Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
awesome-annual-security-reports
A curated list of annual cyber security reports
https://github.com/jacobdjwilson/awesome-annual-security-reports
Last synced: 2 days ago
JSON representation
-
Threat Intelligence
- ENISA - [Threat Landscape Report](Annual%20Security%20Reports/2023/ENISA-Threat-Landscape-2023.pdf) (2023) - An annual summary of key cybersecurity threats, trends, and attack techniques. It examines threat actors, motivations, impacts, and suggests mitigation strategies.
- Google Cloud - [Threat Horizons Report](Annual%20Security%20Reports/2024/Google-Cloud-Threat-Horizons-Report-H12024.pdf) (2024) - Offers insights on cloud security risks and practical advice for businesses using cloud services, based on Google's research and expert knowledge.
- Microsoft - [Digital Defense Report](Annual%20Security%20Reports/2024/Microsoft-Digital-Defense-Report-2024.pdf) (2024) - Analyzes global cybersecurity trends, offering insights into threat actor tactics, emerging vulnerabilities, and strategies for improving digital defense.
- Blackpoint - [Annual Threat Report](Annual%20Security%20Reports/2024/Blackpoint-Cyber-Annual-Threat-Report-2024.pdf) (2024) - Analyzes current cyber threats, attack techniques, and emerging trends, providing actionable intelligence for organizations to enhance their security posture.
- CheckPoint - [Cybersecurity Report](Annual%20Security%20Reports/2024/CheckPoint-Cybersecurity-Report-2024.pdf) (2024) - Examines global cybersecurity trends, offering insights into attack vectors, threat actor tactics, and strategies for improving organizational cyber resilience.
- Cisco - [Talos Year In Review](Annual%20Security%20Reports/2023/Cisco-Talos-Year-In-Review-2023.pdf) (2023) - Provides a comprehensive analysis of cyber threats and attack trends observed by Cisco's threat intelligence team throughout the year.
- Flashpoint - [Global Threat Intelligence Report](Annual%20Security%20Reports/2024/Flashpoint-Threat-Intel-Report-2024.pdf) (2024) - A comprehensive analysis of global cyber threats, providing insights into threat actor motivations, tactics, and emerging attack trends.
- Flashpoint - [Midyear Cyber Threat Index](Annual%20Security%20Reports/2024/Flashpoint-Midyear-CTI-Index-2024.pdf) (2024) - Provides a snapshot of current cyber threat trends, offering insights into evolving attack patterns and threat actor activities.
- IBM - [X-Force Threat Intelligence Index](Annual%20Security%20Reports/2024/IBM-X-Force-Threat-Intelligence-Index-2024.pdf) (2024) - Provides a comprehensive analysis of global cyber threats, offering insights into attack trends, threat actor tactics, and industry-specific vulnerabilities.
- Rapid7 - [Mid-Year Threat Review](Annual%20Security%20Reports/2023/Rapid7-Mid-Year-Threat-Review-2023.pdf) (2023) - Provides a snapshot of current cyber threats and attack trends, offering insights into emerging vulnerabilities and mitigation strategies.
- Rapid7 - [Attack Intelligence Report](Annual%20Security%20Reports/2024/Rapid7-Attack-Intelligence-Report-2024.pdf) (2024) - Analyzes attack patterns and techniques, offering insights into adversary tactics and strategies for improving organizational cyber defense.
- Secureworks - [State of the Threat](Annual%20Security%20Reports/2024/Secureworks-State-of-the-Threat-Report-2024.pdf) (2024) - Provides a detailed analysis of the evolving cybersecurity landscape based on global intelligence gathering and incident response data.
- DeepInstinct - [Threat Landscape Report](Annual%20Security%20Reports/2023/Deep-Instinct-Cyber-Threat-Landscape-Report-2023.pdf) (2023) - Examines evolving cyber threats, offering insights into attack techniques, malware trends, and strategies for enhancing organizational cybersecurity.
- Expel - [Annual Threat Report](Annual%20Security%20Reports/2024/Expel-Annual-Threat-Report-2024.pdf) (2024) - Provides an overview of cyber threats and attack trends observed by Expel's security operations team throughout the year.
- WatchGuard - [Threat Report](Annual%20Security%20Reports/2024/WatchGuard-Threat-Report-2024.pdf) (2024) - Provides an analysis of current cyber threats and attack trends, offering insights into network security challenges and strategies for improving organizational cybersecurity.
- FBI - [Internet Crime Report](Annual%20Security%20Reports/2023/FBI-Internet-Crime-Report-2023.pdf) (2023) - Examines cybercrime complaints to protect the public, track trends, support investigations, and promote awareness of internet-facilitated crimes.
- CrowdStrike - [Threat Hunting Report](Annual%20Security%20Reports/2024/CrowdStrike-Threat-Hunting-Report-2024.pdf) (2024) - Provides comprehensive insights into over 245 advanced persistent threats (APTs) and adversary tactics through global threat monitoring and analysis.
- CrowdStrike - [Global Threat Report](Annual%20Security%20Reports/2024/Crowdstrike-Global-Threat-Report-2024.pdf) (2024) - Analyzes global cyber threats, offering insights into adversary tactics, emerging attack trends, and strategies for improving cyber defense.
- TrendMicro - [Annual Cybersecurity Threat Report](Annual%20Security%20Reports/2023/Trendmicro-Annual-Cybersecurity-Report-2023.pdf) (2023) - Analysis of global cyber threats, examining attack trends, emerging vulnerabilities, and strategies for enhancing organizational security posture.
