Skip to content
85

Awesome Annual Security Reports

A curated list of annual cyber security reports

1.2k stars145 forks509 entriesLast push Sep 30, 2026 (today)License MIT

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Analysis Reports >Global Threat Intelligence

Artic Wolf Labs

Cybersecurity Predictions (2025) - Analyzes evolving threat landscapes and predicts key cybersecurity challenges for 2025. The report highlights the increasing sophistication of social engineering attacks, emphasizing the critical need for robust multi-factor authentication implementations and…

Artic Wolf Labs

Threat Report (2026) - Analyzes the evolving cybersecurity threat landscape by examining incident response data from global digital forensics engagements to identify critical trends in ransomware, business email compromise, and data exfiltration. Key findings reveal that 92 percent of incidents…

In 2 listsDetails

Astra

Cybersecurity Statistics Report (2026) - Analyzes the evolving cybersecurity landscape and the prevalence of diverse threat vectors including ransomware, malware, and social engineering tactics. Key findings reveal that cyberattacks occur every 39 seconds with an average of 2,200 daily incidents,…

Axur

Threat Landscape (2025) - Analyzes the 2025 cybersecurity threat landscape, focusing on evolving attack vectors and their impact on organizations. Key insights reveal a significant increase in supply chain attacks, a shift in social engineering tactics targeting IT professionals, and the growing…

BeazleySecurity

Quarterly Threat Report Q1 (2026) - Examines the state of cyber threats and vulnerabilities, highlighting supply chain compromises and administrative attacks. Key findings reveal that over 15200 new vulnerabilities were publicly disclosed, representing a 43% increase compared to the previous…

Biocatch

Digital Banking Fraud Trends In The United States (2026) - Examines the current and future digital banking fraud landscape in the United States, highlighting evolving threats such as artificial intelligence driven impersonation and social engineering. Key insights reveal that 78 percent of banking…

Bitdefender

IoT Security Report (2025) - Examines the evolving Internet of Things threat landscape by analyzing data from over 58 million devices across global smart homes. Key findings reveal that streaming devices and smart televisions account for over 47 percent of all detected vulnerabilities, while the…

Bridewell

Cyber Threat Intelligence Report (2025) - Analyzes the cyber threat landscape of 2025, focusing on malicious infrastructure tracking and emerging threats. The report highlights a decrease in Cobalt Strike usage alongside a rise in Sliver and Brute Ratel, with Lumma Stealer, Redline Stealer, and…

Cato Networks

Threat Report (2026) - Examines the evolving threat landscape of 2026 by focusing on the integration of advanced automation and decentralized network architectures within modern enterprise environments. Telemetry data collected throughout the year reveals that threat actors are increasingly…

Chainalysis

Crypto Crime Report (2026) - Analyzes the 2026 landscape of illicit cryptocurrency activity, focusing on the professionalization of laundering networks and the escalation of nation-state sanctions evasion. Findings reveal that illicit addresses received 154 billion dollars in 2025, representing a…

Check Point

Cybersecurity Report (2026) - Examines the evolving threat landscape in 2025, focusing on the integration of artificial intelligence, multi-channel social engineering, and the transformation of ransomware into a data-driven extortion economy. Key findings reveal that ClickFix social engineering…

Cisco

Cyber Threats Trends Report (2025) - Analyzes current cyber threat trends, focusing on information stealers, Trojans, ransomware, RATs, and APTs. Key findings reveal a significant increase in the sophistication and volume of attacks, particularly concerning the use of information stealers and the…

Cisco

Talos Year In Review (2025) - Examines the threat landscape of 2025, detailing how adversaries weaponized new vulnerabilities and targeted legacy infrastructure. Key findings reveal a 178% surge in device compromise attacks targeting multi-factor authentication, alongside a 74% increase in…

Cloudflare

Threat Report (2026) - Investigates the evolving threat landscape of 2026, focusing on the industrialization of cyber attacks and the shift toward high-trust exploitation within modern cloud and identity ecosystems. Key findings reveal that adversaries are leveraging automated tools to achieve a…

Cloudflare

Security Signals Report (2026) - Analyzes the transition toward autonomic resilience in enterprise security, emphasizing the necessity of governing autonomous systems and mitigating systemic risks within modern digital architectures. Key findings reveal that 98 percent of employees utilize…

Coalition

Cyber Claims Report (2026) - Analyzes the global cyber risk landscape and the effectiveness of proactive risk management strategies using proprietary claims data from over one hundred thousand policyholders. Key findings reveal that while global claims frequency rose by 3 percent, the average…

Crowd Strike

Global Threat Report (2026) - Analyzes security findings and threat trends reported by CrowdStrike for 2026, examining key attack patterns, vulnerability data, and defensive recommendations drawn from data collected across hundreds of security practitioners. Findings span 10 or more priority risk…

Crowd Strike

Threat Hunting Report (2026) - Examines the 2026 threat landscape and frontline hunting observations to highlight how adversaries exploit trust, software supply chains, and emerging artificial intelligence attack surfaces. Key findings reveal that 88 percent of vulnerability exploitation occurred…

Cyber Proof

Mid Year Cyber Threat Landscape (2025) - Analyzes the H1 2025 cyber threat landscape, focusing on the surge of AI-powered ransomware operations, intensified targeting of the manufacturing sector, and strategic shifts in supply chain infiltration. Key insights include a 60% increase in ransomware…

CyberProof

Global Threat Intelligence Report (2026) - Investigates the evolving landscape of global cyber threats in 2025, focusing on the rapid weaponization of vulnerabilities and the strategic shift toward identity abuse within business-critical systems. Key findings reveal that ransomware activity in the…

Cyble

Global Threat Landscape (2025) - Analyzes the global threat landscape of H1 2025, highlighting a significant 54% increase in ransomware attacks compared to the previous year. The report identifies CL0P, Akira, and Qilin as the top ransomware operators, with North America being the most targeted…

Darktrace

Annual Threat Report (2026) - Analyzes the global cyber threat landscape through behavioral analysis and real world customer data from across international regions. Key findings reveal that software as a service and email based social engineering account for nearly 70% of all recorded incidents,…

Dataminr

Cyber Threat Landscape Report (2026) - Analyzes the evolving 2025 cyber threat landscape by examining the surge in sophisticated threat actor activity, systemic vulnerability re-exploitation, and the critical need for context-aware risk prioritization. Key findings reveal a 225 percent increase in…

Deep Instinct

Threat Landscape Report (2025) - Analyzes global malware trends and ransomware attacks in 2024, offering predictions for 2025. Key findings highlight a continued rise in ransomware attacks targeting specific sectors, coupled with the evolving tactics of ransomware groups and the impact of…

Deloitte

Global Cyber Threat Intelligence Report (2025) - Analyzes global cyber threat trends throughout 2024, focusing on the evolution of ransomware, nation-state espionage, and shifting initial access techniques. Key findings include the continued dominance of ransomware driven by the emergence of new…

Department of Homeland Security

Threat Assessment (2025) - Analyzes homeland security threats in 2025, focusing on terrorism, transnational crime, and threats to critical infrastructure. Key concerns include the evolving tactics of nation-state actors, the persistent threat of cyberattacks targeting critical infrastructure, and…

DigiCert

Ultraddos Biannual Report (2025) - Analyzes the landscape of distributed denial of service attacks during the first half of 2025, documenting a significant shift in threat actor behavior and infrastructure capacity. Key findings reveal an 84.37 percent decrease in total attack volume compared to…

DNS Filter

Annual Security Report (2026) - Analyzes the evolving landscape of DNS layer security and threat activity, documenting the increasing volume and sophistication of malicious traffic across global networks. Key findings reveal that threat activity grew by more than 30 percent over the past year,…

Eset

Threat Report (2026) - Examines the emerging threats within the H1 2026 security landscape, focusing on the rapid expansion of agentic artificial intelligence attack surfaces and evolving social engineering tactics. Key findings reveal that security systems scanned nearly 900,000 artificial…

Europool

Internet Organized Crime Threat Assessment (2026) - Investigates the evolving landscape of internet organized crime, focusing on how artificial intelligence, encryption, and resilient infrastructure facilitate sophisticated cybercriminal operations across the European Union. Findings highlight…

Expel

Annual Threat Report (2026) - Investigates the evolving threat landscape across identity, endpoint, and cloud infrastructure to provide actionable insights for organizational defense strategies. Findings reveal that identity-based attacks remain the primary threat vector, accounting for 68.6…

F5

Advanced Persistent Bots Report (2025) - Examines the behavior of advanced persistent bots across 200 billion transactions, assessing the impact of mitigation on web and mobile API platforms. Analysis reveals that while overall automated attacks declined in most sectors, the Hospitality industry…

FBI

IC3 Report (2025) - Examines the annual volume of cybercrime complaints, total financial losses, and prevalent fraud categories tracked by the Federal Bureau of Investigation Internet Crime Complaint Center. Key findings reveal that total losses surpassed $20 billion across more than one million…

Flashpoint

Global Threat Intelligence Report (2026) - Analyzes the evolving global threat landscape, focusing on the convergence of artificial intelligence, identity exploitation, and automated attack frameworks. Key findings reveal a 1,500 percent surge in illicit AI discussions alongside the compromise of…

Forescout

Threat Review (2025) - Analyzes the threat landscape of the first half of 2025, emphasizing the persistence of known vulnerabilities and the blurring distinction between hacktivist and state-sponsored actors. Key insights highlight that 47% of newly exploited vulnerabilities were pre-existing,…

Fortinet

Global Threat Report (2025) - Analyzes the evolving global threat landscape and attacker tactics. Key findings reveal a surge in cyber reconnaissance activity driven by automated scanning and a significant shift in attacker focus towards cloud environments and post-exploitation techniques.

Guardz

SMB Threat Report (2025) - Analyzes the SMB threat landscape, highlighting the rise of phishing, cloud-based attacks, and identity-based breaches. The report reveals a shift towards AI-enhanced social engineering, stolen credentials as a primary attack vector, and the increasing exploitation of…

Guardz

State of MSP Threat Report (2026) - Examines the evolving MSP threat landscape and analyzes identity-driven attacks, artificial intelligence-powered threats, and endpoint vulnerabilities observed across managed SMB environments. Key findings reveal a 190% surge in ransomware behavioral detections…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

Honeywell

Cyber Threat Report (2025) - Focuses on cybersecurity incidents impacting operational technology environments and the increasing cybersecurity and non-compliance risks faced by companies. Key findings include a 46% increase in ransomware extortion incidents, the emergence of the CL0P ransomware…

Huntress

Threat Report (2025) - Analyzes the 2024 cyber threat landscape, focusing on ransomware attacks and their impact across various sectors. Key findings reveal a concerning increase in ransomware attacks targeting healthcare and technology sectors, with a notable rise in the use of Remote Monitoring…

IBM

X Force Threat Intelligence Index (2026) - Investigates the evolving threat landscape of 2025 by analyzing incident response data and vulnerability trends across global software and cloud ecosystems. Key findings reveal a 44 percent increase in the exploitation of public-facing applications as an…

Infoblox

DNS Threat Landscape Report (2026) - Examines the escalating scale of industrialized cybercrime and automated threat infrastructures through telemetry analysis of trillions of DNS queries. Key findings reveal that 22 percent of over 120 million newly registered domains were weaponized, while…

Intel471

Cyber Threat Trends and Outlook Report (2026) - Analyzes the 2025 cyber threat landscape, focusing on the evolution of extortion tactics, supply chain vulnerabilities, and the practical application of artificial intelligence by criminal actors. Key findings reveal a significant 63% increase in…

K7 Security

Cyber Threat Monitor Report (2025) - Analyzes the global cyber threat landscape and its impact on various industries, highlighting evolving attack vectors and prevalent malware. Key findings indicate a significant rise in human-centric phishing attacks and the persistent exploitation of unpatched…

Kaspersky

Security Services Global Report (2026) - Analyzes global threat intelligence and security service metrics to uncover prominent adversary tactics and regional targeting trends. Key findings reveal that the government sector accounts for 19 percent of attacks while ransomware encryption drives 33.1…

KnowBe4

Phishing Threat Trends Report (2026) - Analyzes the evolving landscape of phishing threats in 2026, focusing on the integration of artificial intelligence and multi-platform attack vectors across corporate environments. Key findings reveal that 85.8 percent of phishing attacks are now AI driven,…

Kroll

Threat Landscape Report (2025) - Analyzes the evolving threat landscape in the cryptocurrency era, detailing emerging cybercrime tactics and regulatory responses. Key findings reveal a significant surge in crypto-related theft, reaching $1.93 billion in the first half of 2025, and a 40% increase…

Mandiant

M Trends (2026) - Investigates the evolving global threat landscape through an analysis of over 500,000 hours of frontline incident response engagements conducted throughout 2025. Key findings reveal that global median dwell time has increased to 14 days, while threat actors are increasingly…

Microsoft

Digital Defense Report (2025) - Focuses on the evolving cybersecurity threat landscape, highlighting the increasing role of AI in both attacks and defenses. Key findings reveal adversaries are leveraging AI for social engineering and vulnerability discovery, while defenders are using it to…

Mile2

Global Cyberthreat Report (2026) - Identifies a landscape where cyber risk has transitioned from a technical IT problem to a systemic economic force. The report emphasizes that in 2026, cyber resilience is a test of executive governance and decision-making discipline under pressure.

