2016 in the archive: the year with a hole in it
A quarter of this year is not here. What that looks like from inside the record, and what can honestly be said about the rest of it.
Last reviewed September 4, 2026
- A quarter of the year is missing. 148 entries where the rate predicts about 711.
- The gap is invisible from inside. The entries present are an ordinary week's filing.
- The thin months are the best described. 82% carry summaries against 24%.
- The year's biggest event lands in it. October holds 3 entries on the subject.
The shape of the year, and the part that is not here
Each column is a month. The dashed line is the rate the year runs at across its nine complete months. Three columns are faded because the record for them is incomplete, and the distance between those columns and the line is the estimate.
Faded: Aug at 36, Sep at 42, Oct at 70. The nine complete months run at 237 a month, peaking in Feb at 273.
How big is the hole?
Three months holding 148 entries, at 49 a month, in a year running at 237 a month everywhere else. If those months would otherwise have matched the rest, roughly 563 entries are absent — about a fifth of what the year should contain.
That figure rests on an assumption and cannot do otherwise. Nothing inside a record reports what is not in it, so the size of an absence has to be inferred from what surrounds it. The estimate would be wrong if those three months had genuinely been quiet, and there is no version of this calculation that does not require assuming they were not.
What makes the assumption defensible is the recovery. The month after the gap returns to 195 and the one after that to 201, both close to the year's ordinary level. A real reduction in activity does not end on a particular date and resume at its previous rate, and the sharpness of both edges is what distinguishes a gap in collection from a change in the world.
A second check points the same way, and it turns on how the thinning is distributed. A genuine lull is always selective: conference-driven material vanishes first, seasonal campaigns disappear, anything pegged to a product launch calendar goes with them, while the steady background carries on much as before. What survives inside these three months is nothing so uneven. It is a proportional slice, with the familiar categories sitting at close to the weights they hold elsewhere in the year. Uniform thinning across unrelated topics is the fingerprint of subtraction; selective thinning is the fingerprint of a quiet spell, and the second is simply not present.
The gap was found by looking at the shape rather than by reading anything. That is the only way it could have been found, and it is the reason the shape gets looked at first on every page in this series.
What does a hole look like from inside?
Like an ordinary week. The first entries filed inside the missing months:
- Safety of Our Data is 'Unknown' - IT SECURITY GURU
- Accenture, Endgame team up to become the Van Helsing of cybersecurity | Network World
- Mobile Security News Roundup: Top Stories From July
- Study Finds Ransomware Hits Almost 40 Percent of Enterprises - Network Security on Top Tech News
- Artificial Intelligence Is Key to Autonomous Cyber Security Future - Contributed Content on Top Tech News
A question about whether anybody knows where their data is. A partnership between two firms. A monthly roundup of mobile stories. A study putting ransomware at forty percent of enterprises. A piece about automation. If those five arrived in a week from any year of this archive they would be unremarkable, and that is the finding.
A record cannot report its own absences. Every entry present is complete, correctly dated and internally consistent; the missing ones leave no trace at all, because a thing that was never filed does not file a note saying so. Somebody reading these months entry by entry would find nothing wrong with any of them and would conclude that the autumn of 2016 was uneventful.
Which is the general point and the reason this year gets a page rather than a footnote. Gaps are detectable only in aggregate, only by comparison, and only by somebody who thought to look. Every other kind of error in a dataset announces itself eventually; an omission never does.
The thin months are the best described
This is the part that resists the comfortable explanation. Inside the gap, 82% of entries carry a written summary. Outside it, 24%. The months with a fifth of the volume have more than three times the descriptive coverage.
If the record had simply been running badly for a quarter — an interruption, a lapse in attention, a system not working — the entries captured during it would be expected to be worse rather than better. They are markedly better, and by a margin too large to be chance.
Two readings fit. One is that a smaller, more selective capture was operating in those months, taking fewer items and describing each properly. The other is that whatever supplied most of the year's volume was absent, leaving behind a residue that had always been better documented and was simply usually outnumbered.
