2018 in the archive: the year the record got smaller
A quarter fewer entries than the year before. Working out what that measures turns out to be a better question than the one it appears to answer.
Last reviewed September 3, 2026
- The year boundary is not where anything happened. The decline begins in September 2017 and runs past December 2018.
- The deadline explains a fraction. Regulation writing halved in pace; the year fell by 17% across the same date.
- Both obvious causes fail. Neither the deadline nor the number of publications survives being measured across seven years.
- Smaller, and better documented. 66% of 2018 carries a written summary — the highest proportion here.
The shape of four years, month by month
Forty-eight columns, one per month, from January 2016 to December 2019. The twelve belonging to 2018 are marked. Three faded columns in 2016 are months where this record is incomplete, and the section further down explains why they are shown rather than quietly dropped.
Red: the twelve months of 2018. Faded: Aug 2016, Sep 2016, Oct 2016, where the record is incomplete. Peak of the series 273; 2018 runs from 181 in Jan down to 114 in Nov.
Where does the decline actually begin?
Between August and September 2017. The month of Aug holds 209 entries; Sep holds 178. Nothing in the following twenty-eight months returns to the earlier level.
Averaged, the two regimes are 225 entries a month up to that point and 152 afterwards, a reduction of about 32%. Through 2019 the rate settles at 141, so the new level persists rather than recovering.
That matters because a fall of a quarter between two calendar years suggests something happened between them — a decision, an interruption, a change of circumstance dated to around the new year. Nothing did. The line was crossed in early autumn of the previous year, and December to January is simply where the counting restarts.
Did the deadline cause it?
It was the obvious explanation and it is worth stating before it is dismantled. The previous year produced a continuous stream of writing about a data protection regulation that had not yet applied. It applied from 25 May 2018. A subject that had sustained a year of countdown pieces should, on that account, stop producing them — taking a large slice of the field's output with it.
Half of that holds. Entries about the regulation run at 0.39 a day before the deadline and 0.19 a day after it, a reduction of about 51%. The countdown genre did end, more or less on schedule.
The other half does not. Across the same boundary the year's total moves from 5.38 entries a day to 4.47, a fall of about 17% — far too small to be carrying a decline of a quarter. And the regulation did not go away as a subject at all: counted as a share of entries with a written summary, regulation and compliance rise from 2.5% in 2015 to 9.9% in 2017 and 11.2% here, the highest of the three.
What changed was the genre rather than the subject. Countdown pieces stopped and enforcement pieces started, which is a substitution rather than a subtraction. The deadline is a real event with a real effect on what was written, and it is not the reason the record shrank.
Publishing that is the point of having tested it. A hypothesis that survives its own measurement is worth more than one that was never put at risk, and this one only partly survived.
The number that looked like the answer
How many publications each year is drawn from seemed to be it. Taken at three points the series reads as a clean narrowing, and it lines up with the decline almost exactly. Counted across every year this archive holds, it does not:
- 20152,997entries ·245publications
- 20162,277entries ·216publications
- 20172,368entries ·211publications
- 20181,758entries ·51publications
- 20191,687entries ·228publications
- 20201,891entries ·233publications
- 20211,628entries ·232publications
2018 sits at 51. Every other year falls between 211 and 245, and the year immediately after returns to 228 while volume stays at 1,687 — lower than 2018 itself. A quantity that recovers while the thing it supposedly explains keeps falling is not the explanation.
What separates 2018 from its neighbours is the tail rather than the core. The same handful of trade titles supplies most of both years. Where they differ is in occasional contributors: 2018 has 22 publications appearing exactly once, against 163 the following year. The concentrated middle is stable and the edge is missing.
That is a fact about how provenance was captured in one year, and this archive holds nothing capable of explaining it from the inside. It is worth stating precisely because it is the kind of detail that looks like a finding until it is checked against a longer run.
The general lesson is the one this page keeps arriving at from different directions. Three points selected from a series will nearly always describe a line, and the line will nearly always point where the person selecting them was already looking. The seventh point is what tests it, and here the seventh point removed the conclusion.
What happens when one publication supplies a quarter of a year?
The largest single source of 2018 accounts for 28% of every entry that names one. In 2015 no publication reached a tenth of the year.
A dependency of that size transfers editorial decisions upstream. What that outlet chose to cover on a Tuesday, how often it published, which subjects its readers were assumed to care about, and whether it took a fortnight off in August — all of it now shapes the record directly, and none of it is visible from inside the record.
None of that is a criticism of the outlets involved, several of which are among the more careful in the field. It describes what a derived record inherits: anybody counting anything in an aggregation is partly measuring the publishing schedules of whoever supplied it.
Read it as an illustration rather than a trend. On the evidence just set out, 2018 is the only year here that reaches this level of dependency.