Mimecast

Global Threat Intelligence Report (2025) - Analyzes the global threat landscape, focusing on risks posed by business communications, collaboration environments, and human workers. Key findings reveal a surge in ClickFix attacks, the weaponization of legitimate services, and the increasing use of…

NC Tech

State Of Cybersecurity (2025) - Analyzes the evolving landscape of cybersecurity threats and challenges for 2025, detailing emerging attack vectors and defense strategies. Key insights reveal a significant increase in AI-driven attacks, the growing sophistication of ransomware-as-a-service models,…

NCSC

Annual Review (2025) - Assesses the evolving cyber threat landscape and the critical necessity for organizational resilience within the United Kingdom. Findings indicate that 48 percent of all incidents handled by the National Cyber Security Centre were of national significance, while highly…

Nexusguard

DDoS Threat Analysis and Industry Perspectives (2025) - Examines distributed denial of service trends and regional threat distributions across global digital infrastructure. Key findings reveal that total attacks surged by 97.3 percent to exceed 686,000 incidents, while the largest carpet bombing…

Okta

Secure Identity Commitment (2025) - Examines the Secure Identity Commitment initiative launched by Okta to fortify enterprise identity infrastructure through product innovation and rigorous internal security hardening. Internal data from late 2025 reveals that the platform successfully blocked…

Orange Cyber Defense

Security Navigator (2026) - Evaluates the landscape of global cybersecurity threats and incident response performance through extensive data collected from managed security operations. Findings reveal that 13.7 percent of potential incidents are confirmed as true positives, with 40.6 percent of…

Palo Alto

Global Incident Response Report (2026) - Analyzes security findings and threat trends reported by PaloAlto for 2026, examining key attack patterns, vulnerability data, and defensive recommendations drawn from data collected across hundreds of security practitioners. Findings span 10 or more…

PDI

Cyber Threat Landscape Report Q1 (2026) - Analyzes the cyber threat landscape for the first quarter of 2026 by examining more than four trillion security events collected across global environments. Key findings reveal a staggering 247 percent surge in exploit activity alongside a 61 percent year…

Picus

Red Report (2026) - Analyzes the evolution of global adversary tradecraft by mapping over 15.5 million malicious actions to the MITRE ATT&CK framework. Findings reveal a strategic shift toward long-lived persistence, as 80% of the top ten techniques now prioritize evasion while 38% of observed…

Plume

Residential Proxy Malware (2026) - Examines the proliferation of residential proxy networks within Android applications, highlighting how sideloaded streaming tools quietly enroll compromised devices into monetization frameworks without user consent. Key findings reveal that 100% of analyzed…

Rapid7

Initial Access Brokers Report (2026) - Investigates the evolving landscape of initial access brokers across five major cybercrime forums, documenting a strategic shift toward targeting larger enterprises with high-value, high-privilege credentials. Key findings reveal that the average alleged…

Recorded Future

State of Security (2026) - Analyzes the global threat landscape in 2025, focusing on how geopolitical fragmentation and the erosion of diplomatic norms have accelerated cyber espionage and hybrid conflict. Key findings reveal a 33% increase in new ransomware variants compared to the previous year,…

Recorded Future

Payment Fraud Intelligence Report (2025) - Analyzes the evolving landscape of payment fraud, documenting how threat actors are leveraging industrial-scale support networks and artificial intelligence to maximize the impact of stolen financial data. Key findings reveal that while the volume of…

Red Canary

Threat Detection Report (2026) - Analyzes the evolving cybersecurity landscape by examining over one hundred thousand confirmed threats across diverse infrastructure and identity environments. Key findings reveal that identity based attacks surged by 850 percent year over year, now accounting for…

In 2 lists

Relia Quest

Annual Threat Report (2025) - Analyzes 2024 cyber-threat trends, focusing on initial access tactics and their effectiveness. Key findings reveal inadequate logging as the root cause of most breaches, with session hijacking bypassing multi-factor authentication in all successful business email…

Resilience

Cyber Risk Report (2025) - Analyzes cyber risk trends based on claims experience and threat intelligence, highlighting the evolution of third-party risk and the impact of vendor-related incidents. Key findings include a surge in social engineering effectiveness due to AI, an increase in the…

Securtas

Annual Intelligence Estimate Report (2026) - Examines the global corporate security and risk landscape for 2026, providing comprehensive threat assessments across multiple regional sectors and critical infrastructure domains. Key findings highlight that 100 percent of evaluated strategic drivers…

Shieldworkz

Global OT And IoT Threat Landscape Report (2025) - Analyzes the global OT and IoT threat landscape, highlighting the increasing sophistication and strategic intent of cyberattacks targeting critical infrastructure.

SilentPush

Threat Actor Study (2025) - Analyzes global threat actor activity and infrastructure trends from 2024, focusing on AI-powered scaling, infrastructure laundering, and Access-as-a-Service models. Key findings highlight persistent state-sponsored APTs, the evolution of FIN7, Scattered Spider, and…

SonicWall

Cyber Threat Report (2025) - Analyzes the evolving landscape of cyber threats in 2024, focusing on the rise of ransomware, BEC attacks, and the impact of AI-powered tools. Key findings highlight a significant increase in ransomware and BEC attacks, coupled with the concerning ease with which…

SonicWall

Cyber Protect Report (2026) - Examines the state of cybersecurity and protection outcomes for small and mid-market businesses, highlighting critical operational vulnerabilities and threat trends. Key insights reveal that high-severity intrusion prevention system hits increased by 20.8 percent to…

Sophos

Threat Report (2025) - Analyzes the 2025 cyber threat landscape facing small and midsized businesses, identifying ransomware and compromised network devices as the most critical operational risks. Key findings reveal that ransomware accounts for over 90% of incident response cases for mid-sized…

Sophos

Active Adversary Report (2026) - Investigates the evolving threat landscape through an analysis of 661 incident response cases, focusing on the persistent reliance of attackers on established tools and techniques. Findings reveal that identity-related tactics now dominate the threat environment,…

Sopra Steria

State of Security (2026) - Examines the evolving cybersecurity landscape and the transformative impact of generative artificial intelligence on both offensive and defensive operations. Key findings reveal that rapid technological integration has enabled a 99.9 percent cost reduction in model…

Spycloud

The Identity Security Reckoning (2026) - Investigates the evolving landscape of identity security and the industrialization of cybercrime as organizations face increasing threats from sophisticated, commoditized attack vectors. Key findings reveal that corporate users now possess an average of 146…

StationX

Phishing Statistics (2026) - Analyzes the current landscape of phishing attacks, documenting the evolution of social engineering tactics and the increasing integration of artificial intelligence in malicious campaigns. Key findings reveal that 82.6 percent of phishing emails are now AI generated,…

Switzerland

Cybersecurity Report (2025) - Examines the state of cyberthreats and incident reporting in Switzerland, highlighting national trends and operational security challenges. Key insights reveal that the centre received 29,006 voluntary and 145 mandatory reports during the second half of 2025, with…

Thales

Data-Threat-Report (2026) - Analyzes security findings and threat trends reported by Thales for 2026, examining key attack patterns, vulnerability data, and defensive recommendations drawn from data collected across hundreds of security practitioners. Findings span 10 or more priority risk areas,…

Thinkst

Scapes Q4 (2025) - Examines the state of networking and foundational security research through an analysis of over 1370 conference talks and 1200 blog posts published during the final quarter of the year. Key findings reveal that up to 28 percent of evaluated autonomous systems permit IP source…

Trend Micro

Annual Cybersecurity Threat Report (2025) - Analyzes enterprise cyber risk exposure across sectors and regions using telemetry from Trend Vision One's Cyber Risk Index framework. Key findings show the education sector maintained the highest risk throughout 2024, while larger organizations…

Truesec

Threat Intelligence Report (2026) - Analyzes the evolving global threat landscape and the shifting tactics of cyber adversaries as documented in the Truesec 2026 intelligence report. Data indicates a positive trend in incident response, showing a decrease in successful ransomware encryption across…

WatchGuard

Threat Report (2025) - Analyzes network and endpoint threat activity observed across WatchGuard security appliances in Q1 2025. Notable findings include a 171% spike in network-detected malware per device and a 712% increase in new, unique endpoint malware samples, signaling a surge in evasive and…

Whitehouse

Cybersecurity Posture of the United States (2025) - Assesses the evolving national security landscape of the United States by examining the multifaceted threats posed by transnational criminal organizations, terrorist groups, and major state adversaries. Key findings indicate that while synthetic…

With Secure

Supply Chain Threat Report (2025) - Analyzes the increasing threat of supply chain attacks, highlighting their impact and the factors contributing to their rise. The report details notable incidents like the 3CX compromise and the MOVEit Transfer vulnerability, emphasizing the potential for…

ZScaler

Securing Digital India Against AI Cyber Threats (2026) - Examines the escalating risks facing population scale digital infrastructure and artificial intelligence platforms across critical sectors in India. Key findings highlight that 100% of surveyed organizations must transition from traditional…

Analysis Reports >Regional Assessments

Australian Signals Directorate

Cyber Threat Report (2025) - Analyzes the Australian cyber threat landscape for 2023-2024, focusing on state actors, critical infrastructure attacks, cybercrime, hacktivism, and national resilience efforts. Key findings highlight a significant increase in ransomware attacks targeting critical…

Canada

National Cyber Threat Assessment (2025) - Analyzes the cyber threats facing Canada from state adversaries and cybercrime, forecasting trends up to 2026. The report highlights the increasing aggressiveness of state adversaries in cyberspace, the resilience of cybercrime due to the…

Durin

Home Access Report (2025) - Surveys homeowner practices regarding smart lock and electronic keypad access code sharing and management. Key findings reveal that 78% of holiday travelers share codes, with 22% of homeowners never changing their access codes.

Ensign

Cyber Threat Landscape Report (2025) - Analyzes the cyber threat landscape in the Asia-Pacific region, highlighting trends and developments observed in 2025. Key findings include increased activity from state-sponsored groups, the persistence of ransomware, and attacks targeting business and…

Intel471

UK Threat Landscape Report (2025) - Analyzes the escalating cyber threat landscape in the United Kingdom and outlines strategic preparations for the upcoming Cyber Security and Resilience Bill. Key findings reveal that the UK ranked as the second most impacted nation for initial access broker…

Interpol

Africa Cyber Threat Assessment Report (2025) - Reveals a steep rise in cyber-related crime across the continent, with online scams, ransomware, business email compromise, and digital sextortion identified as the most prevalent threats. According to INTERPOL, cybercrime now accounts for more than…

Lastpass

APAC Regional Report (2025) - Analyzes the evolving cyber threat landscape across the Asia Pacific region, documenting a surge in espionage, ransomware, and credential-based attacks targeting critical industries. Findings indicate that the region accounted for 34 percent of global cyber incidents…

National Cyber Security Centre

Cyber Threat Report (2025) - Analyzes the 2025 cyber threat landscape for New Zealand organizations, detailing five key judgments regarding prevalent threats. Key findings indicate a rise in state-sponsored actors, commercialized cybercrime tools, hacktivist activity driven by global conflicts,…

New Zealand

Cyber Security Action Plan 2026pdf (2026) - Examines national cyber security strategy and threat mitigation across critical infrastructure, establishing immediate government priorities and regulatory frameworks for the coming years. Key findings outline fifteen targeted initiatives spanning…

Norwegian Police

Threat Assessment (2026) - Analyzes the evolving landscape of criminal threats in Norway, focusing on the professionalization of criminal networks and their increasing exploitation of digital infrastructure. Key findings reveal that violence and threats accounted for over 10 percent of all…

Office of the Director of National Intelligence

Annual Threat Assessment (2026) - Assesses the global threat landscape facing the United States, focusing on transnational organized crime, illicit drug trafficking, and emerging technological challenges. Key findings indicate that synthetic opioid-related overdose deaths declined by nearly 30…

Security Scorecard

State of South Koreas Cybersecurity (2026) - Analyzes the cybersecurity posture of South Korea’s top one hundred publicly traded companies by evaluating externally observable risk signals and supply chain dependencies. Findings reveal that 46 percent of these organizations received a D or F…

DSCI & Seqrite

India Cyber Threat Report (2025) - Analyzes the evolving cyber threat landscape in India using telemetry collected from 8.44 million endpoints across the country. Key findings reveal over 369 million security detections during 2024, with Trojans emerging as the most prevalent malware category,…

Seqrite

India Cyber Threat Report (2026) - Analyzes the evolving cyber threat landscape in India by examining telemetry data from over eight million endpoints to identify critical vulnerabilities and attack patterns. Key findings reveal that Trojans and file infectors constitute nearly 70 percent of all…

Sweden

National Strategy for Cybersecurity (2025) - Examines the national cybersecurity strategy and digital resilience framework implemented for the years 2025 to 2029. Key findings reveal that the government approach focuses on 2 core pillars and 8 specific strategic targets to mitigate critical skills…

United States Department of Defense

State of DevSecOps (2025) - Focuses on the adoption of DevSecOps practices within the United States Department of Defense. A key finding is the Air Force's launch of a new software directorate, highlighting a move towards integrating security earlier in the software development lifecycle.

In 2 lists

Analysis Reports >Sector Specific Intelligence

Anthropic

The State of AI (2026) - Examines the current landscape of AI agent adoption and deployment across enterprises, based on a survey of over 500 technical leaders. Key findings reveal that 57% of organizations deploy agents.

Bio Catch

Global Scams Report (2025) - Analyzes global scam trends, highlighting the increasing sophistication and prevalence of social engineering tactics. Key findings reveal a 65% increase in reported scams, with significant regional variations and the emergence of industrialized fraud operations…

BioCatch

Digital Banking Fraud Trends in Latin America (2026) - Examines the current threat landscape and digital banking fraud trends across Latin America, drawing on data from 36 financial institutions. Key findings reveal a 155% increase in social engineering scam cases and.

Cyber Int

Travel Threat Landscape Report (2025) - Analyzes the cyber threat landscape targeting the travel and tour operations industry, highlighting recent cyber events and future predictions.

Digi Americas

Financial Sector Threat Landscape (2025) - Investigates the cybersecurity landscape of the Latin American financial sector, focusing on systemic vulnerabilities, regulatory gaps, and the tactics of prominent threat actors. Findings reveal that the region faces a disproportionate risk, with 79…

European Payments Council

Payments Threats and Fraud Trends Report (2025) - Investigates the evolving landscape of payment threats and fraud, emphasizing the critical role of artificial intelligence in scaling sophisticated cyberattacks against financial infrastructures. Findings indicate that social engineering remains a…

FDIC

Cybersecurity and Resilience Report (2025) - Surveys the FDICs comprehensive strategy for strengthening both its internal cybersecurity and the resilience of the financial services sector. Key initiatives include significant policy updates in 2024, such as Directive 1.

Futuriom

Top Cloud and AI Infrastructure Trends (2026) - Surveys the top cloud and AI infrastructure trends for 2026, identifying leading private companies and market dynamics. Key findings reveal aggregate AI capital expenditure spending is approaching $1 trillion annually.

Gatepoint Research

The State Of Network Security In Transportation And Logistics (2025) - Analyzes the network security landscape in the transportation and logistics sector, highlighting priorities, challenges, and technology adoption. The report reveals that staying ahead of cybersecurity threats is a top concern…

GSMA

Security Landscape (2026) - Analyzes the evolving mobile telecommunications security landscape, focusing on critical threats such as software vulnerabilities, supply chain compromises, and the democratization of attack tools. Key findings highlight that the global scam economy now costs victims 1…

HardenStance

Telco Strategies for Consumer Security (2026) - Investigates global telecommunication operator strategies and investments in consumer cybersecurity software. Key findings indicate that global spending reached $441 million in 2025, which amounts to less than 0.1% of the $442 billion total annual…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

HardenStance

Briefing MWC25 Taking Stock of Telco Security (2025) - Examines the current state of telecommunications security following industry discussions at the Mobile World Congress, revealing significant sector vulnerabilities and rising threat actor activities. Key findings highlight that China nexus…

Health ISAC

Annual Threat Report (2026) - Analyzes the evolving threat landscape within the global health sector, focusing on the systemic risks posed by ransomware, supply chain exploitation, and the integration of insecure medical devices. Key findings from a survey of nearly 250 industry professionals…

Intuition Lab

AI Medical Device Cybersecurity Regulations and Risks (2026) - Examines the cybersecurity landscape for artificial intelligence enabled medical devices by evaluating regulatory mandates, technical standards, and emerging threat vectors. Key findings reveal that 53 percent of connected medical…

Nokia

Threat Intelligence Report (2025) - Analyzes the 2025 threat landscape for the telecommunications sector, identifying a strategic shift from opportunistic attacks to coordinated, infrastructure-level campaigns targeting core networks and lawful interception systems. Key insights include the…

Six Map

Research Energy Sector Exposure Assessment (2025) - Analyzes the external exposures of 21 leading U.S. energy providers to assess their security posture and identify systemic risks. The study found nearly 40,000 hosts with over 58,000 exposed services, including a significant number running on…

TableMedia

European Deep Tech Report (2026) - Examines the state of European Deep Tech, focusing on its funding landscape, talent pool, and market opportunities. Key findings reveal that European Deep Tech VC funding reached $20.3 billion, comprising an.

