
SU012 PeerSpot SecurityScorecard Reviews, Competitors and Pricing 2026 I realized that because my company was acquired by a bigger organization, SecurityScorecard started associating other portfolio company vulnerabilities to our score, which was not helpful because it was giving us wrong data.
SU013 SoftwareReviews (Info-Tech Research Group) SecurityScorecard Security Ratings Customer Reviews 2026
SU014 TrustRadius SecurityScorecard Reviews & Ratings 2026
SU015 AuditXYZ SecurityScorecard Review 2026: Pricing, Features, and Verdict Ratings accuracy has faced criticism. External-only assessment cannot capture the full picture of an organization's security posture, and false positives or misleading ratings can create friction with vendors who dispute their scores.
SU016 Black Kite Black Kite vs. SecurityScorecard — Competitive Comparison Data transparency — Moderate; proprietary algorithms with 'black box' elements. Provides insight into scoring factors but with limited visibility into underlying data and calculation logic. In the April 2026 Forrester Wave for Cybersecurity Risk Ratings Platforms, SecurityScorecard scored a 1 in the category for AI capabilities and customer AI adoption, signaling a below par AI offering.
SU017 Macnica Corporation Macnica Wins SecurityScorecard Japan Partner of the Year 2025
SU018 Invest Tokyo (Tokyo Metropolitan Government) CASE 27: We supported the establishment of a Japanese subsidiary of SecurityScorecard
SU019 BusinessWire (SecurityScorecard press release) SecurityScorecard Reaffirms FedRAMP and Achieves StateRAMP Ready Status SecurityScorecard empowers hundreds of public sector organizations to deliver their missions and be more resilient.
SU020 National Defense ISAC (ND-ISAC) Security Scorecard — National Defense ISAC Member Resource
SU021 Markets Financial Content (BusinessWire syndication) SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide
SU022 Christian & Timbers SecurityScorecard Boosts Revenue 36% with New CRO Hire Early 2024: Revenue hit $144.3M (+36% YoY); customer base expanded to 2,600; MAX managed services became fastest-growing product.
SU023 FeaturedCustomers 131 SecurityScorecard Customer Reviews & References — Winter 2026 Market Leader Read 56 SecurityScorecard reviews and testimonials from customers, explore 55 case studies and customer success stories. Customer Rating: 4.8/5.0 based on 3007 reference ratings.
SU024 SecurityScorecard SecurityScorecard In The News — February 2026
SU025 Coverager Aon partners with SecurityScorecard
SU026 Invest Tokyo (Tokyo Metropolitan Government) CASE 27: SecurityScorecard Japan Subsidiary — Business Development Centre Tokyo
SR001 Safe Security SAFE and SecurityScorecard Resolve Legal Dispute and Announce Research Collaboration SecurityScorecard has exceeded $150M ARR, with MAX offering growing at unprecedented triple-digit rates.
SR002 SecurityScorecard via BusinessWire SecurityScorecard Unveils TITAN AI: A New Era of Threat-Informed Third-Party Risk Management TITAN AI provides 99.9% accurate risk attribution with a near-zero refute rate, both internal teams and external vendors trust the findings.
SR003 PeerSpot SecurityScorecard: Pros and Cons 2026 Inaccuracies arise from associating unrelated company vulnerabilities to our score, which was not helpful because it was giving us wrong data and giving us vulnerabilities we did not have.
SR004 Insurance-Canada.ca Aon Advances Cyber Risk Capabilities With SecurityScorecard SecurityScorecard's industry-leading outside-in risk management capabilities will be offered to clients to complement Aon's CyQu platform.
SR005 Security Boulevard (Techstrong Group) SecurityScorecard Debuts TITAN AI to Automate Third-Party Risk Management Workflows
SR006 SecurityScorecard SecurityScorecard Acquires LIFARS, Empowers Organizations with a Complete View of Cyber Risk and an Accelerated Path to Cyber Resilience
SR007 Munich Re Cyber insurance: Risks and trends 2026 More than two thirds of large organisations experienced at least one third-party cybersecurity incident in the past 12 months.
SR008 Tracxn SecurityScorecard — 2026 Funding Rounds & List of Investors
SR009 Premier Alternatives SecurityScorecard — Private Company Valuation & Stock Data Valuation $359.5M Market implied
SR010 AuditXYZ SecurityScorecard Review 2026: Pricing, Features, and Verdict Ratings accuracy has faced criticism. External-only assessment cannot capture the full picture of an organization's security posture, and false positives or misleading ratings can create friction with vendors who dispute their scores.
SR011 UpGuard BitSight vs SecurityScorecard: 2025 Comparison SecurityScorecard takes 10 days to perform a non-intrusive scan across the entire IPv4 web space, whereas UpGuard's scan is completed in just 24 hours.
