Every question this site answers
496 of them, across 40 pages, at an average of 12.4 per page. They are listed here because a question is easier to recognise than a subject: you rarely arrive wanting to read about supply chain risk, you arrive wanting to know whether anybody can tell you what is in your build.
The openings are worth a glance before the list. what 145, how 83, is 54, why 52, does 44, are 22. The gap between the first and the second is the interesting part: definitional questions outnumber procedural ones by a wide margin, which is the shape of people deciding whether something matters to them before deciding what to do about it. A collection weighted the other way would be a manual, and a manual is only useful to somebody who has already made that first decision.
Each question is answered on the page it is listed under. Reviewed 2026-08-31.
Security answers: the questions that keep coming back20 questions
- How do you evaluate the security of a cloud provider?
- What should a company do about data on employees' phones?
- Where do you start with securing a large amount of data?
- Are the annual threat predictions worth reading?
- What does a board actually need from security?
- Is bring-your-own-device still a policy question?
- How do you find out whether staff credentials are already exposed?
- Is security awareness training worth the money?
- Why do two competent people give opposite security advice?
- What is the first thing a small organisation should do?
- How do I check a supplier's security without a security team?
- Should we manage employees' personal phones?
- Is multi-factor authentication enough?
- How often should we run a penetration test?
- Do we need cyber insurance?
- What logs should we keep, and for how long?
- Is it safe to use free security tools?
- How do we know our backups actually work?
- Who should security report to?
- What should we do first if we think we have been breached?
The password did not fail because it was weak14 questions
- Are passwords still a problem in 2026?
- Is SMS two-factor authentication worth having?
- What is the difference between an app code and a passkey?
- How widely are passkeys actually used?
- Do passkeys work if I lose my phone?
- What is prompt bombing?
- Should we still force staff to change passwords every 90 days?
- Are password managers safe?
- Is biometric authentication more secure?
- What attack does no authentication method stop?
- What should a small organisation do first?
- Does single sign-on make things better or worse?
- What is number matching and why was it added?
- Is passwordless the same as passkeys?
Where the ordinary rules invert14 questions
- Why is industrial equipment connected to the internet at all?
- What happened to water utilities in 2026?
- How sophisticated are these attacks?
- Why can't operational systems just be patched?
- What is the difference between IT and OT security?
- Is disconnecting a compromised system the right response?
- How old is the equipment in question?
- Did Colonial Pipeline show that attackers can control physical systems?
- What is network segmentation and why does it come up constantly here?
- Who is actually responsible for securing a small utility?
- Should a small utility buy specialist OT security products?
- Does the integrator who built the plant still have access?
- What should an operator do first?
- Does safety certification conflict with security updates?
The sector where a breach is measured in minutes14 questions
- Why is healthcare attacked so often?
- Do ransomware attacks on hospitals harm patients?
- What happens to hospitals near one that is attacked?
- How much does a healthcare breach cost?
- Why can't hospitals just switch to paper?
- Are medical devices the main problem?
- Why is medical equipment so old?
- Does HIPAA make hospitals secure?
- What should a hospital prioritise?
- Are smaller hospitals more exposed than large ones?
- Is patient data more valuable than card data?
- Should a hospital pay a ransom?
- Who is accountable for the harm at a neighbouring hospital?
- How long do these disruptions last?
The fraud that passes every check14 questions
- What is authorised push payment fraud?
- How large are payment losses now?
- Is banking security getting better or worse?
- Who pays when somebody is tricked into transferring money?
- Why does it matter that the receiving bank pays half?
- Does more security friction reduce fraud?
- Why is card fraud less discussed than it used to be?
- Are financial firms actually attacked more than other sectors?
- What is operational resilience regulation about?
- How does concentration risk apply to finance?
- What should a small business do to protect its payments?
- Can a cloned voice really fool somebody?
- Why do banks freeze accounts so aggressively now?
- Are cryptocurrency losses counted in these figures?
Cyber security in 2026: where the risk actually sits12 questions
- What is the most common way attackers get in?
- Should we prioritise patching or identity?
- How long do breaches go unnoticed?
- Does faster containment actually save money?
- What does a data breach cost on average?
- Are companies still paying ransoms?