TRM Labs

Crypto Crime Report (2026) - Analyzes the illicit cryptocurrency market in 2025, highlighting key trends and activities. The report finds that while overall illicit crypto volume decreased, ransomware demands reached an all-time high and terrorist financing via cryptocurrency expanded, with…

TRM Labs

Global Crypto Policy Review Outlook (2025) - Analyzes global cryptocurrency policy developments and their impact on institutional adoption. Key findings indicate that over 70% of reviewed jurisdictions advanced stablecoin regulation, while approximately 80% saw financial institutions announce new…

Trustwave

Energy Utilities Risk Radar (2025) - Analyzes the unique cybersecurity challenges and evolving threat landscape facing the critical energy and utilities sector. Key findings highlight an 80% year-over-year increase in ransomware attacks, predominantly initiated by phishing 84% and leveraging…

Trustwave

Healthcare Risk Radar (2025) - Analyzes the evolving cybersecurity risk profile of the healthcare sector, detailing emergent threats and vulnerabilities. Key findings reveal that 45% of attacks originated from exploiting public-facing applications, with ransomware groups like Ransomhub and LockBit…

Trustwave

Hospitality Risk Radar (2025) - Examines the persistent threat landscape and unique cybersecurity challenges facing the hospitality sector. Key findings highlight a massive attack surface from publicly exposed services, which account for 61.5% of initial access attempts, and a significant volume…

Trustwave

Manufacturing Risk Radar Report (2025) - Analyzes the evolving threat landscape for the manufacturing sector in 2025. Key findings highlight the increasing convergence of IT and OT systems, a persistent rise in ransomware attacks, and the need for enhanced security measures across all attack stages.

Upstream

Global Automotive Cybersecurity Report (2026) - Analyzes security findings and threat trends reported by Upstream for 2026, examining key attack patterns, vulnerability data, and defensive recommendations. Key findings reveal that the integration of Physical AI and Large Language Models has…

Veriti

The State of Healthcare Cybersecurity (2025) - Analyzes the evolving threat landscape within the healthcare sector, focusing on the systemic vulnerabilities and ransomware risks facing medical organizations in the United States. Key findings reveal that nearly 400 healthcare organizations reported…

Visa

Biannual Threats Report (2025) - Analyzes the payments ecosystem's threat landscape, focusing on evolving fraud tactics and scams. Key insights reveal a significant increase in ransomware and data breach incidents, alongside sophisticated fraud schemes leveraging malicious mobile applications and…

Visa

Spring Biannual Threats Report (2026) - Examines the structural shifts reshaping payment security and the migration of criminal threats from technical compromises to behavioral manipulation. Key findings reveal that global ransomware activity rose 26% while device-token fraud declined 9.6% year…

Analysis Reports >Application Security

Akamai

State of Apps and API Security (2025) - Documents a year of material escalation in cyber risks, specifically highlighting how Artificial Intelligence is supercharging both offensive and defensive strategies. Akamai observed over 311 billion web application and API attacks in 2024, a 33% increase…

Armis

Early Warning Insights for Software Supply Chain Attacks (2025) - Investigates the rising threat of software supply chain attacks driven by artificial intelligence and the practice of rapid, unverified code deployment. Research indicates that as many as 40 percent of code suggestions generated by…

Black Duck

Open Source Risk Analysis Report (2026) - Analyzes the current state of open source software usage and security risks across commercial codebases, highlighting the impact of rapid development and artificial intelligence integration. Key findings reveal that 65% of organizations experienced a…

Contrast Security

Software Under Siege (2025) - Highlights the increasing prevalence and impact of application-layer attacks targeting custom code, APIs, and application logic. The report reveals that applications face an average of 81 confirmed attacks per month, coupled with nearly 30 serious vulnerabilities,…

Data Dog

State Of DevSecOps (2026) - Analyzes the current state of DevSecOps by investigating the prevalence of exploitable vulnerabilities and the risks associated with rapid software dependency updates. Findings indicate that 87 percent of organizations maintain at least one exploitable vulnerability in…

Digital AI

Application Security Threat Report (2025) - Quantifies evolving risks in modern application security. Key findings highlight industry trends, attack data categorized by industry and OS, and regional variations in attack rates.

F5

Office of the CTO Report Continuous API Sprawl (2026) - Examines the rapid expansion and economic impact of application programming interfaces across modern enterprise environments, detailing the primary factors driving continuous digital sprawl. Key findings reveal that the total number of…

Fluid Attacks

State Of Attacks (2026) - Analyzes the state of cybersecurity and vulnerability management across diverse software development environments, documenting trends in risk exposure and remediation efficiency throughout 2025. Key findings reveal that while the vulnerability remediation rate increased…

Fortinet

Web Application Security Report (2026) - Examines the security posture of web applications and APIs in the context of artificial intelligence adoption, highlighting a widening readiness gap between modernization and operational control. Key findings reveal that 74% of organizations observed an…

Git Guardian

State of Secrets Sprawl (2026) - Examines the state of secrets sprawl and security vulnerabilities, detailing the impact of rapid development cycles and AI adoption. Key findings reveal 28.65 million new hardcoded secrets in public GitHub commits during 2025, representing a 34% year-over-year…

Grip

SaaS Security Risks Report (2026) - Examines the state of SaaS and artificial intelligence security risks, highlighting how unmanaged enterprise adoption creates critical operational vulnerabilities. Key findings reveal that 100 percent of analyzed organizations operate environments with embedded…

Kodem

State of AppSec Workflow (2025) - Analyzes application security workflows, identifying key bottlenecks and pain points in current practices. The primary bottleneck is remediation, exacerbated by alert fatigue and inefficient vulnerability triage, highlighting the need for increased automation and…

Legit Security

State of Application Risk Report (2025) - Examines the current state of application risk in 2025, focusing on common vulnerabilities and security testing inefficiencies. Key findings reveal significant issues with secrets exposure, AI-related risks, and software supply chain vulnerabilities,…

Orca

State of AppSec Report (2026) - Analyzes the current state of application security across the modern software delivery lifecycle by evaluating telemetry from over 1,000 production organizations. Findings reveal that 78 percent of organizations operate with critical vulnerabilities in production,…

Reversing Labs

Software Supply Chain Security Report (2026) - Examines the evolving landscape of software supply chain security, highlighting how attackers increasingly exploit open-source ecosystems and CI/CD workflows to achieve persistence. Research reveals a 73% increase in malicious open-source packages…

Robotti

AppSec Report (2026) - Examines the evolving landscape of application security, emphasizing the transition toward executive accountability and the integration of secure by design principles within modern development lifecycles. Key findings indicate that 50 percent of C level executives will have…

Salt

State Of API Security (2025) - Highlights the persistent challenges and evolving landscape of API security, driven by rapid digital transformation and cloud migration. Despite widespread API adoption and a nearly universal encounter with security issues, many organizations struggle with accurate…

Seraphic Security

Zero Trust Browser Security (2025) - Examines the evolving zero trust browser security market, highlighting its transition from fragmented point solutions to integrated platforms that serve as a central control plane for enterprise security. Market data indicates that the sector generated 622.0…

Sonatype

State of The Software Supplychain (2026) - Examines the state of the software supply chain, documenting how massive growth in open source usage has created critical infrastructure vulnerabilities and systemic operational risks. Key findings reveal that 65 percent of open source vulnerabilities…

Veracode

State Of Software Security Report (2026) - Analyzes the current state of software security by evaluating the widening gap between the rapid creation of vulnerabilities and the limited capacity of organizations to remediate them effectively. Findings indicate that security debt now impacts 82…

Wallarm

API Threat Stats Report (2026) - Examines the evolving landscape of API threats and risks in 2025, highlighting how attackers exploit repeatable failures in identity, access control, and exposed interfaces. Key findings reveal that 36% of published AI vulnerabilities involve APIs, with cross-site…

Wiz

State of Code Security (2025) - Examines the security posture of code repositories and CI/CD pipelines, highlighting the deep connection between code and cloud environments. It reveals that 61% of organizations have secrets exposed in public repositories , with GitHub dominating the VCS landscape…

Analysis Reports >Cloud Security

Bellsoft

State-of-Container-Security (2025) - Analyzes security findings and threat trends including key attack patterns, vulnerability data, and defensive recommendations drawn from data collected across hundreds of security practitioners. Findings span 10 or more priority risk areas, providing actionable…

Censys

State Of The Internet (2025) - Analyzes adversary infrastructure, focusing on command-and-control servers and surrounding tools used by threat actors. The report reveals trends in malware detection, C2 server time-to-live, open directory lifespans, and the use of residential proxy infrastructure,…

Data Dog

State Of Cloud Security (2025) - Analyzes cloud security posture across AWS, Azure, and Google Cloud with a focus on identity risks, default security gaps, and the uneven adoption of guardrails like IMDSv2, data perimeters, and public access blocks. The study highlights persistent trouble spots…

Fidelis

AWS Security (2026) - Evaluates the critical security practices required to protect complex cloud environments as organizations scale their infrastructure into 2026. Key findings indicate that misconfigurations remain a primary driver of cloud breaches, with Verizon data showing that credential…

Fortinet

360 Protection AWS (2026) - Examines cloud and artificial intelligence workload security within Amazon Web Services environments, highlighting the complexities of managing dynamic cloud infrastructures and expanding threat landscapes. Key findings reveal that 69% of organizations experienced…

Google

Threat Horizons Report (2025) - Analyzes security findings and threat trends reported by Google for 2025, examining key attack patterns, vulnerability data, and defensive recommendations drawn from data collected across hundreds of security practitioners. Findings span 10 or more priority risk…

HPE

VPN Exposure Report (2025) - Examines the current state of VPN security and the shift toward modern remote access alternatives based on a comprehensive survey of industry professionals. Key findings reveal that 48% of organizations have experienced a VPN-related cyberattack, while 72% maintain…

Orca

Estimating Return on Investment for the Cloud (2026) - Evaluates the economic impact of transitioning to a unified cloud security platform by comparing fragmented legacy toolsets against modern agentless and artificial intelligence capabilities. Analysis demonstrates that a representative…

Recorded Future

Cloud Threat Hunting And Defense Landscape (2025) - Analyzes the evolving cloud threat landscape by identifying five primary attack vectors posing significant risk to cloud environments. Key insights reveal that initial compromises often stem from misconfigured cloud endpoints or stolen…

Netskope

Cloud and Threat Report (2026) - Analyzes the enterprise threat landscape and the rapid, widespread adoption of generative artificial intelligence across corporate environments. Key findings reveal a sixfold increase in prompt volume and a doubling of data policy violations, with the average…

Orca

State of Cloud Security Report (2025) - Analyzes security challenges in multi-cloud environments, with a focus on AI risk, data exposure, and neglected assets. Key findings reveal that 62% of organizations have at least one vulnerable AI package, 38% expose sensitive databases to the public, and…

Sysdig

Cloud Native Security and Usage Report (2026) - Analyzes the current state of cloud native security and the transition toward autonomous, agentic vulnerability management as human capacity reaches its operational limits. Key findings reveal that while organizations have reduced image bloat by 50…

Toc Consulting

The State of AWS Security (2026) - Examines the evolving AWS threat landscape, focusing on the transition from traditional misconfiguration exploits to sophisticated attacks involving autonomous agentic systems. Key findings reveal that 48 percent of cybersecurity professionals identify agentic AI…

Trend Micro

Annual Cybersecurity Threat Report (2025) - Analyzes enterprise cyber risk exposure across sectors and regions using telemetry from Trend Vision One's Cyber Risk Index framework. Key findings show the education sector maintained the highest risk throughout 2024, while larger organizations…

Unosecure

Cloud Compliance Pulse (2025) - Provides a half-yearly benchmark of cloud compliance and identity security posture across 50 organizations, utilizing automated control scans for a data-driven assessment. It reveals that 98% of firms exhibit at least one high-severity gap, with 70% of critical…

Varonis

State Of Data Security Report (2025) - Analyzes the state of data security in 2025, focusing on the impact of AI adoption on data risk across 1,000 organizations. The report reveals that 90% of organizations have exposed sensitive cloud data, 88% have stale ghost users, and 99% have sensitive data…

WithSecure

Salesforce Threat Landscape Report (2026) - Investigates the evolving Salesforce threat landscape by analyzing detection telemetry and publicly reported incidents to document how cybercriminal groups exploit high-trust access paths. Findings reveal that malicious activity is increasingly dominated…

Wiz

Cloud Data Security Snapshot (2025) - Analyzes current cloud data security exposure trends. A significant finding reveals that 54% of cloud environments have exposed assets containing sensitive data, highlighting the critical need for improved access controls and vulnerability management.

Wiz

State of AI in the Cloud (2025) - Analyzes the current state of AI in cloud environments, focusing on adoption rates, security challenges, and governance issues. Key findings reveal DeepSeek's rapid growth and the continued dominance of OpenAI, alongside a rising trend of self-hosted AI…

Zscaler

VPN Risk Report (2026) - Examines the security risks of enterprise virtual private network infrastructure through a survey of 822 information technology and cybersecurity professionals. Key findings reveal that 61 percent of organizations experienced confirmed or suspected artificial…

Analysis Reports >Vulnerabilities

Beyond Trust

Microsoft Vulnerability Report (2026) - Analyzes the 2026 Microsoft Vulnerability Report to assess shifting threat patterns and the evolving risk landscape within the Microsoft software ecosystem. While total vulnerability volume decreased by 6 percent to 1,273, the number of critical…

Chainguard

The Cost of CVEs (2025) - Aanalyzes the financial impact of CVE management on organizations using containerized environments. Key findings indicate that mid-market organizations can unlock significant value through decreased risk $2.8M, increased revenue $2.2M, and faster innovation $3.3M by…

Deepstrike

Vulnerabilities Statistics (2025) - Analyzes the global surge in cybersecurity vulnerabilities throughout 2025, documenting a record pace of disclosures and the increasing speed of weaponization by threat actors. Key findings reveal that over 21,500 vulnerabilities were cataloged by midyear, with…

Edgescan

Vulnerability Statistics Report (2026) - Analyzes the state of full stack security by evaluating millions of assets across diverse industries to identify critical vulnerabilities and remediation trends. Key findings reveal that 31.9 percent of discovered web application and API vulnerabilities are…

GreyNoise

State of the Edge Report (2026) - Investigates the evolving security landscape of decentralized edge infrastructure, focusing on the increasing exploitation of routers, firewalls, and remote access gateways. Data from the sensor network reveals a 40 percent increase in unique IP addresses…

GreyNoise

Mass Internet Exploitation Report (2025) - Examines the evolution of mass internet exploitation and the rapid weaponization of newly disclosed vulnerabilities observed through a global network of passive sensors. Data indicates that attackers are increasingly prioritizing N-day vulnerabilities…

Imperva

Bad Bot Report (2025) - Analyzes the 2025 Imperva Bad Bot Report, detailing the evolving landscape of automated internet traffic and its impact on businesses. Key findings reveal that automated traffic now surpasses human activity at 51%, with malicious bots comprising 37% of all internet traffic,…

Flexera

Annual Vulnerability Review (2025) - Analyzes the monthly vulnerability landscape based on Secunia Research data, providing insights into emerging threats and trends. Key findings include a significant year-to-date increase in advisories and the identification of actively exploited zero-day…

