patch&proof.
← Research library

Methods / Research chapter

Data Methodology and Source Register

Research date: September 14–15, 2026. How this research package was produced, what its limits are, and what must be re-verified before publication.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. How this research package was produced, what its limits are, and what must be re-verified before publication.


1. Method

Eight parallel research streams were run against the brief, each with an explicit defensive-scope constraint and an instruction to prioritize primary sources from the previous 12 to 24 months:

  1. Cybersecurity fundamentals and the 25 security domains
  2. The cybercrime threat landscape and threat actors
  3. Frameworks, standards, and the legal/regulatory landscape
  4. The defensive tooling market, pricing, and independent evidence
  5. Penetration testing, professional practice, and education
  6. Security operations, incident response, and organizational baselines
  7. The industry ecosystem, case studies, and AI in cybersecurity
  8. Security economics, pitfalls, and careers

Each stream conducted 12 to 17 web searches plus targeted page fetches, produced a sourced markdown brief with inline links and publication dates, and flagged uncertain or conflicting material explicitly. Combined raw research: approximately 45,000 words. The eighteen deliverables in this package were synthesized from those briefs.


2. Evidence labeling scheme

Applied throughout, and recommended for the site itself:

Label Meaning
[Confirmed] Official government or law-enforcement statements, court records, regulatory filings, or victim disclosures — generally corroborated across sources
[Vendor] Statistics from commercial telemetry or vendor-run surveys; valuable but self-interested and often methodologically opaque
[Assessment] Analytic judgment, including attribution and intent, by a named source or by us
[Estimate] Modeled, survey-based, or extrapolated figures; directional rather than precise

Attribution of state-sponsored activity is almost always an assessment, even when published by a government. Financial impact figures are almost always estimates unless drawn from a company's own financial disclosures.


3. Known methodological limits of the major sources

FBI IC3 Annual Report. Covers only losses reported to IC3, by US complainants. Underreporting is severe and uneven across crime types — BEC is comparatively well reported because banks push victims to file; ransomware is badly underreported because organizations avoid disclosure. Not a measure of total cybercrime, and not internationally comparable.

Verizon DBIR. A convenience sample of incidents contributed by partner organizations. Coverage skews toward sectors and geographies where contributors operate. Year-over-year changes can reflect changes in the contributor pool rather than in the threat landscape. Verizon's own team cautions against over-reading single-year movements.

Mandiant M-Trends. Drawn from Mandiant's incident-response engagements — organizations that both suffered a significant incident and could afford a top-tier IR firm. Excellent for tradecraft trends, unrepresentative as population data.

IBM / Ponemon Cost of a Data Breach. Interviews with roughly 600 breached organizations, using activity-based costing that includes soft costs such as lost business and diverted staff time. Excludes mega-breaches. Skews mid-to-large enterprise. Per-record extrapolations are not valid and have been publicly criticized. Best used as a longitudinal index, not a price list.

Chainalysis. On-chain tracing produces a defensible floor for ransom payments, not a total: payments outside traced wallets, non-crypto payments, and unidentified addresses are missing.

Coveware. Caseload data from ransomware negotiations — a sample of victims who engaged a negotiator, which skews toward organizations with insurance and counsel.

Sophos State of Ransomware. A survey of IT leaders, with recall bias and self-selection. Its medians run well above DBIR's because its sample is enterprise-skewed.

ENISA Threat Landscape. EU-focused incident tracking. Its dominance of DDoS by volume reflects hacktivist campaign counting, which is why volume and impact must be reported separately.

CrowdStrike Global Threat Report. Vendor telemetry from CrowdStrike's installed base, which skews toward organizations that buy premium EDR.

ISC2 Workforce Study. Survey-based; the widely cited "gap" figure extrapolates from managers' stated desired headcount rather than funded roles.

IANS/Artico Security Budget Benchmark. CISO self-report, 587 respondents, skewing toward organizations with a CISO at all.

Gartner spending forecasts. Modeled end-user spending; the denominator in "security as a percentage of IT" varies by what is counted as IT.

Pricing trackers (CostBench, SIEMCostCalculator, MDRCost, PAMCost, SOARPricing). Independently maintained third-party aggregators of negotiated-contract data. Useful anchors; not quotes. Most enterprise security pricing is quote-gated, and discounts of 14% or more are routine.

AI vendor threat reports. Anthropic's and Google's disclosures about AI-enabled attacks are unusually detailed and transparent, but they describe activity on the vendors' own platforms, and independent verification of scope is not possible.