- BD - [Product Security Annual Report](Annual%20Security%20Reports/2023/BD-Product-Security-Annual-Report-2023.pdf) (2023) - Highlights cybersecurity threats in healthcare, addressing the growing sophistication and frequency of cyberattacks through transparency, collaboration, and adherence to high security standards.
- Upstream - [Global Automotive Cybersecurity Report](Annual%20Security%20Reports/2024/Upstream-Global-Automotive-Cybersecurity-Report-2024.pdf) (2024) - Analysis of over 1,468 automotive cybersecurity incidents, monitoring trends across open, deep, and dark web forums to help safeguard the Smart Mobility ecosystem against emerging threats.
- White House - [Cybersecurity Posture of the United States](Annual%20Security%20Reports/2024/Whitehouse-Cybersecurity-Posture-of-the-United-States-2024.pdf) (2024) - Evaluates the U.S. cybersecurity posture, covering federal agency resilience against cyber threats, policy effectiveness, and readiness to counter emerging security risks affecting national interests.
- Ensign - [Cyber Threat Landscape Report](Annual%20Security%20Reports/2024/Ensign-Cyber-Threat-Landscape-Report-2024.pdf) (2024) - Analysis of key cyber threats across Asia, focusing on Singapore, Malaysia, Indonesia, South Korea, Australia, and Greater China.
- Fortinet - [Global Threat Landscape Report](Annual%20Security%20Reports/2023/Fortinet-Global-Threat-Report-2H-2023.pdf) (2023) - Analyzes global cyber threats and attack trends, offering insights into emerging vulnerabilities, malware variants, and strategies for improving organizational cybersecurity.
- RedCanary - [Threat Detection Report](Annual%20Security%20Reports/2024/RedCanary-Threat-Detection-Report-2024.pdf) (2024) - Examines current attack techniques and detection strategies, offering insights into improving organizational threat detection capabilities.
- ASD - [Cyber Threat Report](Annual%20Security%20Reports/2024/ASD-Cyber-Threat-Report-2024.pdf) (2024) - Insights into Australia’s evolving cyber threat landscape, attack trends, and defense strategies.
- US Department of Defense - [OSINT Strategy 2024–2028](Annual%20Security%20Reports/2024/USDoD-OSINT-Strategy-2024.pdf) (2024) - This strategy outlines the Department of Defense's approach to open-source intelligence (OSINT) as a vital resource for decision-makers and warfighters, emphasizing OSINT's role in enhancing situational awareness and operational effectiveness.
-
Surveys
-
Ransomware
- Spycloud - [Ransomware Defense Report](Annual%20Security%20Reports/2023/Spycloud-Ransomware-Defense-Report-2023.pdf) (2023) - This report examines ransomware defense strategies and trends across different sectors.
-
Industry Trends
- Splunk - [State of Security](Annual%20Security%20Reports/2023/Splunk-State-of-Security-2023.pdf) (2023) - This report provides an overview of the current state of security, including trends and challenges across different sectors.
-
Application Security
- Synopsys - [Global State of DevSecOps 2023](Annual%20Security%20Reports/2023/Synopsys-Global-State-of-DevSecOps-2023.pdf) (2023) - This report provides insights into the global state of DevSecOps practices and trends across different sectors.
-
-
AI and Emerging Technologies
- HiddenLayer - [AI Threat Report](Annual%20Security%20Reports/2024/HiddenLayer-AI-Threat-Landscape-Report-2024.pdf) (2024) - Provides insights into the AI threat landscape across various industries.
- Snyk - [AI Generated Code Security Report](Annual%20Security%20Reports/2023/Snyk-AI-Generated-Code-Security-Report-2023.pdf) (2023) - Examines the security implications of AI-generated code across different sectors.
- Zscaler - [ThreatLabz AI Security Report](Annual%20Security%20Reports/2024/Threatlabz-AI-Security-Report-2024.pdf) (2024) - Examines the intersection of artificial intelligence and cybersecurity, offering insights into AI-powered threats, defensive applications of AI, and strategies for securing AI systems and models.
- AICD - [Directors Introduction to AI](Annual%20Security%20Reports/2024/AICD-Directors-Introduction-to-AI-2024.pdf) (2024) - Provides an overview of artificial intelligence tailored for directors, highlighting its strategic implications, governance considerations, and best practices for AI implementation in organizations.
- Okta - [The State of Secure Identity](Annual%20Security%20Reports/2023/Okta-The-State-of-Secure-Identity-2023.pdf) (2023) - Drawing on billions of authentications, this report explores trends and methods of common identity attacks, the role of AI in identity security, and unique attack patterns across industries, regions, and company sizes.
- Zimperium - [Global Mobile Threat Report](Annual%20Security%20Reports/2024/Zimperium-Global-Mobile-Threat-Report-2024.pdf) (2024) Highlights a growing trend of attackers prioritizing mobile devices as a primary target, focusing on threats like phishing and "mishing" (mobile phishing) covering the enterprise mobile footprint, global threat landscape, and specific industries targeted by these attacks.
-
Threat Intelligence and Incident Response
- The Anti-Phishing Working Group (APWG) - A global coalition focused on unifying the global response to cybercrime.
- The Cyber Threat Alliance (CTA) - An industry-driven group of cybersecurity organizations that share threat intelligence and conduct collaborative research to combat cyber threats.
- The Forum of Incident Response and Security Teams (FIRST) - Provides platforms, means and tools for incident responders to always find the right partner and to collaborate efficiently.
- The Global Cyber Alliance (GCA) - An international, cross-sector effort dedicated to reducing cyber risk.