Greyn Noise

Early Warning Signals Attacker Behavior Precedes New Vulnerabilities Report (2025) - Analyzes the correlation between spikes in attacker activity and subsequent CVE disclosures, particularly in edge technologies. The report reveals that in 80% of analyzed cases, attacker activity spikes preceded…

Hornet

Cybersecurity Report (2026) - Examines the 2026 cybersecurity threat landscape based on Hornetsecurity's analysis of over 72 billion emails processed, highlighting evolving attack vectors and defensive strategies. Key findings reveal a 131% surge in malware-laden emails, a 29% increase in…

Intruder

Exposure Management Index (2025) - Analyzes cybersecurity exposure trends across 3,000 small to midsize organizations, focusing on vulnerability detection and response metrics. Key findings reveal a 19% increase in high-severity issues driven by AI-weaponized legacy CVEs, alongside a significant…

Intruder

Attack Surface Management Index (2026) - Examines the current state of attack surface management by analyzing the visibility gap and vulnerability remediation challenges across diverse digital infrastructures. Research indicates that over 60 percent of organizations remain unaware of at least one…

Rapid7

Threat Landscape Report (2026) - Investigates the acceleration of the global threat landscape and the collapse of predictive lead times for vulnerability exploitation. Key findings reveal that confirmed exploitation of high severity vulnerabilities increased by 105 percent year over year, while…

Recorded Future

Malware And Vulnerability Trends (2025) - Analyzes malware and vulnerability trends observed in the first half of 2024, focusing on exploitation of remote access and security software. Key insights reveal a significant 103% increase in Magecart infections and the continued dominance of infostealer…

Telefonicatech

Security Status Report (2025) - Analyzes the cybersecurity landscape of the first half of 2025, covering mobile security, significant vulnerabilities, and APT operations. Key insights reveal a growing concern over the sustainability of critical infrastructure like CVE, alongside a surge in…

Torq

AI SOC Leadership Report (2026) - Examines the current state of artificial intelligence integration within security operations centers, highlighting the operational challenges caused by fragmented toolsets and the evolving role of analysts. Key findings reveal that while 79 percent of…

Vuln Check

State Of Exploitation (2026) - In 2025, VulnCheck identified 884 Known Exploited Vulnerabilities KEVs for which evidence of exploitation was observed for the first time. Our analysis shows that 28.96% of KEVs in 2025 were exploited on or before the day their CVE was published, an increase from the…

VulnCheck

Exploit Intelligence Report (2026) - Analyzes the 2025 vulnerability and exploit landscape to provide actionable intelligence on threat actor behavior and the evolving exploit ecosystem. Key findings reveal that while only one percent of disclosed vulnerabilities were exploited in the wild, the…

Analysis Reports >Ransomware

Abnormal

Read Replied Compromised Employee Engagement Trends (2025) - Analyzes employee engagement trends with vendor email compromise attacks, revealing significant behavioral blind spots. The report highlights a 44.2% overall employee engagement rate with VEC messages and a failure to report 98.5% of…

Akamai

Ransomware Report (2025) - Focuses on the evolving ransomware landscape in 2025, highlighting the increasing complexity and volatility of threats. The report reveals the integration of AI and LLMs by ransomware groups, the rise of quadruple extortion tactics, and the weaponization of compliance…

Cyfirma

Tracking Ransomware (2026) - Investigates the evolving ransomware landscape in early 2026, highlighting a shift toward user-mediated access, browser-centric exploitation, and psychological coercion over traditional encryption. Data indicates that ransomware activity reached 683 incidents in…

Gen Digital

Threat Report (2026) - Examines the evolving threat landscape of 2026, highlighting a strategic shift where malicious actors increasingly abuse established digital trust and routine workflows. Key findings reveal that tech support scams surged by 61.6% to reach 20.3 million blocked attacks, while…

Guidepoint

GRIT Ransomware Annual Report (2026) - Threat actors continue to evolve in their tactics, techniques, and procedures with AI/LLM enabling more rapid adaptation and continuing to reduce barriers to entry for less-skilled and unskilled actors. Key findings include an in-depth look at the RansomHub…

Howden

Cyber Report Rebooting Growth (2025) - Examines the current state and future growth potential of the cyber insurance market, with a specific focus on unlocking new risk pools in underserved European regions. Key findings reveal an estimated €307 billion economic.

Rapid7

Threat Landscape Report Q3 (2025) - Analyzes the evolving global threat landscape in the third quarter of 2025, focusing on ransomware trends, nation-state espionage, and the exploitation of critical infrastructure. Key findings reveal that 88 distinct ransomware groups were active during this…

Symantec

Ransomware Threat Landscape (2026) - Analyzes the evolving ransomware threat landscape and the shift toward encryptionless extortion tactics during 2025. While traditional ransomware attacks saw a marginal 0.8 percent increase, the total volume of extortion incidents surged by 23 percent when…

Veeam

Ransomware Trends (2025) - Analyzes the evolving ransomware threat landscape and proactive resilience strategies for 2025. Key findings reveal a slight decrease in overall attack impact, a significant decline in ransom payments, and a rise in data exfiltration attacks as threat actors adapt to…

Vipre

Email Threat Report (2025) - Examines email-based threat trends and evolving social engineering tactics observed in Q2 2025, emphasizing human-centered attacks. Key findings highlight the sustained targeting of manufacturing and retail, a significant shift towards customized phishing deployments,…

ZScaler

Threatlabz Ransomware Report (2025) - Examines the current ransomware landscape, detailing top trends, targets, and evolving attack methodologies. Key findings reveal a 145.9% surge in blocked ransomware attempts and a 92.7% increase in data exfiltration, signaling a broader shift towards…

With Secure

Ransomware Threat Report (2025) - Analyzes the evolving ransomware threat landscape, highlighting trends and developments from 2021. The report indicates a decrease in new ransomware families but emphasizes ransomware's continued prevalence, accounting for nearly one-fifth of identified threats,…

Analysis Reports >Data Breaches

Allianz

Commercial Directors and Officers Insurance Insights (2026) - Examines the evolving landscape of directors and officers liability, highlighting how geopolitical instability, cyber threats, and artificial intelligence are driving increased litigation and regulatory scrutiny. Key findings reveal…

Cyentia

Information Risk Insights Study (2025) - Analyzes incident probability and the increasing risks associated with third-party relationships. A key finding is that incident probability has almost quadrupled in the last 15 years, driven in part by threat actors exploiting trusted relationships with…

Deepstrike

Cybersecurity Statistics (2026) - Analyzes the global cybersecurity landscape by evaluating incident volumes, financial impacts, and evolving threat vectors across diverse industries. Key findings reveal a 32 percent year over year increase in global ransomware attacks reaching 7,419 incidents in…

IBM

Cost Of A Data Breach Report (2026) - Examines the economic impact of security incidents and artificial intelligence adoption trends across global organizations. Key findings reveal that the global average cost of a data breach climbed twelve percent to reach 4.99 million dollars, while extensive…

Identity Theft Resource Center

Annual Data Breach Report (2025) - Analyzes the U.S. data breach landscape in the first half of 2025, identifying a persistent dominance of cyberattacks and supply chain vulnerabilities. Key findings highlight a sharp decline in victim notices despite steady compromise volumes, alongside a…

ORDR

Cybersecurity Statistics Report (2026) - Examines the evolving cybersecurity landscape and the financial impact of data breaches across various industries in 2026. Global cybercrime costs are projected to reach 10.5 trillion dollars this year, while organizations utilizing artificial intelligence…

Riskrecon

Ripples Across The Risk Surface (2025) - Investigates the prevalence and financial impact of multi-party ripple incidents, which occur when a single cybersecurity breach propagates across multiple organizations. Analysis of over 1,500 incidents reveals that while ripple events are less frequent…

RPC

Annual Insurance Review (2026) - Examines the evolving landscape of insurance risks, focusing on the intersection of artificial intelligence, cybersecurity, and emerging litigation trends in the United States. Key findings indicate that while cyber claim frequency remained stable, severity dropped…

Security Score Card

Third Party Breach Report (2025) - Analyzes the landscape of third-party cyber risk and its impact on organizations globally. Key findings indicate a significant increase in third-party breaches, with Retail & Hospitality and Technology sectors experiencing the highest exposure, and file transfer…

Verizon

Data Breach Investigations Report (2026) - Analyzes the landscape of global cybersecurity threats by examining over 31,000 security incidents and 22,000 confirmed data breaches across 145 countries. Findings reveal that vulnerability exploitation has become the primary initial access vector at 31…

Analysis Reports >Physical Security

Australia

Securing Space Cyber Security for Low Earth Orbit Satellite Communications (2026) - Examines the cyber security risks and mitigation strategies associated with low earth orbit satellite communications across space, ground, and user segments. Key findings highlight that 100 percent of legacy space…

CitizenLab

Bad Connection (2026) - Investigates the systemic exploitation of global telecommunications infrastructure by covert surveillance actors leveraging insecure 3G and 4G signalling protocols. The research identifies two distinct threat campaigns that utilized customized tooling to spoof operator…

Dragos

OT Cybersecurity Report A Year in Review (2026) - Examines the rising sophistication of operational technology threat groups that actively map control loops to disrupt physical processes. Key findings reveal that ransomware impacted over 3300 industrial organizations in 2025, while adversaries…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

Security Industry Association

Security Megatrends (2026) - Examines the evolving landscape of security technology and its integration into broader business operations. Key insights reveal a significant shift towards AI-driven software solutions and the reinvention of hardware to provide richer data, while security solutions…

Genetec

State of Physical Security (2026) - Analyzes the current state of physical security, focusing on global trends and challenges in 2026. This report explores how the industry is adapting and how strategic innovation¹ is redefining what’s possible in physical security. Technology must be managed and…

NMFTA

Transportation Industry Cybersecurity Trends Report (2026) - Analyzes the 2026 cybersecurity landscape for the transportation industry, characterizing the convergence of cargo theft and cybercrime as a comprehensive operational resilience challenge. Key findings identify the emergence of…

Nozomi

Networks OT IoT Security Report (2025) - Analyzes operational technology and internet of things cybersecurity trends in the second half of 2024. Key findings reveal a significant increase in sophisticated attacks targeting industrial control systems, highlighting the growing need for robust…

United States Air Force

Science and Technology Vision (2025) - Examines the cyberspace science and technology vision of the United States Air Force across multiple operational domains through the year 2025. Key insights detail strategic planning across 10 core sections to address escalating threats and expand attack…

Waterfall

OT Cyber Threat Report (2025) - Examines operational technology cyber threats and security trends, highlighting the rising frequency of attacks impacting physical infrastructure. Key findings reveal a 146 percent increase in sites suffering physical impairment, growing from 412 locations in 2023…

Waterfall Security

OT Cyber Threat Report (2026) - Analyzes the landscape of cyber incidents impacting physical operations and critical infrastructure, documenting a notable shift in threat actor behavior throughout 2025. Key findings reveal a 25% reduction in total recorded breaches compared to 2024, yet…

Analysis Reports >AI and Emerging Technologies

Akamai

Fraud and Abuse Report (2025) - Investigates the evolving landscape of fraud and abuse driven by the rapid proliferation of artificial intelligence bots and automated threat methodologies. Key findings reveal that AI bot traffic surged by 300 percent over the past year, while the commerce sector…

Anthropic

Threat Intelligence Report (2025) - Examines how threat actors are leveraging advanced AI models, particularly Claude, to escalate and refine their cyber operations. Key findings demonstrate AI is weaponized as an active agent in sophisticated attacks like vibe hacking for data extortion, and…

BitDefender

Global Scam Intelligence Report (2026) - Examines the evolving landscape of digital fraud and social engineering by analyzing global telemetry data to identify trends in automated scam campaigns and infrastructure. Key findings reveal a 45 percent year over year increase in reported scam attempts…

Crown

International AI Safety Report (2026) - Examines the evolution of general purpose artificial intelligence, focusing on the technical shift toward reasoning systems and the proliferation of autonomous agents. Key findings highlight that distillation techniques have significantly lowered barriers to…

Cloud Security Alliance

Shadow AI Asset Blindness (2026) - Examines the proliferation of shadow artificial intelligence within enterprise environments and the resulting security risks stemming from a lack of formal governance and asset visibility. Key findings indicate that 91 percent of enterprise artificial…

Elpaccto2

Weaponizing AI (2025) - Examines the integration of artificial intelligence within organized crime networks and the resulting challenges for law enforcement agencies across Europe and Latin America. Criminal organizations are increasingly leveraging generative models to automate illicit…

EuropeanTelcoISAC

Security Landscape (2026) - Surveys the evolving cybersecurity landscape and strategic priorities for European telecommunications providers in 2026. Key findings reveal the landscape comprises eight threats, one distinct opportunity, and one combined development, driven.

Google

Advances In Threat Actor Usage Of AI Tools (2025) - Focuses on the increasing use of AI tools by threat actors, highlighting a shift towards deploying novel AI-enabled malware in active operations. Key findings include the emergence of malware families using LLMs for dynamic code generation and…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

HardenStance

Briefing MWC25 Taking Stock of Telco Security (2025) - Examines the current state of telecommunications security following industry discussions at the Mobile World Congress, revealing significant sector vulnerabilities and rising threat actor activities. Key findings highlight that China nexus…

HiddenLayer

Quarterly AI Threat Landscape Update July (2026) - Examines the quarterly developments in the artificial intelligence threat landscape, focusing on emerging cyber capabilities, autonomous agent ecosystems, and AI-driven malware. Key findings reveal that an unearned frontier model discovered…

HumanSecurity

The State of AI Traffic and Cyberthreat Benchmark Report (2026) - Examines the rapid evolution of internet traffic and the escalating threat landscape driven by the proliferation of artificial intelligence and automated systems. Data from over one quadrillion interactions reveals that AI-driven…

Imperva

API Security Threat Report (2026) - Examines API security threats and token handling risks across 32,725 endpoints and 1,104 customer accounts. Key findings reveal that nearly 40% of endpoints carry multiple authentication risks simultaneously, with sensitive data appearing in 49.8% of detections…

Intezer

AI SOC Report (2026) - Analyzes the state of security operations in 2025 by examining over 25 million alerts across global enterprise environments to identify critical gaps in threat detection and triage. Key findings reveal that nearly 2 percent of low-severity endpoint alerts represent genuine…

Kela

AI Threat Report (2025) - Analyzes the weaponization of AI by cybercriminals, focusing on emerging threats and attack vectors. Key findings reveal a 200% increase in mentions of malicious AI in 2024, highlighting the rapid growth of dark AI tools and their use in automated phishing, vulnerability…

Latio

AI Security Report (2026) - Examines the current landscape of application security, focusing on the transition toward platform consolidation and the integration of artificial intelligence into development workflows. Key findings indicate that 84 percent of security practitioners prioritize the…

Microsoft

National Security in the Age of AI and Quantum (2026) - Analyzes the intersection of artificial intelligence and quantum computing as critical drivers of national security and economic stability in the modern digital landscape. Findings indicate that a single week of cyber disruption in the…

In 2 lists

MNP

Risk Trends (2026) - Examines the evolving landscape of enterprise risk management, focusing on the compounding threats posed by artificial intelligence, climate change, and cybersecurity vulnerabilities. Key findings indicate that 65 percent of Canadian business leaders identify cyber risks as a…

Opswat

State Of File Security Report (2025) - Examines the current state of file security, detailing prevalent threats, management practices, and the integration of advanced technologies. Key findings reveal that file-based breaches have already cost organizations an average of $2.7M over the past two…

