FundamentalsBeginnerFoundation13 validated evidence records

Cybersecurity

30 sec

The practice of protecting systems, networks, applications, identities, and data from unauthorized access, disruption, manipulation, or destruction.

Know

What is Cybersecurity?

Cybersecurity combines people, process, and technology to manage risks to digital systems and information. It includes prevention, detection, response, recovery, governance, and continuous improvement rather than a single product or defensive tool.

Why it matters

Organizations depend on digital systems for money, operations, customer trust, intellectual property, communications, and safety. A cyber incident can affect all of them at once.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Government / AuthoritativeStandard / framework

EU manufacturer reporting duties apply from September 11, 2026

Applies 2026-09-11European Parliament and Council

The Cyber Resilience Act's Article 14 covers actively exploited vulnerabilities and severe product-security incidents: early warning within 24 hours and notification within 72 hours of awareness. Final vulnerability reports are due within 14 days after a corrective or mitigating measure becomes available; final severe-incident reports within one month after the incident notification.

Why this is evidence

Articles 14, 69, and 71 distinguish reporting triggers and transitional coverage. Article 14 applies from September 11, 2026; general application begins December 11, 2027. These are duties for in-scope manufacturers and products, not universal reporting requirements for every organization.

See the source — European Parliament and Council: Regulation (EU) 2024/2847 — Articles 14, 69 and 71
Standards / FrameworkStandard / framework

NIST finalizes its CSF 2.0 informative-references guide

2026-08-25NIST

NIST finalized SP 1347 on August 25. It explains relationships between CSF 2.0 outcomes and other documents and introduces tools for finding and using those mappings.

Why this is evidence

This is a final framework-mapping resource. A crosswalk establishes relationships between documents; it does not itself prove that an organization implemented a control or achieved an outcome.

See the source — NIST: SP 1347: NIST Cybersecurity Framework 2.0: Informative References Quick-Start Guide
Emerging / ResearchResearch / emerging practice

NIST releases draft guidance on AI-assisted CSF analysis

2026-08-19; comments due 2026-10-15NIST

NIST's initial public draft SP 1353 describes AI use in CSF analysis and reporting, with structured prompts, three notional use cases, and simulated organizational materials. The announcement sets an October 15, 2026 comment deadline.

Why this is evidence

This is draft guidance on an evolving workflow, not a new mandatory standard or proof that AI-generated assessments are accurate. Its stated purpose differs from general AI best practices and comprehensive cybersecurity guidance.

See the source — NIST: Using AI for CSF 2.0 Analysis and Reporting—New Quick-Start Guide Available for Comment
Government / AuthoritativeMeasured outcome

Phishing and spoofing remained among the most frequently reported internet crimes

2025FBI Internet Crime Complaint CenterCross-sector

The FBI's 2025 Internet Crime Report recorded more than one million complaints overall and identified phishing/spoofing among the most frequently reported complaint categories.

Why this is evidence

This is large-scale victim reporting evidence that phishing is not a theoretical training scenario; it remains a common real-world attack and fraud mechanism.

See the source — FBI: 2025 Internet Crime Report
Government / AuthoritativeGovernment advisory

Scattered Spider targeted enterprise help desks and identity controls

2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors

A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.

Why this is evidence

The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.

See the source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A
Government / AuthoritativeOperational validation

CISA red team gained persistent access while MFA blocked access to a sensitive system

2023-02-28CISACritical infrastructure

During a CISA red-team assessment, the team gained persistent network access and moved laterally, but MFA prompts prevented access to one sensitive business system. CISA also recommended EDR, modern identity practices, centralized cybersecurity data, and Zero Trust architecture.

Why this is evidence

This controlled assessment shows both the failure modes of incomplete monitoring and the practical defensive value of MFA, endpoint visibility, identity controls, and modern architecture.

See the source — CISA: CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks
Primary / ConfirmedLaw-enforcement case

Qakbot infected more than 700,000 computers and enabled ransomware operations

2023-08-29U.S. Department of Justice / FBICross-sector

The Justice Department and FBI disrupted Qakbot infrastructure after identifying more than 700,000 infected computers worldwide. Qakbot was used to deliver additional malware and ransomware.

Why this is evidence

This provides direct law-enforcement validation of malware as a delivery and access mechanism used in broader criminal ecosystems.

