# SecurityScorecard Acquires Driftnet to Strengthen Supply Chain Threat Visibility


Third-party risk management platform adds internet-scanning capabilities as vendor breaches account for nearly one-third of all security incidents


SecurityScorecard, a leading third-party risk management (TPRM) platform, has acquired Driftnet, a UK-based internet scanning and threat intelligence startup. The acquisition underscores an industry-wide pivot toward supply chain security as organizations grapple with escalating vendor-related breaches and the emerging risks posed by AI-driven automation deployed across interconnected enterprise ecosystems.


Driftnet's core strength lies in its ability to scan networks in real time, identifying exposed assets, misconfigurations, and potential attack vectors. Organizations can search by domain, IP address, or business entity to uncover open ports, vulnerable services, weak credentials, and active attack campaigns targeting their networks or those of their vendors. For SecurityScorecard's TPRM customers, this acquisition adds a critical layer of visibility into the external threat landscape that third parties face—and how those threats might cascade to their own environments.


## Why Third-Party Risk Has Become a Board-Level Concern


The urgency driving this acquisition reflects a sobering reality: nearly one-third of breaches involve third parties, according to SecurityScorecard's own research. That number is likely both underreported and rising.


The shift toward remote and hybrid work, accelerated during the COVID-19 pandemic, fundamentally expanded the attack surface. Organizations no longer operate in isolation. They depend on:


  • Software vendors and SaaS platforms
  • Cloud infrastructure providers
  • Managed service providers (MSPs)
  • Contractors, consultants, and development partners
  • Supply chain management tools and platforms

  • Each connection creates a potential entry point. A breach at a seemingly minor vendor can compromise critical systems upstream. The 2020 SolarWinds supply chain attack and the 2021 Kaseya ransomware incident demonstrated that attackers no longer need to target you directly—they can compromise your vendors instead.


    ## The Challenge: Visibility at Scale


    Most organizations lack meaningful visibility into their third-party ecosystems beyond basic contractual agreements. "One-tier visibility" is now insufficient. Companies need to understand not just what *their vendors* do, but what *their vendors' vendors* do—and whether those downstream partners maintain adequate security practices.


    SecurityScorecard's research identified a critical gap: third parties often deploy automation tools and AI with weak access controls, exposed credentials, and no centralized visibility. This creates a compounding risk problem. As enterprises accelerate adoption of automated tools and agentic AI (autonomous systems that take actions on their own), vendors frequently implement these same capabilities in their own environments—often with minimal governance.


    ## Driftnet: From Startup to Strategic Asset


    Driftnet offers something many TPRM platforms lack: active external threat reconnaissance. Rather than relying solely on vendor questionnaires, compliance certifications, or historical breach data, Driftnet scans the internet for real, observable evidence of risk.


    The platform identifies:


  • Exposed services: Open ports, unpatched services, and internet-facing systems that shouldn't be
  • Configuration weaknesses: Misconfigured cloud buckets, insecure API endpoints, improper DNS settings
  • Credential leaks: Exposed API keys, SSH keys, or credentials appearing in public repositories or dark web markets
  • Active threats: Exploit kit activity, command-and-control (C2) communication patterns, or evidence of active reconnaissance targeting a specific organization or its supply chain

  • For security teams managing hundreds or thousands of vendors, this capability is transformative. Instead of asking vendors "Are you secure?" (to which nearly all answer yes), teams can now observe whether vendors *actually exhibit* signs of compromise or misconfiguration.


    ## The AI Acceleration Problem


    SecurityScorecard CEO Dr. Aleksandr Yampolskiy highlighted a particularly acute challenge in his statement about the acquisition: AI and agentic automation have exploded across enterprise environments, but most TPRM programs have zero visibility into the risks these tools introduce.


    This is a critical distinction. Traditional TPRM focuses on:

  • Vendor financial stability
  • Contractual obligations
  • Compliance certifications (ISO 27001, SOC 2, etc.)
  • Historical breach records

  • But AI automation introduces *new* failure modes that older risk models don't capture:


    | Risk Category | Traditional Model | AI/Automation Reality |

    |---|---|---|

    | Access Control | Assume humans review changes | Automated systems make decisions autonomously |

    | Credential Management | Rely on vetting processes | AI agents may generate or rotate credentials without logging |

    | Lateral Movement | Assume strong network segmentation | Automation crosses trust boundaries to optimize workflows |

    | Detection Blindness | Assume logs exist | Automated tools may operate without human oversight or logging |


    An AI-powered automation tool deployed by a vendor—even with good intentions—could introduce vulnerabilities that neither the vendor nor their customers fully understand.


    ## Implications for Organizations


    This acquisition signals that the security industry recognizes a hard truth: traditional vendor risk management is no longer sufficient.


    Organizations should expect TPRM platforms to evolve in three directions:


    1. Active Monitoring: Moving beyond questionnaires to continuous, automated scanning of vendor infrastructure

    2. Supply Chain Mapping: Visualizing not just direct vendors but upstream dependencies and their risk profiles

    3. AI Risk Assessment: Building models to detect unusual behavior that might indicate compromise or misconfiguration introduced by automated systems


    For security leaders, this means TPRM is becoming less about compliance theater and more about operational threat intelligence. The platform becomes a continuous scanning engine rather than an annual audit checkpoint.


    ## Technical Implementation Questions


    Organizations integrating TPRM with active scanning capabilities should consider:


  • Scope creep: Scanning third parties can uncover dozens of issues. Which require immediate remediation? Which are acceptable risks?
  • Vendor relationships: Will vendors view external scanning as surveillance or partnership? How will you manage friction?
  • False positives: Internet scanning generates noise. Misconfigurations are common; not all expose actual risk.
  • Access controls: If you can see a misconfiguration, what authorization do you have to act on it?

  • ---


    ## HackWire Analysis


    This acquisition reflects a broader consolidation in the TPRM and threat intelligence space, but it solves a specific and urgent problem that most organizations haven't yet articulated: we can't see what our vendors are actually doing.


    The industry has spent two decades building governance frameworks around vendor management—questionnaires, certifications, audit rights—all of which assume vendors are transparent about their security posture. But that model breaks down in a world of autonomous AI, supply chain tools, and complex interconnected systems. A vendor's security team might not even know what an AI system they deployed is doing in their environment.


    The real insight here is about *observability as security*. Just as DevOps teams learned that production visibility is non-negotiable, security teams are learning that vendor visibility is non-negotiable. You can't manage risk you can't see.


    The timing of this acquisition also matters. Ransomware gangs have increasingly focused on supply chain compromise because it's higher-ROI than direct attacks. Healthcare, manufacturing, and finance sectors have been particularly hard hit. As attackers become more sophisticated, organizations will demand real-time intelligence about vendor infrastructure risk—not annual reviews.


    The hidden risk in this trend is that external scanning can itself become a liability. If SecurityScorecard's platform identifies a vulnerability in a vendor's infrastructure but that vendor doesn't patch it, does SecurityScorecard bear liability? Does the customer? These legal questions are still unsettled, and they'll complicate how aggressively platforms can recommend or act on findings.


    For defenders, the concrete next step is simple: demand visibility into your vendors' actual security posture, not their compliance certifications. Ask TPRM providers what they can *observe* about your vendors' infrastructure, not what vendors *claim* about their practices. The gap between those two things is where breaches live.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Supply Chain Security](https://www.hackwire.news/category/supply-chain-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)