Every source this book stands on, sorted by how much weight it can carry — plus an honest list of the things it could not confirm.
Who needs this: Anyone checking a claim, building their own reference library, or deciding how much of this book to trust | Read time: 14 min | Maps to: —
A bibliography is where a manual either earns its keep or quietly admits it was making things up. Anyone can write "studies show." Rather fewer will tell you which study, who paid for it, how big the sample was, and whether the number you just quoted at your board came from a peer-reviewed journal or from a landing page with a demo button at the bottom.
So this appendix does three jobs. It gives you the full source list, grouped so you can tell a statute from a survey. It marks, explicitly, where a vendor's telemetry has been treated as evidence and where it has not. And it ends with a section listing everything in this book that could not be nailed down — the deadlines still in motion, the famous statistics with no visible parent, the war stories nobody involved has ever formally published.
That last section is the one I would read first. A manual that marks its own edges is more useful than one that presents every claim at the same confidence, because it tells you where you still have to do your own work.
The research behind this book used a three-tier convention, and it is worth keeping when you build your own reading list.
| Tier | What it means | How to use it |
|---|---|---|
| Primary / authoritative | A statute, regulation, standard, government advisory, court filing, sworn testimony, or a first-party incident disclosure by the organization that was breached | Cite it directly. Quote it in a board paper. |
| Instrumented telemetry | A vendor report with a published methodology and a defined population — DBIR, M-Trends, Coveware, VulnCheck, Dragos | Real data, commercial framing, population = their customers. Name the source whenever you quote the number. |
| Secondary / marketing | Blogs, aggregators, "2026 statistics" content sites | Use as a pointer to a real source, never as the source. |
One rule that saved this book from several errors: where a tier-2 report and another tier-2 report disagreed, the disagreement was described rather than resolved. The clearest example is in Chapter 1 — Verizon's DBIR puts vulnerability exploitation first, while Sophos, Coveware and Mandiant put identity first. Both are correct for their populations. A book that picked a winner would have been tidier and wrong.
| Document | Publisher | Date | URL |
|---|---|---|---|
| The NIST Cybersecurity Framework 2.0 (CSWP 29) | NIST | Feb 2024 | csrc.nist.gov |
| SP 800-61r3 — Incident Response Recommendations and Considerations | NIST | Apr 2025 | nvlpubs.nist.gov |
| SP 800-53 Rev. 5 — Security and Privacy Controls | NIST | — | csrc.nist.gov |
| SP 800-171 Rev. 3 — Protecting CUI | NIST | May 2024 | csrc.nist.gov |
| SP 800-207 — Zero Trust Architecture | NIST | Aug 2020 | csrc.nist.gov |
| SP 800-84 — Test, Training and Exercise Programs | NIST | — | nvlpubs.nist.gov |
| SP 800-218 (SSDF v1.1) and 800-218A (GenAI profile) | NIST | Jul 2024 (218A) | csrc.nist.gov · 800-218A |
| AI RMF 1.0 and the Generative AI Profile (AI 600-1) | NIST | Jan 2023 / Jul 2024 | nist.gov · AI 600-1 |
| IR 8596 — Cybersecurity Framework Profile for AI (preliminary draft) | NIST | Dec 2025 | nvlpubs.nist.gov |
| Post-Quantum Cryptography project (FIPS 203/204/205, IR 8547) | NIST | ongoing | csrc.nist.gov |
| Federal Government Cybersecurity Incident and Vulnerability Response Playbooks | CISA | Nov 2021 | cisa.gov |
| Incident Response Plan (IRP) Basics | CISA | — | cisa.gov |
| National Cyber Incident Scoring System (NCISS) | CISA | — | cisa.gov |
| Federal Incident Notification Guidelines | CISA | — | cisa.gov |
| Zero Trust Maturity Model v2.0 | CISA | Apr 2023 | cisa.gov |
| #StopRansomware Guide and "I've Been Hit By Ransomware" | CISA | — | guide · checklist |
| Best Practices for Event Logging and Threat Detection | ASD ACSC, CISA, FBI, NSA + partners | Aug 2024 | cisa.gov |
| 2026 Minimum Elements for a Software Bill of Materials | CISA, NSA, FBI, ACSC, CCCS, NKIB, ANSSI | Jul 2026 | cisa.gov |
