Know
What is Cybersecurity?
Cybersecurity combines people, process, and technology to manage risks to digital systems and information. It includes prevention, detection, response, recovery, governance, and continuous improvement rather than a single product or defensive tool.
Why it matters
Organizations depend on digital systems for money, operations, customer trust, intellectual property, communications, and safety. A cyber incident can affect all of them at once.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
EU manufacturer reporting duties apply from September 11, 2026
The Cyber Resilience Act's Article 14 covers actively exploited vulnerabilities and severe product-security incidents: early warning within 24 hours and notification within 72 hours of awareness. Final vulnerability reports are due within 14 days after a corrective or mitigating measure becomes available; final severe-incident reports within one month after the incident notification.
Articles 14, 69, and 71 distinguish reporting triggers and transitional coverage. Article 14 applies from September 11, 2026; general application begins December 11, 2027. These are duties for in-scope manufacturers and products, not universal reporting requirements for every organization.
NIST finalizes its CSF 2.0 informative-references guide
NIST finalized SP 1347 on August 25. It explains relationships between CSF 2.0 outcomes and other documents and introduces tools for finding and using those mappings.
This is a final framework-mapping resource. A crosswalk establishes relationships between documents; it does not itself prove that an organization implemented a control or achieved an outcome.
NIST releases draft guidance on AI-assisted CSF analysis
NIST's initial public draft SP 1353 describes AI use in CSF analysis and reporting, with structured prompts, three notional use cases, and simulated organizational materials. The announcement sets an October 15, 2026 comment deadline.
This is draft guidance on an evolving workflow, not a new mandatory standard or proof that AI-generated assessments are accurate. Its stated purpose differs from general AI best practices and comprehensive cybersecurity guidance.
Phishing and spoofing remained among the most frequently reported internet crimes
The FBI's 2025 Internet Crime Report recorded more than one million complaints overall and identified phishing/spoofing among the most frequently reported complaint categories.
This is large-scale victim reporting evidence that phishing is not a theoretical training scenario; it remains a common real-world attack and fraud mechanism.
Scattered Spider targeted enterprise help desks and identity controls
A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.
The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.
CISA red team gained persistent access while MFA blocked access to a sensitive system
During a CISA red-team assessment, the team gained persistent network access and moved laterally, but MFA prompts prevented access to one sensitive business system. CISA also recommended EDR, modern identity practices, centralized cybersecurity data, and Zero Trust architecture.
This controlled assessment shows both the failure modes of incomplete monitoring and the practical defensive value of MFA, endpoint visibility, identity controls, and modern architecture.
Qakbot infected more than 700,000 computers and enabled ransomware operations
The Justice Department and FBI disrupted Qakbot infrastructure after identifying more than 700,000 infected computers worldwide. Qakbot was used to deliver additional malware and ransomware.
This provides direct law-enforcement validation of malware as a delivery and access mechanism used in broader criminal ecosystems.
SolarWinds confirmed malicious code was inserted into Orion software builds
SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.
This primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.
Capital One data theft exploited a misconfigured cloud-facing control
The Justice Department described an intrusion into Capital One data through a misconfigured web application firewall; the case ultimately resulted in a federal conviction for computer intrusions and wire fraud.
The case demonstrates how cloud security depends on configuration, identity permissions, monitoring, and data-access controls rather than the cloud provider alone.
Log4Shell provides a concrete example of a CVE with remote-code-execution impact
NVD records CVE-2021-44228, commonly known as Log4Shell, describing how attacker-controlled JNDI endpoints could lead to arbitrary code execution in affected Log4j versions.
This is a practical example of how a CVE identifier, severity information, affected versions, and technical impact are used together during vulnerability response.
NIST documents centralized security log management as a foundation for detection and investigation
NIST SP 800-92 provides practical guidance for enterprise security log management and explicitly discusses centralized log management and SIEM technology.
SIEM and security-data architectures depend on reliable collection, storage, access, analysis, retention, and governance of telemetry—not merely buying a search interface.
NIST updated incident-response guidance for CSF 2.0
NIST SP 800-61 Rev. 3 integrates incident response throughout cybersecurity risk management and focuses on improving detection, response, and recovery effectiveness.
Automation belongs inside a governed incident-response capability; speed is useful only when the surrounding decision, evidence, containment, and recovery processes are sound.
ATT&CK connects techniques to documented adversary procedures
MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.
It gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.
Understand the mechanics
How it works
- 1
Identify important assets, users, systems, and data.
- 2
Understand threats, vulnerabilities, and likely business impact.
- 3
Apply preventive and detective controls based on risk.
- 4
Monitor for suspicious behavior and control failures.
- 5
Respond to incidents and restore trusted operations.
- 6
Improve controls based on lessons learned and changes in the threat landscape.
Practice
What to watch for
- Unmanaged assets
- Unpatched high-risk vulnerabilities
- Unexpected account activity
- Unusual network or endpoint behavior
- Security controls that are not monitored or tested
Perform
What to do
- 1
Determine what asset, identity, or data is affected.
- 2
Follow the organization’s incident or escalation process.
- 3
Contain immediate risk before making irreversible changes.
- 4
Preserve evidence and document decisions.
How to reduce the risk
- Asset and identity inventory
- Least privilege
- Secure configuration
- Patch and vulnerability management
- Logging and monitoring
- Backups and recovery planning
- Security education and exercises
Business impact
- Operational disruption
- Financial loss
- Data exposure
- Regulatory impact
- Customer and partner trust
- Safety or mission impact
What different roles should do
Everyone
- Protect credentials
- Report suspicious activity
- Follow approved security processes
Security
- Prioritize controls based on risk
- Measure detection and response effectiveness
Framework & standards context
- NIST Cybersecurity Framework (CSF) 2.0
Source transparency
Authoritative sources
Last reviewed: 2026-09-02