This archive does not contain what is needed to choose between them, and the honest thing is to say so rather than pick the more satisfying one. What both readings share is the conclusion that matters: the gap is a property of collection, not of the field, and the entries inside it are evidence about a smaller population rather than a worse one.
It also means the summary rate for 2016 as a whole — 28% — is a blend of two different regimes and describes neither. Any figure that averages across a discontinuity has the same problem, and most published averages never mention whether they contain one.
Who supplied the year, inside and outside the gap?
611 entries name where they came from, across 216 distinct publications. Split by the gap, the difference is as sharp as the one in summaries: 80 publications inside the three months against 166 outside them.
Half the breadth, in a fifth of the volume. Proportionally the gap months draw on more distinct titles per entry than the rest of the year, which is the same signature the summaries showed: fewer items, each better attributed and better described.
The six most frequent publications across the year:
- 47helpnetsecurity.com
- 28itproportal.com
- 23securityaffairs.co
- 21itsecurityguru.org
- 21theregister.co.uk
- 19informationsecuritybuzz.com
Two independent measurements now point the same way, which is worth more than either alone. Whatever happened in those three months did not degrade the record; it reduced it, and what survived is a better-documented sample than the surrounding year rather than a damaged version of it.
That distinction has a practical edge. A degraded record should be discounted. A reduced one should be reweighted, and its contents are usable for anything that does not depend on how much of it there is — which is precisely the line this page has been drawing between rates, proportions and totals.
The year's defining event lands in the gap
The autumn of 2016 produced the outages that made everybody understand what a network of compromised domestic devices could do — cameras, recorders and routers, assembled into something that took large parts of the internet off the air for hours.
Botnet and denial-of-service subjects appear 61 times across the nine complete months and 5 times inside the three missing ones. October, the month it happened, holds 3.
So the single event this year is remembered for is almost entirely absent from this record of it. Not because it was ignored, and not because the subject was uninteresting — it appears throughout the rest of the year — but because it occurred during the weeks that were not captured.
The consequence for anybody counting is severe and specific. A subject measured across 2016 in this archive will be understated by whatever share of it happened in the autumn, and that share is not uniform across subjects. An event-driven category loses more than a continuous one, because continuous subjects are still being written about in the other nine months and events are not.
Which means the gap does not merely reduce this year. It distorts it, in the direction of making events look smaller relative to conditions than they already are — an effect running in the same direction as the bias every other page in this series has described, and adding to it.
What the autumn's outages actually were
Worth setting down plainly, since this archive records so little of it and the mechanism explains why the subject mattered far beyond the week it happened.
The material was domestic hardware. Security cameras, digital video recorders and home routers, sold on price, shipped with a short list of factory credentials, and reachable from the open internet over a remote-login protocol that predates almost everybody using it. Assembling them required no exploit and no vulnerability in the ordinary sense — scanning wide address ranges, trying a handful of username and password pairs, and keeping whatever answered.
The target was not the services that went dark. It was a company providing name resolution: the lookup that turns a typed address into a machine to connect to. Flooding it meant that services which were running perfectly well became unreachable, because nothing could find them. Users experienced an outage at companies that had suffered no outage.
Three parties, and none of them in the relationship you would expect. The owners of the cameras noticed nothing; their devices continued recording their hallways throughout. The affected businesses had no contractual link to the devices and no ability to influence them. And the intermediary between them was a dependency almost nobody had written down, because resolution is the kind of service you only think about when it stops.
That arrangement is why it became a reference point. Every subsequent argument about concentration — a single provider whose failure takes an unrelated set of organisations with it — has this shape, and this is the earliest instance in this archive where all three parties are clearly separable.
The remedy proposed afterwards was equally instructive, because there was not really one available to the victims. A business cannot patch a stranger's camera, cannot compel a manufacturer in another jurisdiction to ship an update, and cannot decline to depend on name resolution. What followed was regulatory: labelling schemes, procurement rules, proposals about default passwords in consumer equipment, and eventually legislation in several countries requiring unique credentials on shipped devices.
