In the first half of 2026, the industry published 35,364 new CVEs. That is 195 a day. One every 7.4 minutes, around the clock, weekends included. The full-year pace projects to roughly 70,000, and FIRST (the people who forecast these things for a living) revised their annual estimate upward mid-year because AI-assisted vulnerability discovery blew through the old curve. One CVE authority saw disclosures jump 164% in a single quarter after AI tooling was pointed at its own codebase.
Now the other side of the ledger. The best data we have on remediation capacity, from Cyentia’s multi-year study of hundreds of enterprises, says the typical organization fixes about 10% of its open vulnerabilities in any given month. Not 10% of the new ones. Ten percent of the pile.
And the clock that matters most has stopped being a clock. Mandiant’s latest M-Trends puts the mean time-to-exploit at negative seven days. Negative. Exploitation now routinely begins before a patch even exists.
I have spent more than three decades trying to prevent breaches. I built the firewalls, ran the scanners, chased the patch SLAs, argued for the budget, and stood in front of boards promising that this year’s prevention investment would finally get us ahead of it. I am here to tell you that the math never worked, it is getting worse at machine speed, and the organizations that will come through the next five years intact are not the ones with the fewest vulnerabilities. They are the ones that detect fast, decide fast, and recover fast.
None of that comes off a shelf. There is no SKU for a fast decision at 3 a.m. Speed is a skill, and skills come from practice under pressure. You do not rise to the occasion; you fall to the level of your preparation.
We need to get better at being breached. On purpose, and with budget attached.
The Strategy Nobody Will Admit Is Failing
Prevention’s report card came in this year, and it is rough reading.
Verizon’s 2026 Data Breach Investigations Report, the largest dataset in its 19-year history, found that vulnerability exploitation is now the number one way attackers get in, at 31% of breaches. In nineteen years of that report, exploitation had never beaten stolen credentials to the top spot. It just did. The thing the vulnerability management industry exists to prevent is now the leading way breaches begin.
In April 2026, NIST formally restructured the National Vulnerability Database around a triage model, reclassified roughly 29,000 backlogged CVEs as “Not Scheduled,” and committed to fully enriching only 15 to 20 percent of incoming vulnerabilities. The United States government’s official vulnerability database looked at the volume and gave up on comprehensive coverage. If NIST cannot even catalog them all, your team is not going to eliminate them all.
Meanwhile, the median dwell time, the number of days an attacker sits inside a network before anyone notices, rose to 14 days in the latest M-Trends. That is the second year in a row it has moved the wrong direction, and the highest it has been since 2022. And roughly half of victim organizations still learn about their own breach from somebody else. The FBI. A researcher. A journalist. Increasingly, the attacker, who has helpfully left a note.
Here is the part where I argue against myself, because the counterargument is real and deserves better than a strawman. Microsoft’s telemetry says basic security hygiene still stops 98 to 99 percent of attacks. I believe that number, with the caveat that it is Microsoft-defined, Microsoft-measured, and published in a report that also sells Microsoft security products. Patching, MFA, least privilege: keep doing all of it. The 98% is the cheapest risk reduction you will ever buy.
But the residual 1 to 2 percent is where every catastrophe you have ever read about lives. Compliance does not save you there; the roster of breach victims is full of organizations that had clean SOC 2 reports and PCI certificates framed on the wall. And the marginal dollar tells the real story. Once the cheap hygiene is in place, each additional prevention dollar buys a thinner and thinner slice of that stubborn residual, while the response capabilities that determine whether the residual becomes a bad week or a bankruptcy sit unfunded. The economics literature has been saying this for a generation. Gordon and Loeb’s canonical model puts a hard ceiling on rational prevention spend at about 37% of expected loss. A WEIS paper by Ross Anderson and most of the security economics field concluded, back in 2019, that it “would be economically rational to spend less in anticipation of cybercrime… and more on response.” Seven years ago. Peer-reviewed. Largely ignored.
The sophisticated rebuttal here says nobody patches everything anyway: only about 6% of CVEs are ever exploited, and exploit-prediction triage like EPSS buys you the same coverage for roughly an eighth of the work. All true, and if you are not triaging that way, start. But triage optimizes which fraction of the pile you fix. It does nothing about the window, and the vulnerabilities that do get exploited increasingly get hit before the patch ships. Prioritization cannot close a window that opens before you can act. Something has to be watching what comes through it.
