Titan AI is in beta. Features and behavior may change, and some functionality is still in development. To share feedback or report an issue, complete the support form.
Security events provide a centralized feed of external breaches, zero-day exploits, and emerging threats that may impact your supply chain.
Security incidents often surface first in fragmented sources such as news coverage, breach reporting, and hacker forums. By the time teams manually connect those signals to vendors, products, or vulnerabilities, valuable response time can be lost.
By mapping fragmented signals, such as hacker forums and news reports, directly to your existing vendors and findings data, the platform lets you quickly assess potential impact and decide whether further investigation is needed.
Navigating the feed
The Security events page is designed as a feed of active events, helping teams quickly scan for new developments and focus on events that may require attention.
Each event can include one or more sources. Information extracted from these sources is then mapped to existing SecurityScorecard data using signals such as:
- Company names mapped to vendors
- CVEs mapped to findings
- Products mapped to organizations or product detections
Each event card summarizes the "who, what, and when" of a potential threat:
-
Priority indicators
Use event tags to distinguish between confirmed incidents and unverified chatter.- If a breach is confirmed, you will see a Compromise tag with a Breach subtype.
- If the breach is alleged, you will see a Threat tag with a Hacker Chatter subtype.
-
Event status: The status badge indicates the current state of the event: Active means the event is ongoing, Investigating means it is under review, and Closed means it has been resolved.
- Impact summary : The "Impact" row displays the logos of vendors in your portfolio mapped to the event, showing up to three logos with an overflow count for additional vendors, and a total count of all affected vendors. It also shows the number of confirmed impacted individuals (red triangle) and potentially affected individuals (circle).
Investigate a security event
Selecting an event from the Security events feed opens the event details page, where you can review the available information and assess potential impact across your vendors.
The event details page consolidates the external reporting, mapped vendor relationships, and investigation progress in one place.
Key sections include:
-
Description: A summary of the event based on the available sources, including details about the vulnerability, attack, or breach being reported.
-
Impact summary
Provides a portfolio-level view of how the event affects your vendors. It includes three subsections:- Vendor impact translation: The number of vendors with confirmed exposure (red triangle) and potential exposure (circle) linked to the event.
- Response progress: A progress bar showing how many vendors have responded, have a pending response, or have not yet been contacted, along with the last activity date.
-
Impact result: A donut chart breaking down vendors by outcome (Not impacted, Impacted, and Potentially impacted).
-
Timeline: A chronological view of when the event was first detected and when new sources or intelligence were added.
-
Sources: The external articles, advisories, or intelligence sources used to identify and validate the event.
-
Vendor impact table
A list of vendors potentially affected by the event, including:- The reasoning for why the vendor is linked to the event
- The current investigation status
- The outcome of the impact analysis
From this view, you can track investigation progress and determine whether the event requires escalation.
Vendor overview panel
Selecting a vendor row in the Vendor overview table on an event opens a side panel with more detail about that vendor's connection to the event. The panel's Overview tab summarizes the vendor's impact status, evidence, and any notes your team has added.
Summary fields
Four fields summarize the vendor's status:
- Impact reasoning: Why the vendor appears on this event. Possible values are Victim entity, Named victim, and Detected connection. Victim entity and Named victim mean the vendor was directly named in the source of the event; Detected connection means the vendor was surfaced because SecurityScorecard detected a relationship (such as a fourth-party connection) tying it to the event.
- Impact result: Whether the vendor has confirmed it was impacted. Values are Potential (default, not yet confirmed either way), Impacted, or Not impacted.
- Last activity: The most recent triage action taken on this vendor, such as Flag, Unflag, Initial request, or Follow-up request. Shows No activity if nothing has happened yet.
- Last engagement: The date of that most recent activity. Shows No engagement yet if the vendor hasn't been engaged.
Impact result
Shows the vendor's own response about whether it was impacted by the event. Before the vendor has been reached out to, it reads "You haven't started investigating this vendor." Once a request has been sent, it shows as pending. Once the vendor responds, the full impacted/not-impacted statement is displayed here.
Note
Use this section to leave internal notes about the vendor for your team. Select + Add note to write a new note; existing notes show the author and the date they were added, and can be edited or removed. Notes are only visible to your organization; the vendor cannot see them.
Impact evidence
Lists the evidence behind the vendor's inclusion in the event, grouped into up to two categories:
- Named in source: Lists the source articles or leaks the vendor was directly named in.
- 4th party connection: Lists any other vendors (fourth parties) that this vendor is connected to, and that connection's relevance to the event. Each connected vendor is shown as its own collapsible row, identified by domain, with a count of how many pieces of evidence support that connection.
Expanding a 4th party connection shows an evidence table with these columns:
- Detection method: How the connection was identified. Possible values are HTTP Request, Detected Library, DNS, Breach, Products detected, TLS, and X.509.
- Evidence: A description of the specific evidence found for that detection method.
- Last detected: The date that evidence was most recently observed.