- The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) - Focuses on operational issues of Internet abuse including botnets, malware, spam, viruses, and mobile messaging abuse.
- Ponemon Institute - Considered the pre-eminent research center dedicated to privacy, data protection and information security policy.
-
Working Groups
- The Internet Engineering Task Force (IETF) - Develops and promotes internet standards, including those related to security.
- The Cloud Security Alliance (CSA) - Promotes best practices for providing security assurance within cloud computing.
- The Open Web Application Security Project (OWASP) - A professional community that produces research concerning web application security, made freely available to the online community.
- The Open Source Security Foundation (OpenSSF) - A cross-industry collaboration to improve the security of open source software.
- Industrial Control Systems Joint Working Group (ICSJWG) - Facilitates information sharing and collaboration for cybersecurity in industrial control systems.
-
Policy and Advocacy
- World Economic Forum (Centre for Cybersecurity) - A global initiative that brings together stakeholders from industry, government, and academia to improve cybersecurity globally and secure the digital economy.
- The Rand Corporation - An American not-for-profit organization which conducts research and analysis on various aspects of cybersecurity and cyber policy focused on national security.
- Electronic Frontier Foundation (EFF) - A non-profit organization defending civil liberties in the digital world, including privacy and cybersecurity issues.
- The Internet Security Alliance (ISA) - A multi-sector trade association focused on thought leadership, policy advocacy, and standards development for cybersecurity.
- Center for Strategic and International Studies (CSIS) - Technology Policy Program - A think tank with a Technology Policy Program that conducts research and provides insights into technology and cybersecurity policies.
-
Resources
-
Government and Non-profits
- Australian Cyber Security Centre (ACSC) - Provides cyber security advice and support to Australian businesses and individuals.
- Canadian Centre for Cyber Security - Canada's national authority on cybersecurity.
- Cyber Peace Institute - A non-profit organization focused on reducing the impact of cyberattacks on civilians and promoting peace in cyberspace by supporting international cooperation and collective action.
- European Union Agency for Cybersecurity (ENISA) - A European Union agency that contributes to EU cybersecurity policy, enhances trust in digital services, and supports incident response capabilities across Europe.
- National Cyber Security Centre (NCSC) - The UK's technical authority for cyber incidents.
- National Institute of Standards and Technology (NIST) - A U.S. agency that develops cybersecurity standards and guidelines.
- German Federal Office for Information Security (BSI) - Germany's national cyber security authority providing IT security services and guidance.
- Internet Security Research Group (ISRG) - A non-profit organization focused on reducing financial, technological, and educational barriers to secure communication over the Internet.
- Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC) - Japan's central organization for national cybersecurity strategy and incident response.
- Korean Internet & Security Agency (KISA) - South Korea's government agency dedicated to promoting cybersecurity and a safer internet environment.
- National Cyber Security Centre - Netherlands (NCSC-NL) - The Dutch national cyber security center providing guidance and incident response.
- Norwegian National Security Authority (NSM) - Norway's expert body for information and object security, providing guidance and incident response capabilities.
- Singapore Cyber Security Agency (CSA) - Singapore's national agency overseeing cybersecurity strategy and development.
- MITRE Corporation - an American not-for-profit organization which conducts research and development supporting various U.S. government agencies.
- Cybersecurity and Infrastructure Security Agency (CISA) - A U.S. government agency responsible for enhancing the security and resilience of the nation's critical infrastructure.
- Europol - European Cybercrime Centre (EC3) - A strategic alliance focused on combating cybercrime within the European Union.
- Cybersecurity Forum Initiative (CSFI) - An American non-profit organization that promotes cybersecurity awareness and research.
- Center for Internet Security (CIS) - An American non-profit organization that provides cybersecurity solutions and best practices.
-
Working Groups
- Industrial Control Systems Joint Working Group (ICSJWG) - Facilitates information sharing and collaboration for cybersecurity in industrial control systems.
- Web Application Security Consortium (WASC) - An international group of experts, industry practitioners, and organizational representatives who produce security standards and research.
-
-
Reports
-
Analysis
- Trellix - [Advanced Threat Research Report](Annual%20Security%20Reports/2024/Trelllix-Advanced-Threat-Research-Report-2024.pdf) (2024) - This report provides highlights insights, intelligence, and guidance gleaned from multiple sources of critical data on cybersecurity threats.
- Microsoft - [Digital Defense Report](Annual%20Security%20Reports/2023/Microsoft-Digital-Defense-Report-2023.pdf) (2023) - This comprehensive report analyzes global cybersecurity trends, offering insights into threat actor tactics, emerging vulnerabilities, and strategies for improving digital defense.
- Cofense - [Annual State of Email Security](Annual%20Security%20Reports/2024/Cofense-Annual-State-of-Email-Security-2024.pdf) (2024) - This report focuses on email-based threats, phishing trends, and strategies for improving organizational email security posture.
- CrowdStrike - [Threat Hunting Report](Annual%20Security%20Reports/2023/Crowdstrike-Threat-Hunting-Report-2023.pdf) (2023) - The Threat Hunting Report provides insights into advanced persistent threats, adversary tactics, and proactive threat hunting methodologies.
- CrowdStrike - [Global Threat Report](Annual%20Security%20Reports/2024/Crowdstrike-Global-Threat-Report-2024.pdf) (2024) - This comprehensive report analyzes global cyber threats, offering insights into adversary tactics, emerging attack trends, and strategies for improving cyber defense.