| AA23-320A — Scattered Spider | CISA, FBI + partners | upd. Jul 2025 | cisa.gov |
| AA24-038A — Volt Typhoon | CISA, NSA, FBI + Five Eyes | Feb 2024 | cisa.gov |
| AA25-239A — Salt Typhoon | 13-nation joint advisory | Aug 2025 | cisa.gov |
| AA24-109A — #StopRansomware: Akira (updated) | CISA, FBI + partners | Nov 2025 | cisa.gov |
| Emergency Directives ED 25-03 (Cisco) and ED 26-01 (F5) | CISA | Sep / Oct 2025 | ED 25-03 · ED 26-01 |
| Tabletop Exercise Packages (CTEP) | CISA | — | cisa.gov |
| Incident management: plan your response processes | NCSC UK | — | ncsc.gov.uk |
| Guidance on effective communications in a cyber incident | NCSC UK | — | ncsc.gov.uk |
| Guidance for organizations considering payment in ransomware incidents | NCSC UK + insurance bodies | — | ncsc.gov.uk |
| Putting staff welfare at the heart of incident response | NCSC UK | — | ncsc.gov.uk |
| PQC migration timelines (2028 / 2031 / 2035) | NCSC UK | — | ncsc.gov.uk |
| Annual Review 2025 — Incident Management | NCSC UK | 2025 | ncsc.gov.uk |
| Threat Landscape 2025 | ENISA | Oct 2025 | enisa.europa.eu |
| Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments | US Treasury OFAC | Sep 2021 | ofac.treasury.gov |
| RFC 3227 — Guidelines for Evidence Collection and Archiving | IETF | — | rfc-editor.org |
These are the instruments behind Chapter 15 and Appendix C. Read the instrument, not the summary — including this book's summary.
| Instrument | Where | URL |
|---|---|---|
| GDPR Art. 33 (breach notification) | EU | gdpr-info.eu |
| EDPB Guidelines 9/2022 on breach notification, v2.0 | EU | edpb.europa.eu |
| NIS2 — Directive (EU) 2022/2555, Art. 23 | EU | eur-lex.europa.eu |
| DORA — Regulation (EU) 2022/2554, and RTS 2025/301 fixing the clocks | EU | DORA · RTS |
| Cyber Resilience Act — Regulation (EU) 2024/2847, Art. 14 | EU | EUR-Lex · EC reporting page |
| AI Act Arts. 55, 73, 99 | EU | artificialintelligenceact.eu · EC service desk |
| SEC cybersecurity disclosure rules (Item 1.05 / Item 106) | US | Press release 2023-139 · small-entity guide |
| CIRCIA — statute page and the April 2024 NPRM | US | CISA · 89 FR |
| HIPAA Breach Notification Rule (45 CFR 164.400–414) | US | hhs.gov |
| NYDFS 23 NYCRR 500.17 | US (NY) | law.cornell.edu |
| FCC data breach reporting rules, 89 FR (Feb 2024) | US | federalregister.gov |
| TSA — Enhancing Surface Cyber Risk Management NPRM; ratification of Security Directives | US | NPRM · ratification |
| CMMC — 32 CFR program rule and 48 CFR acquisition rule | US | 32 CFR · 48 CFR |
| California SB 446 (30-day notice, 15-day AG sample) | US (CA) | leginfo.ca.gov |
| Data Breach Notification Laws: 50-State Survey, 2026 edition | US | Privacy Rights Clearinghouse |
| Cyber Security (Ransomware Payment Reporting) Rules 2025 | Australia | legislation.gov.au · Home Affairs factsheet |
| ICO guidance on personal data breaches, and the NIS Regulations | UK | ICO breaches · ICO NIS |
| Cyber Security and Resilience Bill — parliamentary status | UK | Commons Library CBP-10442 |
| Framework | Current version | URL |
|---|---|---|
| CIS Critical Security Controls | v8.1 (Jun 2024) | cisecurity.org · Implementation Groups |
| ISO/IEC 27001:2022 + Amd 1:2024 | 2022 | iso.org |
| ISO/IEC 27035-1 / -2 (incident management) | 2023 | iso.org · part 2 |
| MITRE ATT&CK | v19.2 (Apr 2026) | attack.mitre.org · v19 release notes |
| MITRE D3FEND / ATLAS | 1.6.0 / 5.6.0 | d3fend.mitre.org · atlas-data |
| FAIR — Standard v3.0, O-RA v2.0.1 | Jan 2025 | FAIR Institute · O-RA · FAIR-CAM |
| CSA Cloud Controls Matrix | v4.1 (Jan 2026) | cloudsecurityalliance.org |
| SOC 2 Trust Services Criteria | 2017 w/ 2022 points of focus | AICPA |
| PCI DSS | v4.0.1 (Jun 2024) | PCI SSC · future-dated requirements |
| HITRUST CSF | v11.8.0 (May 2026) | HITRUST advisories |
| SLSA | v1.2 | slsa.dev |
| OWASP Top 10 for LLM Applications | 2025 / 2026 editions | genai.owasp.org |
| OWASP Top 10 for Agentic Applications | Dec 2025 | genai.owasp.org |
| Shared responsibility models | AWS / Azure / Google | AWS · Microsoft · Google |
Three different things wear the same jacket here. Keep them apart.