OrcaRouter

The AI Threat Report (2026) - Examines the state of enterprise artificial intelligence security and threat progression, evaluating adoption gaps and architectural defense requirements. Key findings reveal that while 88% of organizations use artificial intelligence in business functions, 97% of…

Pindrop

Voice Intelligence And Security Report Report (2025) - Examines the evolving landscape of voice intelligence and security, focusing on the impact of generative AI on fraud. Key findings reveal a more than 1,300% surge in deepfake attacks and a 26% increase in overall fraud attempts, with deepfake…

Reco

State Of Shadow AI Report (2025) - Examines the pervasive adoption and inherent security risks of unsanctioned AI tools across enterprises. Key findings reveal OpenAI accounts for 53% of all shadow AI usage, while many popular tools lack fundamental security controls and persist unsanctioned for…

Sophos

AI Security Report (2026) - Examines the integration of artificial intelligence into enterprise cyber attack chains across a global customer base of over 625,000 organizations, focusing on compressed adversary timelines and automated malware development. Key findings reveal that threat actors…

Straiker

STAR Labs AI Threat Report Vol 1 (2026) - Examines the security posture of artificial intelligence agents across enterprise deployments, highlighting emerging attack vectors and structural risks. Key findings reveal that 36% of coding-agent attacks achieved remote code execution, 91% of…

Trendmicro

Security Predictions (2026) - Examines the industrialization of cyberthreats driven by artificial intelligence and the rapid expansion of autonomous agentic systems within modern enterprise environments. Key findings indicate that the adoption of vibe coding tools has led to a 660 percent increase…

Zscaler

AI Security Report (2026) - Examines the explosive growth of artificial intelligence and machine learning adoption within enterprise environments through a comprehensive evaluation of telemetry data. Key findings reveal that global transaction volumes surged by 83 percent year-over-year to reach…

Accenture

State of Cybersecurity Resilience (2025) - Analyzes the widening gap between AI adoption and cybersecurity maturity across global enterprises. Key findings reveal only 13% of organizations possess advanced capabilities to defend against AI-driven threats, while just 10% have reached a proactive…

Allianz

Risk Barometer (2026) - Investigates the primary global business risks for 2026 by surveying 3,338 respondents across 97 countries to identify emerging threats and organizational vulnerabilities. Cyber incidents remain the leading global concern for the fifth consecutive year, maintaining a…

Allianz

Commercial Cyber Security Trends (2025) - Examines the evolving landscape of cyber security resilience, focusing on the integration of artificial intelligence and the impact of stringent regulatory frameworks like the Digital Operational Resilience Act. Key findings indicate that the global cyber…

Anthropic

Agentic Coding Trends Report (2026) - Examines the evolution of agentic coding in 2026, focusing on the transition from individual AI assistants to coordinated multi-agent systems that manage complex software development lifecycles. Research indicates that while developers utilize AI in 60% of…

Aon

Global Cyber Risk Report (2025) - Analyzes the global cyber risk landscape and the cyber insurance market, providing insights into cyber security controls and event impacts. Key findings reveal a 22% increase in cyber claims frequency despite a 77% decline in average ransomware payouts, with…

Armis

State of Cyberwarfare (2026) - Investigates the evolving landscape of global cyberwarfare in 2026, focusing on the integration of agentic artificial intelligence into state-sponsored and criminal attack methodologies. Key findings reveal that 79 percent of IT decision-makers identify artificial…

Artic Wolf Labs

The State Of Cybersecurity (2025) - Analyzes the 2025 cybersecurity landscape, highlighting a pivotal shift in executive priorities and incident response preparedness. Key findings reveal that artificial intelligence has displaced ransomware as the top security concern for 29% of respondents, even…

At Bay

Insursec Report (2026) - Analyzes the evolving cyber threat landscape and its financial impact on businesses by examining over one hundred thousand policy years of claims data. Key findings reveal that ransomware severity increased 16 percent to an average of 508,000 dollars, while third party…

ATIS

Enhanced 5G And Zero Trust Cloud (2025) - Analyzes the implementation and operational challenges of applying Zero Trust Architecture to 5G cloud environments, specifically addressing the infrastructure hosting the 5G Core, OSS/BSS, and Open Radio Access Networks. Key findings from the ATIS study…

Axis

Perspectives (2026) - Examines the evolution of intelligent internet protocol cameras from passive surveillance tools into strategic enterprise assets that drive operational efficiency and business intelligence. Key findings indicate that the integration of edge computing and artificial…

Balbix

State of Security Posture Report (2026) - Examines the state of security posture management and reveals that cybersecurity teams struggle to measure and improve their defenses as organizations transition to the cloud. Key findings indicate that 62% of organizations lack confidence in their overall…

Big ID

Data Discovery And Classification Top 5 (2025) - Profiles BigID as a leading vendor in the 2025 data discovery and classification market, utilizing a ten-factor evaluation framework to assess its operational and technical maturity. Analysis highlights the platform's ability to automate sensitive…

Binalyze

The State Of Cybersecurity Investigations (2025) - Analyzes the state of cybersecurity investigations within US enterprises, revealing significant gaps in crisis management frameworks and response capabilities. Key findings indicate that most organizations fail to learn from cyberattacks, leading…

Bitsight

Security Digitization And The Global Supply Chain (2025) - This report analyzes the complexity and inherent risks within the modern digital supply chain. By leveraging data from over 500,000 organizations and 61.5 million relationships, Bitsight maps the interconnectedness of the global economy to…

Black Duck

State Of Embedded Software Quality And Safety (2025) - Analyzes the evolving landscape of embedded software, highlighting the impact of AI adoption and software supply chain management. Key findings reveal a significant governance gap in AI implementation, the rise of SBOMs as a commercial…

Black Duck

Balancing AI Usage And Risk (2025) - Analyzes the current state of DevSecOps, focusing on the friction between development velocity and security automation. Key findings highlight that while high-velocity pipelines are common, security lags behind, with tool sprawl often overwhelming teams with…

Bridewell

Cybersecurity in Critical National Infrastructure (2026) - Analyzes the evolving cybersecurity landscape within United Kingdom critical national infrastructure, focusing on the transition from reactive awareness to proactive regulatory execution. Findings reveal that 93 percent of organizations…

Canada

The State of Cybersecurity in Canada (2025) - Analyzes the evolving cybersecurity landscape in Canada, focusing on the critical risks posed by supply chain vulnerabilities, cloud misconfigurations, and a persistent national talent shortage. Key findings reveal that IoT and cloud misconfigurations…

Capgemini

B2B Pulse Report (2026) - Examines the evolving role of telecommunications providers in business-to-business markets, highlighting strategic imperatives and digital transformation trends across global enterprise ecosystems. Key findings reveal that 74% of organizations demand strategic partnership…

Chainguard

Engineering Reality Report (2026) - Analyzes the current state of the developer experience, highlighting key challenges and opportunities for improvement. Key findings indicate that 72% of engineers struggle to find time for new feature development due to demands on their time, while AI and…

Chainguard

State Of Trusted Open Source (2025) - Analyzes the state of trusted open source software consumption and its associated risks. Key findings reveal that 98% of vulnerabilities occur outside the top 20 most popular projects, highlighting significant security burdens in less visible software…

Cisco

State of Wireless Report (2026) - Examines the strategic role of wireless infrastructure in the era of artificial intelligence, highlighting its evolution into a critical growth engine for modern enterprises. Key findings reveal that while 78 percent of organizations report significant operational…

Comcast

Business Cybersecurity Threat Report (2025) - Analyzes the 2025 cybersecurity threat landscape based on 34.6 billion detected events, highlighting evolving adversary tactics and the need for layered defense. Key findings reveal a significant increase in resource development activities, the…

ConnectEU

State of Digital Communications (2026) - Examines the state of the European digital communications ecosystem, highlighting significant gaps in infrastructure investment and global competitiveness. Key findings reveal that while 5G coverage reached 94.9 percent of the population in 2025, total…

Connectwise

MSP Threat Report (2026) - Examines the evolving threat landscape for managed service providers, focusing on how adversaries exploit trusted identities, software supply chains, and user behavior to bypass traditional security controls. Key findings reveal a 58 percent year over year increase in…

Cyber Edge

Cyberthreat Defense Report (2025) - Analyzes the current state of cybersecurity defenses and the perceptions of IT security professionals. Key insights reveal a plateauing trend in successful cyberattacks, a significant preference for AI in security products, and persistent challenges with the…

Cyberedge

Cyber Threat Defense Report (2026) - Examines global IT security postures and threat defense strategies based on responses from 1200 qualified professionals across 17 countries. Key insights reveal that 80.7% of surveyed organizations experienced at least one successful cyberattack in the past…

Darktrace

The State Of Cybersecurity In The Finance Sector (2025) - Examines the state of cybersecurity in the finance sector, detailing evolving risks to confidentiality, integrity, and availability. Key findings reveal a significant increase in sophisticated phishing techniques like AiTM and QR code…

Deloitte

NASCIO Cybersecurity Study (2026) - Analyzes the evolving cybersecurity landscape for state governments, focusing on the impact of sophisticated threats, artificial intelligence, and shifting resource allocations. Key findings reveal that the percentage of state chief information security officers…

Deloitte

Future of Cyber Survey (2025) - Surveys the state of global cybersecurity leadership, analyzing strategic paradoxes and organizational maturity across various industries. Key findings reveal that 17 percent of surveyed enterprises qualify as frontrunners with advanced capabilities, while 60…

Duha

State of Security Vendors RSAC (2026) - Examines the current landscape of cybersecurity vendors at the RSA Conference, focusing on marketing trends, booth design strategies, and the prevalence of artificial intelligence terminology. Key findings reveal that 37 percent of the 607 observed…

Elastic

Global Threat Report (2025) - Analyzes the evolving landscape of cyber threats, highlighting a significant shift towards high-velocity attacks that weaponize trusted enterprise tools. Key insights reveal adversaries are prioritizing immediate execution over stealth, with Windows execution tactics…

Elastic

State Of Detection Engineering (2025) - Analyzes the practice of detection engineering within Elastic Security, detailing their approach to rule development and enhancement. Key findings highlight the impact of real-world threat analysis, automated rule validation, and the Detection Engineering…

ENISA

Threat Landscape Report (2025) - Outlines the organizational scope and collaborative foundation of the 2025 Threat Landscape report, dedicated to enhancing the Union's infrastructure and digital security. Key contributors include EEAS STRATCOM, Europol EC3, and various Information Sharing and…

FAIR Institute

State Of Cyber Risk Management Report (2026) - Examines the evolving landscape of corporate cyber risk oversight and provides a standardized framework for boards to integrate security into enterprise strategy. Documents the critical nature of this mandate by noting that global cyberattacks now…

FERMA

Demystifying Cyber Insurance (2025) - Analyzes the current state of the European cyber insurance market, identifying a transition from extreme volatility to a buyer-friendly environment characterized by softening rates and enhanced organizational resilience. Key findings highlight that while large…

FINOS

State of Open Source in_Financial Services (2025) - Analyzes the current state of open source software adoption and strategic maturity within the global financial services sector. Key findings indicate that 87 percent of organizations now view open source as critical to their future, while 49…

Forescout

Riskiest Devices (2025) - Analyzes millions of devices to identify the most vulnerable assets in enterprise networks, revealing that network equipment has overtaken endpoints as the riskiest IT category. Key findings highlight a 15% increase in industry-wide risk, the unprecedented addition of 12…

Forrester

Iot Security Solutions Report (2025) - Evaluates the landscape of IoT security solutions for Q3 2025, categorizing top vendors like Nozomi Networks and Claroty into Leaders, Strong Performers, and Contenders. The report emphasizes that while asset discovery is foundational, effective security…

Fortinet

Threat Predictions (2026) - Analyzes the acceleration of cybercrime and its industrialization, highlighting the increasing speed and scale of attacks. Key insights reveal that AI-driven autonomous agents and the convergence of fraud and cybercrime will drive unprecedented operational throughput…

Fortinet

Insider Risk Report (2025) - Examines the state of enterprise insider risk management and highlights current operational maturity levels, tool effectiveness, and visibility gaps across modern hybrid environments. Key insights reveal that 77% of organizations experienced insider driven data loss in…

Google

Cloud ROI Of AI (2025) - Focuses on the impact of AI agents on business value, highlighting the shift from predictive to agentic AI. The report finds that 88% of agentic AI early adopters are seeing a positive ROI on gen AI, driven by executive commitment and strategic deployment across various…

Google

Cybersecurity Forecast (2026) - Analyzes the evolving cybersecurity landscape for 2026, focusing on the impact of artificial intelligence, persistent cybercrime, and nation-state activities. Key insights reveal adversaries fully embracing AI for sophisticated attacks, a significant rise in…

GRCEngineer

The State of GRC (2026) - Examines the current state of governance, risk, and compliance practices by analyzing survey data from 795 industry professionals to identify trends in tool adoption and team structure. Key findings reveal that 59.1% of practitioners remain commercially unaddressed by…

GRF

Top Risks Report (2026) - Examines the primary strategic, cybersecurity, and operational risks facing nonprofits and government contractors in the Washington DC region during 2026. Key findings indicate that 58 percent of organizations report an increase or stability in attack frequency compared…

GSMA

Post Quantum Cryptography For 5g Roaming (2026) - Examines the security implications of post quantum cryptography implementation for non terrestrial networks within global telecommunications. Key insights detail alignment across 24 pages of technical documentation referencing version 1.0…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

HealthISAC

Annual Threat Report (2025) - Examines the evolving cyber threat landscape within the global health sector, focusing on the prevalence of ransomware, supply chain vulnerabilities, and nation-state espionage. Key findings reveal that threat actors executed 458 ransomware attacks against healthcare…

Hiscox

Cyber Readiness Report (2025) - Examines the cybersecurity posture of 5,750 SMEs across multiple countries, focusing on the growing influence of artificial intelligence and the persistence of ransomware threats. Highlights that while 59% of businesses experienced an attack in the last year, a…

ISACA

State Of Cybersecurity (2025) - Analyzes the global cybersecurity landscape, focusing on workforce dynamics, diminishing budget optimism, and the expanding integration of artificial intelligence. Key findings reveal that adaptability has surpassed experience as the primary hiring qualification,…

Kiteworks

Data Security Compliance Risk Annual Survey (2025) - This year’s findings reveal a stark truth: Organizations operating blind face exponentially higher risks than those with clear visibility and governance.

Kong

API Security Perspectives (2025) - While 55% of organizations experienced an API security incident in the past year, 85% say they’re confident in their organization’s security capabilities. This confidence may be misplaced, given 77% acknowledge the potential for significant security risks from AI…

Mix Mode

State Of AI In Cybersecurity Report (2025) - Analyzes the current state of AI adoption in cybersecurity, detailing its impact on threat detection and response capabilities. Key findings indicate that while AI significantly improves threat prioritization and SOC efficiency, organizations struggle…

Mobile World Live

Industry Survey Report (2026) - Scrutinizes the evolving landscape of the mobile telecommunications industry in 2026, focusing on strategic priorities, emerging business opportunities, and the integration of advanced connectivity technologies. The findings highlight a significant shift in…

Momentum

Cybersecurity Almanac (2025) - Analyzes the cybersecurity M&A and capital markets landscape for 2025, detailing strategic activity across acquisitions, IPOs, and financings. Key insights reveal a record $119 billion in strategic activity, with strategic buyers dominating the market and an emerging…

Nametag

Workforce Impersonation Report (2026) - Focuses on insider threats and adaptation of Enterprise security strategies. In 2025, a growing number of breaches that began with someone pretending to be a legitimate member of the workforce. Nearly every major breach now carries an element of impersonation.