A year with no second wind
The highest month of 2018 is Jan, its first, at 181. No month afterwards reaches it. The lowest is Nov at 114, and the twelve figures descend with only small interruptions between those two points.
That shape is unusual and worth dwelling on. The peak of 2015 falls in April and the peak of 2017 in May, both pushed up by something the field was reacting to. A year whose maximum is January contains no such moment: whatever raised the level happened before the year opened, and these twelve months are the decay curve.
It also settles a question the annual figure cannot. A total of 1,758 reads like a level — the rate at which this record ran during 2018 — and it is nothing of the kind. It is the average of a quantity that began the year near 181 a month and ended it near 114, so it describes no month in particular and the middle of a movement rather than a state.
Two samples from one slope, subtracted, yield a difference that looks like an event. That is the arithmetic behind the twenty-six percent this page opened with.
Cryptojacking arrived, and then left
Mining cryptocurrency on hardware belonging to somebody else is the one genuinely new subject of 2018. Its whole life is legible in five numbers:
- 22017
- 332018
- 82019
- 32020
- 42021
Nothing beforehand, a sharp peak, and then a decline to almost nothing over the following three years. Among entries carrying a summary it occupies 1.6% of 2018 and does not register at all in either earlier year.
The mechanics were mundane. A dozen lines of JavaScript embedded in a page, a wallet address to credit, a throttle so the visitor's fan did not give the game away, and a hashing loop that ran for as long as the tab stayed open. A handful of publishers adopted it openly as an alternative to advertising, complete with a consent prompt. The overwhelming majority of deployments asked nobody, sat on sites whose owners had themselves been compromised, and ceased when the best-known operator withdrew its script. The arithmetic was unglamorous even from the attacker's side: a busy site might yield a few dollars daily, which is precisely why it was run at scale and abandoned the moment the exchange rate moved.
The rise and the fall have the same cause, which is what makes it instructive. Mining in a browser was profitable when the currency was expensive and the scripts were easy to embed; it stopped being profitable when the price fell and the best-known script was withdrawn. The attack disappeared because the business case did, not because anybody defended against it particularly well.
Very few threats end that cleanly. Most persist because the underlying incentive persists, which is why the categories that dominate this archive in later years are the same ones that dominate it now. Cryptojacking is the exception that shows what the rule depends on: attacks are priced, and one that stops paying stops happening.
Ransomware went the other way
Measured as a share of entries carrying a written summary, so that the years are comparable, the subjects move like this:
- 2.5%9.9%11.2%regulation and compliance
- 11.8%14.6%10.2%the cloud
- 0.8%5.8%5.1%the internet of things
- 2.6%3.3%4.7%phishing
- 2.5%9.4%4.3%ransomware
- 0%0.1%1.6%cryptojacking
2015 · 2017 · 2018
Ransomware falls from 9.4% to 4.3%, roughly halving in the year after the one that made it famous. Nothing about the activity supports reading that as a retreat; what receded was the novelty, and with it the supply of things left to say.
This is the clearest warning on the page against treating coverage as a proxy for threat. A reader tracking the field through volume alone would have concluded in 2018 that ransomware was a diminishing problem, at the precise moment it was becoming the operational risk that would define the following decade — an argument this site sets out at length in its guide to what ransomware costs and how it gets in.
Phishing moves the opposite way and for a duller reason: it never had novelty to lose, so its share drifts upward as louder subjects exhaust themselves.
The famous breaches are less than one percent
2018 produced a hotel group losing hundreds of millions of guest records, an airline whose payment pages were altered to skim card details, a flaw in the processors underneath almost every machine in use, and a political data scandal that reached parliamentary committees on two continents. Their coverage here:
- 9Meltdown and Spectre
- 2The hotel group breach
- 2The airline breach
- 2Magecart
- 1Cambridge Analytica
15 entries between them, about 0.9% of the year. That is a smaller share than the equivalent events took in 2015, in a year with fewer entries to divide.
The processor flaw is the interesting one, because it should have been an exception. It affected essentially all computing hardware, the mitigation cost measurable performance, and the disclosure process itself became a story. It draws 9 entries, concentrated almost entirely in the opening weeks of the year.
The airline case deserves more than the entries it received, for a different reason. Nothing was extracted from a database. A script placed on the payment page copied card details as customers typed them, so the information was taken at the instant of entry and never sat anywhere waiting to be stolen. Every control designed around protecting stored records is irrelevant to that, which is part of why the category took years to be treated as its own problem rather than as a variety of website defacement.
Two entries is what a genuinely novel mechanism received in a year whose record was drawn from 51 publications. That is the cost of a narrow record stated concretely: not that anything was misreported, but that a small thing which turned out to matter had almost nowhere to appear.