SR012 Coverager Aon partners with SecurityScorecard
SR013 SC Media Dr. Aleksandr Yampolskiy Dr. Aleksandr Yampolskiy, Co-Founder and Chief Executive Officer of SecurityScorecard, is a globally recognized cybersecurity innovator, leader, and expert.
SR014 Netcraft The False Positive Tax: How Bad Automation Destroys Security Program Credibility 33% of companies have been late responding to actual cyberattacks because they were tied up investigating false positives.
SR015 SecurityScorecard SecurityScorecard 2025 Global Third-Party Breach Report Reveals Surge in Vendor-Driven Attacks 35.5% of all breaches in 2024 were third-party related. 41.4% of ransomware attacks now start through third parties.
SR016 FinancialContent SecurityScorecard Unveils TITAN AI: A New Era of Threat-Informed Third-Party Risk Management
SR017 Forbes Technology Council Aleksandr Yampolskiy | Co-Founder and Chief Executive Officer — SecurityScorecard Since SecurityScorecard's inception in 2014, he has led the company with a vision to create a new language for measuring and communicating risk.
SR018 PeerSpot Bitsight vs SecurityScorecard (2026) — IT Vendor Risk Management Comparison The mindshare of SecurityScorecard is 5.7%, down from 11.1% compared to the previous year.
SR019 Gartner Peer Insights Bitsight vs SecurityScorecard 2026 | Gartner Peer Insights
SR020 SecurityScorecard Leadership — SecurityScorecard
SR021 SelectHub SecurityScorecard Reviews 2026: Pricing, Features & More Some user reviews point out occasional false positives in the security ratings provided by SecurityScorecard, which could lead to inaccurate risk assessments if not addressed.
SR022 GDPR Enforcement Tracker (CMS Law) Fines Database — GDPR Enforcement Tracker
SR023 Intellizence Largest Layoffs, Downsizing, and Hiring Freeze Data 2025-26
SR024 Notice.co SecurityScorecard Stock — Valuation, Stock Price, IPO
SR025 SecurityScorecard Regulatory Compliance & Cyber Risk | SecurityScorecard
SR026 TrustRadius SecurityScorecard Reviews & Ratings 2026
SR027 SoftwareFinder SecurityScorecard Reviews – Pros, Cons & Features 2026
SR028 G2 The G2 on SecurityScorecard
SR029 SecurityScorecard SecurityScorecard Research Library
SR030 SecurityScorecard Cybersecurity Risk Management: Definition, Frameworks, & More
SV001 Yahoo Finance (Reuters) SecurityScorecard raises $180 million at nearly $1 billion valuation The latest round values the company at close to $1 billion, according to a person familiar with the matter. It brings SecurityScorecard's total funding to date to more than $290 million.
SV002 Premier Alternatives SecurityScorecard — Private Company Valuation & Stock Data Valuation: $359.5M market implied. Share Price: $1.66. 52-Week Change: -13.0%.
SV003 Windsor Drake Cybersecurity Valuation Report 2026 The broader public cybersecurity market trades at about 7.8x revenue right now. Private markets tell a different story: the median revenue multiple for private cybersecurity companies in 2025 stands at 15.2x, significantly higher than the public median.
SV004 Multiples.vc Multiples Cybersecurity Index IBM: EV/Revenue 4.3x; Palo Alto Networks: 18.2x; CrowdStrike: 27.0x. Data as of June 28, 2026.
SV005 Multiples.vc Tenable — Multiples.vc — Public Comps and Valuation Multiples Tenable trades at 3.3x EV/Revenue multiple. As of June 28, 2026, Tenable has market cap of $3B and EV of $3B.
SV006 SecurityWeek BitSight Raises $250 Million at $2.4 Billion Valuation Cybersecurity ratings company BitSight on Monday announced receiving a $250 million investment from credit ratings giant Moody's in a deal valuing BitSight at $2.4 billion.
SV007 Acquiry Google / Wiz: The $32 Billion Cybersecurity Bet The revenue multiple of 45–65x ARR is one of the highest ever paid in a large-scale cybersecurity transaction.
SV008 TechCrunch Google wraps up $32B acquisition of cloud cybersecurity startup Wiz Google has officially acquired Israeli cybersecurity firm Wiz for $32 billion in cash. The deal comes after Wiz crossed $1 billion in ARR in 2025.
SV009 SecurityWeek Netskope Raises Over $908 Million in IPO The IPO initially valued the company at roughly $7.3 billion. Prior to the IPO Netskope reported annual recurring revenue (ARR) of $707 million in the first half of 2025.
SV010 Latka SecurityScorecard Revenue 2024: $144.3M Est. ARR In 2024, SecurityScorecard's revenue reached $144.3M. SecurityScorecard reached a $980M valuation in 2021, set during its Series E round. SecurityScorecard has raised $293.4M in total funding across 6 rounds.