NCC Group

Cyber Threat Intelligence Report (2025) - Analyzes the October 2025 cyber threat landscape, highlighting a sharp reversal in ransomware trends and the rising prevalence of fileless malware techniques. Key findings include a 41% increase in global attacks driven largely by the Qilin group, the…

NCC Group

Cyber Threats in Sport (2026) - Examines the evolving cyber threat landscape within the global sports industry, focusing on the vulnerabilities created by rapid digital transformation and extensive connectivity. Research indicates that 70 percent of sports organizations experienced a cyber…

Net Diligence

Cyber Claims Study (2025) - Analyzes over 10,000 cyber insurance claims from 2020 to 2024 to evaluate the financial impact of incidents across small-to-medium enterprises and large organizations. Key findings reveal that ransomware and business email compromise remain the primary loss drivers,…

Netscout

DDoS Threat Intelligence Report (2025) - Designed to quickly equip readers with actionable intelligence, it delivers insights critical for ongoing network operations and strategic planning. The digital battlefield of 2025 is defined by an unprecedented escalation in DDoS warfare, with more than 8…

Netskope

Unified Data Security (2026) - Examines the state of data security tooling and visibility gaps across enterprise environments, focusing on the challenges of tracking sensitive information as it moves into artificial intelligence workflows. Key findings reveal that 58 percent of organizations…

Norton

Cyber Safety Insights Report (2025) - Examines the cyber safety landscape for children, focusing on AI integration and cyberbullying trends. Key insights reveal that 36% of global parents notice their children using AI for companionship, while the US leads with 24% of children experiencing…

Picus

Blue Report (2025) - Developed by Picus Labs, this annual study is based on over 160 million attack simulations performed on the Picus Security Validation Platform, providing a comprehensive view of how security products and configurations perform across modern enterprise environments. The Blue…

Pillar

State Of Attacks On Genai (2025) - Analyzes real-world attacks on Generative AI applications, revealing critical security vulnerabilities. Key findings indicate a 90% data leakage rate in successful attacks, with adversaries requiring only 42 seconds and an average of 5 interactions to compromise…

Process Unity

State of Third Party Risk Assessments (2026) - Examines the current state of third-party risk management programs and the maturity gap between organizational perception and operational reality. Data reveals that 90 percent of organizations experienced at least one third-party breach in the past…

Proofpoint

Cyber Insecurity Healthcare (2025) - Examining the ongoing cyber insecurity within the healthcare industry, detailing its financial repercussions and direct impact on patient care. Key findings indicate 93 percent of organizations experienced an average of 43 cyberattacks, with 72 percent…

Prophet

State Of AI In Secops (2025) - Focuses on the challenges and opportunities surrounding the adoption of AI in Security Operations Centers. The report reveals that a significant percentage of alerts are ignored, leading to critical breaches, and highlights the growing prioritization of AI for…

PWC

Global Digital Trust Insights Report (2026) - Assesses the global cyber risk landscape and the strategic shift toward proactive investment in response to geopolitical volatility and emerging technological threats. Surveys of 3887 business and technology leaders reveal that while 60 percent are…

SANS

Cyber Threat Hunting Survey (2025) - Analyzes the decade-long evolution of threat hunting capabilities within organizations, addressing persistent challenges posed by AI adoption and cloud environments.

SANS

SOC Survey (2025) - Focuses on the structure, staffing, and challenges of modern Security Operations Centers based on the 2025 SANS SOC Survey. Key findings reveal that while core SOC functions remain consistent, there's a growing interest in cloud-native security operations, and geopolitical…

SANS

Detection and Response Survey (2025) - Surveys the current landscape of detection and response operations, focusing on how organizations manage escalating cloud complexity and persistent resource constraints. Data from the global respondent base indicates that banking, technology, and…

SANS

State Of ICS Security (2025) - Examines the current state of industrial control systems and operational technology security by analyzing incident trends, regulatory impacts, and defensive maturity across critical infrastructure sectors. Key findings reveal that while 50 percent of incidents are…

Search Light Cyber

The Correlation Between Dark Web Exposure And Cybersecurity Risk (2025) - Analyzes the relationship between dark web exposure and organizational cybersecurity risk, utilizing data from over 9,000 organizations to validate the predictive nature of pre-attack intelligence. Key findings demonstrate a…

SecurityScorecard

Supply Chain Cybersecurity Trends Report (2026) - Examines the current state of third-party risk management and the growing disconnect between leadership confidence and actual supply chain security maturity. Key findings reveal that while 90 percent of leaders believe they can maintain operations…

SISA Sappers

Report (2026) - Investigates the evolving payment security landscape in 2026, focusing on the rise of autonomous agentic commerce, upstream identity fraud, and the critical migration toward post-quantum cryptographic standards. Key findings reveal that the transition to quantum-resistant…

Sophos

State Of Ransomware In Healthcare (2025) - Analyzes the state of ransomware in the healthcare sector during 2025, detailing the causes, consequences, and recovery experiences from attacks. Key findings include a 91% drop in the average ransom demand to $342K, a significant decrease in the data…

Splunk

State Of Security (2025) - Examines the evolving challenges and future strategies for Security Operations Centers. Highlights that inefficiencies, primarily from excessive tool maintenance and alert overload, significantly hinder operations, while AI is becoming a key driver for efficiency despite…

Tailscale

State of Zero Trust (2025) - Focuses on the current state of Zero Trust adoption, highlighting the challenges and frustrations faced by IT, security, and engineering teams. Key insights reveal that fewer than one-third of organizations employ identity-based access as their primary model, while 83%…

Trelllix

Advanced Threat Research Report (2025) - Analyzes the intense escalation of the global cyber threat landscape between April and September 2025, detailing the evolving tradecraft of Advanced Persistent Threats and the rising adoption of AI-powered malware. Key findings highlight a strategic focus…

Vanta

State Of Trust Report (2025) - Analyzes the current state of trust in businesses, highlighting the impact of AI on risk, compliance, and security. The report reveals a significant AI readiness gap, with adoption outpacing expertise, and emphasizes the increasing importance of governed automation…

Verizon

Mobile Security Index (2025) - Examines the intersection of AI-driven risks and human decision-making within the mobile security landscape, utilizing survey data from 762 professionals to benchmark industry resilience. Key insights highlight the critical necessity of mobile device management and…

Viking Cloud

Cyber Threat Landscape (2026) - Examines the 2026 small and medium business threat landscape to highlight how cybersecurity risks have surpassed economic concerns as the primary operational threat. Key findings reveal that 75 percent of surveyed leaders view cyberattacks as their top operational…

World Economic Forum

Global Risks Report (2026) - Examines the evolving global risk landscape across multiple timeframes, highlighting emerging geopolitical and economic challenges. Key findings reveal that 50% of surveyed leaders anticipate a turbulent or stormy outlook over the next two years, increasing to 57% over…

Wipro

State Of Cybersecurity Report (2025) - Analyzes the cybersecurity landscape, focusing on nation-state cyber warfare and data breaches. The report reveals that 86% of nation-state attacks are espionage-related, with intellectual property theft as the primary motive, and a rise in breaches targeting…

World Economic Forum

Global Cybersecurity Outlook (2026) - Analyzes the global cybersecurity landscape in 2026, focusing on the impact of AI, geopolitics, and cybercrime. Key findings reveal that 94% of respondents anticipate AI will be the most significant driver of change, while 87% identified AI-related…

Yubico

Global State Of Authentication Report (2025) - Analyzes global authentication habits and the persistent perception-reality gap between employee security beliefs and modern cyber vulnerabilities. Key findings from the survey of 18,000 employed adults reveal that 40% of employees have never received…

Zscaler

VPN Risk Report (2026) - Examines the security risks of enterprise virtual private network infrastructure through a survey of 822 information technology and cybersecurity professionals. Key findings reveal that 61 percent of organizations experienced confirmed or suspected artificial…

Survey Reports >Executive Perspectives

Arkose Labs

The Agentic AI Security Report (2026) - Analyzes the security risks and operational challenges posed by the rapid integration of autonomous AI agents within enterprise environments. Findings from a survey of 300 global enterprise leaders reveal that 97 percent anticipate a material AI agent driven…

BioCatch

Digital Banking Fraud Trends in Thailand (2026) - Examines the current landscape of digital banking fraud in Thailand, focusing on the operational challenges posed by social engineering scams and the proliferation of mule account networks. Key findings indicate that 80% of surveyed banking leaders…

Cogility

Insider Risk Decay (2026) - Evaluates potential risk indicator decay rates within organizational insider threat mitigation programs to demonstrate how threat weight attenuates over time. Industry data reveals that 83% of organizations experienced an insider incident in 2024, with remediation costs…

CSC

The Chief Information Security Officer Outlook (2025) - Analyzes the cybersecurity concerns of CISOs in 2025, highlighting the increasing complexity and intensity of threats, particularly domain-related attacks.

Cyentia

CISO Engagement Study (2025) - Focuses on how cybersecurity buyers engage with AI driven topics, evolving content formats, and shifting sponsor behavior across global regions and industries. The data shows AI dominates user interest, OT security is underserved despite growing demand, webinars lead…

F5

Insider AI Threat Report (2025) - Examines the growing insider AI threat stemming from employees unmonitored use of artificial intelligence across organizational levels. Key findings reveal that 52% of employees are willing to use AI against company policy.

Hitch Partners

Global CISO Leadership Report (2026) - Analyzes security findings and threat trends reported by Hitch Partners for 2026, examining key attack patterns, vulnerability data, and defensive recommendations. Based on an analysis of over 625 security leaders, the report highlights that CISOs are…

HPE

Zero Trust Security Report (2026) - Examines the state of Zero Trust adoption and the execution gap across modern hybrid enterprises. Key findings reveal that while 82 percent of surveyed organizations view Universal Zero Trust Network Access as essential, only 17 percent have fully implemented…

Interisle

Malicious Registrations in the Domain Name Market (2026) - Investigates the prevalence of malicious registrations within the generic top level domain market, documenting how cybercriminal demand drives significant portions of new domain creation. Findings reveal that malicious actors registered…

Kibu

Quarterly Threat Report Q1 (2026) - Examines the evolving threat of North Korean state-sponsored fake employee schemes, which leverage sophisticated social engineering and artificial intelligence to infiltrate organizations. Key findings reveal that 98% of successful cyber intrusions.

Kroll

State of Cyber Resiliency Report (2026) - Analyzes the state of cyber resiliency, highlighting the significant disconnect between corporate strategy and security execution. Key findings indicate that 72% of organizations frequently experience misalignment between business and cybersecurity…

Proofpoint

Voice of the CISO Report (2025) - Examines the challenges, expectations, and priorities of CISOs in 2025, focusing on the impact of AI and persistent threats. The report reveals a growing concern among CISOs regarding potential cyberattacks and data loss, despite confidence in their cybersecurity…

Salt

CISO and CIO Investment Priorities (2025) - Surveys key cybersecurity investment priorities for CISOs and CIOs in 2025, as detailed in a white paper by Osterman Research and sponsored by Salt Security. Key findings highlight shifts in priorities based on evolving threat landscapes and increased…

Splunk

CISO Report (2026) - Assesses the evolving responsibilities and strategic challenges faced by modern security leaders in an increasingly complex digital landscape. Key findings indicate that 78 percent of security executives now express significant concern regarding personal liability for security…

Team8

CISO Survey (2025) - Outlines critical trends and strategic imperatives shaping the future of cybersecurity, based on the 2025 CISO Village Survey. Notable findings reveal record cybersecurity budget increases, a dual perception of AI as both a threat and a defensive tool, and heightened CISO…

Wiz

CISO Budget Survey Report (2026) - Analyzes the 2026 CISO Budget Benchmark survey, highlighting current spending trends and priorities in cybersecurity. Key findings reveal that while budgets are increasing, 56% of professionals believe they are insufficient, with cloud complexity and tool sprawl…

Zscaler

Threatlabz AI Security ANZ Executive Perspective (2026) - Investigates the rapid integration of artificial intelligence across Australian and New Zealand organizations and the resulting expansion of the enterprise attack surface. Red team testing reveals that all evaluated systems contained…

Survey Reports >Workforce and Culture

CompTIA

State of Cybersecurity (2025) - Analyzes the current state of cybersecurity, focusing on organizational priorities, incident impact, and workforce development needs. Key findings reveal that cybersecurity is a high priority for 59% of organizations, yet 56% experienced significant incident impact,…

CompTIA

State of the Tech Workforce (2026) - Analyzes the state of the United States technology workforce by examining employment trends, economic impact, and the integration of artificial intelligence across various industry sectors. Key findings indicate that net tech employment reached approximately…

Cyentia

State of HRM Insight Report (2025) - Examines the landscape of human risk management by analyzing over two hundred real-time behavioral and threat signals across more than one hundred organizations. Findings indicate that human risk is highly concentrated, with 10 percent of users accounting for…

Fortinet

Cybersecurity Skills Gap Report (2026) - Examines the intersection of artificial intelligence adoption and the global cybersecurity skills shortage across organizations. Key findings reveal that 91% of respondents use or experiment with artificial intelligence-powered security solutions, while 52%…

Fortinet

Email Security Report (2026) - Examines the state of email security defenses and organizational readiness against evolving email-based threat vectors. Findings reveal that 75 percent of security professionals consider integrating email tools into broader security infrastructure crucial.

Gurucul

Insider Risk Report (2026) - Examines the escalating operational and financial burden of insider risks driven by widespread artificial intelligence adoption, expanding cloud environments, and fragmented security tooling. Key findings reveal that 90% of organizations experienced at least one…

ISACA

State of Privacy (2026) - Examines the current landscape of privacy staffing, operational challenges, and budgetary trends within global enterprises. Key findings reveal that the median privacy staff size has decreased to five from eight in the previous year, while 51 percent of respondents…

ISC2

Cybersecurity Workforce Study (2025) - Examines the state of the global cybersecurity workforce, detailing prevailing economic pressures, technological adaptations, and skills shortages across multiple sectors. Key findings reveal that a record 16,029 participating practitioners report budget cuts…

Mimecast

The State Of Human Risk (2026) - Examines the evolving landscape of human risk in cybersecurity, focusing on insider threats and user-driven errors. Key findings reveal that a single insider-driven data exposure costs an average of $13.

