Resources

Research & Reports

Original research on third-party risk, vendor breaches and industry posture — published quarterly.

Why teams choose this

Industry benchmarks

Quarterly posture benchmarks across financial services, healthcare, retail and SaaS.

Threat reports

Deep dives into emerging threat actors, ransomware crews and supply-chain incidents.

State of Cyber Risk

Annual report tracking the global state of third-party cyber risk.

Original research

Peer-reviewed analyses produced by our in-house research team.

40+
Reports published
Quarterly
Benchmark cadence
Open
Datasets available
// features

What's included

  • Quarterly Industry Benchmark Reports
  • Annual State of Third-Party Cyber Risk
  • Threat-actor deep dives
  • Supply-chain incident post-mortems
  • Open datasets for academic use
// how it works

How it works

  1. 01
    Connect

    Add your domain or vendor list — no agents, no DNS changes. a research request starts within minutes.

  2. 02
    Analyze

    Our engine continuously ingests open-source intelligence, scan data and threat feeds to produce an objective risk score.

  3. 03
    Act

    Receive prioritized remediations, alerts and exportable evidence — share with your team, board or auditors.

Quick Answers

Research & Reports — frequently asked questions

Is research free to download?
Most reports are free with a business email. Some datasets require an account for licensing reasons.
Can I cite your research?
Yes — please cite SecurityRating.com Research and link to the source report.
Do you collaborate with academia?
Yes. We share anonymized datasets with researchers under data-use agreements.
How often is research published?
Industry Benchmark Reports quarterly; threat-actor deep dives monthly; the annual State of Third-Party Cyber Risk every January. Subscribers get embargoed access 1–2 weeks before public release.
Is research methodology peer-reviewed?
Yes. Methodology for benchmark and risk-correlation studies is reviewed by independent academics (LSE, NYU and others). Methodology appendices are public.
Can I license raw data for my own research?
Yes. Anonymized datasets are licensed to academics under data-use agreements and to commercial researchers under separate terms. Contact research@securityrating.com.

Ready to see Research & Reports in action?

Talk to our team about a 30-minute walkthrough tailored to your environment, or run a free non-intrusive scan of any domain.