Primary and peer-reviewed. These carry weight on their own.
First-party incident disclosures. A company reporting on its own compromise or its own platform's abuse. Best available evidence on specifics; read the significance framing as advocacy.
Vendor telemetry. Real instrumentation, commercial framing, customer-shaped population. Quote with the source attached, every time.
| Report | Publisher | Used in this book for |
|---|---|---|
| M-Trends 2026 | Mandiant / Google Cloud | Dwell time, initial vectors, the 22-second broker hand-off, recovery denial |
| DBIR 2026 (via SecurityWeek; also Help Net Security) | Verizon | Exploitation vs. credential abuse, third-party involvement, KEV remediation rates |
| Global Threat Report 2026 | CrowdStrike | Breakout time, malware-free detections, cloud intrusion growth |
| State of Ransomware 2026 | Sophos | Identity-first ransomware, payment and recovery economics |
| Cyber extortion payment trends, Q2 2026 | Coveware by Veeam | Payment rates, the mean/median divergence |
| State of Exploitation 1H-2026 | VulnCheck | KEV timing, and the AI-discovered-CVE reality check |
| OT/ICS Year in Review 2026 | Dragos | OT threat groups, control-loop mapping |
| Ransomware and cyber extortion, Q2 2026 | ReliaQuest | Leak-site volumes and brand rotation |
| Agentic threat actor in the orchestration plane | Sysdig | The second confirmed agentic intrusion |
| Salesloft Drift / UNC6395 analysis | AppOmni | SaaS-to-SaaS OAuth compromise |
| Trivy → LiteLLM campaign | Resecurity | Transitive CI/CD compromise |
| Tycoon 2FA analysis | Group-IB | AiTM kit economics |
| AI vs. human spear phishing, longitudinal | Hoxhunt | The 2023→2025 swing in AI phishing effectiveness |
Marketing content. A family of "2026 cybersecurity statistics" sites surfaced constantly during research and contributed nothing. Their figures were either uncheckable or traceable to each other in a circle. Statistics whose only home was a marketing page were excluded — if a number's only parent is a page that also sells you a webinar, it is not a statistic. It is an advertisement wearing a lab coat.
That rule holds for numbers. It does not hold absolutely for everything else, and pretending otherwise would be the same dishonesty in the other direction. A small number of incident case summaries and definitional sources in this book do come from vendor blogs, because no better source exists for them. They are named inline every time they appear, so you can weigh them yourself, and they are named here too.
| Source | Publisher | Used in this book for |
|---|---|---|
| Deepfake attack examples | Adaptive Security | The LastPass voice-clone case summary, in Chapters 4, 7 and 19 |
| SOC metrics that matter | Prophet Security | SOC metric definitions, in Chapters 9 and 16 and Appendix E |
| MTTD, MTTC and MTTR | Crogl | The same metric definitions, as the second corroborating source |
These are the most valuable documents in this appendix, and it is not close. Read them in full — not the summary, not the LinkedIn thread. A vendor report tells you what happens across a population. These tell you what happened inside one organization, in order, including the parts nobody enjoyed writing down.
| Document | Publisher | Date | URL |
|---|---|---|---|
| Learning Lessons from the Cyber-Attack — 16 lessons, published voluntarily | British Library | Mar 2024 | bl.uk |
| Review of the Summer 2023 Microsoft Exchange Online Intrusion | Cyber Safety Review Board | Apr 2024 | cisa.gov |
| GAO-18-559 — Data Protection: Actions Taken by Equifax and Federal Agencies | US GAO | 2018 | gao.gov |
| GAO-25-107947 — TSA pipeline and rail cyber risk management | US GAO | 2025 | gao.gov |
| Testimony of Joseph Blount on the Colonial Pipeline ransomware attack | Senate HSGAC | Jun 2021 | hsgac.senate.gov · House Homeland |
| SEC v. SolarWinds and Timothy Brown — internal communications as evidence | US SEC | Oct 2023 | sec.gov |
| Change Healthcare — the Citrix portal without MFA (Congressional testimony, via press) | reported | May 2024 | Cybersecurity Dive |
| Remediating Targeted-threat Intrusions — the whack-a-mole failure chain | Aldridge / Mandiant, Black Hat USA | 2012 | blackhat.com |
Why these matter more than anything else on the list: they were written by people with every incentive to say less, and they said more. The British Library published sixteen lessons naming its own legacy estate, its own MFA gap at a supplier endpoint, and its own risk process failing to aggregate small accepted risks into a visible large one. The CSRB traced a Microsoft key-rotation control that was abandoned after an operational outage — a safety control retired by an availability incident, which is a pattern every one of us has lived through. GAO documented that Equifax's patch notice went to a distribution list that was out of date.
