The 2026 InfoSec Playbook · Daniel Ramos

#Appendix H — Sources and Further Reading

Every source this book stands on, sorted by how much weight it can carry — plus an honest list of the things it could not confirm.

Who needs this: Anyone checking a claim, building their own reference library, or deciding how much of this book to trust | Read time: 14 min | Maps to:

A bibliography is where a manual either earns its keep or quietly admits it was making things up. Anyone can write "studies show." Rather fewer will tell you which study, who paid for it, how big the sample was, and whether the number you just quoted at your board came from a peer-reviewed journal or from a landing page with a demo button at the bottom.

So this appendix does three jobs. It gives you the full source list, grouped so you can tell a statute from a survey. It marks, explicitly, where a vendor's telemetry has been treated as evidence and where it has not. And it ends with a section listing everything in this book that could not be nailed down — the deadlines still in motion, the famous statistics with no visible parent, the war stories nobody involved has ever formally published.

That last section is the one I would read first. A manual that marks its own edges is more useful than one that presents every claim at the same confidence, because it tells you where you still have to do your own work.

#How to read this list

The research behind this book used a three-tier convention, and it is worth keeping when you build your own reading list.

TierWhat it meansHow to use it
Primary / authoritativeA statute, regulation, standard, government advisory, court filing, sworn testimony, or a first-party incident disclosure by the organization that was breachedCite it directly. Quote it in a board paper.
Instrumented telemetryA vendor report with a published methodology and a defined population — DBIR, M-Trends, Coveware, VulnCheck, DragosReal data, commercial framing, population = their customers. Name the source whenever you quote the number.
Secondary / marketingBlogs, aggregators, "2026 statistics" content sitesUse as a pointer to a real source, never as the source.

One rule that saved this book from several errors: where a tier-2 report and another tier-2 report disagreed, the disagreement was described rather than resolved. The clearest example is in Chapter 1 — Verizon's DBIR puts vulnerability exploitation first, while Sophos, Coveware and Mandiant put identity first. Both are correct for their populations. A book that picked a winner would have been tidier and wrong.

#Primary government and standards sources

DocumentPublisherDateURL
The NIST Cybersecurity Framework 2.0 (CSWP 29)NISTFeb 2024csrc.nist.gov
SP 800-61r3 — Incident Response Recommendations and ConsiderationsNISTApr 2025nvlpubs.nist.gov
SP 800-53 Rev. 5 — Security and Privacy ControlsNISTcsrc.nist.gov
SP 800-171 Rev. 3 — Protecting CUINISTMay 2024csrc.nist.gov
SP 800-207 — Zero Trust ArchitectureNISTAug 2020csrc.nist.gov
SP 800-84 — Test, Training and Exercise ProgramsNISTnvlpubs.nist.gov
SP 800-218 (SSDF v1.1) and 800-218A (GenAI profile)NISTJul 2024 (218A)csrc.nist.gov · 800-218A
AI RMF 1.0 and the Generative AI Profile (AI 600-1)NISTJan 2023 / Jul 2024nist.gov · AI 600-1
IR 8596 — Cybersecurity Framework Profile for AI (preliminary draft)NISTDec 2025nvlpubs.nist.gov
Post-Quantum Cryptography project (FIPS 203/204/205, IR 8547)NISTongoingcsrc.nist.gov
Federal Government Cybersecurity Incident and Vulnerability Response PlaybooksCISANov 2021cisa.gov
Incident Response Plan (IRP) BasicsCISAcisa.gov
National Cyber Incident Scoring System (NCISS)CISAcisa.gov
Federal Incident Notification GuidelinesCISAcisa.gov
Zero Trust Maturity Model v2.0CISAApr 2023cisa.gov
#StopRansomware Guide and "I've Been Hit By Ransomware"CISAguide · checklist
Best Practices for Event Logging and Threat DetectionASD ACSC, CISA, FBI, NSA + partnersAug 2024cisa.gov
2026 Minimum Elements for a Software Bill of MaterialsCISA, NSA, FBI, ACSC, CCCS, NKIB, ANSSIJul 2026cisa.gov
AA23-320A — Scattered SpiderCISA, FBI + partnersupd. Jul 2025cisa.gov
AA24-038A — Volt TyphoonCISA, NSA, FBI + Five EyesFeb 2024cisa.gov
AA25-239A — Salt Typhoon13-nation joint advisoryAug 2025cisa.gov
AA24-109A — #StopRansomware: Akira (updated)CISA, FBI + partnersNov 2025cisa.gov
Emergency Directives ED 25-03 (Cisco) and ED 26-01 (F5)CISASep / Oct 2025ED 25-03 · ED 26-01
Tabletop Exercise Packages (CTEP)CISAcisa.gov
Incident management: plan your response processesNCSC UKncsc.gov.uk
Guidance on effective communications in a cyber incidentNCSC UKncsc.gov.uk
Guidance for organizations considering payment in ransomware incidentsNCSC UK + insurance bodiesncsc.gov.uk
Putting staff welfare at the heart of incident responseNCSC UKncsc.gov.uk
PQC migration timelines (2028 / 2031 / 2035)NCSC UKncsc.gov.uk
Annual Review 2025 — Incident ManagementNCSC UK2025ncsc.gov.uk
Threat Landscape 2025ENISAOct 2025enisa.europa.eu
Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware PaymentsUS Treasury OFACSep 2021ofac.treasury.gov
RFC 3227 — Guidelines for Evidence Collection and ArchivingIETFrfc-editor.org