- BKA - [Bundeslagebild Cybercrime 2023](Annual%20Security%20Reports/2023/Bundeslagebild-Cybercrime-2023.pdf) (2023) - This report provides an overview of cybercrime trends in Germany, offering insights into attack patterns, perpetrator profiles, and law enforcement responses.
- DNSFilter - [Annual Security Report](Annual%20Security%20Reports/2024/DNSFilter-Annual-Security-Report-2024.pdf) (2024) - This report focuses on DNS-based threats and security trends, providing insights into domain-based attacks and strategies for improving network security.
- Veeam - [Ransomware Trends Report Executive Summary](Annual%20Security%20Reports/2023/Veeam-Ransomware-Trends-2023.pdf) (2023) - The Ransomware Trends Report provides an overview of current ransomware attack patterns, data recovery challenges, and strategies for improving organizational ransomware preparedness and resilience.
- Nucleus - [State of Vulnerability Management](Annual%20Security%20Reports/2023/Nucleus-State-of-Vuln-Management-2023.pdf) (2023) - This report examines the current state of vulnerability management practices, highlighting challenges, trends, and best practices in identifying and addressing security vulnerabilities.
- Dragos - [ICS/OT Cybersecurity Year In Review Report](Annual%20Security%20Reports/2023/Dragos-Year-In-Review-Report-2023.pdf) (2023) - The ICS/OT Cybersecurity Year In Review Report examines threats and trends specific to industrial control systems and operational technology environments.
- Duo - [Trusted Access Report](Annual%20Security%20Reports/2024/Duo-Trusted-Access-Report-2024.pdf) (2024) - This report analyzes trends in authentication and access management, offering insights into multi-factor authentication adoption and secure access strategies.
- Fortinet - [Global Threat Landscape Report](Annual%20Security%20Reports/2023/Fortinet-Global-Threat-Report-2023.pdf) (2023) - This report analyzes global cyber threats and attack trends, offering insights into emerging vulnerabilities, malware variants, and strategies for improving organizational cybersecurity.
- Horizon3.ai - [Proactive Cybersecurity Unleashed](Annual%20Security%20Reports/2023/Horizon3-Proactive-Cybersecurity-Unleashed-2023.pdf) (2023) - This report focuses on proactive cybersecurity strategies, offering insights into threat hunting, vulnerability assessment, and offensive security techniques.
- Huntress - [Huntress SMB Threat Report](Annual%20Security%20Reports/2023/Huntress-SMB-Threat-Report-2023.pdf) (2023) - The SMB Threat Report examines cyber threats specifically targeting small and medium-sized businesses, offering insights into attack trends and mitigation strategies.
- Mandiant - [MTrends Special Report](Annual%20Security%20Reports/2024/Mandiant-M-Trends-2024.pdf) (2024) - The MTrends Special Report offers insights into advanced persistent threats, emerging attack techniques, and strategies for improving organizational cyber defense.
- NCC Group - [Threat Monitor Report](Annual%20Security%20Reports/2023/NCCGroup-Threat-Monitor-Report-2023.pdf) (2023) - The Threat Monitor Report provides an analysis of current cyber threats, offering insights into attack trends, vulnerabilities, and strategies for improving organizational cybersecurity.
- PaloAlto - [Unit 42 Attack Surface Threat Report](Annual%20Security%20Reports/2023/PaloAlto-Unit42-ASM-Threat-Report-2023.pdf) (2023) - This report examines attack surface vulnerabilities and emerging threats, offering insights into strategies for reducing organizational attack surfaces.
- Proofpoint - [State of the Phish](Annual%20Security%20Reports/2024/Proofpoint-State-of-the-Phish-2024.pdf) (2024) - The State of the Phish report analyzes phishing trends, social engineering tactics, and strategies for improving organizational resilience against email-based threats.
- Proofpoint - [Human Factor Report](Annual%20Security%20Reports/2023/Proofpoint-Human-Factor-Report-2023.pdf) (2023) - This report focuses on the human element in cybersecurity, examining social engineering tactics, insider threats, and strategies for improving security awareness.
- Secureworks - [State of the Threat](Annual%20Security%20Reports/2023/Secureworks-State-of-the-Threat-Report-2023.pdf) (2023) - This report provides an overview of the current threat landscape, offering insights into emerging attack trends, threat actor motivations, and strategies for improving cyber defense.
- Guidepoint - [GRIT Ransomware Annual Report](Annual%20Security%20Reports/2023/Guidepoint-Ransomware-Annual_Report-2023.pdf) (2023) - The GRIT Ransomware Annual Report offers a comprehensive analysis of ransomware trends, attack techniques, and mitigation strategies, providing valuable insights for organizations to enhance their ransomware resilience.
- Slashnext - [State of Phishing 2023](Annual%20Security%20Reports/2023/SlashNext-The-State-of-Phishing-Report-2023.pdf) (2023) - The State of Phishing report analyzes current phishing trends, techniques, and mitigation strategies, offering insights into protecting against email-based threats.
- Veracode - [State of Software Security](Annual%20Security%20Reports/2024/Veracode-State-of-Software-Security-Report-2024.pdf) (2024) - This report examines trends in application security, offering insights into common vulnerabilities, secure development practices, and strategies for improving software security throughout the development lifecycle.
- SonicWall - [Cyber Threat Report](Annual%20Security%20Reports/2024/SonicWall-Cyber-Threat-Report-2024.pdf) (2024) - This comprehensive report examines global cyber threats, offering insights into malware trends, attack vectors, and strategies for improving organizational cybersecurity.