See the source — U.S. Department of Justice: Qakbot Malware Disrupted in International Cyber Takedown
Primary / ConfirmedConfirmed incident

SolarWinds confirmed malicious code was inserted into Orion software builds

2020-12-14SolarWindsSoftware supply chain

SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.

Why this is evidence

This primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.

See the source — U.S. Securities and Exchange Commission: SolarWinds Form 8-K — December 14, 2020
Primary / ConfirmedLaw-enforcement case

Capital One data theft exploited a misconfigured cloud-facing control

2019-07-29Capital OneFinancial services

The Justice Department described an intrusion into Capital One data through a misconfigured web application firewall; the case ultimately resulted in a federal conviction for computer intrusions and wire fraud.

Why this is evidence

The case demonstrates how cloud security depends on configuration, identity permissions, monitoring, and data-access controls rather than the cloud provider alone.

See the source — U.S. Department of Justice: Seattle Tech Worker Arrested for Data Theft Involving Large Financial Services Company
Government / AuthoritativeStandard / framework

Log4Shell provides a concrete example of a CVE with remote-code-execution impact

2021-12Apache Log4j / NVDCross-sector software

NVD records CVE-2021-44228, commonly known as Log4Shell, describing how attacker-controlled JNDI endpoints could lead to arbitrary code execution in affected Log4j versions.

Why this is evidence

This is a practical example of how a CVE identifier, severity information, affected versions, and technical impact are used together during vulnerability response.

See the source — NIST National Vulnerability Database: CVE-2021-44228 Detail
Standards / FrameworkStandard / framework

NIST documents centralized security log management as a foundation for detection and investigation

2006 / ongoing revisionNISTCross-sector

NIST SP 800-92 provides practical guidance for enterprise security log management and explicitly discusses centralized log management and SIEM technology.

Why this is evidence

SIEM and security-data architectures depend on reliable collection, storage, access, analysis, retention, and governance of telemetry—not merely buying a search interface.

See the source — NIST: SP 800-92 Guide to Computer Security Log Management
Standards / FrameworkStandard / framework

NIST updated incident-response guidance for CSF 2.0

2025-04NISTCross-sector

NIST SP 800-61 Rev. 3 integrates incident response throughout cybersecurity risk management and focuses on improving detection, response, and recovery effectiveness.

Why this is evidence

Automation belongs inside a governed incident-response capability; speed is useful only when the surrounding decision, evidence, containment, and recovery processes are sound.

See the source — NIST: SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations
Technical ValidationStandard / framework

ATT&CK connects techniques to documented adversary procedures

Continuously maintainedMITRECross-sector

MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.

Why this is evidence

It gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.

See the source — MITRE: MITRE ATT&CK

Understand the mechanics

How it works

  1. 1

    Identify important assets, users, systems, and data.

  2. 2

    Understand threats, vulnerabilities, and likely business impact.

  3. 3

    Apply preventive and detective controls based on risk.

  4. 4

    Monitor for suspicious behavior and control failures.

  5. 5

    Respond to incidents and restore trusted operations.

  6. 6

    Improve controls based on lessons learned and changes in the threat landscape.

Practice

What to watch for

  • Unmanaged assets
  • Unpatched high-risk vulnerabilities
  • Unexpected account activity
  • Unusual network or endpoint behavior
  • Security controls that are not monitored or tested

Perform

What to do

  1. 1

    Determine what asset, identity, or data is affected.

  2. 2

    Follow the organization’s incident or escalation process.

  3. 3

    Contain immediate risk before making irreversible changes.

  4. 4

    Preserve evidence and document decisions.

How to reduce the risk

  • Asset and identity inventory
  • Least privilege
  • Secure configuration
  • Patch and vulnerability management
  • Logging and monitoring
  • Backups and recovery planning
  • Security education and exercises

Business impact

  • Operational disruption
  • Financial loss
  • Data exposure
  • Regulatory impact
  • Customer and partner trust
  • Safety or mission impact

What different roles should do

Everyone

  • Protect credentials
  • Report suspicious activity
  • Follow approved security processes

Security

  • Prioritize controls based on risk
  • Measure detection and response effectiveness

Framework & standards context

  • NIST Cybersecurity Framework (CSF) 2.0

Keep learning

RiskThreatVulnerabilityControlDefense in DepthIncident Response

Source transparency

Authoritative sources

Last reviewed: 2026-09-02