SecurityScorecard Investigates S&P 500 Companies Breaches and New Cybersecurity Regulations

By Alex Passett

The landscape of cybersecurity is, without a shred of doubt, prone to dynamic shifts. According to the U.S. Securities and Exchange Commission (SEC), new cybersecurity regulations will require publicly traded organizations to provide proper disclosure of quote-unquote “material” cyber incidents within a period of four days.

Alright, four days. At least it isn’t four hours, right?

Nevertheless, many organizations – plus key policymakers and investors therein – still lack the ability to tap into key insights that shine a bright-enough overhead light, so to speak, on the evolution of the current threat landscape. (Which, as we’ve established, evolves rapidly.)

What’s the next step, then?

SecurityScorecard’s threat researchers have clinched an answer.

With such new breach requirements (and the increased need for breach visibility) on the horizon, SecurityScorecard conducted its S&P 500 Cyber Threat Report. This report analyzes the security ratings of S&P 500 companies and offers avenues down which security teams may trek in order to shore up the state of their respective cybersecure systems.

Here's a long-story-short version of the report’s findings:

  • 21% of S&P 500 companies reported breaches in 2023: Bad actors chase money trails, and ransomware operators target S&P 500s based on their stocks’ market values (while demanding higher and higher ransoms, as time passes). The bigger targets, in attackers’ eyes, are usually more capable of paying these ransoms, so ensuring that “the bigger they are, the harder they fall” doesn’t happen vis-à-vis strengthened cybersecurity is a sure-fire must in 2024.
  • 25% of the reported S&P 500 breaches impacted financial services, fintech, and insurance companies: Financial institutions are responsible for substantial assets, and those wielding ransomware know how interconnected segments of the financial sector can be. Compromising a “big player” could lead to additional gains for bad actors. Thus, a company ensuring it’s protected can also have a significant effect on other companies, as well.
  • 52% of breached companies unfortunately reported exposed Personal Identifiable Information (PII): Once an attack has been enacted, the access of critical employee info (used against them either via ransom or via impersonation) can lead to legitimate crises on personal, professional, and wholescale operational levels. This is why, again, up-to-date cybersecurity protocols with maximized across-the-board visibility is vital.

The report also covered increasingly sophisticated social engineering risks that company associates face, supply chain attack statistics, and more.

“Regulatory pressure continues to grow, and companies need a unified definition of cybersecurity due diligence with clear metrics,” said Dr. Aleksander Yampolskiy, SecurityScorecard’s CEO. “Just as credit scores standardized the financial world, companies need a universal framework to measure cybersecurity risk and define materiality.”

Click here to download and read the full threat report.




Edited by Greg Tavarez
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE
Related Articles

SkySwitch Bets Native AI Can Turn UCaaS Partners into Workflow Specialists

By: Erik Linask    9/1/2026

AI-powered UCaaS is transforming how MSPs and technology providers serve SMB customers by combining voice automation, customer experience, and busines…

Read More

4 Benefits of 24/7 Managed IT Support Services

By: Contributing Writer    8/26/2026

Modern IT environments grow more complex by the quarter, leaving internal teams stretched thin across expanding cloud infrastructures, security protoc…

Read More

We Asked Four AI Assistants to Recommend an MSP. Here Is What Decided the Answer

By: Contributing Writer    8/25/2026

A buyer who used to search "managed IT services near me" now asks ChatGPT which provider suits a 50-person firm. The assistant returns two or three na…

Read More

From Visibility to Action: Pure IP Is Rethinking Enterprise Technology Cost Management

By: Erik Linask    8/20/2026

As distributed enterprises struggle with rising carrier costs, unused services, billing errors and complex infrastructure, continuous technology cost …

Read More

While the DOW Reviews CMMC, MSPs Should Be Reviewing Their GTM

By: Contributing Writer    8/19/2026

The Department of War''s July 13 decision to suspend CMMC Phase II implementation changes the near-term opportunity for Managed Service Providers (MSP…

Read More