2021 in the archive: one subject, and where the record stops
The last year held here, the one in which a single subject took over, and the ordinary Tuesday on which the record simply ends.
Last reviewed September 3, 2026
- One entry in five. No subject reaches 19.4% in any other year here.
- The rise had a false ending. The share halved in 2018 before quadrupling from it.
- The label took six years. A tagging gap of 84 in 2017 is gone by 2021.
- The record ends mid-sentence. 9 days before a disclosure that shaped everything after it.
The arc of one subject, in seven years
Each column is a year, and the height is the share of that year's summarised entries mentioning ransomware. Shares rather than counts, so that a year with half the volume of another is still comparable to it.
Share of entries carrying a written summary. 2021 in red at 19.4%, against a low of 4.3% four years earlier.
Why did it dip in 2018?
Because the writing had run out, not because the attacks had. 2017 produced the two incidents that made the subject famous, and a novel mechanism generates a fixed quantity of explanation: how it spreads, what it encrypts, who should have patched, what to do differently. Once those are written, a second instance of the same shape produces a fraction of the output.
So the share halves the following year, and a reader tracking the field through volume would have recorded a receding problem. What was actually happening in those months was the change in business model that made everything afterwards possible: targets selected for their inability to tolerate downtime, ransoms negotiated rather than posted, and eventually the addition of publication as a second lever when encryption alone stopped working on organisations that kept backups.
None of that is novel in the way a self-spreading worm is novel. It is commercial refinement, and commercial refinement is close to unwritable — there is no mechanism to explain and no patch to recommend, only a slow change in who gets attacked and what they are asked for.
The dip is therefore the most instructive point on the chart. It is the moment when coverage and consequence pointed in opposite directions, and it lasted long enough that anybody sampling the field in 2018 or 2019 would have drawn the wrong conclusion with perfectly good data.
Did the classification ever catch up?
It did, and the interval is measurable. Counting entries that mention the subject against entries carrying a tag for it:
- 2017188mentions ·104tagged
- 2021315mentions ·319tagged
In 2017 the label trailed the text by 84 entries, which was the evidence for an argument made on that year's page: a taxonomy records the concerns of the moment it was designed and goes on constraining what can be counted long after those concerns have moved.
By 2021 the two are level, with the tag applied marginally more often than the word appears — which happens when a label becomes routine enough to be attached on the basis of what a piece is about rather than what it says.
Six years is the interval, and it is worth carrying as an estimate. That is roughly how long a classification scheme takes to absorb a category that did not exist when it was drawn up, which sets a floor on how quickly any tag-based measurement can register something genuinely new. Anybody counting an emerging subject by its label is reading a description of the past.
The famous incidents are still almost nothing
2021 produced the incidents that finally moved the subject onto front pages: a fuel pipeline shutdown that emptied filling stations across several states, a set of mail server flaws exploited against tens of thousands of organisations, and a compromise that reached its victims through the companies managing their systems for them.
- 10The mail server flaws
- 8The fuel pipeline shutdown
- 8The managed-services compromise
24 entries between them, or 1.5% of the year, against 315 for the category they belong to. The pattern holds exactly as it held in 2015 and 2018: events are rounding errors and conditions are the record.
The third of those is the one with the most durable lesson. Reaching victims through the companies contracted to administer their systems inverts the usual assumption about outsourcing: the provider was engaged precisely because it could reach everything, and that reach is what made it worth compromising. Delegating administration delegates the blast radius with it, and no contract clause changes the arithmetic. What a clause can do is decide who pays afterwards, which is a separate question that buyers routinely mistake for the first one.
There is a difference this time, and it is in the direction of the gap rather than its size. In earlier years the famous events were small because nothing connected them to a larger argument. Here they are small because the larger argument had already been made, continuously, for three years — the pipeline did not introduce the subject, it confirmed it, and confirmation is much less productive than introduction.
What did a fuel shortage do that argument could not?
It converted an operational risk into a queue. For most of the period covered by this archive, the case for treating availability as a security property had to be made by analogy: imagine the systems stopping, imagine what depends on them. In the spring of 2021 that stopped being hypothetical for several million people at once, most of whom had no interest in the mechanism.
Government action follows in the same year — 46 entries touch sanctions, executive orders or federal activity, which is the second largest subject here after the cloud. The sequence is legible: the harm becomes visible to people outside the field, and the response arrives through instruments the field does not control.