4. Conflicts identified during research

These are genuine conflicts in the source material, not errors. Present both figures where they appear.

Item Conflict Guidance
IC3 2025 US losses $20.9B in most coverage; $20.8B in at least one summary Verify against the IC3 PDF before publishing
Global average breach cost IBM 2025 edition: $4.44M, down 9%. IBM 2026 edition: $4.99M, a record, up 12% Consecutive editions; use 2026 as current and cite the 2025 decline as context
Ransomware share of breaches DBIR 2026: 48%. IBM 2026: 39% of incidents Different datasets and definitions; attribute separately, never blend
Third-party breach involvement DBIR 2025: ~30%. DBIR 2026: 48%, up 60% The trend is robust; the exact 2026 figure should be verified against the report itself
Median dwell time M-Trends 2025: 11 days. M-Trends 2026: 14 days Consecutive editions; report the direction and both figures
Ransomware payment rate Chainalysis: ~28%. Coveware: record low, 15% for exfiltration-only. Sophos 2025 survey: ~50% paid Different populations entirely; Sophos surveys enterprises, Coveware sees negotiated cases
Malicious npm package counts Sonatype's cumulative counts versus a 2026 analysis claiming 1.2M Counting methodologies differ wildly; cite Sonatype's method explicitly or avoid a number
AI-supported phishing share ENISA: >80% of observed social engineering by early 2025 Treat as a soft estimate; the direction is well supported, the precision is not
CISA workforce reduction Proposal was ~$495M and ~1,000 positions; reporting indicates roughly a third of staff lost via cuts, buyouts, and attrition Distinguish the budget proposal from reported outcomes; several sources are advocacy-framed

5. Items requiring re-verification before publication

Regulatory status (highest priority — all were moving at the research date):

  • CIRCIA final rule effective date
  • HIPAA Security Rule final rule timing (2027 or later per current reporting)
  • UK Cyber Security and Resilience Bill passage status
  • EU AI Act high-risk deadlines under the November 2025 digital-omnibus proposal
  • Canada's Bill C-8 status
  • FCC post-Salt-Typhoon rule status, which shifted with FCC leadership
  • Cybersecurity Information Sharing Act of 2015 reauthorization status
  • UN Convention against Cybercrime ratification count
  • CMMC phase-in schedule
  • US Cyber Trust Mark rollout stage
  • CA/Browser Forum certificate-lifetime milestone dates
  • China GB 44495/44496 automotive standard effective dates

Figures and details:

  • Exact IC3 2025 loss figure from the primary PDF
  • DBIR 2026's exact third-party-breach share from the report itself
  • Current CISA Secure by Design signatory count
  • Current CVE program governance status following the April 2025 funding scare and the CVE Foundation's creation
  • Specific npm worm incident names and dates against primary advisories
  • Scope of the August 2026 synced-passkey research before making any claim about passkey weaknesses
  • Specific deepfake-fraud loss aggregates, which vary widely by source
  • Quote-gated certification and platform prices (CompTIA, ISACA, GIAC, HTB, Vanta, Drata, Secureframe) — these were market-reported estimates, not published list prices
  • levels.fyi exact percentiles for security engineering compensation

Sourcing upgrades: Where a statistic in this package is attributed to a vendor blog roundup — mobile threat statistics, API security percentages, ransomware statistic compilations, deepfake statistics — replace the citation with the primary report before publishing the number, or drop the number.


6. Primary source register

Threat and incident data

  • FBI IC3 2025 Annual Report — ic3.gov
  • Verizon DBIR 2026 — verizon.com/business/resources/reports/dbir/
  • Mandiant M-Trends 2026 — cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
  • CrowdStrike 2026 Global Threat Report
  • ENISA Threat Landscape 2025 — enisa.europa.eu
  • Europol IOCTA 2025 — europol.europa.eu
  • Chainalysis Crypto Crime Report 2026 — chainalysis.com
  • Coveware by Veeam quarterly reports — veeam.com
  • Sophos State of Ransomware 2025 — sophos.com
  • IBM Cost of a Data Breach 2025 and 2026 — ibm.com/reports/data-breach
  • Ponemon/DTEX Cost of Insider Risks 2025
  • UK NCSC Annual Review 2025 — ncsc.gov.uk

