Skip to content
The Cyber Security Place

About

The Cyber Security Place exists to collect what threatens the financial and operational side of running an organisation, and to say plainly what follows from it.

What is here

An archive of 15,376 reports published between 2014 and 2021, drawn from 969publications across the trade and general press. Each entry summarises what was reported and links to the original article at the publication that wrote it. The summaries are quoted from those publications; where you cite something, cite them rather than this site.

Alongside the archive sit 33 written guides, one for each subject the archive covers in depth. They are not summaries of the archive. They set out what is currently known about a problem, what the evidence supports, and what somebody could do about it on a Monday morning — each carrying the date it was last reviewed, because a page about a moving subject that does not say when it was written is asking to be trusted on faith.

There is also a glossary of 50 terms, weighted towards the ones where two parties use a word and mean different things; a directory of 245 security suppliers, each carrying that firm's own description of itself; and 32 interactive tools, each stating what it assumes.

How it is written

Four commitments, stated because they are checkable rather than because they are flattering.

Figures carry their origin. Where a number is quoted, the page says what it measures and, where sources disagree, that they disagree. Several of the guides exist largely because two credible sources answer the same question differently.

Nothing is invented to fill a gap. Where the record does not support a statement, the statement is not made. That is visible in the directory, which publishes the listings that can be reproduced and no others.

Every page works without scripting. The interactive pieces are shortcuts laid over content that is already there as text and tables. Anything that only works with JavaScript is unavailable to a reader, a search engine and an archive at the same time.

Every page is available as plain text. Append .md to any address for a Markdown version, and llms.txt maps the site for anything reading it by machine.

What is covered

The subjects are the ones that reach a business rather than a laboratory: breaches and what follows them, ransomware, fraud and identity, the security of software and of the components it is assembled from, cloud and network infrastructure, endpoints and the phones that now hold the keys to everything else, regulation and its deadlines, and what artificial intelligence has changed on both sides of the contest.

The site map lists everything, and the search covers every headline in the archive.

Judging whether a page is current

Two dates matter and they mean different things. An archive entry carries the date it was published, and it is a record of what was reported then — it is not updated, because a record that changes is not a record.

A written guide carries the date it was last reviewed, and that date is the claim. A subject that moves quickly and a page that has not been looked at for a year are a combination worth noticing, and stating the date is what makes it possible to notice.