- Is ransomware getting more or less common?
- Why has security awareness training not reduced human-caused breaches?
- Where should a small team start?
- How should I read the statistics vendors publish?
- Do the numbers on this page come from one source?
- What is the fastest way to find something specific here?
Ransomware in 2026: how attacks start, what they cost, and what reduces the damage12 questions
- What is ransomware?
- Do backups still protect you?
- How do attackers usually get in?
- We have multi-factor authentication. Are we covered?
- Should we pay the ransom?
- How much does an incident cost?
- How long until we are running again?
- Does cyber insurance cover this?
- Do we have to tell anyone?
- Is paying illegal?
- What single control helps most?
- Are small organisations actually targets?
Data breaches in 2026: what they cost, how long they hide, and the clocks that start12 questions
- What counts as a data breach?
- How long do breaches usually go unnoticed?
- Why do credential-driven breaches take so much longer to find?
- What does a breach cost?
- Which sector has it worst?
- How fast do we have to tell the regulator?
- Does the clock start when we find it or when we understand it?
- How much of our exposure comes from suppliers?
- What actually reduces the cost?
- Do we have to tell the people affected?
- What are the penalties?
- Is a misconfigured cloud bucket really a breach?
Phishing in 2026: why the old advice stopped working and what replaces it12 questions
- What is phishing?
- Does multi-factor authentication stop phishing?
- Why has phishing suddenly got harder to spot?
- How much more effective are AI-written lures?
- What is adversary-in-the-middle?
- What actually defeats credential phishing?
- Is awareness training worth doing?
- What is business email compromise?
- How should someone report a suspicious message?
- Do email filters still help?
- What about voice and text?
- What single change helps most?
Malware in 2026: most intrusions no longer involve a file12 questions
- What is malware in 2026?
- What does living off the land mean?
- Does antivirus still do anything?
- What is an infostealer?
- Why do stolen session cookies matter so much?
- What is fileless malware?
- What is malware-as-a-service?
- Why does the same infection get sold on?
- Does polymorphism defeat detection?
- What single control helps most against this?
- Is a reboot enough to clean an in-memory infection?
- How long does an infostealer take to do its work?
IoT security in 2026: the estate kept growing after everyone stopped talking about it12 questions
- What counts as an IoT device?
- Why are these devices so consistently insecure?
- How many devices ship with default credentials?
- What is the single most useful thing to do?
- How large have IoT botnets become?
- Does the EU Cyber Resilience Act change anything?
- What are the penalties under that regime?
- Should we just avoid connected devices?
- How do we find the devices we do not know about?
- What about medical and industrial equipment?
- Is a device safe once it is behind a firewall?
- How long should we expect firmware support to last?
Supply chain security in 2026: twelve decisions, fifteen hundred dependencies12 questions
- What counts as a supply chain attack?
- How many components does a typical application contain?
- How much malicious activity is on the package registries?
- What is typosquatting in this context?
- What is dependency confusion?
- Does an SBOM actually help?
- Is an SBOM enough on its own?
- What is the fastest thing to fix?
- How do managed service providers fit in?
- What does the Cyber Resilience Act require here?
- Can we audit our way out of this?
- What should a supplier questionnaire actually ask?
Security awareness in 2026: even a 4% click rate loses over twelve campaigns12 questions
- Does security awareness training work?
- Why do published figures disagree so widely?
- What click rate should we expect?
- Is the report rate a better metric than the click rate?
- Do phishing simulations do harm?
- Should people still be told to look for spelling mistakes?
- What is human risk management?
- What does NIS2 require on training?
- Does DORA require the same thing?
- What single control removes most of the exposure?
- If authentication is fixed, is training pointless?
- How often should refreshers run?
The argument is no longer whether to encrypt12 questions
- Is HTTPS enough to keep my browsing private?
- What percentage of web traffic is encrypted now?
- Does encryption help attackers?
- Should we decrypt and inspect traffic at work?
- What is Encrypted Client Hello?
- Are encryption backdoors technically possible?
- What is 'harvest now, decrypt later'?
- When do current encryption algorithms stop being safe?
- Has anyone actually migrated to post-quantum cryptography?
- Is a VPN worth paying for?
- Does encryption satisfy data protection obligations?
