patch&proof.
← Research library

Overview / Research chapter

Executive Summary — Cybersecurity, Cybercrime, Defense & Penetration Testing

Research date: September 14–15, 2026. All findings reflect sources available on those dates, weighted toward publications from the previous 12–24 months. Every

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. All findings reflect sources available on those dates, weighted toward publications from the previous 12–24 months. Every figure below is traceable to a source in the companion documents. This material is educational; it is not legal, financial, or investment advice.


1. What this research package contains

Eighteen deliverables built from roughly 45,000 words of sourced primary research across eight parallel work streams: fundamentals and domains, the cybercrime threat landscape, frameworks and law, the defensive tooling market, penetration testing and education, security operations and organizational baselines, the industry ecosystem and AI, and security economics and careers.

# Deliverable File
1 Executive summary, data methodology 00-executive-summary.md (this file)
2 Cybersecurity fundamentals + domain map 01-fundamentals-and-domain-map.md
3 Cybercrime threat landscape 02-cybercrime-threat-landscape.md
4 Defensive controls guide 03-defensive-controls-guide.md
5 Security frameworks and standards guide 04-frameworks-and-standards.md
6 Security tool comparison tables 05-security-tool-comparison.md
7 Penetration testing and ethical hacking guide 06-pentesting-and-ethical-hacking.md
8 Incident response playbooks 07-incident-response-playbooks.md
9 Security baselines by organization type 08-security-baselines-by-org-type.md
10 AI and cybersecurity report 09-ai-and-cybersecurity.md
11 Cybersecurity economics analysis 10-cybersecurity-economics.md
12 Legal and regulatory overview 11-legal-and-regulatory-overview.md
13 Career and education guide 12-careers-and-education.md
14 Risks and pitfalls report 13-risks-and-pitfalls.md
15 Website information architecture, headlines, roadmap 14-website-strategy-and-ia.md
16 Editorial and safety policy 15-editorial-and-safety-policy.md
17 Data methodology and source register 16-data-methodology-and-sources.md
18 Ecosystem and case-study reference 17-ecosystem-and-case-studies.md

2. The ten findings that should shape the site

1. Vulnerability exploitation has overtaken stolen credentials as the leading way in. The Verizon 2026 DBIR put vulnerability exploitation at roughly 31% of breaches — the first time in the report's nineteen-year history that exploits led. Mandiant's M-Trends 2026 independently put exploits at 32% of initial infection vectors, the sixth consecutive year at number one in its casework. Meanwhile median time-to-patch worsened to about 43 days and organizations remediated only about 26% of CISA Known Exploited Vulnerabilities, down from 38%. The gap between how fast flaws are weaponized and how fast they are fixed is the defining operational problem of 2026.

2. Identity is where most large incidents actually begin or turn. Credentials appear in roughly 39% of breaches (DBIR 2026). Voice phishing rose to about 11% of Mandiant's initial infection vectors — now the number-two vector — driven almost entirely by calls to IT help desks to trigger password and MFA resets. Snowflake (2024), MGM and Caesars (2023), the UK retail wave (2025), and the Salesloft Drift OAuth theft (2025) were all identity failures, not exploit failures.

3. Ransomware attacks are up, ransom revenue is down. Chainalysis tracked about $820M in on-chain ransomware payments in 2025, down 8% year over year, while claimed attacks rose roughly 50%. The payment rate hit an all-time low near 28%, and Coveware measured only 15% payment among exfiltration-only victims in Q2 2026. Better backups, regulatory pressure, law-enforcement disruption, and eroded trust that paying helps are all contributing. The honest framing for readers: defense is working on the economics even as attack volume rises.

4. Third parties are now implicated in roughly half of breaches. DBIR 2026 put third-party involvement at about 48%, up 60% year over year. Change Healthcare, CDK Global, MOVEit, Salesloft Drift, and the 2025–26 npm compromises all show the same shape: one vendor's failure cascading across hundreds or thousands of customers. Vendor inventory and OAuth-integration governance are now front-line controls, not procurement paperwork.