That is the pattern this site describes in its guide to critical infrastructure, and 2021 is where it becomes unarguable. An organisation can decide how much downtime it will tolerate right up until the point where somebody else's tolerance is what matters.
The archive registers the consequence more strongly than the event, which is consistent with everything else on this page. Eleven entries for the shutdown; forty-six for what governments did about it and things like it.
The rest of the year is the same background
Underneath the dominant subject, 2021 looks like every other year here:
- 126the cloud
- 46government action and sanctions
- 38the supply chain
- 24critical infrastructure
- 21zero trust
- 17staffing and burnout
- 12cyber insurance
- 6negotiation and payment
The cloud heads that list, which is worth stating carefully because it is not the largest subject of 2021 — ransomware is, by a distance. What the cloud does is never be absent: measured on a comparable basis it sits between 6% and 14.6% in every one of the seven years here, and it has never once been the leading subject of any of them.
Persistence and prominence are different properties, and the cloud has only ever had the first. A subject that is permanently second is invisible to anybody looking for what dominated a year, and it outlasts every subject that did.
Two of the smaller entries repay attention. Negotiation and payment appear 6 times and cyber insurance 12, in the year when both became central to how ransomware actually resolved. The commercial machinery around an attack — who negotiates, who pays, who reimburses, what a policy excludes — was decisive and barely written about.
That is a gap in the record rather than in the world, and it is the kind that is invisible unless somebody counts. Nothing about reading this archive would tell you that the insurance question was live in 2021; there are twelve entries.
The attackers acquired brand names
Named groups appear 75 times in 2021. A handful of recurring names, written about the way a trade publication writes about firms — what they charge, which sectors they avoid, whether they honour an agreement, who has taken over whose customers.
The apparatus behind those names is the reason the subject stopped being describable as malware. There are affiliates who rent the tooling and hand over a share of proceeds. There are leak sites with countdown timers, staged so that a portion of the stolen material is published to demonstrate that the rest exists. There are negotiation portals with support chat. There are press statements, occasional apologies, and stated rules about hospitals that are honoured unevenly and mostly for reputational reasons.
There is also rebranding, which is what makes counting them unreliable. A group under sufficient law-enforcement attention dissolves and reappears under a different name with the same people and the same code, so a table of group activity partly measures how often the marketing changed.
What all of that describes is a market with entry costs, specialisation and reputational pressure, and markets respond to incentives rather than to patching. The interventions that followed reflect it: sanctions on payment addresses, pressure on exchanges, insurance conditions, and arrests. Those are instruments for altering the economics of a business, and by 2021 that is what everybody involved had concluded they were dealing with.
The consequence for a defender is unwelcome and specific. An attacker running a business chooses targets by expected return, which means the question stops being whether you are interesting and becomes whether you are cheap — and the properties that make an organisation cheap to attack are the same unglamorous ones this archive has been recording for seven years.
What happened to the word breach?
It was replaced. Shares of summarised entries, six subjects across the seven years:
| Subject | 2015 | 2016 | 2017 | 2018 | 2019 | 2020 | 2021 |
|---|---|---|---|---|---|---|---|
| ransomware | 2.5% | 7.6% | 9.4% | 4.3% | 5.1% | 8.8% | 19.4% |
| breach | 12.4% | 13.8% | 16.1% | 17.5% | 14.3% | 7.4% | 6.7% |
| the cloud | 11.8% | 10.1% | 14.6% | 10.2% | 10.3% | 6% | 9.2% |
| phishing | 2.6% | 3.2% | 3.3% | 4.7% | 5.7% | 5.5% | 7.4% |
| mobile working | 14.3% | 10% | 8.9% | 6.2% | 5.2% | 4% | 3.9% |
| regulation | 2.5% | 4.6% | 9.9% | 11.2% | 4.5% | 2.7% | 2.1% |
The word breach leads 4 consecutive years and peaks at 17.5% in 2018. By 2021 it has fallen to 6.7%, while ransomware has travelled in the opposite direction. The two lines cross in 2020.
The events did not stop being breaches. Data was still taken and people were still notified. What changed is which word the field reached for, and it reached for the one that names the mechanism and the demand rather than the outcome — which is a more useful description for a reader deciding what to do, and a worse one for anybody counting incidents over time.
