Skip to content
The Cyber Security Place

What each guide turns on

24 subjects, drawing on 10,211 archive entries between them. Each line below is the finding the guide is built on rather than a description of the subject, because knowing what a piece argues is the only thing that helps you decide whether to read it.

  1. Data breaches918 entries

    Noticing takes roughly three times longer than stopping, and almost every improvement of the last decade landed on the shorter half.

  2. The national catalogue admitted it could not keep up. Severity scores stopped ranking work and started justifying it.

  3. Malware753 entries

    Most of what arrives is not novel and does not need to be: the same handful of families, delivered through channels that were already trusted.

  4. $15.9bn reported lost in a year, almost half to investment schemes, and no product in this industry touches any of it.

  5. Ransomware636 entries

    Payment rates collapsed and the crime did not: extortion moved from encrypting data to publishing it, which needs no decryption key and no restore to fail.

  6. Insider risk630 entries

    A careless incident costs $747,107 and a malicious one $742,125 — and the careless kind happens more than twice as often.

  7. The scarce resource is not budget but authority: responsibility for outcomes decided by somebody else.

  8. The outages that cost most were not attacks. A dependency bought without noticing takes more services down than any adversary.

  9. Phishing491 entries

    Two decades of training, and the share of breaches involving a person went up. The measure improved the click rate and not the outcome.

  10. The decade's win — encrypting the whole web — blinded the defenders. Around 90% of malware now arrives over an encrypted connection.

  11. People & skills408 entries

    The annual study stopped estimating the shortage, and 318 of 5,260 openings were genuinely entry-level.

  12. Machine identity402 entries

    Around 31% of identity breaches trace to a credential nobody on the team recognises, and 64% of secrets leaked in 2022 were still valid four years later.

  13. AI agents388 entries

    The incident rate is published as 65%, 88% and 97% because nobody agrees what counts. What the documented cases share is that the log kept the credential and never the instruction.

  14. The best-defended sector loses the most money, because the attacks that work there bypass the defences entirely and target the payment instruction.

  15. A model that assumes an identity to verify, arriving in estates where a majority of identities belong to nobody.

  16. The device outlives the company that made it, and the update that would fix it needs a business that no longer exists.

  17. The simulated phishing test measures who clicks, which is not the thing anybody wants to change and is the only thing it can report.

  18. The password stopped being the weak point and the recovery process became it, because resetting a factor is a conversation with a human.

  19. Healthcare233 entries

    The harm is measured in mortality, not in records. An outage in a hospital is a clinical event before it is a technical one.

  20. Nobody can say what is in their build, and the inventory that would answer it stopped being optional the morning a component turned malicious.

  21. Cyber insurance174 entries

    No law made mid-sized companies enforce a second factor on email. The underwriting questionnaire did it in about three years.

  22. State operations are 74% espionage and 28% financial. The sum exceeds a hundred, and with it goes the line between political and criminal.

  23. The announced catastrophe did not arrive; continuous quiet access did, and it is far harder to justify a budget against.

  24. The plan fails at the same three points every time: who decides, who speaks, and who has the telephone numbers.

Every guide is also available as Markdown: append .md to its path. Reviewed 2026-08-31.