#Regulation and law

These are the instruments behind Chapter 15 and Appendix C. Read the instrument, not the summary — including this book's summary.

InstrumentWhereURL
GDPR Art. 33 (breach notification)EUgdpr-info.eu
EDPB Guidelines 9/2022 on breach notification, v2.0EUedpb.europa.eu
NIS2 — Directive (EU) 2022/2555, Art. 23EUeur-lex.europa.eu
DORA — Regulation (EU) 2022/2554, and RTS 2025/301 fixing the clocksEUDORA · RTS
Cyber Resilience Act — Regulation (EU) 2024/2847, Art. 14EUEUR-Lex · EC reporting page
AI Act Arts. 55, 73, 99EUartificialintelligenceact.eu · EC service desk
SEC cybersecurity disclosure rules (Item 1.05 / Item 106)USPress release 2023-139 · small-entity guide
CIRCIA — statute page and the April 2024 NPRMUSCISA · 89 FR
HIPAA Breach Notification Rule (45 CFR 164.400–414)UShhs.gov
NYDFS 23 NYCRR 500.17US (NY)law.cornell.edu
FCC data breach reporting rules, 89 FR (Feb 2024)USfederalregister.gov
TSA — Enhancing Surface Cyber Risk Management NPRM; ratification of Security DirectivesUSNPRM · ratification
CMMC — 32 CFR program rule and 48 CFR acquisition ruleUS32 CFR · 48 CFR
California SB 446 (30-day notice, 15-day AG sample)US (CA)leginfo.ca.gov
Data Breach Notification Laws: 50-State Survey, 2026 editionUSPrivacy Rights Clearinghouse
Cyber Security (Ransomware Payment Reporting) Rules 2025Australialegislation.gov.au · Home Affairs factsheet
ICO guidance on personal data breaches, and the NIS RegulationsUKICO breaches · ICO NIS
Cyber Security and Resilience Bill — parliamentary statusUKCommons Library CBP-10442