A subject index built on the earlier vocabulary would show a collapse in incidents across exactly the period when they were increasing. That is the sharpest instance in this archive of a measurement problem that has appeared in every one of these pages: the thing being counted is a word, and words move underneath the phenomena they describe.
It also explains why several of the subjects here look like they are declining. Mobile working falls from 14.3% to 3.9% without anybody deciding that phones had stopped mattering. The term simply stopped being the one people used, having been absorbed into descriptions that no longer need to mention it.
Where does a record end?
On 2021-11-30, and nothing about that day announces it. The final entries filed are:
- How to combat ransomware with visibility
- F secure and cyberpeace institute partnership to counter attacks against vulnerable communities
- Flipping the traditional security model on its head taking a data first approach to cybersecurity
- How sboms for cybersecurity reduce software vulnerabilities
- The true cost of rising cyber threats according to a cybersecurity cfo
A piece on visibility. A partnership announcement. An argument about inverting the usual security model. Something on inventories of software components. A survey of costs. It is an entirely ordinary Tuesday's filing, and the collection stops.
Records do not conclude. They are kept until something changes for whoever is keeping them, and the last day looks like the day before it because nobody knew it was the last day. Every archive anybody consults has this property somewhere, and the endpoint is almost never marked.
It has a practical consequence for anyone using one. The final months of a collection are systematically the least reliable part of it — not because the material is worse, but because nothing that happened afterwards has been allowed to revise them. Every other year in this archive has been read back over by the years that followed. 2021 has not.
Nine days
A flaw in a Java logging library, present in an enormous proportion of enterprise software and exploitable by causing an application to write a particular string to a log, was disclosed on 2021-12-09. That is 9 days after this archive's last entry. It appears in the collection 0 times.
The date is the one figure on this page not counted from the archive, for the obvious reason, and it is cited rather than derived.
Why it reached so far is worth a sentence, because it explains the panic rather than the severity. A logging library is a component nobody chooses deliberately: it arrives inside something else, which arrived inside something else, several layers down from anything an organisation believes it runs. The exposure was therefore not a list of affected products but a question about every product, and answering it required knowing what your software was made of — which almost nobody did.
What makes the coincidence worth a section is the fourth item in that final day's filing. It concerns inventories of software components — knowing which libraries are inside the products an organisation runs. Ten days later that would stop being a governance aspiration and become the only way to answer the question everybody was suddenly asking, which was whether they were affected.
Nobody on 2021-11-30 knew that. The piece was filed because it was a reasonable subject that week, among a partnership announcement and a cost survey, and it sat there being sensible and unurgent for nine days.
Which is the closing observation this archive supports better than any other: the material that turns out to matter is filed alongside the material that does not, in the same week, at the same size, with nothing to distinguish them. That was true of the exploit leak in April 2017, of ransomware at two percent in 2015, and it is true of the last entry here.
What the seven years show
Read end to end, the pattern that survives every year is the one about attention. Events are compact and conditions are continuous, so a record assembled week by week fills with conditions and reduces events to rounding errors — regardless of how much harm the events did.
The second is that novelty, not severity, sets the volume. The same category can halve in coverage while getting worse, as it did between 2017 and 2018, because what generates writing is having something new to say.
The third is that instruments change under you. Publication counts, summary coverage, tagging discipline and the composition of sources all move across these years, each producing apparent trends in what is being measured. A finding that has not been checked against the instrument is a finding about the instrument.
And the fourth, which is less comfortable: the subject that ended up dominating was visible from the start, at two and a half percent, indistinguishable from a dozen other things at two and a half percent that came to nothing. Recognising which of the small things matters is not a capability this record demonstrates anybody having.
Which year should somebody read first?
It depends on what the question is, and the five written pieces answer different ones.
2015 is the one to read for what a field looks like before it has decided what matters. It is the largest year here and the one nothing is remembered from — the events that are still named account for under two percent of it, and its busiest month contains none of them.
2017 is about the gap between where harm occurred and where attention went. It is the year of the attacks everybody remembers, and by volume it was a year about a compliance deadline.
2018 is the one about the instrument rather than the field, and it contains a conclusion that had to be withdrawn when more years were measured. Anybody interested in how a plausible finding fails is better served there than by the pages where nothing went wrong.
2020 is about displacement: what happens to everything else when one subject arrives that everybody has a reason to write about.