- What should a small organisation actually do about encryption?
The first hour is about not closing doors12 questions
- What should I do in the first hour of a security incident?
- Why is rebooting a machine such a bad idea?
- Should we disconnect the affected systems?
- Does having an incident response plan actually help?
- What is a tabletop exercise?
- Should we restore from backup straight away?
- Who should be told first?
- When do we have to notify a regulator?
- Do we need an incident response retainer?
- How do we know when the incident is over?
- What is threat hunting?
- Should the security team have authority to stop the business?
Everyone agrees, and almost nobody has finished12 questions
- What does zero trust actually mean?
- How many organisations have implemented it?
- Why is it taking so long?
- Does it actually reduce losses?
- Is a VPN zero trust?
- Which sectors are furthest along?
- Where should an organisation start?
- Does it mean employees are trusted less?
- What is least privilege and how does it relate?
- Can small organisations do this?
- What does it not solve?
- Is the term still useful?
Two clocks, running in opposite directions12 questions
- How many vulnerabilities are published each year?
- What proportion are ever actually exploited?
- How fast does exploitation start?
- And how fast do organisations patch?
- Is the national vulnerability database still enriching everything?
- Is that a failure?
- Should severity scores be used for prioritisation?
- What is a better ordering?
- Why has exploitation become the leading way in?
- Which equipment is being exploited?
- Is disclosure to blame for the speed?
- What should a small organisation do?
The accountability arrived before the authority12 questions
- Who does the security chief usually report to?
- Is personal liability a real concern now?
- Does that make the job unattractive?
- How much are organisations spending?
- Do boards think they are being informed well?
- Why does future-risk reporting fail?
- What does a good board update look like?
- How long should preparing one take?
- Should the security chief sit on the board?
- Who owns artificial intelligence risk?
- Is a bigger budget the answer to most problems?
- What is the single most useful change?
The record attack lasted thirty-five seconds12 questions
- How big is the largest recorded attack?
- Are enormous attacks becoming routine?
- Why do they do so little damage now?
- So what does take services down?
- How concentrated is the risk?
- Is multi-cloud the answer?
- What is worth doing instead?
- What is a degraded mode?
- Does a status page help?
- Are extortion threats around denial of service still common?
- Where do the botnets come from?
- Is regulation addressing concentration?
Seventy-four per cent espionage, twenty-eight per cent money12 questions
- How much of the problem is actually state actors?
- Do state actors steal money?
- Why does that matter to a defender?
- How do these intrusions usually start?
- Is attribution reliable?
- Does it matter who it was?
- Can insurance refuse to pay for a state attack?
- Did the predicted cyberwar happen?
- What is prepositioning?
- Do these actors use custom tools?
- What should an ordinary organisation actually do?
- Should smaller organisations worry at all?
The year they stopped counting the missing millions12 questions
- How many cybersecurity jobs are unfilled?
- So is there a shortage or not?
- Why are teams not simply hiring?
- Is it hard to get an entry-level job?
- Why did the junior roles disappear?
- What skill is most in demand?
- Do certifications help?
- Should we hire or buy?
- Where is buying clearly right?
- Is burnout as bad as people say?
- What actually retains people?
- How should a small organisation staff this?
Careless costs the same as malicious12 questions
- What does insider risk cost?
- Is a careless insider really as expensive as a malicious one?
- Then why does everyone focus on malice?
- What is an exploited insider?
- Are fake employees a real phenomenon?
- How would you notice one?
- When should a leaver's access be removed?
- What gets missed in offboarding?
- Does monitoring staff work?
- Is this security's problem or the manager's?
- What is the cheapest thing that helps?
- Does trusting people less actually work?
Nothing was hacked12 questions
- How much do individuals actually lose?
- Which scams take the most money?
- Which are the most common?
- Are people who fall for these careless?
- What is the single most useful habit?
- Why does waiting work so well?
- Where do romance scams begin?
- Can I get the money back?
- What should I do first if it has happened?
- Should I report it if the money is gone?
- Does a password manager or antivirus help?
- How do I protect an older relative?
The regulator nobody voted for12 questions
- What does cyber insurance actually cover?
- Why did insurers start demanding security controls?