#Frameworks and control catalogs

FrameworkCurrent versionURL
CIS Critical Security Controlsv8.1 (Jun 2024)cisecurity.org · Implementation Groups
ISO/IEC 27001:2022 + Amd 1:20242022iso.org
ISO/IEC 27035-1 / -2 (incident management)2023iso.org · part 2
MITRE ATT&CKv19.2 (Apr 2026)attack.mitre.org · v19 release notes
MITRE D3FEND / ATLAS1.6.0 / 5.6.0d3fend.mitre.org · atlas-data
FAIR — Standard v3.0, O-RA v2.0.1Jan 2025FAIR Institute · O-RA · FAIR-CAM
CSA Cloud Controls Matrixv4.1 (Jan 2026)cloudsecurityalliance.org
SOC 2 Trust Services Criteria2017 w/ 2022 points of focusAICPA
PCI DSSv4.0.1 (Jun 2024)PCI SSC · future-dated requirements
HITRUST CSFv11.8.0 (May 2026)HITRUST advisories
SLSAv1.2slsa.dev
OWASP Top 10 for LLM Applications2025 / 2026 editionsgenai.owasp.org
OWASP Top 10 for Agentic ApplicationsDec 2025genai.owasp.org
Shared responsibility modelsAWS / Azure / GoogleAWS · Microsoft · Google

#Threat intelligence and industry reporting

Three different things wear the same jacket here. Keep them apart.

Primary and peer-reviewed. These carry weight on their own.

First-party incident disclosures. A company reporting on its own compromise or its own platform's abuse. Best available evidence on specifics; read the significance framing as advocacy.

Vendor telemetry. Real instrumentation, commercial framing, customer-shaped population. Quote with the source attached, every time.

ReportPublisherUsed in this book for
M-Trends 2026Mandiant / Google CloudDwell time, initial vectors, the 22-second broker hand-off, recovery denial
DBIR 2026 (via SecurityWeek; also Help Net Security)VerizonExploitation vs. credential abuse, third-party involvement, KEV remediation rates
Global Threat Report 2026CrowdStrikeBreakout time, malware-free detections, cloud intrusion growth
State of Ransomware 2026SophosIdentity-first ransomware, payment and recovery economics
Cyber extortion payment trends, Q2 2026Coveware by VeeamPayment rates, the mean/median divergence
State of Exploitation 1H-2026VulnCheckKEV timing, and the AI-discovered-CVE reality check
OT/ICS Year in Review 2026DragosOT threat groups, control-loop mapping
Ransomware and cyber extortion, Q2 2026ReliaQuestLeak-site volumes and brand rotation
Agentic threat actor in the orchestration planeSysdigThe second confirmed agentic intrusion
Salesloft Drift / UNC6395 analysisAppOmniSaaS-to-SaaS OAuth compromise
Trivy → LiteLLM campaignResecurityTransitive CI/CD compromise
Tycoon 2FA analysisGroup-IBAiTM kit economics
AI vs. human spear phishing, longitudinalHoxhuntThe 2023→2025 swing in AI phishing effectiveness

Marketing content. A family of "2026 cybersecurity statistics" sites surfaced constantly during research and contributed nothing. Their figures were either uncheckable or traceable to each other in a circle. Statistics whose only home was a marketing page were excluded — if a number's only parent is a page that also sells you a webinar, it is not a statistic. It is an advertisement wearing a lab coat.

That rule holds for numbers. It does not hold absolutely for everything else, and pretending otherwise would be the same dishonesty in the other direction. A small number of incident case summaries and definitional sources in this book do come from vendor blogs, because no better source exists for them. They are named inline every time they appear, so you can weigh them yourself, and they are named here too.

SourcePublisherUsed in this book for
Deepfake attack examplesAdaptive SecurityThe LastPass voice-clone case summary, in Chapters 4, 7 and 19
SOC metrics that matterProphet SecuritySOC metric definitions, in Chapters 9 and 16 and Appendix E
MTTD, MTTC and MTTRCroglThe same metric definitions, as the second corroborating source

#Published post-incident reviews and official investigations

These are the most valuable documents in this appendix, and it is not close. Read them in full — not the summary, not the LinkedIn thread. A vendor report tells you what happens across a population. These tell you what happened inside one organization, in order, including the parts nobody enjoyed writing down.

DocumentPublisherDateURL
Learning Lessons from the Cyber-Attack — 16 lessons, published voluntarilyBritish LibraryMar 2024bl.uk
Review of the Summer 2023 Microsoft Exchange Online IntrusionCyber Safety Review BoardApr 2024cisa.gov
GAO-18-559 — Data Protection: Actions Taken by Equifax and Federal AgenciesUS GAO2018gao.gov
GAO-25-107947 — TSA pipeline and rail cyber risk managementUS GAO2025gao.gov
Testimony of Joseph Blount on the Colonial Pipeline ransomware attackSenate HSGACJun 2021hsgac.senate.gov · House Homeland
SEC v. SolarWinds and Timothy Brown — internal communications as evidenceUS SECOct 2023sec.gov
Change Healthcare — the Citrix portal without MFA (Congressional testimony, via press)reportedMay 2024Cybersecurity Dive
Remediating Targeted-threat Intrusions — the whack-a-mole failure chainAldridge / Mandiant, Black Hat USA2012blackhat.com

Why these matter more than anything else on the list: they were written by people with every incentive to say less, and they said more. The British Library published sixteen lessons naming its own legacy estate, its own MFA gap at a supplier endpoint, and its own risk process failing to aggregate small accepted risks into a visible large one. The CSRB traced a Microsoft key-rotation control that was abandoned after an operational outage — a safety control retired by an availability incident, which is a pattern every one of us has lived through. GAO documented that Equifax's patch notice went to a distribution list that was out of date.

None of that is exotic. All of it is survivable, and all of it is preventable, and you only get to learn it cheaply because somebody else paid for it publicly.

#Practitioner and open-source resources

ResourceWhat it isURL
RE&CTResponse actions as an ATT&CK-shaped matrix; the best model for composable playbooksatc-project.github.io · repo
OASIS CACAO Security Playbooks v2.0The machine-readable playbook schema; use its property list as your metadata checklistdocs.oasis-open.org · SOARCA orchestrator
PagerDuty Incident ResponseRoles, severity, on-call and IC training, open-sourced from internal useresponse.pagerduty.com · repo
Howie: The Post-Incident GuideEight-stage post-incident investigation; "blame-aware" rather than merely blamelesshowie-guide.pagerduty.com
AWS incident response playbook librariesScenario playbooks and a shared template, in gitaws-samples · customer framework
Microsoft incident response playbooksPhishing, password spray, consent-grant abuse — maintained as Markdown with PR reviewlearn.microsoft.com
Counteractive IR plan templatePlan-plus-playbooks in one repo, rendered from sourcegithub.com
SigmaHQPortable detection rule format and 3,000+ ATT&CK-mapped rulessigmahq.io
Palantir Alerting and Detection Strategy frameworkNine-section detection documentation, including Validation and Blind Spotsgithub.com
DeTT&CTScores data-source quality and technique visibility before detection logicNVISO Labs
MITRE CTID Adversary Emulation LibraryFull and micro emulation plans for named actorsctid.mitre.org
Purple Team Exercise FrameworkOpen methodology for CTI + red + blue collaborative exercisesgithub.com
NCSC Exercise in a Box~20 free exercises in micro, tabletop and simulation formatsncsc.gov.uk
Google SRE Book and Workbook — incident managementThe ICS lineage, the living incident document, declaration triggerssre.google · workbook
FEMA NIMS/ICS referenceWhere incident command actually comes fromtraining.fema.gov

#Further reading — the opinionated short list

If you read nothing else from this appendix, read these. They are ordered by how much they will change how you work.