Even a flaw of that reach produces a finite quantity of writing. It is explained, the patches are described, the performance cost is measured, and then the subject is complete regardless of how many machines remain affected. Coverage tracks how much there is to say, and every technical story eventually runs out of sentences.
The vocabulary moved upstairs
The tags applied to 2018 rank like this:
- 317Software Security
- 213Data Security
- 208Cyber Risk
- 204Cyber Security Strategy
- 204Data Breach
- 203Network Security
- 188Cyber security Survey
- 171Malware
Three years earlier the same list ran to identity theft, mobile security and hardware security — divisions of a product catalogue, arranged by what a buyer might purchase. The labels that have climbed into the top eight here and were absent from it then are Data Security, Cyber Risk, Cyber Security Strategy, Cyber security Survey, Malware.
Those are not technical categories. Risk, strategy and data protection are the terms used when the reader is a committee rather than an administrator, and their arrival at the top of a taxonomy is a change of addressee rather than a change of subject matter. A piece tagged network security tells somebody what to configure; a piece tagged cyber risk tells somebody what to approve.
The shift is consistent with everything else on this page. As the record narrowed to fewer publications, those publications were the ones whose commercial model depended on reaching people with budgets — and writing aimed at a budget holder uses the vocabulary of governance, not of configuration.
Whether the field itself moved that way is a separate question this archive cannot settle. What it can show is that the words the record was filed under changed, and that a subject index reflects who was being written for at least as much as what was happening.
There is a hole in this record
Three months in 2016 hold 148 entries between them — Aug at 36, Sep at 42, Oct at 70 — against neighbouring months above two hundred. The rest of 2016 averages 237 a month.
A quarter cannot lose four fifths of its volume and return to normal immediately afterwards. That is not a lull in the industry; it is an absence in the record, and the honest description is that this archive does not adequately cover those weeks.
It is shown on the chart, faded, rather than removed. Removing it would produce a cleaner picture that asserted something false — that the series is continuous and every column comparable. Averaging across it, which is the commoner treatment, would be worse: it drags the 2016 baseline down by about fifty entries a month and makes the later decline look gentler than it was.
Why is the smaller year better documented?
1,156 of the 1,758 entries from 2018 carry a written summary, which is 66% — a higher proportion than any earlier year in this archive, and considerably higher than 2015 at roughly a fifth.
Breadth and depth turn out to be independent. The record covers less of the field and holds more about each thing it covers, which is what happens when the sources feeding it narrow to a handful of publications that write in a consistent format.
For anything counted from text, that is a genuine improvement and a trap in the same movement. Subject counts for 2018 rest on far more material than those for 2015, so they are more reliable within the year and less comparable across years — which is why every cross-year figure on this page is calculated only among entries carrying a summary, in both years being compared.
What is this page actually measuring?
An instrument, mostly. The other pieces in this series measure attention and say so; this one is largely about the apparatus doing the measuring, because 2018 is the year in which the apparatus visibly changed.
Three things are established here and hold. The decline is continuous and begins in September 2017 rather than at the year boundary. Regulation as a share of the year rose rather than fell after its deadline passed. And the count of contributing publications, which looked like the mechanism, turns out to be a single anomalous value that the following year reverses.
Two things are not established. The first is what caused the decline: this page can eliminate the obvious candidates and cannot name a replacement, which is the honest end of the enquiry rather than a gap to be filled with the most plausible remaining story.
The second is whether any of it corresponds to a change in the world. Fewer entries about security is not evidence of less security activity, and this archive contains nothing capable of settling that in either direction.
What survives is the internal structure — proportions, ratios, the shape of a series, the relation between two subjects measured the same way — and the internal structure is where the findings on this page sit. The absolute totals belong to the record, and the record is a smaller thing in 2018 than it was.
What should a reader take from a page like this?
Three habits, and none of them is sophisticated. They are the questions somebody asks when they expect to be wrong, and this page found what it found only because it asked them of itself first.
Ask for the shape rather than the change. Any year-on-year figure should arrive with the monthly series behind it. A step and a slope reduce to the same pair of annual numbers, and they are different phenomena with different explanations. If the series is not offered, the difference has not been established — it has been calculated.
Ask what the denominator is made of. A count assembled from a changing set of contributors partly measures the contributors. That applies to breach registers whose membership grows, to incident statistics collected under a reporting duty that widens, and to vulnerability totals from cataloguing bodies that hire more staff. In each case a rising number is compatible with a static world.
Look for the holes before looking for the trend. A gap in collection and a real decline are indistinguishable in a total, and gaps are common because nobody publishes them. The three months faded on the chart above were found by noticing that a quarter had lost four fifths of its neighbours' volume and recovered instantly, which is not a thing quarters do.
