Annual Cyber Threat Reports
Reading annual cyber threat reports has helped me understand the big-picture threat landscape, APTs and other attackers, TTPs, mitigations, the work of cyber threat intelligence, and how to communicate through threat reports.
Here are a few sources for annual (and semiannual) cyber threat reports, in alphabetical order. Some are freely available, and others require registration (filling out a form) to access. The links should take you to the latest editions of the reports.
If you know of others that are worthwhile, please let me know.
- Accenture Cyber Threat Intelligence Report (semiannual)
- BlackBerry Annual Threat Report (registration required)
- CrowdStrike Annual Global Threat Report (registration required)
- Dragos ICS Year in Review (registration required)
- Fortinet Global Threat Landscape Report (semiannual)
- IBM X-Force Annual Threat Intelligence Index
- Intel 471 The 471 Cyber Threat Report (registration required)
- IronNet Annual Threat Report (registration required)
- Mandiant M-Trends Report (registration required)
- Microsoft Digital Defense Report
- Proofpoint The Human Factor (registration required)
- PwC Cyber Threats [YYYY]: A Year in Retrospect (registration required)
- Red Canary Threat Detection Report
- Secureworks State of the Threat Report (registration required)
- SonicWall Cyber Threat Report (registration required)
- Sophos Threat Report
- Verizon Data Breach Investigations Report (DBIR)
- VMWare Global Security Insights Report (registration required)