Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Tools Help Build and Maintain an AI Asset Inventory?

Managing an artificial intelligence (AI) footprint has emerged as one of the most complex challenges for modern enterprise security and risk teams. As shadow AI, autonomous agents, and embedded third-party models infiltrate corporate environments, traditional methods of software tracking have broken down. Organizations are quickly realizing that maintaining an accurate inventory is not just an IT best practice.

Token Torching: Why Attackers Care About Your Usage Limits

AI is becoming part of almost everything: customer support, security operations, software development, research, analytics, internal workflows, and, most importantly, drafting emails. AI is increasingly embedded in real business processes, and that creates new risks, not to mention the level of unprecedented access mainly of these platforms to our data. Token torching (a type of Denial-of-Wallet (DoW) attack) is one emerging AI risk.

TITAN AI Demo Series: Build Custom Assessment Templates in Minutes with TITAN Agent

Building a strong vendor assessment template used to take hours. With our TITAN Agent, it takes minutes. In this installment of SecurityScorecard's TITAN demo series, see how our TITAN Agent builds customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.

After Mythos: What Cyber Insurers Should Actually Be Asking

One issue we keep hearing from insurance underwriters and portfolio managers is some version of the same question: how do you price a risk that can change between bind and the very next day? The steady stream of headlines about Claude Mythos is the latest reason why this question comes up, but it isn’t really all about Mythos. Frontier AI is collapsing the gap between vulnerability disclosure and weaponized exploit, and the numbers are no longer subtle.

How to Build an AI Asset Inventory

Most organizations that have invested in AI governance have done so without first solving the problem that makes governance possible in the first place: knowing what AI they are actually running. An AI governance program built on an incomplete inventory is governing a partial picture of actual exposure. ‍ The risks concentrated in the AI systems that never made it into the formal catalog are not lower priority because they were not captured. They are simply invisible, which is considerably worse.

Bringing Real-World Cyber Events Directly Into the Cyber Risk Register

Kovrr's cyber risk quantification (CRQ) models are built on a continuously updated database of real-world cyber events, drawing on regulatory disclosures, company filings, legal reports, and proprietary insurance claim intelligence to produce financial exposure estimates grounded in how incidents actually unfold. That intelligence foundation has always informed everything the platform produces, from frequency and severity calculations to the event catalogs that drive each organization's quantification.

TITAN AI Demo Series: How to Send Vendor Questionnaires with TITAN Assess

Vendor questionnaires out the door faster. Responses back sooner. No manual coordination required. In this week's edition of SecurityScorecard Demo Tuesdays, see how TITAN Assess streamlines the entire questionnaire outreach process — so your team spends less time on admin and more time acting on what vendors actually tell you.
Featured Post

The biggest security risks facing financial institutions in 2026

Financial institutions are spending more on security than they were five years ago. They have more security tools, invest more in training, have more policies in place and report on security more regularly. That sounds positive, but it does not automatically make them more secure. One of the biggest challenges for security leaders is deciding where to focus. New vulnerabilities, threat reports and regulatory requirements appear all the time. With so much competing for attention, it can be difficult to separate genuine priorities from the latest headline.

Why third-party risk management is broken, according to CISOs and analysts

Independent journalists, analysts, and working CISOs are all reaching the same conclusion about questionnaire-based, point-in-time risk assessment: it’s no longer enough. Risk and vulnerabilities keep growing, compliance obligations keep stacking up, and AI adds an entirely new surface to account for. CISOs need something better: a continuous approach with visibility across their business, that actually reduces risk rather than just documenting it.

Zero-Day Minus the Scramble: A Better Approach to Vulnerability Risk Management

SCA tools are good at identifying vulnerabilities in your dependencies. They’re not built for the harder part of vulnerability risk management: telling you whether those vulnerabilities are actually reachable in your application, or which assets are running an affected component the moment a zero-day drops. Seemplicity’s SCA Analyst solves both problems inside a single centralized vulnerability management platform.