MITRE

Threat Informed Defense Report (2026) - Examines the state of threat-informed defense and industry adoption of the MITRE framework through a comprehensive survey of security professionals. Key findings reveal that while 82 percent of respondents know about the framework, only 8 percent use it…

N2K

Wicys Cyber Talent Study (2025) - Analyzes the strategic collaboration between N2K Networks and Women in CyberSecurity WiCyS to map member skills against the NICE Workforce Framework. Key findings highlight the exceptional alignment of WiCyS members' capabilities with industry standards,…

Survey Reports >Market and Investment Research

Altitude

Cyber Cybersecurity Market Review (2025) - Analyzes the cybersecurity market landscape, focusing on M&A and financing activities. Key insights reveal a significant surge in M&A deal volume, driven by large strategic acquisitions, alongside continued growth in financing deal counts despite a slight…

Aon

Reinsurance Market Dynamics (2026) - Analyzes the global reinsurance market dynamics as of January 2026, focusing on record capital levels and shifting supply and demand trends across property, casualty, and specialty lines. Global reinsurer capital reached a record 760 billion dollars by…

Baird

Disruptors (2026) - Examines the landscape of private security and infrastructure software companies, profiling 29 influential market vendors across distinct operational categories. Key findings reveal that 70% of these evaluated organizations specialize in advanced cloud, data, and identity…

Clairfield International

Cybersecurity Sector Report (2026) - Examines the cybersecurity market landscape in 2025, focusing on record-breaking merger and acquisition activity alongside shifting valuation trends. The sector recorded 400 deals with a total disclosed value exceeding 84 billion dollars, while Israeli…

Cybersecurity Ventures

Cybersecurity Market Report Q4 (2025) - Analyzes the global cybersecurity market trajectory, projecting that annual spending will reach one trillion dollars by 2031 due to the expanding threat landscape across digitized infrastructure and industrial systems. Key findings indicate that global…

Cybersecurityventures

Cybersecurity Market Report (2026) - Analyzes the global cybersecurity market trajectory and the factors driving record levels of investment across diverse industrial and consumer sectors. Projections indicate that global cybersecurity spending will reach one trillion dollars annually by 2031,…

Gallagher

Cyber Insurance Market Outlook (2026) - Examines the evolving cyber insurance market and the complex threat landscape, highlighting how increased capacity and carrier competition have stabilized pricing despite rising systemic risks. Key findings reveal that while ransomware payment rates dropped…

Guy Carpenter

US Cyber Industry Exposure Database (2025) - Analyzes the US cyber industry exposure and loss curve for 2025, detailing market conditions and providing benchmarks for risk transfer. Key findings indicate a heightened risk landscape due to deregulation and nation-state activity, necessitating…

Houlihanlokey

How AI Is Reshaping Digital Engineering (2025) - Examines the transformative impact of artificial intelligence on digital engineering, highlighting the shift toward agentic systems and consulting-led delivery models. Key findings indicate that the market for artificial intelligence related…

IT Harvest

State Of Cyber (2025) - Examines the performance and key trends of the global cybersecurity industry during H1 2025. Key insights include an overall market contraction of 6.4% in vendor growth, juxtaposed with AI Security emerging as a dominant sector, comprising nearly one in three new startups.

MomentumCyber

Cybersecurity Services Market Review (2026) - Analyzes the cybersecurity services market, documenting a historic acceleration in merger and acquisition activity driven by the increasing demand for human-led defense strategies. Key findings reveal that the sector reached a record 45 deals in the…

NAIC

Cybersecurity Insurance Report (2025) - Analyzes the financial performance and operational trends of the United States cybersecurity insurance market using annual regulatory filing data and industry statistics. Key findings reveal that direct written premiums contracted by 7 percent to reach…

Recorded Future

State Of Threat Intelligence (2025) - Analyzes the adoption and maturity of threat intelligence within enterprise cybersecurity, focusing on investment trends and strategic decision-making. Key findings reveal that 76% of organizations invest over $250,000 annually, with 91% planning to increase…

UKCyber

Security Sectoral Analysis Report (2025) - Analyzes the economic performance and growth trajectory of the United Kingdom cyber security sector through a comprehensive assessment of 2,165 active firms. Findings indicate robust expansion across the industry, with total annual revenue reaching 13.2…

Survey Reports >Application Security

Akamai

APAC API Security (2026) - Investigates the state of application programming interface security across major Asia Pacific markets, highlighting how rapid artificial intelligence adoption is outpacing existing governance and visibility frameworks. Findings reveal that 81 percent of organizations…

AppOmni

State Of Saas Security Report (2025) - Analyzes the state of SaaS security in 2025, revealing a surge in security incidents despite organizations expressing confidence in their security posture. Key findings indicate a disconnect between perceived visibility and actual risk reduction, with 75% of…

BlackDuck

BSIMM16 (2026) - Analyzes the maturity and evolution of software security initiatives across diverse industry verticals by documenting observed development practices. Studies conducted on 111 participating organizations reveal that successful programs prioritize scaling security activities through…

Checkmarx

Future Of Application Security (2025) - Analyzes the current state and future challenges of application security amidst rapid developer velocity and the pervasive integration of AI in development workflows.

Cycode

State of Application Security Posture Management (2025) - Examines application security challenges and strategies from the perspectives of CISOs, AppSec Directors, and DevSecOps managers across the UK, US, and Germany. Key findings reveal inefficiencies strain the relationship between security and…

Cypress Data Defense

State of Application Security (2025) - Analyzes the state of application security and its impact on product velocity, revealing significant challenges in detection and integration. Key findings indicate that 62% of companies ship insecure code, 60% experience release delays due to security issues,…

Traceable

Global State of API Security (2025) - Annual survey gathering insights from 1,548 respondents across 100+ countries on the state of API security. Key findings reveal a persistent increase in API-related breaches, the inadequacy of traditional security solutions, and the growing risk posed by bot…

Survey Reports >Cloud Security

Checkpoint

Cloud Security Report (2025) - Focuses on the escalating cloud security challenges organizations face, including fragmented environments and outdated defenses. The report reveals that cloud-related breaches are rising, detection is largely reactive, and slow remediation extends risk exposure,…

Crowd Strike

SaaS Security Posture Management (2025) - Analyizes the 2024 SaaS Security Posture Management market, benchmarking companies' innovation and growth potential. Key findings highlight a competitive landscape with significant growth opportunities and best practices for companies seeking to improve…

Darktrace

Remote Workforce Security Report (2026) - Examines the cybersecurity risks and operational challenges introduced by the sudden shift to a remote workforce across global organizations. Key findings reveal that 80% of security professionals are moderately to extremely concerned about remote work…

Fortinet

Cloud Security Report (2026) - Analyzes the state of cloud security by surveying 1,163 cybersecurity leaders to evaluate the impact of infrastructure complexity on organizational risk and operational maturity. Key findings reveal that 69% of organizations identify tool sprawl and visibility gaps…

Google

Cybersecurity Forecast 2025 (2025) - Insights from Google Cloud leaders on emerging cybersecurity trends. Key predictions include the continued rise of ransomware and multifaceted extortion, the increasing use of AI by attackers, and the persistent threat from state-sponsored actors like China,…

HardenStance

Proven ways to block CLI spoofing scams (2025) - Examines the growing threat of caller ID spoofing and voice fraud, outlining technical mitigation strategies and regulatory responses for telecommunications providers. Key findings reveal that one major spoofing service alone generated 170000…

Hughes

Secure Network Access Report (2025) - Examines the state of secure network access, evaluating the adoption trends of technologies like secure access service edge and zero trust models across modern hybrid enterprises. Key findings reveal that 52% of organizations struggle most with securing remote…

MixMode

Cloud Security Report (2026) - Investigates the current state of cloud security and multi-cloud deployment strategies, detailing the challenges organizations face in securing modern digital environments. Key findings reveal that 75% of security professionals are extremely or very concerned about…

Prowler

State of Cloud Security Report (2026) - Investigates the current state of cloud security operations and the practical integration of artificial intelligence within modern enterprise environments. Findings reveal that security teams manage an average of 71 incidents per week, while 42 percent of…

RedHat

State of Cloud Native Security (2026) - Examines the state of cloud-native security and governance maturity across modern enterprise environments. Key insights reveal that 97% of organizations experienced at least one security incident in the past year, while 79% report that generative artificial…

Snyk

Cloud Native Application Security Report (2026) - Examines the state of cloud native application security, highlighting deployment practices and vulnerability management trends. Key findings reveal that over 56 percent of organizations experienced a security incident involving misconfigurations or…

Survey Reports >Identity Security

Cerbos

Authorization Maturity Model CISO Benchmark (2026) - Evaluates the evolving landscape of authorization maturity for modern enterprises, specifically addressing the critical governance requirements for artificial intelligence agents and autonomous workloads. Key findings emphasize that achieving…

Cogility

Insider Risk Report (2025) - Examines the state of insider risk management and modern data security challenges across corporate networks. Key findings reveal that 92 percent of recent incidents lacked proper access controls, while 96 percent of organizations feel confident despite 70 percent…

CyberArk

State of Machine Identity Security Report (2025) - Focuses on the critical and often-overlooked area of machine identity security. Key findings reveal that a significant percentage of organizations are concerned about risks stemming from compromised machine identities and expired certificates,…

CyberArk

Identity Security Threat Landscape Report (2025) - Examines the impact of cyberattacks on identity, including cyber debt, GenAI, machine identities, and third- and fourth-party risks. Key findings reveal a growing cyber debt fueled by these factors, highlighting the need for proactive security…

Dashlane

State of Credential Security Report (2025) - Examines the state of credential security in the modern workplace, highlighting how artificial intelligence and shadow information technology expand the attack surface for organizations. Key findings reveal that 74 percent of information technology…

Descope

State of Customer Identity Report (2025) - Analyzes the pervasive authentication stagnation noting 87% of organizations use passwords despite only 2% viewing them as effective. Highlights that open-source solutions nearly double revenue loss compared to commercial platforms , while AI trust…

Duo

State Of Identity Security Report (2025) - Analyzes the state of identity security and the challenges IT and security leaders face in 2025. Key findings reveal low confidence in identity providers and significant gaps in MFA adoption, despite a growing awareness of AI-driven threats and a trend…

Guidepoint

Identity Access Management Maturity Report (2025) - Analyzes the current state of Identity and Access Management maturity across organizations, evaluating the effectiveness of their practices and investments. Key findings indicate that most organizations are underfunded and overly reliant on…

Hypr

State of Passwordless Identity Assurance (2026) - Analyzes the current state of passwordless identity assurance and the transition toward industrializing security practices amidst a shifting threat landscape. Key findings reveal that generative and agentic artificial intelligence have become the…

ManageEngine

Identity Security Outlook (2026) - Investigates the evolving landscape of identity security, focusing on the rapid proliferation of non-human identities and the strategic shift toward vendor consolidation. Key findings reveal that 89 percent of organizations report machine-to-human identity ratios…

Netskope

VPNs Under Siege Report (2026) - Examines the state of remote access security and the transition from legacy virtual private networks and network access control systems to zero trust network access. Key findings reveal that 56 percent of organizations experienced a virtual private network related…

Okta

Secure Sign In Trends Report (2025) - Organizations are maintaining the steady adoption of traditional defenses while rapidly shifting toward advanced security standards. The analysis reveals that while overall multi-factor authentication adoption within the workforce context has reached 70%,…

Omada

State Of Identity Governance (2026) - Examines the current state of identity governance and security, focusing on the challenges of managing non-human identities and the rapid adoption of artificial intelligence within enterprise environments. Research involving 577 security leaders reveals that…

OpenSystems

SASE Report (2026) - Examines the adoption of managed secure access service edge and zero trust architectures across hybrid enterprise environments. Key findings reveal that 76% of organizations cite heightened security requirements as the primary driver for replacing legacy virtual private…

Sail Point

Horizons Of Identity Security (2025) - Examines the evolving landscape of identity security and organizational maturity, highlighting its transformation from foundational control to a critical security frontier. Key findings highlight the potential for strategic investments to improve security…

Spy Cloud

Identity Threat Report (2025) - Analyzes the landscape of identity-based cyber threats, highlighting trends, benchmarks, and strategies for enhanced protection. Key findings reveal that while most organizations are concerned about identity-based attacks and ransomware, significant defense gaps…

Survey Reports >Penetration Testing

Cobalt

State of Pentesting (2026) - Examines the current state of offensive security and penetration testing by synthesizing data from thousands of assessments and a survey of 450 industry professionals. Findings reveal a significant remediation gap where top performers resolve high-risk vulnerabilities…

HackerOne

Hacker Powered Security Report (2025) - Analyzes the evolving landscape of hacker-powered security, focusing on the integration of AI and the human element. Key insights reveal a significant surge in AI-related vulnerability reports and a growing trend of researchers upskilling to leverage AI in…

Survey Reports >Privacy and Data Protection

Bridewell

Global Regulatory Landscape Guide (2026) - Scrutinizes the evolving global regulatory landscape for 2026, focusing on the integration of data privacy, artificial intelligence governance, and cybersecurity resilience frameworks across the United Kingdom and Europe. Key findings highlight a…

Cisco

Privacy Benchmark Study (2025) - Highlights evolving trends in data privacy, examining the impact of regulation, investment, and the increasing role of artificial intelligence. Key insights reveal a paradoxical preference for local data storage despite higher trust in global providers, sustained…

Drata

State of GRC (2025) - Focuses on the evolving role of Governance, Risk Management, and Compliance, transitioning from a cost center to a strategic business driver. A key finding highlights the challenges GRC teams face in balancing compliance complexity and business growth, including concerns…

Episki

State of GRC Trends Budgets and Benchmarks (2026) - Analyzes the current state of governance, risk, and compliance, highlighting the shift toward continuous assurance and multi-framework management within enterprise organizations. Key findings reveal that while compliance budgets are climbing, the…

Fortinet

Data Security Report (2025) - Examines the current state of enterprise data protection and reveals that 77% of organizations experienced insider-related data loss over an 18-month period. Key findings indicate that 72% of companies lack visibility into how users interact with sensitive data across…

Hyperproof

IT Risk and Compliance Benchmark Report (2026) - Analyzes the current state of governance, risk, and compliance programs by evaluating organizational structures, framework adoption, and the operational challenges of scaling security readiness. Key findings indicate that while 86 percent of…

Immuta

State of Data Security Report (2025) - A survey of 700+ data professionals examines the current state of data security, including challenges, trends, and best practices across various industries. Key findings reveal that security and access remain top concerns amidst growing data demands, with…

Kiteworks

Data Security Compliance Risk Forecast (2026) - Examines the evolving landscape of enterprise data security and artificial intelligence governance, highlighting critical gaps in organizational readiness as agentic systems move into production. Key findings reveal that 60 percent of organizations…

Kiteworks

Data Sovereignty Report (2026) - Surveys 286 professionals across Canada, the Middle East, and Europe to assess organizational understanding and experience with data sovereignty requirements and compliance risks. Key findings reveal that one in three respondents.

Proofpoint

Data Security Landscape Report (2025) - Investigates the current state of enterprise data security by analyzing the frequency of data loss incidents, the impact of human behavior, and the emerging risks associated with artificial intelligence and agentic workspaces. Research findings indicate that…

Survey Reports >Ransomware

Delinea

State Of Ransomware Report (2025) - Analyzes the evolving ransomware threat landscape and organizational responses, highlighting key trends and challenges. Key findings indicate a surge in ransomware breaches and data extortion, alongside increasing executive concern despite the limited…

Semperis

Ransomware Risk Report (2025) - Analyzes the global ransomware landscape, evaluating attack frequency, success rates, and the critical role of identity infrastructure. Key findings indicate a modest global decrease in ransomware success, yet 78% of organizations were still targeted, with 83% of…

Sophos

State Of Ransomware (2025) - Outlines the state of ransomware in 2025, examining technical and operational attack vectors, data handling, and the financial and human costs of incidents. Notably, data encryption rates are at a six-year low of 50%, and median ransom payments dropped by 50%, though…

Sophos

State Of Ransomware In Manufacturing (2025) - Outlines technical and organizational root causes of incidents within manufacturing. Insights reveal specific vulnerabilities exploited by actors and provide a comparison to other industrial sectors.

