Field Manual · 2026 Edition

The 2026
InfoSec Playbook

A field manual for the year the old playbook stopped working — written for the people who get called at 2 a.m.

Written by Daniel Ramos · Chief Technology Officer, Intelligent Automation, LLC

What is in it

Chapters20
Scenario playbooks14
Controls, tiered and tagged464
Cited sources371
Words275,883

The argument

Your playbook assumes you have time to think.

What actually changed between 2024 and 2026, why the playbook you already have will fail against it, and how to read the rest of this book.

“Open your incident response documentation and find the step that handles an OAuth refresh token stolen from a vendor you authorized years ago. Not ‘contain the threat’ — the actual step. If that branch is missing, it is not a slightly outdated playbook. It is a playbook for a different decade.”

Chapter 1 — Why 2026 Broke the Old Playbook

This is not a book arguing that the threat landscape got worse. It always gets worse; that is neither news nor help. The argument is narrower and more useful: the specific assumptions older playbooks were built on have been individually falsified, and each one breaks a named step in the procedure you already have.

Why it is different

Every claim carries its source. Where sources disagree, it says so.

A security manual that cannot tell you where its claims come from is a blog post with delusions of grandeur.

371distinct sources
1,537citations in text
43“verify” callouts
464tiered controls

It argues against itself where the evidence does. Chapter 1 makes an identity-first case, then confronts the Verizon DBIR finding that vulnerability exploitation overtook credential abuse — a direct contradiction. Rather than pick a favorite, it explains why both are right for their populations and lands the operational reading: exploitation gets you through the perimeter, identity gets you through the company.

It also disarms its own best statistics. On ransom payments: the quarterly average is $1.88M and the median is $150K, because a handful of very large payments distort the mean. The book’s instruction is explicit — do not use the average to set a reserve or an insurance limit.

Contents

Twenty chapters.

Colored by the NIST CSF 2.0 Function each chapter primarily serves.

01

Why 2026 Broke the Old Playbook

What actually changed between 2024 and 2026, why the playbook you already have will fail against it, and how to read the rest of this book.

02

Plan, Playbook, Runbook

How to write incident documentation that a tired person can execute at 03:00 without stopping to work out who is allowed to decide.

03

The Coverage Model

A one-page model of everything a 2026 security program is accountable for — six NIST CSF 2.0 Functions, 29 domains, every one wired to a testable control and a named owner — so you can find the work nobody owns before an incident finds it for you.

04

Identity and Access: The New Perimeter

How to build an identity control plane that a modern adversary cannot phish, socially engineer, or replay — and how to take it back in the right order when they get in anyway.

05

Zero Trust Architecture

How to build an access architecture where every request is verified regardless of network location, score yourself honestly against CISA's maturity model, and turn "isolate that host" into a policy change instead of a desk visit.

06

Cloud, Container and Kubernetes Security

How to configure a cloud control plane so it produces evidence, detect the identity and misconfiguration attacks that actually happen there, and contain a compromised account, instance, cluster or workload without destroying the only proof you will ever get.

07

Using and Securing AI

Inventory every AI system touching your data, govern it against a standard an auditor recognises, use it in the SOC where it is actually good, and build the human process checks that stop an AI-enabled attacker — because the technology ones do not.

08

Data, Cryptography and the Post-Quantum Clock

How to know what data you hold, hold less of it, encrypt what remains under keys you actually control, and get your cryptography off algorithms that have a published expiry date.

09

Detection and Monitoring

How to build a logging, detection and triage capability that finds the adversary yourself instead of waiting for someone else to call you — and how to prove honestly what it does and does not cover.

10

Vulnerability and Exposure Management

How to find what you expose, decide what to fix first using evidence of real exploitation rather than a severity score, hit a deadline you can defend, and prove the fix actually landed.

11

Third-Party and Supply Chain Risk

How to know who is inside your estate, rank them by the access they hold rather than the money they cost, verify their claims properly, write terms that still bite at renewal, and survive the day the breach is theirs.

12

Resilience, Backup and Recovery

How to build a backup and recovery capability that survives an adversary who is specifically hunting it — immutable storage, credentials that live outside the domain you are restoring, restore tests with a stopwatch, and an identity-first recovery order.

13

The Incident Response Lifecycle

The canonical model, vocabulary, roles and gates that every scenario playbook in this book assumes you already have.

14

The Scenario Playbooks

Fourteen executable scenario playbooks, plus the rules for reading them, choosing between them, and running more than one of them at the same time.

15

Communications, Legal and Regulatory Notification

Who says what, to whom, on which clock — and the legal machinery that decides whether your incident becomes a footnote or an exhibit.

16

Governance, Frameworks and Metrics

How to pick the two frameworks you actually need, run a risk register a business will use, quantify cyber risk in money, and walk into a board meeting with three slides, a trend and one decision.

17

Automation and Orchestration

How to write a playbook that a machine can execute and a human can take over mid-step, where to put the approval gates, and which automations will quietly hurt you.

18

Exercising the Playbook

How to design, run, score and close out the exercises that turn a plausible-looking playbook into one you know works — for the price of a conference room and three hours, not a seven-figure tool.

19

Departmental Playbooks

Seven one-page playbooks — Finance, HR, Legal, Communications, Sales/CS, Engineering, Executive and Board — that give the people outside security a role they can actually perform, and that plug cleanly into the central incident response plan.

20

The First 180 Days

A sequenced, dependency-honest plan that turns everything in this book into six months of work a real team can actually finish.

Chapter 14

Fourteen scenario playbooks.

Each one written to be run at 2 a.m. by somebody who did not write it.

14.1

Ransomware with Data Exfiltration

14.2

Business Email Compromise and Payment Fraud

14.3

SaaS and Cloud Account Takeover

14.4

Identity Provider and Privileged Credential Compromise

14.5

Third-Party and Supply Chain Breach

14.6

Insider Threat

14.7

Data Breach with Regulatory Obligations

14.8

DDoS and Service Unavailability

14.9

Deepfake and AI-Enabled Social Engineering

14.10

Kubernetes and Container Compromise

14.11

AI System Compromise

14.12

Edge Device and Perimeter Appliance Exploitation

14.13

Web Application Compromise and Mass Exploitation

14.14

OT and ICS Incident

Daniel Ramos

Chief Technology Officer
Intelligent Automation, LLC

  • Publisher, Cyber Shield Weekly
  • Builder of the Argos OS security platform
  • Fairfield, New Jersey

About the author

Written by someone who runs the on-call rotation.

This is not a survey of the literature. It is what a working practitioner needed to exist and could not find — a manual that treats an incident as a procedure with named roles and a clock, rather than a topic to have opinions about.

Opinions in the book are the author’s and not those of any client, vendor or standards body. It is published free, in full, with no email wall, because a field manual nobody can open is not a field manual.

Credit where it is owed. Chapter 3 discusses the CISO MindMap, which is the creation of Rafeeq Rehman and has been built and updated by him annually since 2012. It is © 2012–2026 Rafeeq Rehman, is not the basis of this book’s own model, and is discussed as an independent cross-check. Get the real thing — a single, beautifully dense page — from rafeeqrehman.com and put it on a wall.

Before you rely on it

This is not legal advice.

Chapter 15 and Appendix C summarize breach-notification obligations across a dozen regimes to help you build a response process. They are a starting point for a conversation with counsel, not a substitute for one. Deadlines change, national transpositions differ, sector rules layer on top, and the facts of your incident determine which clocks actually run. Get a lawyer — before the incident, so you are not interviewing firms at 2 a.m.

Two ways to read it.

The field edition is the brief — cover to cover in twenty minutes. The full manual is all 275,883 words, every chapter checklist, and every source link.

Secured by IA