None of that is exotic. All of it is survivable, and all of it is preventable, and you only get to learn it cheaply because somebody else paid for it publicly.
| Resource | What it is | URL |
|---|---|---|
| RE&CT | Response actions as an ATT&CK-shaped matrix; the best model for composable playbooks | atc-project.github.io · repo |
| OASIS CACAO Security Playbooks v2.0 | The machine-readable playbook schema; use its property list as your metadata checklist | docs.oasis-open.org · SOARCA orchestrator |
| PagerDuty Incident Response | Roles, severity, on-call and IC training, open-sourced from internal use | response.pagerduty.com · repo |
| Howie: The Post-Incident Guide | Eight-stage post-incident investigation; "blame-aware" rather than merely blameless | howie-guide.pagerduty.com |
| AWS incident response playbook libraries | Scenario playbooks and a shared template, in git | aws-samples · customer framework |
| Microsoft incident response playbooks | Phishing, password spray, consent-grant abuse — maintained as Markdown with PR review | learn.microsoft.com |
| Counteractive IR plan template | Plan-plus-playbooks in one repo, rendered from source | github.com |
| SigmaHQ | Portable detection rule format and 3,000+ ATT&CK-mapped rules | sigmahq.io |
| Palantir Alerting and Detection Strategy framework | Nine-section detection documentation, including Validation and Blind Spots | github.com |
| DeTT&CT | Scores data-source quality and technique visibility before detection logic | NVISO Labs |
| MITRE CTID Adversary Emulation Library | Full and micro emulation plans for named actors | ctid.mitre.org |
| Purple Team Exercise Framework | Open methodology for CTI + red + blue collaborative exercises | github.com |
| NCSC Exercise in a Box | ~20 free exercises in micro, tabletop and simulation formats | ncsc.gov.uk |
| Google SRE Book and Workbook — incident management | The ICS lineage, the living incident document, declaration triggers | sre.google · workbook |
| FEMA NIMS/ICS reference | Where incident command actually comes from | training.fema.gov |
If you read nothing else from this appendix, read these. They are ordered by how much they will change how you work.
Here is the honest inventory. Nothing below is asserted anywhere in this book as fact; where the subject was unavoidable, the text says what is known and marks the rest. Treat this section as your personal verification backlog.
CIRCIA's final rule. As of 5 September 2026 the rule is not published. CISA's own page says work continues and attributes the delay to funding lapses; the statutory October 2025 deadline was missed, a May 2026 target slipped, and the July 2026 Unified Agenda points at September 2026 (CISA; Hunton). What to do: build the 72-hour and 24-hour capability now, because the clocks are statutory and short, but do not put a compliance date on a slide. Check the Federal Register public inspection desk before you brief a board.
The alert-fatigue statistics everyone quotes. "62% of alerts ignored," "40% never investigated," "70%+ of analysts burned out" — these trace to vendor surveys, not primary research, and could not be verified. The defensible anchor is the 2025 ACM Computing Surveys review, whose full text is paywalled; even its "four major causes of alert fatigue" could only be read as an abstract-level claim, so this book does not enumerate them. What to do: if you need a number for a budget case, measure your own false-positive rate. It is more persuasive than a survey anyway, and you already have the data.
Maersk and NotPetya. The single surviving domain controller in Accra, the nine-day Active Directory recovery, the quotes attributed to the CISO, the server and endpoint rebuild counts, the cost figure — all of it comes from press coverage, vendor blogs and conference reporting. Maersk has never published an equivalent of the British Library review. What to do: the lesson (your recovery cannot depend on the identity plane you are about to declare compromised) is sound and independently supported. The specifics are anecdote. Do not put the numbers in a slide with a Maersk logo on it.
NCISS numeric score bands. CISA's document describes the weighted 0–100 formula and names the six priority levels, but the per-level score bands and category weights are supplied in an accompanying reference tool that was not retrieved. What to do: use NCISS's structure — especially the Purdue-style Location of Observed Activity and the campaign-aggregation rule — and set your own bands. Anyone reproducing NCISS numerically must obtain that tool from CISA.