That is the pattern whenever harm falls on somebody with no relationship to its source. Contractual pressure works when a buyer can walk away; here the buyer of the insecure device suffered nothing and the party suffering had bought nothing. The only lever left sits with whoever can set conditions on manufacture, and reaching for it took years.
It is also, on the evidence above, the single worst-recorded major event in the collection. The month holds 3 entries about it. Anybody reconstructing the period from this archive alone would not know it had happened.
The subject that was not there yet
The European data protection regulation appears 0 times in 2016. It was adopted that April.
The following year it appears 64 times, and by the year after that it is the largest single subject in this archive, generating more entries than the attacks everybody remembers. The gap between adoption and attention is roughly eighteen months.
That interval is the useful part. A rule with a two-year implementation period produces almost nothing while the period is long, and everything once the deadline is close enough to organise around. Nobody writes readiness advice twenty-four months out because nobody is ready to read it.
The same shape should be expected of anything with a distant compliance date. The absence of writing about an obligation says nothing about whether the obligation exists, and the arrival of writing about it is a signal about calendars rather than about risk.
What can honestly be said about three quarters of a year?
A fair amount, provided the arithmetic is done on the part that exists.
Rates work. 237 entries a month across nine complete months is a real measurement and comparable with any other year measured the same way. It happens to sit close to the surrounding years, which is worth knowing.
Proportions within the complete months work. The share of the nine months given to any subject is calculated on a consistent base and is not affected by what is missing from the other three.
Totals do not work. 2,277 is a count of what survived, not of what the year contained, and every use of it in a comparison would understate 2016 by about a fifth.
Anything seasonal does not work. The missing months are consecutive and contain an entire quarter, so any question about how a subject behaved across the year has a hole in exactly the place that would answer it.
That last category is the one that catches people. A gap does not merely subtract; it subtracts from a particular place, and any analysis whose shape depends on that place is not weakened but invalidated.
Does this change the other pages?
In one place, and it is already stated there. The page for 2018 uses 2016 as part of a baseline for a decline, and it excludes these three months from the average rather than letting them drag it down. With them included the baseline falls by about fifty entries a month and the later decline looks gentler than it was.
Elsewhere the effect is smaller because the comparisons are proportional. A subject's share of the entries carrying a summary is unaffected by a gap that removed entries of both kinds, and every cross-year figure in this series is calculated that way for unrelated reasons that turn out to help here.
The general practice is worth naming since it applies well beyond this archive. When part of a series is known to be incomplete, the choice is between excluding it, interpolating across it, or showing it and saying so. The first hides a real observation, the second invents data, and the third is the only one that leaves the reader able to disagree.
What the year that is there holds
Across the nine complete months, the familiar background:
- 177the cloud
- 161mobile working
- 106ransomware
- 74the internet of things
- 66botnets and denial of service
- 6elections and political interference
The cloud leads, ransomware follows. Political interference appears 6 times, in the year of the election it is now permanently associated with — another event-shaped subject that a record like this one handles badly, and one whose most consequential months are partially inside the gap.
Political interference is the year's other event-shaped subject, and it behaves the same way. Compromised mailboxes, documents released in instalments to sustain coverage, and an argument about attribution that ran for years — none of which produces the continuous stream of writing that a condition does, and all of which peaks in weeks that this record covers thinly.
Ransomware at 106 is worth noting against what came later. Measured as a share of entries with a summary it runs about seven and a half percent here, which is a good deal higher than the two and a half of the year before. The climb that this series traces across seven years begins in these months rather than in the famous year that followed.
What the labels record
The eight most-used tags of 2016:
- 178Software Security
- 133Cyber Security Report
- 130Cyber Attack
- 88Data Breach
- 66Identity Theft
- 65Cyber Crime
- 65Hacking
- 61Hardware Security
These are still product categories, arranged by what a reader might be buying rather than by what might be happening to them. Software, network, mobile, hardware: the divisions of a catalogue, and the same ones the year before used.
What is not here is the year's own event. A network of compromised domestic devices taking services offline has no label in this list, because the taxonomy was drawn up for a world in which the things being secured belonged to the organisation securing them. A camera in somebody's house attacking a company neither of them had heard of does not fit any of these headings.