- Sophos - [Threat Report](Annual%20Security%20Reports/2024/Sophos-Threat-Report-2024.pdf) (2024) - The Threat Report provides an analysis of current cyber threats and attack trends, offering insights into emerging vulnerabilities and strategies for improving cyber defense.
- Thales - [Data Threat Report](Annual%20Security%20Reports/2024/Thales-Data-Threat-Report-2024.pdf) (2024) - The Data Threat Report analyzes current trends in data security, offering insights into emerging threats, compliance challenges, and strategies for protecting sensitive information.
- Trellix - [Advanced Threat Research Report](Annual%20Security%20Reports/2023/Trelllix-Advanced-Threat-Research-Report-2023.pdf) (2023) - This report provides in-depth analysis of advanced cyber threats, offering insights into emerging attack techniques, malware trends, and strategies for improving organizational cyber resilience.
- IBM - [Cost of a Data Breach Report](Annual%20Security%20Reports/2023/IBM-Cost-of-a-Data-Breach-Report-2023.pdf) (2023) - The Cost of a Data Breach Report provides an in-depth analysis of the financial impact of data breaches, offering insights into breach causes, mitigation strategies, and the long-term consequences of security incidents.
- DataGrail - [Privacy Trends 2024](Annual%20Security%20Reports/2024/DataGrail-Privacy-Trends-2024.pdf) (2024) - DataGrail's report examines the current state of privacy, including emerging regulations, challenges, and best practices across different sectors.
- ISACA - [Privacy in Practice](Annual%20Security%20Reports/2024/ISACA-Privacy-in-Practice-2024.pdf) (2024) - This report analyzes trends in privacy staffing, budgets, awareness training, breaches, and privacy by design, offering insights to help organizations improve their privacy programs.
- NCC Group - [Annual Research Report](Annual%20Security%20Reports/2023/NCCGroup-Annual-Research-Report-2023.pdf) (2023) - The Annual Research Report provides insights into cutting-edge cybersecurity research, emerging threats, and innovative defense strategies across various industries and technologies.
- Mandiant - [MTrends Special Report](Annual%20Security%20Reports/2024/Mandiant-M-Trends-2024.pdf) (2024) - The MTrends Special Report offers insights into advanced persistent threats, emerging attack techniques, and strategies for improving organizational cyber defense.
-
Surveys
- ISC2 - [Cyberthreat Defense Report](Annual%20Security%20Reports/2024/ISC2-Cyberthreat-Defense-Report-2024.pdf) (2024) - ISC2's report examines the current state of cyberthreat defense, including emerging threats and defense strategies across various industries.
- Cobalt - [State of Pentesting](Annual%20Security%20Reports/2024/Cobalt-State-of-Pentesting-2024.pdf) (2024) - This report offers an overview of the current state of penetration testing, including trends, challenges, and best practices across various industries.
- Accenture - [State of Cybersecurity Resilience](Annual%20Security%20Reports/2023/Accenture-State-of-Cybersecurity-2023.pdf) (2023) - This report provides insights into the state of cybersecurity resilience across various industries, highlighting key trends and challenges faced by organizations.
- Fortra - [Penetration Testing Report](Annual%20Security%20Reports/2023/Fortra-Pentesting-Report-2023.pdf) (2023) - Fortra's report provides insights into the current landscape of penetration testing, including common vulnerabilities and industry-specific challenges.
- Forrester - [The State Of Vulnerability Risk Management](https://reprints2.forrester.com/#/assets/2/1730/RES179028/report) (2023) - Forrester's report provides insights into vulnerability risk management practices and trends across various industries.
- Mend - [State of Supply Chain Threats](Annual%20Security%20Reports/2023/Mend-State-of-Supply-Chain-Threats.pdf) (2023) - This report examines the current state of supply chain threats and vulnerabilities across different sectors.
-
-
Industry Trends
- Splunk - [State of Security](Annual%20Security%20Reports/2024/Splunk-State-of-Security-2024.pdf) (2024) - Provides an overview of the current state of security, including trends and challenges across different sectors.
- Deloitte - [Future of Cyber Survey](Annual%20Security%20Reports/2023/Deloitte-Future-of-Cyber-Survey-2023.pdf) (2023) -Explores the future of cybersecurity, providing insights into emerging trends, technologies, and strategies across different sectors.
- Proofpoint - [Voice of the CISO Report](Annual%20Security%20Reports/2024/Proofpoint-Voice-of-the-CISO-Report-2024.pdf) (2024) - Insights into the perspectives and challenges faced by Chief Information Security Officers across different sectors.
- PwC - [Global Digital Trust Insights](Annual%20Security%20Reports/2024/PWC-Global-Digital-Trust-Insights-Report-2024.pdf) (2024) - Examines global trends in digital trust and cybersecurity across various industries.
- Aon - [Intangible vs. Tangible Risk Report](Annual%20Security%20Reports/2024/Aon-Intangible-vs-Tangible-Risk-Report-2024.pdf) (2024) - Analyzes cyber and enterprise risk management trends from a survey of over 2,300 respondents across global regions, providing insights into the evolving landscape of tangible and intangible risks.
- KnowBe4 - [Cybersecurity Culture Report](Annual%20Security%20Reports/2024/KnowBe4-Cybersecurity-Culture-Report-2024.pdf) (2024) - Explores the state of cybersecurity culture in organizations, highlighting trends and best practices across different sectors.
- Norton - [Cyber Safety Insights Report](Annual%20Security%20Reports/2023/Norton-Cyber-Safety-Insights-Report-2023.pdf) (2023) - Provides insights into consumer cyber safety trends and challenges across various industries.