The catalogue of figures this bears on is longer than it first appears. Published breach counts. Average detection intervals. Ransom payment averages. Phishing click-through rates. Patch latency medians. Vulnerability disclosure totals. Insurance claim frequencies. Exposed-record tallies, dwell times, mean cost per stolen record, and the annual questionnaires that supply a good many of them. Each is assembled from a population that shifts underneath it — who chose to respond, which threshold obliged somebody to file, which regulator acquired powers that season, how many bodies were collecting at all. Almost every one is quoted as though that population were fixed, and almost none prints its composition beside the number.
Underneath all three sits one preference. Ratios computed inside a single collection survive most of what is wrong with that collection, because whatever distorted the numerator distorted the denominator too. Absolute figures compared across collections survive very little. Nearly every durable finding in this series of pages is a proportion, and that is not a stylistic choice.
What 2018 settled
That a deadline arriving does not end a subject. The regulation applied, enforcement began, and the writing changed genre without reducing in quantity. Every compliance deadline since has behaved the same way, and treating one as a finish line remains a common planning error.
That hardware is in scope. The processor flaws established that a defect can sit beneath the operating system, be unpatchable in the ordinary sense, and require a performance sacrifice as its remedy — which is now a standard category rather than a surprise.
That payment pages are a target in their own right. Altering the checkout of a legitimate site to copy card details as they are typed does not require breaching a database, and it is the earliest form here of the argument this site makes about code arriving from somebody else's server.
And, for anybody reading this archive rather than the field it describes: that a year is not a unit of anything. The most useful finding on this page was produced by ignoring the boundary the page is named after.
Common questions
How many entries does this archive hold for 2018?
1,758, against 2,368 the year before — a fall of about a quarter. 1,156 of them carry a written summary, which is 66% and a higher proportion than any earlier year here.
Did security get quieter in 2018?
There is no reason to think so, and this archive cannot answer the question. What fell is the number of things filed, which is a property of the record rather than of the world. The rest of this page is about telling those two apart.
When does the decline actually start?
Not in 2018. Monthly volume steps down between Aug 2017 at 209 entries and Sep 2017 at 178, and never returns to the earlier level. The average runs 225 a month before that point and 152 after it.
Did the data protection deadline cause it?
No, though it was the obvious suspect. Writing about the regulation did roughly halve in pace once the deadline passed, down about 51%, but the year's total fell only about 17% across the same boundary — and regulation as a share of the year kept rising, from 9.9% in 2017 to 11.2% here.
So what does track the decline?
Nothing this archive can identify. The number of contributing publications looked like the answer until the following years were counted: 2018 draws on 51 titles while every other year here falls between 211 and 245, and 2019 returns to 228 while volume stays low. A single anomalous year cannot explain a decline that continues on both sides of it.
Why is 2018 unusual in how many publications it draws on?
The concentrated core is present in both years — the same handful of trade titles supplies most of each. What 2018 lacks is the tail: it has 22 publications contributing a single entry against 163 in 2019. That is a property of how provenance was captured, and this archive contains nothing that explains it from the inside.
Which month was busiest?
Jan, at 181, which is also the first month of the year. Every subsequent month is lower, and the lowest is Nov at 114. A year whose peak is January is a year in decline throughout.
What was new in 2018?
Cryptojacking — mining cryptocurrency on somebody else's hardware. It appears 33 times in 2018 against 2 the year before, and 8 the year after. It is the clearest example here of a subject that arrived, occupied the field for a few months and left.
Did ransomware keep growing?
It fell. Measured among entries carrying a written summary, ransomware runs at 9.4% in 2017 and 4.3% here — roughly half. A subject can dominate a year and then recede without the underlying activity doing anything of the kind.
How much of 2018 is its famous breaches?
15 entries, about 0.9% of the year. A hotel group, an airline, a processor-level flaw and a data-analytics scandal between them occupy less than one percent of what was filed.
Is there a gap in this record?
Yes, and it is visible. Three months in 2016 hold 148 entries between them against neighbours above two hundred each. That is an absence in the record rather than a quiet quarter, and it is named on this page rather than averaged away.
Why does a smaller year carry more written summaries?
Because breadth and depth are separate. 2018 draws on fewer publications and files fewer items, and a higher share of what it does file carries a summary — 66% here. Less of the field, recorded more fully.
Can these figures be checked?
Yes. Every number is computed from the archive when the page is built rather than typed in. Where a figure compares two years it is calculated on the same basis in both, and where the record is incomplete the page says so.
2018 in the archive
The 1,758 entries behind this page run from January 1, 2018 to December 31, 2018, drawn from 51 publications.
Browse the archive by month, read the same treatment of 2017 or 2015, or search across every year.