Classification lags in a specific direction, and it is always the same one. Categories exist for what was already understood when they were written, so the arrival of something genuinely new is invisible to a tag-based count by construction, and stays invisible until somebody adds a heading — which happens years later, if at all.
It is the same mechanism the page for 2017 measured on ransomware, where the label trailed the text by eighty-four entries. Here the lag is not eighty-four but total: there is no label at all, and the subject exists in this archive only in the words people wrote.
What 2016 settled
That consumer hardware is infrastructure. Devices sold on price, shipped with a default password and never updated turned out to be capable, in sufficient numbers, of removing access to large parts of the internet — which is the argument this site sets out about connected devices and who is responsible for them.
That availability can be attacked without touching the target. Nothing belonging to the affected services was compromised; what failed was something they all depended on, which is the earliest clear instance in this archive of the concentration argument that recurs every year afterwards.
That responsibility for a device outlives the sale of it. Nobody had previously needed an answer to who maintains a camera for the decade it hangs on a wall, because nothing much depended on it. The question arrived with the outages and has not been satisfactorily answered since; support periods, update commitments and end-of-life declarations remain voluntary in most markets, and a device bought this year will still be running, unpatched and reachable, long after the company that made it has stopped existing or has simply stopped caring.
And, for a reader of records rather than of the field: that a year can look complete and not be. Nothing about 2016 announces the absence. It was found by counting, and the only reason it is on this page rather than quietly averaged into a trend is that somebody compared three months against their neighbours.
Common questions
How many entries does this archive hold for 2016?
2,277, but the figure is misleading on its own. Three months of the year hold 148 entries between them against a rate of 237 a month elsewhere, so the record for 2016 is materially incomplete.
How much is missing?
Roughly 563 entries, if the missing months would otherwise have run at the rate of the other nine. That is an estimate built on an assumption, and it is the only kind of estimate available: nothing inside a record tells you what is not in it.
How was the gap noticed?
By the shape rather than by anything in the entries. Three consecutive months at 49 a month sit between months above two hundred, and a quarter does not lose four fifths of its volume and recover immediately afterwards.
Are the entries in those months poor quality?
The opposite, and it is the most surprising thing here. 82% of the entries inside the gap carry a written summary, against 24% outside it. Far fewer were captured and the ones that were are considerably better described.
Can the entries themselves show that something is missing?
No, and that is the practical lesson. They look like an ordinary week's filing — a mobile security roundup, a study about ransomware, a piece on automation, a vendor partnership. Nothing about material that is present indicates the absence of material that is not.
What does the gap cost 2016 specifically?
Its defining event. Botnet and denial-of-service subjects appear 61 times outside the missing months and 5 times inside them, with 3 in the month of the attacks that made the subject famous.
What was completely absent from 2016?
The European data protection regulation, at 0 entries. It was adopted that year. The following year it appears 64 times and by 2018 it is the largest single subject in the archive.
What fills the year that is there?
The usual background. The cloud leads at 177, then ransomware at 161. Neither is an event and both generate writing continuously, which is the pattern every year in this archive shows.
Should figures for this year be used at all?
Proportions within the nine complete months are usable and any total for 2016 is not. This page treats the year that way throughout: rates rather than counts, and the nine months rather than the twelve wherever the distinction matters.
Does the gap affect the other years?
Only where 2016 is used as a baseline. Cross-year comparisons elsewhere in this series exclude the missing months from any rate calculated for this year, and the pages that mention it say so rather than averaging across it.
Why not simply leave the year out?
Because an incomplete record is still evidence, and because a gap that is shown teaches something a clean series cannot: that collection failures and real declines are indistinguishable from a total, and that the only defence is to look at the shape.
Can these figures be checked?
Yes. Every count is computed from the archive when the page is built, the months treated as incomplete are named explicitly, and every rate says which months it was calculated over.
2016 in the archive
The 2,277 entries behind this page run from January 1, 2016 to December 30, 2016, drawn from 216 publications, with Aug, Sep, Oct incomplete.
Browse the archive by month, read the same treatment of 2015, 2017 or 2018, or search across every year.