Veeam

Data Trust and Resilience Report (2026) - Examines the state of organizational cyber resilience and data protection, highlighting a significant disconnect between executive confidence and actual recovery performance. Key findings reveal that while 90 percent of security leaders express high…

Survey Reports >AI and Emerging Technologies

Akto

State of Agentic AI Security Report (2025) - Examines the rapid integration of agentic artificial intelligence within enterprise environments and the resulting security challenges posed by autonomous workflows. Findings reveal that while 69 percent of organizations are actively piloting or running…

Apono

State of Agentic AI Cyber Risk Report (2026) - Examines the state of agentic AI adoption and the associated cybersecurity risks and organizational preparedness. Key findings reveal that while 100% of cybersecurity leaders agree agentic AI attacks would be more damaging than.

Appdome

Mobile App Consumer Survey (2025) - Examines the evolving landscape of mobile application security and consumer expectations regarding artificial intelligence threats and synthetic fraud. Key findings reveal that 89.4 percent of United States consumers demand robust protections against artificial…

Australian Institute of Company Directors

Directors Introduction to AI (2025) - Offers practical guidance for directors on establishing robust AI governance frameworks, adapting to the technology's unique characteristics. The guide highlights a critical gap in current board oversight of AI, advocating for bespoke governance frameworks…

Big ID

AI Risk And Readiness In The Enterprise (2025) - Analyzes the readiness of enterprises in securing AI, revealing a significant gap between AI adoption and governance. The report highlights that over 93% of organizations lack full confidence in securing AI-driven data, with AI-powered data leaks…

Calypso AI

Insider Threat Report (2025) - Analyzes the evolving landscape of internal AI adoption and its security implications across various organizational levels and industries.

Cisco

State of AI Security (2026) - Examines the evolving landscape of artificial intelligence security, documenting the transition from theoretical vulnerabilities to active, large-scale exploitation of agentic systems and supply chains. Research indicates that while 83 percent of organizations plan to…

Cisco

State of Industrial AI Report (2026) - Examines the state of industrial artificial intelligence adoption and infrastructure readiness across global manufacturing, utilities, and transportation sectors. Key findings reveal that 40 percent of organizations cite cybersecurity concerns as a top…

Clutch Security

MCP A View From The Trenches (2025) - Investigates the security risks of Model Context Protocol server deployments across enterprise environments, revealing a trend of silent, explosive adoption characterized by total security blindness. Critical findings highlight that employees are unwittingly…

Cycode

State Of Product Security (2026) - Examines the current state of product security in the era of artificial intelligence, focusing on the rapid adoption of coding assistants and the resulting expansion of the organizational attack surface. Research indicates that while 97 percent of organizations…

Cyera

State of AI Data Security Reportw. (2025) - Examines the rapid integration of artificial intelligence within enterprise environments and the resulting systemic risks caused by inadequate governance and visibility. Key findings reveal that while 83 percent of organizations have adopted artificial…

Darktrace

State Of AI Cybersecurity (2025) - Analyzes the transformative impact of artificial intelligence on the global threat landscape and the corresponding shift in defensive strategies within security operations centers. Key insights reveal that while 89% of CISOs anticipate long-term challenges from…

DeepInstinct

Voice of SecOps (2025) - Examines the integration of artificial intelligence within security operations and its impact on organizational defense strategies based on a survey of 500 senior cybersecurity experts. Findings reveal that while 86 percent of organizations have increased their use of…

Delinea

AI In Identity Security Report (2025) - Analyzes the widespread adoption of AI in IT operations and the associated risks, emphasizing the necessity for updated identity governance frameworks to manage agentic and generative AI entities. Key findings indicate that while 94% of global organizations…

Deloitte

Tech Trends (2026) - Examines the enterprise shift toward operationalizing artificial intelligence and robotics, focusing on the transition from experimental proof of concept projects to scalable, agentic infrastructure. Key findings reveal that while 64 percent of organizations are increasing…

Gravitee

The AI Governance Gap (2026) - Examines the critical governance gap in enterprise artificial intelligence deployments, focusing on the architectural failure to secure autonomous agents with appropriate identity and access controls. Research indicates that 71 percent of large enterprises have…

Gurucul

Pulse AI SOC Report (2025) - Examines the state of artificial intelligence adoption within security operations centers, focusing on threat detection, workflow automation, and analyst burnout. Key findings reveal that 87% of organizations are currently deploying, piloting, or evaluating artificial…

Hidden Layer

AI Threat Landscape Report (2026) - Examines the evolving threat landscape for artificial intelligence, focusing on vulnerabilities such as data poisoning, prompt injection, and supply chain compromises. Research indicates that as little as 0.1 percent of a training dataset is sufficient to inject…

Hiya

State of the Call (2025) - Examines the evolving landscape of voice communication security, highlighting the persistent risks posed by spam, fraud, and the rapid emergence of artificial intelligence powered deepfakes. Key findings reveal that 80 percent of unidentified calls go unanswered by…

Iconiq

State of AI Bi Annual Snapshot (2026) - Examines the evolving architecture and monetization strategies of artificial intelligence products within enterprise software companies. Key findings reveal that 69% of builders now focus on vertical applications, while teams leverage an average of 3.1…

KPMG

Cybersecurity Considerations (2026) - Examines the evolving landscape of cybersecurity for 2026, focusing on the strategic integration of autonomous security, artificial intelligence governance, and the management of non-human identities within hyperconnected environments. Key findings highlight…

McKinsey

State of AI Trust (2026) - Assesses the current state of artificial intelligence trust and responsible governance across approximately 500 global organizations. Findings reveal that while overall maturity is improving, only 30 percent of enterprises have reached advanced levels in strategy and…

Memcyco

AI-Driven-Fraud (2026) - Analyzes security findings and threat trends reported by Memcyco for 2026, examining key attack patterns, vulnerability data, and defensive recommendations. Based on a survey of 200 C-level executives and directors across scam-targeted industries, the findings highlight…

Netskope

AI Security Report (2026) - Examines the state of artificial intelligence security and governance based on a comprehensive survey of 1253 cybersecurity professionals. Key findings reveal that while 90% of organizations increased their security budgets, 94% still report critical visibility gaps and…

Okta

AI at Work (2025) - Focuses on the perspectives of C-suite executives regarding the transformative impact of artificial intelligence on security, innovation, and efficiency within organizations. Key findings reveal executive sentiment, concerns, and priorities regarding AI implementation,…

OpenAI

Agent Security Enterprise (2026) - Assesses enterprise risk management frameworks for autonomous AI deployments across five core security principles. The guidance emphasizes zero-trust architectures, task-scoped authorization, and boundary enforcement to contain blast radius across locally managed…

Pentera

AI Security Exposure Benchmark (2026) - Investigates the current state of enterprise artificial intelligence adoption and its impact on security posture, highlighting the disconnect between rapid deployment and limited governance. Key findings reveal that while 100 percent of enterprises have…

RedHelix

Cyber Security Trends Report (2026) - Examines the evolving cyber threat landscape in 2026, highlighting the convergence of artificial intelligence, identity-centric exploitation, and commercialized ransomware operations across enterprise environments. Key findings reveal that credential theft…

SailPoint

The Year of The AI Agent (2026) - Examines the security implications and governance challenges surrounding the rapid enterprise adoption of autonomous artificial intelligence agents. Key findings reveal that while 91% of organizations are currently deploying or evaluating these agents, governance…

Salt

Future of Agentic AI Report (2025) - Investigates the critical role of application programming interfaces in supporting agentic artificial intelligence and the resulting security challenges organizations face as they scale these autonomous systems. Findings reveal that while 64 percent of…

SANS

AI Survey (2025) - Analyzes the impact of AI on cybersecurity, three years after the introduction of generative AI. The survey reveals that security teams are lagging in AI adoption, with only half using it for cybersecurity tasks, while 81% express concern over AI-powered threats, highlighting a…

Saviynt

AI Identity Risk Report (2026) - Examines the security risks and governance challenges associated with the rapid enterprise adoption of artificial intelligence identities and autonomous agents. Key findings reveal that 92% of organizations lack full visibility into their artificial intelligence…

Synack

State of Agentic AI in Pentesting (2026) - Examines the integration of agentic artificial intelligence into penetration testing programs to address the scalability limitations of traditional manual security assessments. Key findings reveal that 87 percent of organizations have moved beyond the…

Wiz

AI Security Readiness (2025) - Analyzes the current state of AI security readiness among cloud architects, engineers, and security leaders, highlighting critical gaps. Key findings reveal widespread AI adoption is significantly outpacing the development of in-house security expertise and the…

Resources >Research Consulting

451 Research

A technology research and advisory firm specializing in emerging technology segments including cybersecurity market analysis and trends.

ABI Research

A technology market intelligence company providing strategic guidance on transformative technologies, including cybersecurity and digital security.

Forrester Research

An advisory company that offers paid research, consulting, and event services specialized in market research for information technology.

Frost & Sullivan

A consulting firm offering market research and analysis in cybersecurity, with particular focus on emerging technologies and market opportunities.

Gartner

A technology research and consulting firm which offers private paid consulting as well as executive programs and conferences.

GigaOm

A research firm offering practical, hands-on, practitioner-driven research for businesses.

International Data Corporation (IDC)

A global provider of market intelligence and advisory services.

In 2 lists

KuppingerCole

A global analyst company specializing in information security, identity & access management, and risk management.

Omdia

A global technology research powerhouse focusing on cybersecurity market analysis and digital transformation.

Ponemon Institute

Pre-eminent research center dedicated to privacy, data protection, and information security policy (often partners with industry for annual reports).

Resources >Standards and Certifications

American Institute of CPAs (AICPA)

Developer of the SOC2 framework for managing and safeguarding customer data based on trust service criteria.

FIDO Alliance

An open industry association with a focused mission: authentication standards to help reduce the world's over-reliance on passwords.

The Information Security Forum (ISF)

A global, independent organization dedicated to benchmarking and sharing best practices in information security.

The International Organization for Standardization (ISO)

An international body composed of representatives which conduct closed research for creation of standards (e.g., ISO 27001).

The Information Systems Audit and Control Association (ISACA)

An international professional association focused on IT governance and auditing.

The International Information System Security Certification Consortium (ISC)²

An American not-for-profit organization which conducts research and provides widely recognized cybersecurity certifications.

OASIS Open

A non-profit consortium that drives the development of open standards for the global information society, including cyber threat intelligence sharing (STIX/TAXII).

In 2 lists

SANS Institute

A private U.S. for-profit company which conducts research for consumers of their cybersecurity training and certifications.

In 2 lists

Trusted Computing Group (TCG)

Develops and promotes open standards for hardware-enabled security.

Resources >Threat Intelligence and Incident Response

The Anti-Phishing Working Group (APWG)

A global coalition focused on unifying the global response to cybercrime.

The Cyber Threat Alliance (CTA)

An industry-driven group of cybersecurity organizations that share threat intelligence and conduct collaborative research to combat cyber threats.

Center for Threat-Informed Defense (CTID)

A non-profit, privately funded research and development organization operated by MITRE Engenuity to advance threat-informed defense globally.

The Forum of Incident Response and Security Teams (FIRST)

Provides platforms, means and tools for incident responders to always find the right partner and to collaborate efficiently.

The Global Cyber Alliance (GCA)

An international, cross-sector effort dedicated to reducing cyber risk.

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

Focuses on operational issues of Internet abuse including botnets, malware, spam, viruses, and mobile messaging abuse.

Resources >Policy and Advocacy

The Rand Corporation

An American not-for-profit organization which conducts research and analysis on various aspects of cybersecurity and cyber policy focused on national security.

Center for Strategic and International Studies (CSIS)

A think tank with a Technology Policy Program that conducts research and provides insights into technology and cybersecurity policies.

Electronic Frontier Foundation (EFF)

A non-profit organization defending civil liberties in the digital world, including privacy and cybersecurity issues.

In 2 lists

The Internet Security Alliance (ISA)

A multi-sector trade association focused on thought leadership, policy advocacy, and standards development for cybersecurity.

World Economic Forum (Centre for Cybersecurity)

A global initiative that brings together stakeholders from industry, government, and academia to improve cybersecurity globally and secure the digital economy.

Resources >Working Groups

The Cloud Security Alliance (CSA)

Promotes best practices for providing security assurance within cloud computing.

Cloud Native Computing Foundation (CNCF) Security TAG

Facilitates collaboration to discover and produce resources that enable secure access, policy control, and safety for cloud-native technologies.

In 2 lists

The Internet Engineering Task Force (IETF)

Develops and promotes internet standards, including those related to security.

The Open Web Application Security Project (OWASP)

A professional community that produces research concerning web application security, made freely available to the online community.

In 2 lists

Industrial Control Systems Joint Working Group (ICSJWG)

Facilitates information sharing and collaboration for cybersecurity in industrial control systems.

The Open Source Security Foundation (OpenSSF)

A cross-industry collaboration to improve the security of open source software.

In 2 lists

Resources >Government and Non-profits

Australian Cyber Security Centre (ACSC)

Provides cyber security advice and support to Australian businesses and individuals.

Canadian Centre for Cyber Security

Canada's national authority on cybersecurity.

Center for Internet Security (CIS)

An American non-profit organization that provides cybersecurity solutions, best practices, and the CIS Controls.

Cybersecurity and Infrastructure Security Agency (CISA)

A U.S. government agency responsible for enhancing the security and resilience of the nation's critical infrastructure.

Cyber Peace Institute

A non-profit organization focused on reducing the impact of cyberattacks on civilians and promoting peace in cyberspace.

European Union Agency for Cybersecurity (ENISA)

A European Union agency that contributes to EU cybersecurity policy, enhances trust in digital services, and supports incident response capabilities across Europe.

Europol - European Cybercrime Centre (EC3)

A strategic alliance focused on combating cybercrime within the European Union.

German Federal Office for Information Security (BSI)

Germany's national cyber security authority providing IT security services and guidance.

InfraGard

A partnership between the FBI and members of the private sector for the protection of U.S. Critical Infrastructure.

Internet Security Research Group (ISRG)

A non-profit organization focused on reducing financial, technological, and educational barriers to secure communication over the Internet (creators of Let's Encrypt).

Japan National Center of Incident Readiness and Strategy for Cybersecurity (NISC)

Japan's central organization for national cybersecurity strategy and incident response.

Korean Internet & Security Agency (KISA)

South Korea's government agency dedicated to promoting cybersecurity and a safer internet environment.

MITRE Corporation

An American not-for-profit organization which conducts research and development, famously maintaining the ATT&CK and CVE frameworks.

National Cyber Security Centre (NCSC)

The UK's technical authority for cyber incidents.

National Cyber Security Centre - Netherlands (NCSC-NL)

The Dutch national cyber security center providing guidance and incident response.

National Institute of Standards and Technology (NIST)

A U.S. agency that develops fundamental cybersecurity frameworks and guidelines.

Norwegian National Security Authority (NSM)

Norway's expert body for information and object security.

Singapore Cyber Security Agency (CSA)

Singapore's national agency overseeing cybersecurity strategy and development.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago