Field Manual · 2026 Edition
A field manual for the year the old playbook stopped working — written for the people who get called at 2 a.m.
Written by Daniel Ramos · Chief Technology Officer, Intelligent Automation, LLC
What is in it
The argument
What actually changed between 2024 and 2026, why the playbook you already have will fail against it, and how to read the rest of this book.
“Open your incident response documentation and find the step that handles an OAuth refresh token stolen from a vendor you authorized years ago. Not ‘contain the threat’ — the actual step. If that branch is missing, it is not a slightly outdated playbook. It is a playbook for a different decade.”
Chapter 1 — Why 2026 Broke the Old PlaybookThis is not a book arguing that the threat landscape got worse. It always gets worse; that is neither news nor help. The argument is narrower and more useful: the specific assumptions older playbooks were built on have been individually falsified, and each one breaks a named step in the procedure you already have.
Why it is different
A security manual that cannot tell you where its claims come from is a blog post with delusions of grandeur.
It argues against itself where the evidence does. Chapter 1 makes an identity-first case, then confronts the Verizon DBIR finding that vulnerability exploitation overtook credential abuse — a direct contradiction. Rather than pick a favorite, it explains why both are right for their populations and lands the operational reading: exploitation gets you through the perimeter, identity gets you through the company.
It also disarms its own best statistics. On ransom payments: the quarterly average is $1.88M and the median is $150K, because a handful of very large payments distort the mean. The book’s instruction is explicit — do not use the average to set a reserve or an insurance limit.
Contents
Colored by the NIST CSF 2.0 Function each chapter primarily serves.
Why 2026 Broke the Old Playbook
What actually changed between 2024 and 2026, why the playbook you already have will fail against it, and how to read the rest of this book.
Plan, Playbook, Runbook
How to write incident documentation that a tired person can execute at 03:00 without stopping to work out who is allowed to decide.
The Coverage Model
A one-page model of everything a 2026 security program is accountable for — six NIST CSF 2.0 Functions, 29 domains, every one wired to a testable control and a named owner — so you can find the work nobody owns before an incident finds it for you.
Identity and Access: The New Perimeter
How to build an identity control plane that a modern adversary cannot phish, socially engineer, or replay — and how to take it back in the right order when they get in anyway.
Zero Trust Architecture
How to build an access architecture where every request is verified regardless of network location, score yourself honestly against CISA's maturity model, and turn "isolate that host" into a policy change instead of a desk visit.
Cloud, Container and Kubernetes Security
How to configure a cloud control plane so it produces evidence, detect the identity and misconfiguration attacks that actually happen there, and contain a compromised account, instance, cluster or workload without destroying the only proof you will ever get.
Using and Securing AI
Inventory every AI system touching your data, govern it against a standard an auditor recognises, use it in the SOC where it is actually good, and build the human process checks that stop an AI-enabled attacker — because the technology ones do not.
Data, Cryptography and the Post-Quantum Clock
How to know what data you hold, hold less of it, encrypt what remains under keys you actually control, and get your cryptography off algorithms that have a published expiry date.
Detection and Monitoring
How to build a logging, detection and triage capability that finds the adversary yourself instead of waiting for someone else to call you — and how to prove honestly what it does and does not cover.
Vulnerability and Exposure Management
How to find what you expose, decide what to fix first using evidence of real exploitation rather than a severity score, hit a deadline you can defend, and prove the fix actually landed.
Third-Party and Supply Chain Risk
How to know who is inside your estate, rank them by the access they hold rather than the money they cost, verify their claims properly, write terms that still bite at renewal, and survive the day the breach is theirs.
Resilience, Backup and Recovery
How to build a backup and recovery capability that survives an adversary who is specifically hunting it — immutable storage, credentials that live outside the domain you are restoring, restore tests with a stopwatch, and an identity-first recovery order.
The Incident Response Lifecycle
The canonical model, vocabulary, roles and gates that every scenario playbook in this book assumes you already have.
The Scenario Playbooks
Fourteen executable scenario playbooks, plus the rules for reading them, choosing between them, and running more than one of them at the same time.
Communications, Legal and Regulatory Notification
Who says what, to whom, on which clock — and the legal machinery that decides whether your incident becomes a footnote or an exhibit.
Governance, Frameworks and Metrics
How to pick the two frameworks you actually need, run a risk register a business will use, quantify cyber risk in money, and walk into a board meeting with three slides, a trend and one decision.
Automation and Orchestration
How to write a playbook that a machine can execute and a human can take over mid-step, where to put the approval gates, and which automations will quietly hurt you.
Exercising the Playbook
How to design, run, score and close out the exercises that turn a plausible-looking playbook into one you know works — for the price of a conference room and three hours, not a seven-figure tool.
Departmental Playbooks
Seven one-page playbooks — Finance, HR, Legal, Communications, Sales/CS, Engineering, Executive and Board — that give the people outside security a role they can actually perform, and that plug cleanly into the central incident response plan.
The First 180 Days
A sequenced, dependency-honest plan that turns everything in this book into six months of work a real team can actually finish.
Chapter 14
Each one written to be run at 2 a.m. by somebody who did not write it.
Ransomware with Data Exfiltration
Business Email Compromise and Payment Fraud
SaaS and Cloud Account Takeover
Identity Provider and Privileged Credential Compromise
Third-Party and Supply Chain Breach
Insider Threat
Data Breach with Regulatory Obligations
DDoS and Service Unavailability
Deepfake and AI-Enabled Social Engineering
Kubernetes and Container Compromise
AI System Compromise
Edge Device and Perimeter Appliance Exploitation
Web Application Compromise and Mass Exploitation
OT and ICS Incident
Before you rely on it
Chapter 15 and Appendix C summarize breach-notification obligations across a dozen regimes to help you build a response process. They are a starting point for a conversation with counsel, not a substitute for one. Deadlines change, national transpositions differ, sector rules layer on top, and the facts of your incident determine which clocks actually run. Get a lawyer — before the incident, so you are not interviewing firms at 2 a.m.
The field edition is the brief — cover to cover in twenty minutes. The full manual is all 275,883 words, every chapter checklist, and every source link.