Real-time risk signal feed across 41 monitored vendors. Last refreshed Mar 26, 2026 at 08:42 AM.
Vendors Monitored
41
Across all business units
Active Alerts
7
+2 vs. last week
Risk Score Increased
4
Since last scan
Pending Review
12
Awaiting action
Overdue Reviews
3
Action required
Data breach reported — expedited reassessment required
SecurityScorecard score −18 pts. Public breach affecting 2.4M records disclosed Mar 18.
SOC 2 report expired 45 days ago — evidence not received
2 automated requests sent with no response. Audit evidence gap risk.
Critical CVE published — patch unconfirmed, no owner assigned
CVE-2026-1147 (CVSS 9.1) Mar 19. No vendor owner on record.
| Vendor | Criticality | Risk Score | Δ Delta | New Signal | Source | Status | Owner | Last Review | Action | |
|---|---|---|---|---|---|---|---|---|---|---|
ST Stripe Payment Processing | Critical | 78 | ↑12 | Public data breach reported affecting 2.4M records | SecurityScorecard | Alert | SCSarah Chen | Jan 15, 2026 | ||
SF Salesforce CRM | Critical | 62 | ↑8 | SOC 2 report expired 45 days ago — no replacement received | Manual | Alert | MWMarcus Webb | Dec 10, 2025 | ||
OK Okta Identity & Access | Critical | 55 | ↑5 | CVE-2026-1147 (CVSS 9.1) — patch status unconfirmed | CVE Database | Alert | ?Unassigned | Feb 3, 2026 | ||
AW AWS Cloud Infrastructure | Critical | 32 | ↓3 | IAM policy over-permissioning detected in us-east-1 | Bitsight | Pending Review | PNPriya Nair | Mar 1, 2026 | — | |
GH GitHub Code Repository | High | 41 | — | Scheduled review due in 14 days | Manual | Active | AKAlex Kim | Dec 28, 2025 | — | |
SN Snowflake Data Warehouse | High | 48 | ↑6 | Network security declined — 2 exposed S3 buckets detected | SecurityScorecard | Alert | SCSarah Chen | Feb 20, 2026 | ||
SL Slack Communication | Medium | 29 | ↓2 | No new signals — posture improving | SecurityScorecard | Active | MWMarcus Webb | Jan 8, 2026 | — |