Industry resources
Cybersecurity resources worth bookmarking
A curated directory of the threat intelligence, frameworks, research, and government guidance we point clients to, straight from the organizations that publish them, grouped so you can find what you need.
Sources we trust, in one place
The best references in security are spread across standards bodies, government agencies, and research teams. We keep this list current so you do not have to hunt for them, and so you always have an authoritative source to check a claim against.
Threat intelligence & vulnerabilities
Where to see what attackers are doing right now, and which vulnerabilities matter most.
-
MITRE ATT&CK
The industry-standard knowledge base of real-world adversary tactics, techniques, and procedures.
attack.mitre.org -
CISA Known Exploited Vulnerabilities (KEV)
The vulnerabilities the US government confirms are being actively exploited. Patch these first.
cisa.gov -
NIST National Vulnerability Database (NVD)
The US government vulnerability database, with CVSS scores and technical detail for every CVE.
nvd.nist.gov -
FIRST EPSS
The Exploit Prediction Scoring System: a data-driven estimate of how likely a vulnerability is to be exploited.
first.org -
MITRE CVE Program
The authoritative source for CVE identifiers, the common reference for publicly disclosed vulnerabilities.
cve.org -
SANS Internet Storm Center
A daily handler diary tracking emerging threats and unusual internet-wide activity.
isc.sans.edu
Frameworks & standards
The frameworks and standards most organizations build their security and compliance programs on.
-
NIST Cybersecurity Framework
A widely adopted, voluntary framework for organizing and improving a security program.
nist.gov -
CIS Critical Security Controls
A prioritized, practical set of safeguards against the most common attacks.
cisecurity.org -
CIS Benchmarks
Consensus-based secure-configuration baselines for operating systems, cloud, and software.
cisecurity.org -
ISO/IEC 27001
The international standard for an information security management system (ISMS).
iso.org -
OWASP Top 10
The most critical web application security risks, a common baseline for secure development.
owasp.org -
PCI Security Standards Council
The standards body behind PCI DSS, for any organization that handles payment card data.
pcisecuritystandards.org
Analyst & industry research
Market analysis and annual research that help put technology choices and risk in context.
-
Gartner Cybersecurity
Analyst research, Magic Quadrant evaluations, and market guides across the security landscape.
Most full reports require a Gartner subscription or a vendor-provided reprint.
gartner.com -
Forrester
Analyst research on security and risk, including the Forrester Wave evaluations.
Most reports are subscription-based.
forrester.com -
Verizon Data Breach Investigations Report (DBIR)
An annual, evidence-based analysis of thousands of real-world breaches and the patterns behind them.
verizon.com -
IBM Cost of a Data Breach Report
Annual research on the causes and financial impact of data breaches.
ibm.com
Government & national cyber centres
Official guidance and alerts from national cyber security authorities, Canadian sources first.
-
Canadian Centre for Cyber Security
Canada's national cyber security authority: guidance, alerts, and the National Cyber Threat Assessment.
cyber.gc.ca -
Get Cyber Safe
The Government of Canada's public awareness program, with plain-language guidance for staff and individuals.
getcybersafe.gc.ca -
CISA (United States)
The US Cybersecurity and Infrastructure Security Agency: advisories, guidance, and free security tools.
cisa.gov -
UK National Cyber Security Centre
The UK cyber authority, a source of clear and widely referenced practical guidance.
ncsc.gov.uk
Ransomware & breach checks
Practical help if you are dealing with ransomware, or want to check your exposure.
-
CISA StopRansomware
The US government's central hub for ransomware guidance, alerts, and reporting.
cisa.gov -
No More Ransom
A law-enforcement and industry initiative offering free ransomware decryption tools.
nomoreransom.org -
Have I Been Pwned
Check whether an email address has appeared in known data breaches.
haveibeenpwned.com
Want help putting any of this into practice?
Frameworks and threat feeds only pay off once they are applied to your environment. That is the part we help with, from assessment to implementation.