What each guide turns on
24 subjects, drawing on 10,211 archive entries between them. Each line below is the finding the guide is built on rather than a description of the subject, because knowing what a piece argues is the only thing that helps you decide whether to read it.
- Data breaches918 entries
Noticing takes roughly three times longer than stopping, and almost every improvement of the last decade landed on the shorter half.
- Vulnerabilities & patching872 entries
The national catalogue admitted it could not keep up. Severity scores stopped ranking work and started justifying it.
- Malware753 entries
Most of what arrives is not novel and does not need to be: the same handful of families, delivered through channels that were already trusted.
- Scams against people730 entries
$15.9bn reported lost in a year, almost half to investment schemes, and no product in this industry touches any of it.
- Ransomware636 entries
Payment rates collapsed and the crime did not: extortion moved from encrypting data to publishing it, which needs no decryption key and no restore to fail.
- Insider risk630 entries
A careless incident costs $747,107 and a malicious one $742,125 — and the careless kind happens more than twice as often.
- Security leadership611 entries
The scarce resource is not budget but authority: responsibility for outcomes decided by somebody else.
- Availability & resilience513 entries
The outages that cost most were not attacks. A dependency bought without noticing takes more services down than any adversary.
- Phishing491 entries
Two decades of training, and the share of breaches involving a person went up. The measure improved the click rate and not the outcome.
- Encryption & privacy421 entries
The decade's win — encrypting the whole web — blinded the defenders. Around 90% of malware now arrives over an encrypted connection.
- People & skills408 entries
The annual study stopped estimating the shortage, and 318 of 5,260 openings were genuinely entry-level.
- Machine identity402 entries
Around 31% of identity breaches trace to a credential nobody on the team recognises, and 64% of secrets leaked in 2022 were still valid four years later.
- AI agents388 entries
The incident rate is published as 65%, 88% and 97% because nobody agrees what counts. What the documented cases share is that the log kept the credential and never the instruction.
- Financial services316 entries
The best-defended sector loses the most money, because the attacks that work there bypass the defences entirely and target the payment instruction.
- Zero trust & remote access304 entries
A model that assumes an identity to verify, arriving in estates where a majority of identities belong to nobody.
- IoT & connected devices301 entries
The device outlives the company that made it, and the update that would fix it needs a business that no longer exists.
- Security awareness293 entries
The simulated phishing test measures who clicks, which is not the thing anybody wants to change and is the only thing it can report.
- Passwords & authentication276 entries
The password stopped being the weak point and the recovery process became it, because resetting a factor is a conversation with a human.
- Healthcare233 entries
The harm is measured in mortality, not in records. An outage in a hospital is a clinical event before it is a technical one.
- Supply chain risk187 entries
Nobody can say what is in their build, and the inventory that would answer it stopped being optional the morning a component turned malicious.
- Cyber insurance174 entries
No law made mid-sized companies enforce a second factor on email. The underwriting questionnaire did it in about three years.
- State actors & espionage174 entries
State operations are 74% espionage and 28% financial. The sum exceeds a hundred, and with it goes the line between political and criminal.
- Critical infrastructure114 entries
The announced catastrophe did not arrive; continuous quiet access did, and it is far harder to justify a budget against.
- Incident response66 entries
The plan fails at the same three points every time: who decides, who speaks, and who has the telephone numbers.
Every guide is also available as Markdown: append .md to its path. Reviewed 2026-08-31.