AI Turned an Argument Into Arithmetic
For most of my career, “you can’t prevent everything” was a philosophical position. You could nod at it and then go back to the scanner queue. AI ended the philosophy phase.
In November 2025, Anthropic disclosed that a Chinese state-sponsored group had manipulated Claude Code into running most of a cyber-espionage campaign against roughly thirty organizations, succeeding in a small number of cases. Anthropic’s assessment is that the AI performed 80 to 90 percent of the operational work, with humans stepping in at maybe four to six decision points per campaign. I will be honest about the epistemics here: that autonomy figure is a vendor’s self-reported number, some respected researchers are skeptical, and Anthropic’s own report admits the model frequently overstated its findings and occasionally fabricated credentials it claimed to have stolen. So take the percentage with salt. But then note what you cannot take with salt: MITRE catalogued the operation as ATT&CK Campaign C0062. AI-orchestrated intrusion is now a formally documented adversary behavior with its own campaign entry in the defender’s canon, catalogued the same way we catalogue the work of nation-state crews.
The same season brought Google’s discovery of PROMPTFLUX, experimental malware that queries the Gemini API to rewrite its own source code every hour to evade detection, and PROMPTSTEAL, deployed by Russia’s APT28 against Ukraine, which generates its commands at runtime by querying a language model instead of shipping them hard-coded. Think about what hourly self-rewriting code does to signature-based prevention. The signature becomes a moving target that moves faster than you do. What stays stable is behavior, and behavior is a detection problem.
The academic evidence has firmed up too. A peer-reviewed paper at EACL 2026 showed teams of LLM agents exploiting real zero-day vulnerabilities at a 42% success rate within five attempts. The same research group, testing under stricter conditions on a benchmark called CVE-Bench, puts state-of-the-art agents at more like 13%. When the people with the scariest result also publish the sobering one, believe both. Thirteen percent is not forty-two percent, and anyone quoting only the scary number is selling something. But 13% autonomous zero-day exploitation, at API prices, running in parallel, without sleep, is not a comforting figure either. The UK’s NCSC, in the careful language of a national intelligence assessment, says AI will “almost certainly” continue to shrink the time between disclosure and exploitation through 2027. In NCSC dialect, “almost certainly” is as loud as they ever get.
And the speed numbers keep compressing. CrowdStrike’s 2026 report clocks average breakout time, from initial foothold to lateral movement, at 29 minutes, with the fastest at 27 seconds, and attacks by AI-enabled adversaries up 89% year over year. Vendor telemetry, sure. But Mandiant’s incident data shows the median time from initial access to hand-off between criminal specialist groups collapsed from over eight hours in 2022 to 22 seconds in 2025. Twenty-two seconds. Your help desk cannot answer the phone in 22 seconds.
The skeptics make one point I want to concede in full, because the security leaders I talk to keep making it and they are right: so far, AI has not invented new kinds of attacks. It has changed the volume and the speed of the old ones. But that concession does not rescue prevention. Volume and speed are precisely the axes on which prevention-by-elimination was already losing. An adversary who does the same old things a hundred times faster, against a defender whose patch cycle is measured in weeks, does not need novelty.
And there is a second expansion running underneath the speed story: the terrain itself is growing. Every AI system your business deploys is new attack surface, and businesses are deploying them faster than anyone can inventory. Verizon found employee use of unsanctioned AI tools tripled in a single year, from 15% to 45% of the workforce. IBM found one in five breached organizations had been compromised through exactly that shadow AI, that nearly all AI-related breaches, 97%, hit systems with no AI access controls at all, and that the shadow variety added about $670,000 to the bill. Worse, these systems fail differently than the infrastructure your SOC was built to watch. An AI application can be leaking data through its prompts or drifting quietly off baseline while every dashboard shows green, because nothing in the alert pipeline was designed to notice a model behaving badly. And remember how the espionage campaign I described above was actually run: through a coding agent wired to tool servers over MCP. That is not exotic attacker infrastructure. That is the same plumbing we are all racing to install.
The capability is also diffusing faster than the controls around it. The frontier labs now ship in tiers: safety measures on the public models, more capable restricted tiers, the Mythos class, reserved for approved organizations. I have written before about a Discord group that had access to that restricted tier on day one, through a breached vendor, while the regulators who were supposed to oversee it were still waiting for accounts. Below the frontier, there is a storefront economy of jailbroken wrappers, WormGPT variants built on commodity models and sold through Telegram channels. Capability gates leak. Attack surface compounds. Neither curve is bending back.
Over the last six months, every room of security leaders I have sat in has converged on the same sentence: too many attackers, too many vulnerabilities, too fast, still accelerating. I no longer hear anyone claim they can defend their way out. What I hear, from every chair in those rooms, is that we have to get dramatically better at responding when it happens. Not if. When.
Even with AI on defense, and AI genuinely helps defense, the asymmetry holds for now. The most thorough academic accounting to date, from a Berkeley group, concluded that attack capability currently exceeds defensive application, with the gap expected to narrow over time. “Expected to narrow over time” is doing a lot of work in that sentence. In the meantime, breach is not a risk. It is a schedule.
This Idea Is Older Than Most of Our Careers
Here is the embarrassing part. None of this is new.
In 1997, CERT at Carnegie Mellon, the institution that invented the incident response team, published a technical report arguing that the goal must be systems that “survive attacks that result in successful intrusions.” Not prevent. Survive. That was twenty-nine years ago. In 2003, the distributed systems community formalized intrusion tolerance: assume components are compromised and design the system to stay correct anyway. That lineage runs back to Lamport’s Byzantine Generals in 1982. Distributed systems people solved “assume compromise” forty-four years ago by designing for it. Security people kept trying to eliminate the traitors.
NIST wrote it into a standard in 2021. SP 800-160 Volume 2, the cyber resiliency engineering framework, states its premise in plain English: the discussion “is predicated on the assumption that adversaries will breach defenses” and will establish long-term presence. The success criterion in that document is not zero intrusions. It is completing your mission with the adversary inside.
And look at the framework everyone claims to follow. NIST CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover. Only one of the six, Protect, is about stopping attacks. Now pull up your security budget and map it. Mine never mapped either. Nearly every program I have ever reviewed allocates like Protect is five of the six functions, then wonders why the Respond muscle cramps the first time it gets used in anger.
The regulators have stopped waiting for us. DORA, in force across EU financial services since January 2025, is named the Digital Operational Resilience Act, not the Digital Operational Security Act, and it requires its significant entities to run threat-led penetration tests against live production systems at least every three years. The SEC gives you four business days from the moment you determine an incident is material to disclose it, which is a response-quality test with an enforcement penalty attached. New York’s financial regulator now requires annual proof that you can actually restore critical systems from backup. The UK’s operational resilience regime asks firms to demonstrate they can operate through “severe but plausible disruption,” which is assume-breach written into law. And when the SEC fined four SolarWinds-affected companies in 2024, it was not for being breached. It was for negligently minimizing what happened. The first security executive criminally convicted over a breach, Uber’s Joe Sullivan, was convicted for the cover-up. The ransom was $100,000. The cover-up cost Uber $148 million and cost Sullivan his career. Regulators have fully internalized that breaches happen. What they punish now is response.
The True Test
If breach is inevitable, then response quality is where outcomes diverge. The case files make the point better than any framework.
Maersk got hit by NotPetya in 2017 through the poisoned update channel of a piece of Ukrainian tax software it barely knew it ran. Total prevention failure, roughly $300 million in losses. And yet Maersk is remembered as a success story, because they rebuilt 4,000 servers and 45,000 PCs in about ten days, on the strength of one domain controller in Ghana that survived because a power outage had knocked it offline. Compare Jaguar Land Rover in September 2025: five weeks of halted production, £1.9 billion in economic damage rippling through 5,000 businesses, a government-backed £1.5 billion loan to keep the supply chain alive. Same category of event. The difference was the recovery.
The cleanest natural experiment I have ever seen ran in the UK in spring 2025. The same criminal crew, using the same help-desk social engineering, hit Marks & Spencer and Co-op weeks apart. At M&S, the ransomware detonated; online orders were down for 46 days and the damage ran to roughly £300 million. Co-op detected the intrusion and made a brutal call fast: they pulled their own systems offline before the encryption could fire. Self-inflicted chaos, short and ugly, and their losses came in around a third of their neighbor’s. Nobody at Co-op prevented the breach. They responded their way out of the bottom half of the outcome distribution, and the deciding factor was the willingness of a human being to make an expensive decision in hours rather than convening a committee for a week.
Norsk Hydro, 2019, remains the reputational gold standard: refused to pay, ran daily press briefings, let journalists into the control rooms, and came out of a $70 million incident with its reputation enhanced. Contrast Change Healthcare, which paid a reported $22 million ransom, watched the criminal ecosystem double-cross itself, and saw the data leaked anyway, on the way to a $3 billion cleanup and congressional testimony. One of the sharpest CISOs I know keeps a maxim for the ransom decision: never pay the ransom, but always be prepared to pay. The organizations that end up with regrets are almost never the ones that made the wrong pay/no-pay call. They are the ones that arrived at the decision unprepared to make it.
IBM’s 2025 Cost of a Data Breach numbers put dollars on all of this: breaches contained inside 200 days cost over a million dollars less than the slow ones, organizations that find the breach themselves save about $900,000 over those told by the attacker or the FBI, and heavy use of AI and automation in detection and response shaves $1.9 million and 80 days off the average incident. Survey numbers, not gospel, but the finding never wavers, year after year: after boom, speed is money.
You Fall to the Level of Your Preparation
I wrote a whole piece earlier this year about why everyone suddenly wants a tabletop exercise, so I will not repeat it here. What belongs in this argument is the part boards still get wrong: the exercise program is not a checkbox on the maturity plan. It is the maturity plan. Response capability is a skill, not a document, and your organization either has rehearsed it or has not. IBM found that as many as 37% of organizations with incident response plans do not regularly test them. A plan you have never run is a hypothesis with a logo.
And realism is the active ingredient. There is a fidelity ladder, formalized decades ago in the government’s own exercise doctrine: seminar, workshop, tabletop, then the operations-based tiers where people actually do things, drills, functional exercises, full-scale live-fire. Every rung up buys more transfer to the real event. The research on training under stress, going back to work by Salas and colleagues, shows that realistic pressure inoculates, and the benefit transfers to scenarios you never rehearsed. That is the entire aviation safety model: pilots do not read about engine failures, they fly them in simulators until the response is reflex. You fall to the level of your preparation; I wrote that in the spring, and the attackers have only gotten faster since.
The failure mode is the comfortable tabletop: the scenario everyone has seen before, run in a conference room at 10 a.m. with every key person present, clean data, cooperative executives, and a facilitator steering toward the happy path. Real incidents arrive at 3 a.m., missing your best responder, with gaps in the logs and legal and comms discovering in real time that they have opposite instincts about disclosure. Exercise like that. Put the four-business-day materiality decision in the scenario. Inject the deepfake CFO call. Make the decision-makers, not just the technical team, sit in the chair and feel the clock. The regulators mandating threat-led penetration tests on live production systems have already figured out that fidelity is the point. The exercise should be the hardest version of the day you can afford to rehearse, because the real day will not grade on a curve.
What Shifting Right Actually Means
Let me be precise about what I am arguing, because “shift right” invites two misreadings. The DevOps crowd hears an excuse for shipping garbage and calling the SOC a warranty department. The sharper objection is about the verb: “shift” implies picking something up and moving it, as if I want to carry the patching budget across the boom line and dump it on the incident responders. I do not. Nothing on the left is going anywhere; the table stakes stay funded exactly where they are. The argument is about the marginal dollar, and where the next one goes.
The best analogy here is one you have probably heard, and I am going to use it anyway because it is exactly on point. During the Second World War, the military mapped the bullet holes on bombers returning from missions over Europe and prepared to add armor where the holes clustered. Abraham Wald, a statistician working the problem, caught the error: the holes marked the places a plane could be hit and still fly home. The bombers hit in the clean spots, the engines, the cockpit, were at the bottom of the Channel. Armor the places with no holes. Eighty years of retelling have polished the story, and Wald’s actual memos are drier than the legend, but the math was real and the lesson holds.
We have spent thirty years armoring the bullet holes. A vulnerability finding, an audit exception: damage you can see precisely because the organization survived to log it. The fatal hits land somewhere else, in the intrusion nobody detected, the containment call nobody had authority to make, the restore nobody had rehearsed. Organizations hit there are missing from your benchmark data for the same reason the downed bombers were missing from the damage maps: failed response does not come back to be studied. It becomes a distressed acquisition, or a footnote in someone else’s earnings call. Right of boom is the engine block. No holes in the data, because the planes hit there never made it home.
Now, an observation about how alone this position still is in the market. I recently reviewed a lineup of AI security startups pitching to buyers. Seven of the nine companies in the room were selling some version of the same promise: secure the AI, or let AI do the securing, before anything goes wrong. Different entry points, same bet, all of it left of boom. Almost nobody was selling, and almost nobody was asking about, what happens to the humans and the business after the tools fail. The vendor market has voted, and it voted for more armor on the bullet holes. That is exactly what makes the response side the underpriced asset.
Secure-by-design stays too; making vendors ship less-broken software is the only fix that scales across the whole economy, and it is a decade-scale project we should support while planning to survive the decade. I would note, with some amusement, that CISA’s own Secure by Design pledge includes as a signatory goal “evidence of intrusions.” Even the flagship prevention initiative embeds detection. These agendas are complements. The pathology is prevention-only, the quiet assumption behind most budgets that if we just eliminate enough findings, the response muscle will never really be needed.
Shifting right means treating everything to the right of boom as an engineering discipline with the same rigor prevention got for thirty years:
Detection as engineering, not as a SIEM purchase. Detections written as code, tested like code, mapped against ATT&CK so you know what you cannot see. The open-source stack for this is mature and free: Sigma for portable detection logic, Zeek and Suricata on the wire, osquery and Velociraptor on the endpoint, Atomic Red Team and Caldera to detonate attacker behaviors and prove your detections actually fire before an adversary runs the test for you. With 82% of detected intrusions now malware-free, living on identity abuse and legitimate tools, behavioral detection is not optional. There is nothing else left to detect.
Deception, because it is the cheapest high-signal detection that exists. Canary tokens and decoy credentials produce nearly zero false positives; almost nobody touches them by accident. An attacker moving through unfamiliar terrain has to look around, and every look is a tripwire you paid almost nothing for.
Containment authority decided in advance. Co-op’s advantage was not technology. It was that someone could pull the plug without a three-day approval odyssey. Who in your organization can take a revenue-generating system offline at 2 a.m.? If the answer requires a meeting, you have a 46-day outage in your future.
Recovery that has actually been performed. Backups you have restored from, timed, under the assumption the attacker had admin credentials, because ransomware crews now systematically go for backup infrastructure, virtualization management, and identity systems first. I have watched “immutable” backups turn out to be exactly as immutable as the stolen admin account asked them to be. If you have not done a full restore of a crown-jewel system this year, you do not have backups. You have hope, at enterprise storage prices.
Machine-speed response. Nowhere does the AI curve favor defenders more clearly than in the SOC, because the defender’s bottleneck is analyst throughput and analyst throughput is exactly what language models augment. The agentic SOC products are drowning in vendor superlatives, and the accuracy claims are self-graded homework. But the observation underneath the marketing is sound: attackers moving at 22 seconds will not be caught by humans reading a queue. We fight automation with automation or we lose on latency alone.
Intelligence: If You Do Not Measure Response, You Are Just Hoping
Here is the industry’s strangest asymmetry. We spent twenty years perfecting prevention metrics: vulnerability counts, patch SLAs, scan coverage, risk scores to two decimal places. Then we spent almost nothing measuring whether response actually works. The academic literature is blunt about the consequence; across dozens of policy frameworks, the learning-and-adapting phase is the least addressed of the entire lifecycle. The SANS SOC survey found 69% of SOCs still compile their metrics by hand, and 85% of response is triggered by an endpoint alert going off, which is to say we mostly wait to be told.
Worse, the metrics we do keep are often actively harmful. The UK’s NCSC published a warning about exactly this: tickets closed, time-to-close, detection rules written, log volume ingested, every one of them optimizable in ways that make you blinder. Reward closed tickets and analysts learn to close tickets. Reward a low escalation rate and things quietly stop getting escalated. A metric only matters if a change in it would change a decision.
The metrics that clear that bar are the temporal ones, because resilience is a curve over time, not a static probability. How long until you notice: dwell time, and whether you found it or the attacker’s note did. How long until you decide: the gap between first alert and a human with authority making a containment call. How long until you recover: measured restore time for crown-jewel systems, not the number in the DR binder. Percentage of critical services with a recovery runbook that has been executed, not written. Trend lines on all of it, quarter over quarter.
And this is where exercises earn their keep twice, because a well-instrumented exercise is an intelligence-collection operation against your own organization. Run one with real telemetry and you can capture things production incidents are too chaotic to measure cleanly: how many minutes of dead air before someone took command. Whether the person who pulled the forensic data acted on it or let it scroll past. How long the CEO email sat drafted while the bridge argued. Who went quiet under pressure, who went hero, which team fractured and which one closed ranks. After enough exercises, I got frustrated that none of this was being captured systematically, so I built a framework to score it. I call it VECTOR: Velocity, Evidence, Command, Teaming, Optionality, Resilience. Six behavioral dimensions extracted from the full multichannel record of an exercise, the voice bridge, the chat, the emails to stakeholders, the investigation queries and whether their results changed anything, plus the stress-induced failure modes like tunnel vision and escalation aversion that only show up under pressure. Score it, benchmark it against other teams, and trend it across exercises the way you trend MTTD. The specific framework matters less than the principle: your exercises are generating this intelligence whether or not you collect it. Most organizations let it evaporate in an after-action meeting nobody reads the minutes of.
Close the loop with the discipline the SRE world proved out: blameless post-incident reviews, for real incidents, for near misses, for exercises. Google’s SRE book says it plainly: without a formalized process of learning from incidents, they recur ad infinitum. Blame produces sanitized stories, and organizations learn nothing from sanitized stories. Aviation got safe because every incident and near miss feeds a system that makes the next one less likely. That feedback loop, not any particular tool, is what a mature response capability actually is.
The Scoreboard Changed
I want to end where the honest version of this argument ends, which is not despair.
The offense-defense research suggests the AI advantage tilts toward attackers early and toward defenders as investment scales, and even the pessimists expect the gap to narrow. Fixed vulnerabilities stay fixed; attacks have to keep working. The defenders building machine-speed detection and response today are positioning for the crossover. This is a bad five years, not a bad forever.
But the organizations that come through those five years will not be the ones that finally got the vulnerability count to zero. Nobody gets the count to zero. The count is running 49% ahead of last year’s pace while the typical enterprise fixes a tenth of its pile a month. The organizations that come through will be the ones that assumed the breach, rehearsed the response until it was reflex, measured the rehearsals like they mattered, and could answer three questions with numbers instead of adjectives: How fast do we notice? How fast do we decide? How fast do we recover?
Prevention is table stakes, and I will keep funding it. But it stopped being the test a while ago. One new CVE every 7.4 minutes. Breakout in twenty-nine minutes. Hand-off in twenty-two seconds. The adversary has already shifted right, straight through your perimeter and into your response gap.
The true test of your security program is no longer whether you get breached. It is what happens in the room after you are. Go find out what happens in that room before an adversary schedules the discovery for you.
Sources and further reading
- Verizon, 2026 Data Breach Investigations Report
- Mandiant, M-Trends 2026; Time-to-exploit trends
- Jerry Gamblin, 2026 mid-year CVE review; FIRST, 2026 vulnerability forecast update
- Cyentia Institute, Prioritization to Prediction
- NIST, NVD operations update, April 2026; SP 800-160 Vol. 2; CSF 2.0
- Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign; MITRE ATT&CK, Campaign C0062
- Google Threat Intelligence Group, Advances in threat actor usage of AI tools
- Cato Networks, WormGPT variants powered by Grok and Mixtral
- Zhu et al., Teams of LLM agents can exploit zero-day vulnerabilities (EACL 2026); CVE-Bench
- UK NCSC, Impact of AI on cyber threat to 2027; Could your choice of metrics be harming your SOC?
- CrowdStrike, 2026 Global Threat Report
- IBM, Cost of a Data Breach 2025; 2022 edition
- Anderson et al., Measuring the Changing Cost of Cybercrime (WEIS 2019); Gordon & Loeb via Journal of Cybersecurity
- Ellison et al., Survivable Network Systems (CMU/SEI, 1997)
- Wald, A Method of Estimating Plane Vulnerability Based on Damage of Survivors (1943, reprinted by CNA 1980); Mangel & Samaniego, Abraham Wald’s Work on Aircraft Survivability, JASA (1984)
- Potter et al., Frontier AI’s Impact on the Cybersecurity Landscape
- SEC, charges against four companies for misleading cyber disclosures; DOJ, Sullivan sentencing
- Case coverage: Maersk/NotPetya, Norsk Hydro, M&S / Co-op, Jaguar Land Rover, Change Healthcare
- FEMA, HSEEP doctrine; CISA, Tabletop Exercise Packages
- SANS, SOC Survey 2025
- Google, SRE Book: Postmortem Culture; Shostack et al., That Was Close! Reward Reporting of Cybersecurity Near Misses
- Hilger, From cybersecurity to cyber resilience, Journal of Cybersecurity (2026) — the finding that adaptation is the least-addressed phase across policy frameworks
- Open-source tooling: Sigma, Velociraptor, osquery, Zeek, Atomic Red Team, Caldera, Canarytokens, Stratus Red Team
Leave a comment