  1. The British Library review (bl.uk). Under 30 pages. Every security leader in any organization with legacy systems and a tight budget should read it twice — once for the lessons, once for the tone. It is what institutional honesty looks like.
  2. NIST SP 800-61r3 (PDF). Short, current, and it does something rare: it explains why it abandoned the model everyone still teaches.
  3. PagerDuty's incident response documentation (response.pagerduty.com). The best free training material on the human half of the job. Hand it to a new on-call engineer on day one.
  4. **Sidney Dekker, The Field Guide to Understanding 'Human Error'. The safety-science root of every blameless post-incident review, and the argument for forward-looking accountability instead of finding someone to blame. Pair it with John Allspaw's** "Blameless PostMortems and a Just Culture" (Etsy), which is the ten-minute version.
  5. NCSC's communications and staff-welfare guidance (comms · welfare). The only government guidance I know of dedicated to what a long incident does to the people running it. Read it before you need it.
  6. **Aldridge's *Remediating Targeted-threat Intrusions*** (PDF). Fourteen years old and still the clearest published account of why piecemeal containment loses.
  7. Rafeeq Rehman's CISO MindMap (rafeeqrehman.com). One page, updated annually since 2012. Chapter 3 uses it as an external cross-check against this book's own Coverage Model.
  8. Crafting the InfoSec Playbook — Jeff Bollinger, Brandon Enright and Matthew Valites (O'Reilly, 2015). A genuinely good book, focused on detection-driven playbook development from a large operational SOC. It is a separate and earlier work. This book is not a second edition of it, is not affiliated with it, and its authors had no part in this. The shared word is "playbook." Read theirs too; it holds up better than most 2015 security books, and the parts about building detection logic from your own telemetry have aged particularly well.

#What this book could not verify

Here is the honest inventory. Nothing below is asserted anywhere in this book as fact; where the subject was unavoidable, the text says what is known and marks the rest. Treat this section as your personal verification backlog.

CIRCIA's final rule. As of 5 September 2026 the rule is not published. CISA's own page says work continues and attributes the delay to funding lapses; the statutory October 2025 deadline was missed, a May 2026 target slipped, and the July 2026 Unified Agenda points at September 2026 (CISA; Hunton). What to do: build the 72-hour and 24-hour capability now, because the clocks are statutory and short, but do not put a compliance date on a slide. Check the Federal Register public inspection desk before you brief a board.

The alert-fatigue statistics everyone quotes. "62% of alerts ignored," "40% never investigated," "70%+ of analysts burned out" — these trace to vendor surveys, not primary research, and could not be verified. The defensible anchor is the 2025 ACM Computing Surveys review, whose full text is paywalled; even its "four major causes of alert fatigue" could only be read as an abstract-level claim, so this book does not enumerate them. What to do: if you need a number for a budget case, measure your own false-positive rate. It is more persuasive than a survey anyway, and you already have the data.

Maersk and NotPetya. The single surviving domain controller in Accra, the nine-day Active Directory recovery, the quotes attributed to the CISO, the server and endpoint rebuild counts, the cost figure — all of it comes from press coverage, vendor blogs and conference reporting. Maersk has never published an equivalent of the British Library review. What to do: the lesson (your recovery cannot depend on the identity plane you are about to declare compromised) is sound and independently supported. The specifics are anecdote. Do not put the numbers in a slide with a Maersk logo on it.

NCISS numeric score bands. CISA's document describes the weighted 0–100 formula and names the six priority levels, but the per-level score bands and category weights are supplied in an accompanying reference tool that was not retrieved. What to do: use NCISS's structure — especially the Purdue-style Location of Observed Activity and the campaign-aggregation rule — and set your own bands. Anyone reproducing NCISS numerically must obtain that tool from CISA.

Several regulatory details that sit one layer below the headline. The SEC Item 1.05 rescission story rests on law-firm and trade-association reporting, not on an SEC document — it has been requested, not proposed and not adopted. The UK Cyber Security and Resilience Bill's penalty figures come from commentary, not the Bill text. Whether AI Act Article 73 in its entirety moved to December 2027 was not read from the operative amending article. The Australian SOCI Part 2B 12-hour and 72-hour clocks were not confirmed against a primary source. Several US state deadlines outside New York, California, Texas, Washington and Puerto Rico rest on survey charts rather than statutes. The FCC's 500-customer threshold wording could not be read from the operative rule text.