- USTelecom - [Cybersecurity Culture](Annual%20Security%20Reports/2023/USTelecom-Cybersecurity-Culture-2023.pdf) (2023) - Examines the state of cybersecurity culture in the telecommunications industry and related sectors.
- Verizon - [Mobile Security Index](Annual%20Security%20Reports/2024/Verizon-Mobile-Security-Index-2024.pdf) (2024) - Provides insights into mobile security trends and challenges across various industries.
- World Economic Forum - [Global Cybersecurity Outlook](Annual%20Security%20Reports/2024/WEF-Global-Cybersecurity-Outlook-2024.pdf) (2024) - A global perspective on cybersecurity trends and challenges across different sectors.
- Vanta - [State of Trust Report](Annual%20Security%20Reports/2024/Vanta-State-of-Trust-Report-2024.pdf) (2024) - Explores the growing challenges in building and maintaining trust for organizations, focusing on security risks, compliance burdens, and the increasing third-party vendor risks.
- SANS - [SANS Cyber Threat Intelligence Survey](Annual%20Security%20Reports/2023/SANS-cyber-threat-intelligence-survey-2023.pdf) (2023) - Provides insights into the current state of cyber threat intelligence across different sectors.
- FERMA - [Global Risk Manager Survey Report](Annual%20Security%20Reports/2024/FERMA-Global-Risk-Manager-Survey-Report-2024.pdf) (2024) - Analysis of global risk management practices across 77 countries and six regional associations.
-
Application Security
- BlackDuck - [Global State of DevSecOps](Annual%20Security%20Reports/2023/BlackDuck-Global-State-of-DevSecOps-2023.pdf) (2024) - Provides insights into the global state of DevSecOps practices and trends across different sectors.
- Checkmarx - [Future of Application Security](Annual%20Security%20Reports/2024/Checkmarx-Future-of-Application-Security-2024.pdf) (2024) - Reveals how key stakeholders are responding to the challenges in Application Security from a broad range of industries globally.
- Checkmarx - [State of Software Supply Chain Security](Annual%20Security%20Reports/2024/Checkmarx-State-of-Software-Supply-Chain-Security-2024.pdf) (2024) - Provides insights into current trends in supply chain threats across industries such as banking and finance, insurance, software, technology, engineering, manufacturing, industrial, and public sector.
- Snyk - [State of Open Source Security](Annual%20Security%20Reports/2023/Snyk-State-of-Open-Source-Security-2023.pdf) (2023) - Examines the current state of open source security, including trends and challenges across various industries.
- ArmorCode - [State of Application Security](/Annual%20Security%20Reports/2023/Armorcode-State-of-Application-Security-2023.pdf) (2023) - Examines the current landscape of application security, including emerging threats, best practices, and industry-wide trends.
- Synopsys - [Open Source Risk Analysis Report](Annual%20Security%20Reports/2024/Synopsys-Open-Source-Risk-Analysis-Report-2024.pdf) (2024) - Examines security risks associated with open-source software components, offering insights into vulnerability trends and mitigation strategies.
- RunZero - [RunZero Research Report](Annual%20Security%20Reports/2024/RunZero-Research-Report-Vol1-2024.pdf) (2024) - Examines a broad range of organizational and network security issues through an innovative asset-centric approach, with a focus on "dark matter" in networks, segmentation issues, and unusual asset detection.
- Synopsys - [SANS 2023 DevSecOps Survey](Annual%20Security%20Reports/2023/SANS-DevSecOps-Survey-2023.pdf) (2023) - Examines the current state of DevSecOps practices across various industries.
- Escape - [State of API Exposure](Annual%20Security%20Reports/2024/Escape-State-of-API-Exposure-2024.pdf) (2024)
- Sonatype - [2024 in Open Source Malware Threat Report](Annual%20Security%20Reports/2024/Sonatype-2024-in-Open-Source-Malware-Report-2024.pdf) (2024)
- Cycode - [State of Application Security Posture Management](Annual%20Security%20Reports/2025/Cycode-State-of-Application-Security-Posture-Management-2025.pdf) (2025)
-
Ransomware
- Spycloud - [Ransomware Defense Report](Annual%20Security%20Reports/2024/Spycloud-Ransomware-Defense-Report-2024.pdf) (2024) - Examines malware and ransomware defense strategies and trends across different sectors.
- Veeam - [Ransomware Trends Report](Annual%20Security%20Reports/2024/Veeam-Ransomware-Trends-2024.pdf) (2024) - Provides an overview of current ransomware attack patterns, data recovery challenges, and strategies for improving organizational ransomware preparedness and resilience.
- Zscaler - [ThreatLabz State of Ransomware Report](Annual%20Security%20Reports/2024/Threatlabz-Ransomware-Report-2024.pdf) (2024) - A comprehensive analysis of global ransomware trends, examining attack techniques, ransom demands, and strategies for preventing and mitigating ransomware attacks.
- Fortinet - [Global Ransomware Report](Annual%20Security%20Reports/2023/Fortinet-Global-Ransomware-Report-2023.pdf) (2023) - Provides a global overview of ransomware trends and impacts across various industries.
- PaloAlto - [Unit 42 Ransomware Extortion Report](Annual%20Security%20Reports/2023/PaloAlto-Unit-42-Ransomeware-Extortion-Report-2023.pdf) (2023) - Examines current ransomware and extortion trends, offering insights into attacker tactics, ransom demands, and strategies for improving organizational resilience against ransomware attacks.
- Cyberreason - [Ransomware The True Cost to Business](Annual%20Security%20Reports/2024/Cyberreason-Ransomware-The-True-Cost-to-Business-2024.pdf) (2024) - Examines the true cost of ransomware attacks on businesses across different sectors.
- Guidepoint - [GRIT Ransomware Annual Report](Annual%20Security%20Reports/2023/Guidepoint-Ransomware-Annual_Report-2023.pdf) (2023) - A comprehensive analysis of ransomware trends, attack techniques, and mitigation strategies, providing valuable insights for organizations to enhance their ransomware resilience.
- Sophos - [State of Ransomware](Annual%20Security%20Reports/2024/Sophos-State-of-Ransomware-2024.pdf) (2024) - Examines ransomware attack methods, likelihood, and business impacts based on insights from 5,000 IT and cybersecurity leaders across 14 countries.
-
Research Consulting
- 451 Research - A technology research and advisory firm specializing in emerging technology segments including cybersecurity market analysis and trends.
- ABI Research - A technology market intelligence company providing strategic guidance on transformative technologies, including cybersecurity and digital security.
- Frost & Sullivan - A consulting firm offering market research and analysis in cybersecurity, with particular focus on emerging technologies and market opportunities.
- Forrester Research - An advisory company that offers paid research, consulting, and event services specialized in market research for information technology.
- GigaOm - A research firm offering practical, hands-on, practitioner-driven research for businesses.
- KuppingerCole - A global analyst company specializing in information security, identity & access management, and risk management.
- Omdia - A global technology research powerhouse focusing on cybersecurity market analysis and digital transformation.
- International Data Corporation (IDC) - A global provider of market intelligence and advisory services.
- Gartner - A technology research and consulting firm which offers private paid consulting as well as executive programs and conferences.
-
Privacy and Data Protection
- Cisco - [Data Privacy Benchmark Study](Annual%20Security%20Reports/2024/Cisco-Privacy-Benchmark-Study-2024.pdf) (2024) - Provides insights into data privacy trends, challenges, and breaches across various industries.
- Immuta - [State of Data Security Report](Annual%20Security%20Reports/2024/Immuta-State-of-Data-Security-Report-2024.pdf) (2024) - Examines the current state of data security, including challenges, trends, and best practices across various industries.
- Proofpoint - [Data Loss Landscape](Annual%20Security%20Reports/2024/Proofpoint-Data-Loss-Landscape-2024.pdf) (2024) - Provides an overview of the data loss landscape, including trends and challenges faced by organizations across various industries.
- Proofpoint - [Global Email Security Market Report](Annual%20Security%20Reports/2024/Proofpoint-Global-Email-Security-Market-Report-2024.pdf) (2024) - Benchmarks 21 top email security vendors, highlighting growth opportunities and market trends.
- Code42 - [Annual Data Exposure Report](Annual%20Security%20Reports/2024/Code42-Annual-Data-Exposure-Report-2024.pdf) (2024)
-
Cloud Security
- Google - [Cybersecurity Forecast 2025](Annual%20Security%20Reports/2025/Google-Cybersecurity-Forecast-2025.pdf) (2025) - Insights from Google Cloud leaders on emerging cybersecurity trends.
- ISC2 - [Cloud Security Report](Annual%20Security%20Reports/2024/ISC2-Cloud-Security-Report-2024.pdf) (2024) - Provides insights into cloud security challenges, trends, and strategies across different sectors.
- PaloAlto - [State of Cloud Native Security Report](Annual%20Security%20Reports/2024/PaloAlto-State-of-Cloud-Native-Security-2024.pdf) (2024) - Examines the current state of cloud-native security, including trends, challenges, and best practices across different sectors.
- Fortinet - [Cloud Security Report](Annual%20Security%20Reports/2024/Fortinet-Cloud-Security-Report-2024.pdf) (2024) - Examines the state of cloud security, highlighting key challenges, trends, and best practices for organizations across various industries.
- Sonatype - [State of Cloud Security Report](Annual%20Security%20Reports/2024/Sonatype-State-of-Cloud-Security-2024.pdf) (2024) - Provides insights into the state of cloud security and software supply chain management across different sectors.
- Sophos - [State of Cloud Security Report](Annual%20Security%20Reports/2023/Sophos-State-of-Cybersecurity-2023.pdf) (2023) - Examines the current state of cybersecurity, including trends and challenges faced by organizations across various industries.
- Mend - [State of Supply Chain Threats](Annual%20Security%20Reports/2023/Mend-State-of-Supply-Chain-Threats.pdf) (2023) - Examines the current state of supply chain threats and vulnerabilities across different sectors.
-
Penetration Testing
- Cobalt - [State of Pentesting](Annual%20Security%20Reports/2024/Cobalt-State-of-Pentesting-2024.pdf) (2024) - Offers an overview of the current state of penetration testing, including trends, challenges, and best practices across various industries.
- HackerOne - [Hacker Powered Security Report](Annual%20Security%20Reports/2023/HackerOne-Hacker-Powered-Security-Report-2023.pdf) (2023) - Explores the state of hacker-powered security, including trends in bug bounty programs and vulnerability disclosure across industries.
- Bugcrowd - [The Total Economic Impact Of Bugcrowd Managed Bug Bounty](Annual%20Security%20Reports/2024/Forrester-The-Total-Economic-Impact-Of-Bugcrowd-Managed-BugBounty-2024.pdf) (2024) - Analyzes the economic benefits and impacts of Bugcrowd's managed bug bounty programs, supported by data-driven insights from Forrester.
- HackerOne - [Hacker Powered Security Report](Annual%20Security%20Reports/2024/HackerOne-Hacker-Powered-Security-Report-2024.pdf) (2024) - Explores the state of hacker-powered security, including trends in bug bounty programs and vulnerability disclosure across industries.
-
Vulnerabilities
- Beyond Trust - [Microsoft Vulnerability Report](Annual%20Security%20Reports/2024/BeyondTrust-Microsoft-Vulnerability-Report-2024.pdf) (2024) - Analyzes vulnerabilities in Microsoft products, offering insights into security trends and potential areas of concern for organizations relying on Microsoft technologies.
- Flexera - [Annual Vulnerability Review](Annual%20Security%20Reports/2023/Flexera-Annual-Vulnerability-Review-2023.pdf) (2023) - Provides a comprehensive analysis of global software vulnerabilities, offering insights into trends, severity, and impact across various software products and vendors.
- Qualys - [TruRisk Threat Research Report](Annual%20Security%20Reports/2023/Qualys-Trurisk-Threat-Research-Report-2023.pdf) (2023) - Provides an in-depth analysis of vulnerabilities and threats, offering insights into risk assessment and prioritization strategies.
- Synopsys - [Software Vulnerability Snapshot](Annual%20Security%20Reports/2023/Synopsys-Software-Vulnerability-Snapshot-2023.pdf) (2023) - A snapshot of software vulnerability trends, highlighting common weaknesses, emerging threats, and strategies for improving software security.
- Nucleus - [State of Vulnerability Management](Annual%20Security%20Reports/2023/Nucleus-State-of-Vuln-Management-2023.pdf) (2023) - Examines the current state of vulnerability management practices, highlighting challenges, trends, and best practices in identifying and addressing security vulnerabilities.
- Edgescan - [Vulnerability Statistics Report](Annual%20Security%20Reports/2024/Edgescan-Vulnerability-Statistics-Report-2024.pdf) (2024) Analyzes data from thousands of security assessments and penetration tests on millions of global assets to provide insights into the current state of full-stack security.
- Synack - [State of Vulnerabilities Report](Annual%20Security%20Reports/2024/Synack-State-of-Vulnerabilities-Report-2024.pdf) (2024) This report looks at five industries (healthcare, financial services, U.S. federal government, technology and manufacturing) and their most common vulnerabilities to see how they stack up against each other.
- Trustwave - [Financial Services Risk Radar Report](Annual%20Security%20Reports/2024/Trustwave-Financial-Services-Risk-Radar-Report-2024.pdf) (2024) Highlights the unique threat landscape facing the financial services sector, focusing on notable trends and the growing risk of insider threats. This report provides key insights into the cybersecurity challenges specific to this industry.
-
Identity Security
- Astrix - [State of Non Human Identity](Annual%20Security%20Reports/2024/Astrix-The-State-of-Non-Human-Identity-Security-2024.pdf) (2024) - Highlights growing concerns over non-human identities as attack vectors, limited automation and visibility into API and third-party connections, and an increasing investment in NHI security.
- ConductorOne - [Identity Security Outlook Report](Annual%20Security%20Reports/2024/ConductorOne-Identity-Security-Outlook-Report-2024.pdf) (2024)
- CyberArk - [Identity Security Threat Landscape Report](Annual%20Security%20Reports/2024/CyberArk-Identity-Security-Threat-Landscape-2024.pdf) (2024)
- IDS Alliance - [2024 Trends in Securing Digital Identities](Annual%20Security%20Reports/2024/AICD-Directors-Introduction-to-AI-2024.pdf) (2024) - Provides insights into current plans, historical trends, and approaches to cybersecurity and identity management.
- Omada - [State of Identity Governance](Annual%20Security%20Reports/2024/Omada-State-of-Identity-Governance-2024.pdf) (2024)
- ManageEngine - [Identity Security Survey](Annual%20Security%20Reports/2024/ManageEngine-Identity-Security-Insights-2024.pdf) (2024)
-
Standards and Certifications
- The Information Systems Audit and Control Association (ISACA) - An international professional association focused on IT governance, which conducts research for and on behalf of the members.
- Trusted Computing Group (TCG) - Develops and promotes open standards for hardware-enabled security.
- The International Information System Security Certification Consortium (ISC)² - An American not-for-profit organization which conducts research for consumers of their cybersecurity training and certifications.
- The Information Security Forum (ISF) - A global, independent organization dedicated to benchmarking and sharing best practices in information security.
-
Data Breaches
- Verizon - [Data Breach Investigations Report](Annual%20Security%20Reports/2024/Verizon-Data-Breach-Investigations-Report-2024.pdf) (2024) - Analyzes global data breaches, offering insights into attack patterns, threat actor motivations, and strategies for improving organizational data security and incident response.
- Identity Theft Resource Center - [Annual Data Breach Report](Annual%20Security%20Reports/2023/ITRC-Annual-Data-Breach-Report-2023.pdf) (2023) - A review of 18,800+ data breaches since 2005, impacting 12 billion victims and exposing 19.8 billion records, focusing on root causes and compromised data types.
Categories
Reports
38
Threat Intelligence
27
Resources
20
Industry Trends
13
Application Security
11
Research Consulting
9
Ransomware
8
Vulnerabilities
8
Cloud Security
7
Threat Intelligence and Incident Response
6
Identity Security
6
AI and Emerging Technologies
6
Policy and Advocacy
5
Privacy and Data Protection
5
Working Groups
5
Penetration Testing
4
Standards and Certifications
4
Surveys
3
Data Breaches
2