SV011 SecurityScorecard SecurityScorecard Achieves Record Quarter, Extending Market Leadership Through AI Innovation Triple-digit growth in MAX, the company's flagship SCDR solution, marks the strongest quarterly performance in company history. Leadership in competitive displacement, with a 70% win rate in known competitive opportunities.
SV012 SecurityScorecard (via Business Wire) SecurityScorecard Reports Triple-Digit 2025 Partner Growth as MAX Ecosystem Expands Worldwide SecurityScorecard delivered 160% year-over-year ARR growth across its channel program in 2025. Partner-led pipeline increased 126% year-over-year.
SV013 PR Newswire UpGuard Raises $75M in Series C Funding to Accelerate Market Leadership in Cyber Risk Posture Management UpGuard, a leader in cybersecurity and risk management, today announced it has raised a Series C funding round of $75M from Springcoast Partners.
SV014 Solganick Cybersecurity Mergers and Acquisitions (M&A) Update, Q4 2024 and 2025 Outlook Valuation multiples for publicly-traded cybersecurity companies ranged from a median of 14.3x EV/2024E revenue for high growth (>20%) vendors to a median of 4.7x EV/2024E revenue for low growth (<10%) vendors.
SV015 Founderpath SecurityScorecard Growth Playbook: 7 Strategies That Scaled to $140M ARR According to Crunchbase, the company has raised $292 million in funding and reached a $1 billion valuation. With an average deal size of $30,000–40,000, SecurityScorecard discovered a powerful growth lever.
SV016 Tracxn SecurityScorecard — 2026 Company Profile & Team SecurityScorecard is a series E company based in New York City, founded in 2013. SecurityScorecard has raised $292M in funding with a current valuation of $1B. The company has 233 active competitors.
SV017 Hiive SecurityScorecard Stock | Hiive Price $1.66 | Invest or Sell SecurityScorecard Stock | Hiive Price $1.66 | Invest or Sell
SV018 Notice.co SecurityScorecard Stock $2.20 | How to Buy, Valuation, Stock Price, IPO | Notice.co
SV019 Acquiry SaaS Valuation Multiples in 2026: What the Data Actually Shows Non-AI SaaS (2026): 4–7x ARR multiple. AI-native SaaS (2026): 8–15x ARR multiple. Net Revenue Retention is the single most important metric in SaaS valuation.
SV020 S&P Global Market Intelligence Alphabet's $32B Wiz deal puts Big Tech M&A to the test "This acquisition will open the door to a massive wave of M&A across the tech landscape … especially within cybersecurity, as more cloud operators look to secure their cloud portfolios," Wedbush Securities analyst Dan Ives said.
SV021 SentinelOne Investor Relations SentinelOne Announces First Quarter Fiscal Year 2027 Financial Results Annualized recurring revenue (ARR) grew 23% to $1,163 million as of April 30, 2026. Total revenue grew 21% to $277 million. Non-GAAP gross margin was 77%. Non-GAAP operating margin was 4%.
SV022 Windsor Drake 2026 SaaS Valuation Multiples by ARR Band Private lower middle market SaaS multiples: public multiples set the ceiling, but private lower middle market SaaS businesses transact at a persistent 30–50% discount, reflecting liquidity, scale, concentration, and the absence of audited financials.
SV023 Momentum Cyber Cybersecurity M&A Update Report 2025
SV024 PM Insights SecurityScorecard Valuation Analysis
SV025 ipos.fyi Is SecurityScorecard Going Public? IPO & Stock Info (2026)
SV026 W.Media Cybersecurity Moody's to invest US$250 million in cybersecurity firm BitSight The transaction values BitSight at $2.4 billion, reflecting the company's leadership in a rapidly growing data and analytics market.
SV027 SaaS Mag Cybersecurity SaaS Premium: Highest Multiples in 2026 Public cyber companies trade at a 7.8x revenue median, private cyber startups command 15.2x, and the M&A median runs 16.3x with cloud-security transactions reaching all the way up to 35.5x. ServiceNow paid approximately 23x ARR for Armis at $340M ARR growing 50% year-over-year.
SV028 CybersecurityNews Google Completes Acquisition of Wiz in Historic $32 Billion Deal Wiz had already established itself as a dominant force in cloud security before the acquisition closed, crossing $1 billion in annual recurring revenue (ARR) in 2025, with an anticipated growth rate of 40% in 2026.
SV029 Founderpath SecurityScorecard Growth Playbook: ARR trajectory and capital structure PitchBook data confirms SecurityScorecard has raised $293 million from 30 investors, including Sequoia Capital, Intel Capital, and Google Ventures.
SV030 TechCrunch Netskope follows Rubrik as a rare cybersecurity IPO, both backed by Lightspeed If Netskope goes public at a valuation of $6.5 billion, the company would be among a number of VC-backed companies that have recently debuted below their final private market valuation. The company was last valued at $7.5 billion when it raised a $300 million Series H in 2021.