Government and standards

  • CISA: KEV catalog, Cybersecurity Performance Goals 2.0 (Dec 11, 2025), #StopRansomware Guide, Cyber Hygiene Services, Tabletop Exercise Packages, Secure by Design, SCuBA baselines, Zero Trust Maturity Model v2.0, BOD 20-01 and 22-01, K-12 resources (Aug 12, 2026), joint CVD guidance with NSA (July 2026)
  • NIST: CSF 2.0, SP 800-53 Rev. 5 (Release 5.2.0, Aug 2025), SP 800-171 Rev. 3, SP 800-61 Rev. 3 (Apr 2025), SP 800-115, SP 800-207, SP 1800-35, SP 800-218 SSDF, AI RMF and NIST AI 600-1, FIPS 203/204/205, IR 8547 draft
  • MITRE: ATT&CK v18 (Oct 2025), ATT&CK Evaluations (Dec 2025), ATLAS, CVE program
  • OWASP: Top 10:2025, ASVS 5.0.0, MASVS/MASTG, WSTG, LLM Top 10 (2025 and 2026), GenAI Security Project
  • CIS: Controls v8.1, Implementation Group 1, Benchmarks
  • ISO/IEC: 27001:2022 + Amd 1:2024, 27002, 22301, 29147, 30111, 42001
  • PCI SSC: PCI DSS 4.0.1
  • FIRST: CVSS 4.0, EPSS
  • Cloud Security Alliance: CCM v4, STAR
  • ISA/IEC 62443 series
  • EU: GDPR, NIS2, DORA, Cyber Resilience Act, AI Act; ENISA guidance and the EU vulnerability database
  • UK: Computer Misuse Act 1990, UK GDPR, Data (Use and Access) Act 2025, Cyber Security and Resilience Bill, NCSC Cyber Essentials
  • US: CFAA, DOJ 2022 charging policy, SEC disclosure rules, GLBA Safeguards, NYDFS Part 500, HIPAA, CIRCIA, state breach and privacy laws
  • OFAC ransomware advisory

Market, product, and workforce

  • Gartner security and IT spending forecasts
  • IANS Research / Artico Search Security Budget Benchmark 2025
  • ISC2 Cybersecurity Workforce Study 2025
  • CyberSeek; US BLS Occupational Outlook Handbook
  • AV-Comparatives and AV-TEST
  • Marsh cyber insurance market updates; NAIC Cyber Insurance Market Report 2025; AM Best data
  • HackerOne Hacker-Powered Security Report 2025
  • Third-party pricing trackers: CostBench, SIEMCostCalculator, MDRCost, PAMCost, SOARPricing
  • Vendor pricing pages: Tenable, GitHub, OffSec, ISC2, Hack The Box, TCM Security

AI security

  • Anthropic threat reports (Aug 2025, Nov 2025, Sept 2026)
  • Google Project Zero / DeepMind Big Sleep disclosures; Google Threat Intelligence Group reporting
  • DARPA AI Cyber Challenge results (DEF CON 33, Aug 2025)
  • OWASP GenAI Security Project; NIST AI RMF; MITRE ATLAS

7. What this package does not cover

Stated plainly so the gaps are known rather than assumed:

  • Non-English-language sources. Research was conducted in English, which underweights regional threat reporting from Latin America, Africa, South Asia, and East Asia.
  • Detailed jurisdiction coverage beyond the US, EU, and UK. Australia, Singapore, and Canada are summarized; everywhere else is not covered.
  • Hands-on product testing. No tool in this package was tested by us. All product evidence is third-party.
  • Sector depth beyond the fifteen organization types profiled. Media, legal, hospitality, agriculture, and others are not separately treated.
  • Insurance policy language analysis. Coverage trends are described; policy wordings are not analyzed.
  • Quantitative market sizing beyond the cited Gartner and market-report figures.

Content type Review cadence Trigger for immediate review
Vulnerability and KEV content Weekly New KEV additions, active exploitation reports
Threat landscape Monthly Major incident, new annual report release
Tool pricing and product details Quarterly Acquisition, major release, pricing change
Frameworks Quarterly New version or major revision
Regulations Quarterly Any item in active rulemaking or litigation
Careers and certifications Twice yearly Certification price or structure change
Economics and budgets Annually New Gartner, IANS, IBM, or ISC2 release
Editorial and safety policy Annually Novel situation not covered

The annual report release calendar to build into the editorial plan: Chainalysis Crypto Crime (February), CrowdStrike Global Threat Report (February), Mandiant M-Trends (March), FBI IC3 (April), Verizon DBIR (May), Sophos State of Ransomware (June), IBM Cost of a Data Breach (July), ENISA Threat Landscape (October), ISC2 Workforce Study (December), and MITRE ATT&CK Evaluations (typically December).

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval