SecurityScorecard has acquired Driftnet, a UK-based internet scanning and threat intelligence specialist, in an undisclosed deal that sharpens its push beyond vendor scorecards and into live exposure monitoring across customer supply chains.
Driftnet’s core asset is an internet discovery engine built to find misconfigured and hard-to-detect infrastructure, including services running on non-standard ports and IPv6 environments that many enterprise tools still cover unevenly. SecurityScorecard plans to fold that capability into its TITAN AI platform and use it across third-party risk management, security operations, and threat hunting workflows.
This is less a feature tuck-in than a response to a structural problem in cyber risk. Traditional third-party risk programs were built around questionnaires, periodic reviews, and breach notifications. That model breaks when suppliers are deploying AI agents, internet-facing automation tools, and cloud services faster than governance teams can inventory them. SecurityScorecard is buying visibility. It is also buying speed.
The company said its threat team recently used Driftnet’s engine to identify more than 816,000 internet-exposed AI OpenClaw agent deployments, some already linked to prior breaches. That claim points to the commercial angle behind the deal. Boards increasingly want evidence of active exposure in the vendor base, not backward-looking attestations. Security leaders want the same data set to inform SOC response and vendor remediation. SecurityScorecard is trying to become the system that serves both.
There is also a market timing element. Cybersecurity buyers remain selective, but they are spending on platforms that collapse adjacent workflows and reduce tool sprawl. Acquire.fyi data shows technology M&A volume is down 12.2% year over year, while median deal size is up 47.9%, a sign that buyers are reserving capital for assets with clearer strategic leverage rather than broad consolidation bets.
For competitors in security ratings, attack surface management, and external threat intelligence, the pressure is obvious. Point products that stop at detection will face harder questions. Customers increasingly want a closed loop from discovery to prioritization to action across third parties. SecurityScorecard now has a stronger case that it can provide it.
Source: Company press release and Acquire.fyi's proprietary data