And this one is the arc of a single subject over seven years, including the four in the middle when it appeared to be receding.
Read together they make one argument, which is that a record of what was written is a record of what was writable. That is not the same as what happened, it is not useless either, and the difference between those two statements is most of what these pages are for.
The limits of the whole exercise
Every page in this series measures what one aggregation filed, and none of them measures what happened. The distinction has been stated on each of them and belongs at the end too, where it is easiest to forget.
2021 adds two of its own. It covers 11 months rather than twelve, so any absolute total for it is not comparable with a full year — which is why the argument here runs on shares. And 52% of its entries carry a written summary, so subject counts rest on partial text, as they do everywhere in this archive.
What survives those limits is what has survived them throughout: proportions inside a single year, ratios between subjects measured identically, and shapes across a series long enough that a single anomalous point cannot carry the conclusion. The years where this series reached further than that had to be corrected, which is the strongest argument for the restriction.
What 2021 settled
That ransomware is an economic system rather than a technique. By this year it has negotiators, affiliates, published victim lists, insurance interactions and a government response, and none of that is describable as a piece of malware.
That an attack on a private company is a public event when the company sits underneath something people use. The pipeline made the argument that a decade of writing about critical infrastructure had not, and it made it to an audience that had never read any of it.
That reaching customers through their suppliers works at scale. The managed-services compromise did to service providers what the previous December had done to software updates, and the supplier as the route in stops being a prediction at this point.
What 2021 did not settle is anything about what came next, because the record ends before it. The last nine days of this archive contain a disclosure it never saw, and the years since have been shaped by things filed somewhere else.
Common questions
How many entries does this archive hold for 2021?
1,628, across 11 months. The record stops on 2021-11-30, so 2021 is the only incomplete year here apart from the first.
What dominates 2021?
Ransomware, at 19.4% of the entries carrying a written summary — 165 of 850. That is roughly one entry in five, and the largest share any single subject reaches in any year of this archive.
How did that share develop?
From 2.5% in 2015 it climbs to 9.4% in 2017, falls back to 4.3% in 2018 once the novelty had gone, and then rises for three consecutive years to 19.4%. The dip in the middle is the part most likely to mislead anybody reading a short run of it.
Did the classification ever catch up with the subject?
Yes, and it took about six years. In 2017 this archive held 188 entries mentioning ransomware and 104 tagged for it, a gap of 84. By 2021 the figures are 315 and 319: the label now covers the subject completely.
How much of 2021 is its famous incidents?
24 entries, about 1.5% of the year. A fuel pipeline shutdown, a set of mail server flaws exploited at scale and a compromise reaching through managed service providers account between them for well under one entry in fifty.
Which subjects fill the rest of it?
The same background that fills every year here. The cloud leads at 126, followed by government action at 46 and the supply chain at 38. None of them is an event and all of them generate writing continuously.
When does this archive stop?
On 2021-11-30. There is no closing entry and nothing marks it as an ending — the last day looks like any other, with pieces on visibility, a partnership announcement, software inventories and a cost survey.
Does it cover the Java logging flaw?
No. It appears 0 times in the whole archive, because the disclosure came on 2021-12-09 — 9 days after the last entry. The vulnerability that shaped the following years falls outside this record entirely.
Was ransomware getting worse or just better covered?
This archive cannot separate those, and the honest answer is that both are consistent with what it shows. What it can establish is that the subject's share of writing quadrupled in three years while the number of contributing publications stayed roughly constant, so the change is not an artefact of who was supplying the record.
Why do the named events get so little coverage?
Because an event produces a finite amount of writing and a condition produces it indefinitely. That pattern holds in every year of this archive, and it is the single most consistent finding across all of them.
Is 2021 a good year to draw conclusions from?
With two cautions. It is 11 months rather than twelve, so any absolute total understates it, and 52% of its entries carry a written summary, which is average for this archive rather than good. Shares and ratios survive both; totals do not.
Can these figures be checked?
Yes. Every count is computed from the archive when the page is built. The one date not drawn from it — the disclosure nine days after the record stops — is declared as an external reference rather than presented as a count.
2021 in the archive
The 1,628 entries behind this page run from January 4, 2021 to November 30, 2021, drawn from 232 publications.
Browse the archive by month, read the same treatment of 2020, 2018, 2017 or 2015, or search across every year.