- Is multi-factor authentication really mandatory?
- Are prices going up or down?
- How can it be cheaper and stricter at once?
- What is the war exclusion?
- Could a government statement void my cover?
- What most commonly voids a claim?
- Should a small organisation buy it?
- What should I check before signing?
- Does having a policy make an attack more likely?
- Is the insurer a good regulator?
The credential nobody remembers creating12 questions
- What is a non-human identity?
- How many are there?
- Why is this different from password security?
- What is the actual harm?
- Are leaked secrets actually exploited?
- Does deleting the file fix a leaked key?
- Why do they have so much access?
- Why not just revoke the ones nobody claims?
- What is an orphaned identity?
- Where should a team start?
- Does a secrets manager solve it?
- What single change helps most?
Application security in 2026: finding flaws was never the constraint12 questions
- What is security debt?
- Why does the backlog stop growing at a particular size?
- How much of the debt is our own code?
- Why do third-party flaws take longer to fix?
- Is generated code less secure than hand-written code?
- Does that mean assistants should not be used?
- Has shift left failed?
- What is reachability analysis?
- Which flaw classes recur most?
- How should a backlog be prioritised?
- What does the Cyber Resilience Act change here?
- What single metric is worth reporting to a board?
Cloud security in 2026: the perimeter is a permission list12 questions
- Who is responsible for security in the cloud?
- What is the single most common cause of cloud incidents?
- Why do misconfigurations persist when everybody knows about them?
- How much of the risk is identity rather than network?
- What is a non-human identity?
- Do leaked keys actually get used?
- Is the cloud less secure than a data centre?
- What is blast radius and why does it matter more here?
- Which controls actually bound the blast radius?
- Does multi-cloud improve resilience?
- Why is cloud logging so often incomplete?
- What should a cloud review check first?
Identity fraud in 2026: the applicant who never existed12 questions
- How large are identity fraud losses?
- Which category costs the most?
- Why is account takeover growing fastest?
- What is synthetic identity fraud?
- How much does a synthetic identity cost?
- Can deepfakes get through identity verification?
- Does liveness detection still work?
- Why not simply make verification stricter?
- Does a credit freeze help?
- Is identity theft protection worth paying for?
- Who carries the loss?
- What actually reduces the risk?
Compliance in 2026: four clocks, four starting guns12 questions
- How many incident reporting deadlines can one event trigger?
- What are the NIS2 deadlines?
- What are the DORA deadlines?
- Why is DORA's four hours so much shorter?
- Does reporting under one regime satisfy another?
- What does the Cyber Resilience Act add?
- What is the hardest part of incident reporting?
- What happens if we decide not to report?
- Are directors personally liable now?
- Does compliance make an organisation safer?
- Is certification worth the cost?
- What should exist before an incident happens?
AI security in 2026: the boundary that does not exist12 questions
- What is prompt injection?
- Why can it not simply be patched?
- What is the lethal trifecta?
- Is this only a problem for autonomous agents?
- How much confidential data is going into these services?
- What kind of data leaks most?
- Does a written AI policy reduce incidents?
- When do the EU AI Act obligations bite?
- What does the model supply chain add?
- Is machine learning better for defence or for attack?
- How should an agent be designed so that it cannot be turned?
- What should we ask a vendor selling an agent?
Network security in 2026: the box you bought to keep them out12 questions
- What counts as an edge device here?
- How large is the shift towards attacking them?
- How quickly are these flaws attacked?
- Is patching faster the answer?
- Why can these devices not be monitored like servers?
- Does the public catalogue of exploited flaws cover this?
- What about devices the manufacturer no longer supports?
- Who is actually exploiting these?
- Does zero trust help with this?
- How would we know if an appliance were already compromised?
- What is the single most effective control?
- How long should one of these devices last?
Mobile security in 2026: the endpoint you do not own12 questions
- How much actually happens to one work phone in a year?
- Why do text and voice lures work better than email?
- How common are text-message lures?
- Is a phone more or less secure than a laptop?
- What does device management software actually control?
- Has commercial spyware become a mainstream problem?
- Should personal phones hold work access at all?
- What is the risk from the phone number itself?
- Do passkeys on a phone improve or worsen this?
- What should happen when somebody loses their phone?