Framework counts and version details. Whether a CIS Controls v9 exists; the DoD Zero Trust activity counts and Advanced-level target year; SOC 2 criteria and points-of-focus counts; HITRUST e1/i1 control counts; the ISO/IEC 42001 Annex A control count; what changed in SLSA v1.2; which revision of SP 800-171 CMMC Level 2 currently invokes; the disposition of SP 800-53 IR-10; whether NIST's AI RMF 1.0 has been superseded, given NIST's own note that it is under revision under the White House AI Action Plan; the release date of MITRE ATT&CK v19.2, where one report conflicts with MITRE's own April 2026 version-history date; the D3FEND 1.6.0 release date and whether Restore is a full top-level tactic; the ISO/IEC 27035-3 edition year and whether a Part 4 exists; whether ISO/IEC 27002:2022 received a climate-action amendment alongside 27001; the CSA CCM v4.1 domain names; and individual CIS Benchmark version numbers. Each of these appears confidently in vendor material and could not be confirmed from the standards body. What to do: if a number drives an assessment scope, get it from the body that publishes the standard.

Threat statistics with no visible parent. Infostealer volumes, session-cookie recapture counts, the "84% of AiTM incidents where MFA failed" figure, machine-to-human identity ratios, every circulating RAG-leakage statistic, MCP vulnerability prevalence figures, the Jaguar Land Rover economic-impact numbers, and the "-7 days mean time to exploit" figure. All vendor-blog or aggregator sourced. On RAG in particular: no credible confirmed report of a named real-world RAG-leakage or model-extraction breach could be found, which is why Chapter 7 treats it as a design-risk category rather than an observed-incident category.

Operational specifics that would be dangerous to guess. Exact AWS CLI syntax for forensic snapshot capture, CrowdStrike Falcon containment API request-body field names, the gcloud service-account disable command's exact form, the UpdateInboxRules audit operation, the OMB M-21-31 hot/cold retention split, Veeam hardened-repository internals. Where syntax could not be confirmed against vendor documentation, the action is described in words instead of shown as a command. Check the vendor's current reference page before any of it enters a runbook.

Two documents that may already be stale. CISA's Federal Playbooks still carry a November 2021 publication date and still reference SP 800-61 Rev. 2, not r3. ENISA's Threat Landscape 2026 and NCSC's Annual Review 2026 had not been published as of 5 September 2026; the 2025 editions are current here. Check for newer editions before you cite either.

#Attribution and thanks

Rafeeq Rehman has built and given away the CISO MindMap every year since 2012, most recently on 11 April 2026 (© 2012–2026 Rafeeq Rehman). It is one page, it is free, and it has probably scoped more security programs than any commercial framework — get it from rafeeqrehman.com. This book's Coverage Model is its own work and not a version of his map, but Chapter 3 keeps a reconstruction of his structure alongside it as a deliberate second opinion, because being scope-checked by someone who got here first is worth more than being flattered. That reconstruction, and the color coding by CSF Function, are editorial additions — neither the original artefact nor endorsed by him.

CISA published the Federal Government Cybersecurity Incident and Vulnerability Response Playbooks as a US Government work in the public domain, and explicitly anticipated organizations outside the federal civilian branch using them. Chapters 10 and 13 take that invitation. The NCISS, the CTEP packages, the IRP Basics fact sheet and the joint international logging guidance are all free, all good, and all under-read.

And the organizations that published their own post-incident reviews: the British Library, whose sixteen lessons are the most useful thing published about a ransomware attack in years; the Cyber Safety Review Board; the GAO; and the executives who sat for sworn testimony and answered questions they would rather not have been asked. Every one of them was under commercial, legal and reputational pressure to say less. They said more, so the rest of us could skip the tuition. That is a professional generosity our field does not repay often enough, and the least we owe them is to actually read the documents.

Stay sceptical, stay sourced, and check the footnote before you put the number in front of your board.

#Sources

  1. https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final
  2. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
  3. https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
  4. https://csrc.nist.gov/pubs/sp/800/171/r3/final
  5. https://csrc.nist.gov/pubs/sp/800/207/final
  6. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-84.pdf
  7. https://csrc.nist.gov/projects/ssdf
  8. https://csrc.nist.gov/pubs/sp/800/218/a/final
  9. https://www.nist.gov/itl/ai-risk-management-framework
  10. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
  11. https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8596.iprd.pdf
  12. https://csrc.nist.gov/projects/post-quantum-cryptography
  13. https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
  14. https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf
  15. https://www.cisa.gov/sites/default/files/2023-01/cisa_national_cyber_incident_scoring_system_s508c.pdf
  16. https://www.cisa.gov/federal-incident-notification-guidelines
  17. https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf
  18. https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf
  19. https://www.cisa.gov/stopransomware/ive-been-hit-ransomware
  20. https://www.cisa.gov/resources-tools/resources/best-practices-event-logging-and-threat-detection
  21. https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom
  22. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
  23. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
  24. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a
  25. https://www.cisa.gov/sites/default/files/2025-12/aa24-109a-stopransomware-akira-ransomware.pdf
  26. https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
  27. https://www.cisa.gov/news-events/news/cisa-issues-emergency-directive-address-critical-vulnerabilities-f5-devices
  28. https://www.cisa.gov/resources-tools/resources/ctep-package-documents
  29. https://www.ncsc.gov.uk/collection/incident-management/cyber-incident-response-processes
  30. https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf
  31. https://www.ncsc.gov.uk/files/Guidance-for-organizations-considering-payment-in-ransomware-incidents.pdf
  32. https://www.ncsc.gov.uk/guidance/putting-staff-welfare-at-the-heart-of-incident-response
  33. https://www.ncsc.gov.uk/guidance/pqc-migration-timelines
  34. https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025/chapter-01-cyber-threat-to-the-uk/incident-management
  35. https://www.ncsc.gov.uk/section/exercise-in-a-box/overview
  36. https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf
  37. https://ofac.treasury.gov/system/files/126/ofac_ransomware_advisory.pdf
  38. https://www.rfc-editor.org/rfc/rfc3227.txt
  39. https://gdpr-info.eu/art-33-gdpr/
  40. https://www.edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf
  41. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555
  42. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
  43. https://eur-lex.europa.eu/eli/reg_del/2025/301/oj
  44. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847
  45. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
  46. https://artificialintelligenceact.eu/article/73/
  47. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-73
  48. https://www.sec.gov/newsroom/press-releases/2023-139
  49. https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure
  50. https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
  51. https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements
  52. https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  53. https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17
  54. https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements
  55. https://www.federalregister.gov/documents/2024/11/07/2024-24704/enhancing-surface-cyber-risk-management
  56. https://www.federalregister.gov/documents/2025/01/17/2025-01243/ratification-of-security-directives
  57. https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
  58. https://www.federalregister.gov/documents/2025/09/10/2025-17143/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
  59. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB446
  60. https://privacyrights.org/resources-tools/reports/data-breach-notification-laws-50-state-survey-2026-edition
  61. https://www.legislation.gov.au/F2025L00278/asmade/text
  62. https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf
  63. https://ico.org.uk/for-organizations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
  64. https://ico.org.uk/for-organizations/the-guide-to-nis/incident-reporting/
  65. https://commonslibrary.parliament.uk/research-briefings/cbp-10442/
  66. https://www.cisecurity.org/controls/v8-1
  67. https://www.cisecurity.org/controls/implementation-groups
  68. https://www.iso.org/standard/88435.html
  69. https://www.iso.org/standard/78973.html
  70. https://www.iso.org/standard/78974.html
  71. https://attack.mitre.org/resources/versions/
  72. https://medium.com/mitre-attack/att-ck-v19-the-defense-evasion-split-ics-sub-techniques-new-ai-social-engineering-coverage-ff329cb65d66
  73. https://d3fend.mitre.org/
  74. https://github.com/mitre-atlas/atlas-data
  75. https://www.fairinstitute.org/what-is-fair
  76. https://pubs.opengroup.org/security/o-ra/
  77. https://www.fairinstitute.org/fair-controls-analytics-model
  78. https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1
  79. https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
  80. https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
  81. https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x
  82. https://hitrustalliance.net/advisories/author/hitrust
  83. https://slsa.dev/spec/
  84. https://genai.owasp.org/llm-top-10/
  85. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
  86. https://aws.amazon.com/compliance/shared-responsibility-model/
  87. https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility
  88. https://cloud.google.com/architecture/framework/security/shared-responsibility-shared-fate
  89. https://dl.acm.org/doi/10.1145/3723158
  90. https://dl.acm.org/doi/10.1145/3688810
  91. https://fatiguemanagersnetwork.org/wp-content/uploads/Harrison-et-al.2000_-The-Impact-of-Sleep-Deprivation-on-Decision-Making.pdf
  92. https://journals.sagepub.com/doi/10.2307/2666999
  93. https://arxiv.org/abs/2509.10540
  94. https://www.anthropic.com/research/small-samples-poison
  95. https://www.turing.ac.uk/blog/llms-may-be-more-vulnerable-data-poisoning-we-thought
  96. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  97. https://www.anthropic.com/news/disrupting-AI-espionage
  98. https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack
  99. https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools
  100. https://openai.com/index/disrupting-malicious-ai-uses/
  101. https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/reports/microsoft-digital-defense-report-2025/
  102. https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/
  103. https://docs.litellm.ai/blog/security-update-march-2026
  104. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
  105. https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/
  106. https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/
  107. https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/
  108. https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026
  109. https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
  110. https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
  111. https://www.dragos.com/ot-cybersecurity-year-in-review
  112. https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/
  113. https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape
  114. https://appomni.com/blog/drift-breach-salesforce-unc6395-saas-prevention/
  115. https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action
  116. https://www.group-ib.com/masked-actors/tycoon2fa/
  117. https://hoxhunt.com/blog/ai-powered-phishing-vs-humans
  118. https://www.adaptivesecurity.com/blog/11-deepfake-attack-examples-2026
  119. https://www.prophetsecurity.ai/blog/soc-metrics-that-matter-mttr-mtti-false-negatives-and-more
  120. https://www.crogl.com/resources/blog/mttd-mttc-soc-metrics
  121. https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf/
  122. https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf
  123. https://www.gao.gov/assets/gao-18-559.pdf
  124. https://files.gao.gov/reports/GAO-25-107947/index.html
  125. https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/Testimony-Blount-2021-06-08.pdf
  126. https://www.congress.gov/117/meeting/house/112689/witnesses/HHRG-117-HM00-Wstate-BlountJ-20210609.pdf
  127. https://www.sec.gov/newsroom/press-releases/2023-227
  128. https://www.cybersecuritydive.com/news/unitedhealth-change-attack-tech-takeaways/715200/
  129. https://media.blackhat.com/bh-us-12/Briefings/Aldridge/BH_US_12_Aldridge_Targeted_Intrustion_WP.pdf
  130. https://atc-project.github.io/atc-react/
  131. https://github.com/atc-project/atc-react
  132. https://docs.oasis-open.org/cacao/security-playbooks/v2.0/security-playbooks-v2.0.html
  133. https://github.com/COSSAS/SOARCA
  134. https://response.pagerduty.com/
  135. https://github.com/PagerDuty/incident-response-docs
  136. https://howie-guide.pagerduty.com/
  137. https://github.com/aws-samples/aws-incident-response-playbooks
  138. https://github.com/aws-samples/aws-customer-playbook-framework
  139. https://learn.microsoft.com/en-us/security/operations/incident-response-playbooks
  140. https://github.com/counteractive/incident-response-plan-template
  141. https://sigmahq.io/
  142. https://github.com/palantir/alerting-detection-strategy-framework
  143. https://blog.nviso.eu/2022/03/09/dettct-mapping-detection-to-mitre-attck/
  144. https://ctid.mitre.org/resources/adversary-emulation-library/
  145. https://github.com/scythe-io/purple-team-exercise-framework
  146. https://sre.google/sre-book/managing-incidents/
  147. https://sre.google/workbook/incident-response/
  148. https://training.fema.gov/emiweb/is/icsresource/assets/ics%20review%20document.pdf
  149. https://www.etsy.com/codeascraft/blameless-postmortems
  150. https://rafeeqrehman.com
  151. https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026
This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.