Several regulatory details that sit one layer below the headline. The SEC Item 1.05 rescission story rests on law-firm and trade-association reporting, not on an SEC document — it has been requested, not proposed and not adopted. The UK Cyber Security and Resilience Bill's penalty figures come from commentary, not the Bill text. Whether AI Act Article 73 in its entirety moved to December 2027 was not read from the operative amending article. The Australian SOCI Part 2B 12-hour and 72-hour clocks were not confirmed against a primary source. Several US state deadlines outside New York, California, Texas, Washington and Puerto Rico rest on survey charts rather than statutes. The FCC's 500-customer threshold wording could not be read from the operative rule text.
Framework counts and version details. Whether a CIS Controls v9 exists; the DoD Zero Trust activity counts and Advanced-level target year; SOC 2 criteria and points-of-focus counts; HITRUST e1/i1 control counts; the ISO/IEC 42001 Annex A control count; what changed in SLSA v1.2; which revision of SP 800-171 CMMC Level 2 currently invokes; the disposition of SP 800-53 IR-10; whether NIST's AI RMF 1.0 has been superseded, given NIST's own note that it is under revision under the White House AI Action Plan; the release date of MITRE ATT&CK v19.2, where one report conflicts with MITRE's own April 2026 version-history date; the D3FEND 1.6.0 release date and whether Restore is a full top-level tactic; the ISO/IEC 27035-3 edition year and whether a Part 4 exists; whether ISO/IEC 27002:2022 received a climate-action amendment alongside 27001; the CSA CCM v4.1 domain names; and individual CIS Benchmark version numbers. Each of these appears confidently in vendor material and could not be confirmed from the standards body. What to do: if a number drives an assessment scope, get it from the body that publishes the standard.
Threat statistics with no visible parent. Infostealer volumes, session-cookie recapture counts, the "84% of AiTM incidents where MFA failed" figure, machine-to-human identity ratios, every circulating RAG-leakage statistic, MCP vulnerability prevalence figures, the Jaguar Land Rover economic-impact numbers, and the "-7 days mean time to exploit" figure. All vendor-blog or aggregator sourced. On RAG in particular: no credible confirmed report of a named real-world RAG-leakage or model-extraction breach could be found, which is why Chapter 7 treats it as a design-risk category rather than an observed-incident category.
Operational specifics that would be dangerous to guess. Exact AWS CLI syntax for forensic snapshot capture, CrowdStrike Falcon containment API request-body field names, the gcloud service-account disable command's exact form, the UpdateInboxRules audit operation, the OMB M-21-31 hot/cold retention split, Veeam hardened-repository internals. Where syntax could not be confirmed against vendor documentation, the action is described in words instead of shown as a command. Check the vendor's current reference page before any of it enters a runbook.
Two documents that may already be stale. CISA's Federal Playbooks still carry a November 2021 publication date and still reference SP 800-61 Rev. 2, not r3. ENISA's Threat Landscape 2026 and NCSC's Annual Review 2026 had not been published as of 5 September 2026; the 2025 editions are current here. Check for newer editions before you cite either.
Rafeeq Rehman has built and given away the CISO MindMap every year since 2012, most recently on 11 April 2026 (© 2012–2026 Rafeeq Rehman). It is one page, it is free, and it has probably scoped more security programs than any commercial framework — get it from rafeeqrehman.com. This book's Coverage Model is its own work and not a version of his map, but Chapter 3 keeps a reconstruction of his structure alongside it as a deliberate second opinion, because being scope-checked by someone who got here first is worth more than being flattered. That reconstruction, and the color coding by CSF Function, are editorial additions — neither the original artefact nor endorsed by him.
CISA published the Federal Government Cybersecurity Incident and Vulnerability Response Playbooks as a US Government work in the public domain, and explicitly anticipated organizations outside the federal civilian branch using them. Chapters 10 and 13 take that invitation. The NCISS, the CTEP packages, the IRP Basics fact sheet and the joint international logging guidance are all free, all good, and all under-read.
And the organizations that published their own post-incident reviews: the British Library, whose sixteen lessons are the most useful thing published about a ransomware attack in years; the Cyber Safety Review Board; the GAO; and the executives who sat for sworn testimony and answered questions they would rather not have been asked. Every one of them was under commercial, legal and reputational pressure to say less. They said more, so the rest of us could skip the tuition. That is a professional generosity our field does not repay often enough, and the least we owe them is to actually read the documents.
Stay sceptical, stay sourced, and check the footnote before you put the number in front of your board.