- Are official app stores safe?
- What is the single most useful control?
The security market in 2026: the part nobody audits12 questions
- How many security tools does an organisation actually run?
- How large is the market?
- Why do the numbers disagree so much?
- Is consolidation actually happening?
- Does spending more reduce risk?
- What does a funding round mean for a buyer?
- What happens to a product after acquisition?
- Are analyst rankings worth anything?
- How should a vendor-published statistic be read?
- What is the skills gap figure about?
- How do you buy so that leaving is possible?
- Is there any independently audited figure in this field?
Vendor news in 2026: what an announcement is evidence of12 questions
- Does a large funding round mean the company is safe to buy from?
- Why do two market reports give completely different deal totals for the same year?
- Is an analyst placement worth anything to a buyer?
- What is the difference between a partnership and an integration?
- How do I check whether a newly launched product is actually available?
- Are vendor threat reports trustworthy?
- Can a supplier be penalised for overstating its security?
- What does certification actually cover?
- My supplier was acquired. What should I do first?
- How many security tools does a typical enterprise run?
- Is consolidating onto fewer platforms safer?
- Which announcements are worth reading in full?
The security workforce in 2026: the shortage that was a budget12 questions
- Is there a cyber security skills shortage?
- How common is burnout in security work?
- Do people leave the security profession?
- Will more training courses close the gap?
- Why do security teams struggle to keep up with technology?
- What is the most common cause of unfilled security roles now?
- How many people should a security team have?
- Does automation reduce the workload?
- Is a security certification worth having?
- How should a small team decide what not to do?
- What is the first sign a security function is overloaded?
- Does hiring a CISO fix the problem?
BYOD was the rehearsal12 questions
- Is BYOD still a thing in 2026?
- What replaced BYOD as the unmanaged thing staff bring to work?
- How costly are breaches involving unsanctioned AI tools?
- What is dark data?
- Does deleting data actually reduce risk?
- How long should we keep customer data?
- Are logs an exception to data minimisation?
- Why do old backups and snapshots matter?
- Should we ban staff from using AI tools?
- How do you find data stores nobody remembers creating?
- Who should own data retention?
- What is the cheapest improvement available here?
A security timeline, 2014–2026: what was known, and when12 questions
- What was the most significant cyber security event of the last decade?
- Why do breach victim numbers keep changing?
- How long does it take to find out what actually happened in a breach?
- Was WannaCry preventable?
- What made NotPetya different from ransomware?
- What did SolarWinds change?
- Why is the XZ Utils backdoor considered a near miss?
- Was the 2024 CrowdStrike outage a cyber attack?
- Has the number of major incidents increased over time?
- What is the common thread across these events?
- Why does regulation appear in a security timeline?
- How should a timeline like this be used?
The words that are used to mean two things12 questions
- What is the difference between an incident and a breach?
- Why does a glossary matter more than it used to?
- What does 'managed' mean for a device?
- Is zero trust a product or an architecture?
- What is the difference between risk, threat and vulnerability?
- What does phishing-resistant actually require?
- Does an SBOM mean a document or a capability?
- Why is 'end of life' three dates?
- What is the lethal trifecta?
- Why is prompt injection not just another injection flaw?
- How should a definition be written into a contract?
- What should happen when two teams use one word differently?
What suppliers say about themselves, and what it is worth12 questions
- What does a directory listing actually tell you?
- Why do so many suppliers claim the same capabilities?
- How should a capability list be read?
- How do you shortlist when every candidate looks alike?
- Is a smaller supplier riskier?
- Should you buy through a reseller or direct?
- What should the first meeting cover?
- What is worth checking before contact?
- How useful is a pilot?
- What should a reference call ask?
- How current is this directory?
- Why are some listings missing?
Security calculators: the assumption is the answer12 questions
- What is a security calculator actually for?
- Why do vendor calculators always favour buying?
- Which input carries the result?
- What does a breach actually cost?
- How should a calculator be read?
- Is return on investment the right frame for security?
- What do you do when you have no data?
- What makes a calculator trustworthy?
- Should these numbers go in a board paper?
- Do the tools on this site need JavaScript?
- Are any of these figures measurements of your organisation?
- How do you build one that is worth using?