5. AI has shifted attacker economics faster than defender economics, but both are real. IBM's 2026 report found AI-enabled breaches averaged about $6M and made up roughly a quarter of malicious breaches, up 56% year over year. ENISA reported AI-supported phishing exceeding 80% of observed social engineering by early 2025. On defense, Google's Big Sleep caught a SQLite flaw before attackers could use it, DARPA's AI Cyber Challenge finalists found about 77% of planted vulnerabilities, and IBM measured roughly $2M in breach-cost savings for organizations using AI and automation with governance in place. The credible synthesis is augmentation on both sides — not autonomous AI attackers, and not autonomous AI defenders.

6. Prompt injection is the new unpatched vulnerability class. It has held the number-one slot in the OWASP Top 10 for LLM Applications in both the 2025 and 2026 editions, and 2026 analysis cited by OWASP attributes most agentic-AI production security failures to it. There is no reliable fix; the working answer is architectural — privilege separation between model and tools, human approval for consequential actions, and treating all model input from untrusted sources as untrusted.

7. The regulatory wave is cresting between 2025 and 2027, and it is mostly about resilience and products, not just disclosure. DORA has applied since January 2025. NIS2 enforcement is maturing across member states. The EU Cyber Resilience Act's vulnerability-reporting obligations began September 11, 2026, with full application in December 2027. CMMC clauses entered DoD contracts from November 2025. NYDFS Part 500's final MFA and asset-inventory tranche took effect November 1, 2025. The HIPAA Security Rule overhaul has slipped to 2027 or later, and CIRCIA's final rule is still in late-stage rulemaking. Any regulation tracker on the site needs date-stamping and quarterly review.

8. Tools without staffing produce near-zero value, and the market knows it. IANS/Artico's 2025 benchmark found security budget growth at a five-year low of 4%, security at 10.9% of IT spend, and only 11% of CISOs reporting adequate staffing. A minimally viable 24/7 in-house SOC runs well over $1M a year. For organizations below roughly 1,000 employees, managed detection and response is the rational purchase before any additional console — Huntress publishes about $7.99 per endpoint per month at 100 endpoints, and most competitors are quote-only.

9. Independent product evidence is thinning. Only eleven vendors participated in the 2025 MITRE ATT&CK Enterprise Evaluations, published December 2025; Microsoft, Palo Alto Networks, and SentinelOne all declined. Absence of data is not evidence of weakness, but it shifts the burden onto buyer-run proofs of concept and makes vendor marketing claims harder to check. A site that publishes comparison content should say this out loud.

10. The cybersecurity workforce story is more complicated than the headline gap. ISC2's 2025 study de-emphasized its own "4.8 million gap" framing and recast the problem as a skills gap: 59% report critical skills needs, while 24% had layoffs, 36% had budget cuts, and 39% had hiring freezes. CyberSeek recorded about 514,000 US postings in the year to April 2025, concentrated at mid and senior levels. Demand for experienced practitioners is real; the entry level in 2025–26 is genuinely difficult. Any career content that repeats bootcamp marketing will lose credibility with the audience most likely to link to the site.


3. Headline numbers (with their caveats)

Metric Figure Source Caveat
US reported cybercrime losses, 2025 $20.9B across 1,008,597 complaints (+26% YoY) FBI IC3 2025 Annual Report Reported US losses only; underreporting is severe. One summary cites $20.8B — verify against the IC3 PDF before publishing
Global average breach cost $4.99M (2026 edition, a record, +12%); $4.44M (2025 edition, −9%) IBM Cost of a Data Breach Ponemon activity-based costing across ~600 orgs; excludes mega-breaches; not predictive for small businesses
US average breach cost ~$10.22M (2025 edition) IBM CODB 2025 US is a persistent cost outlier
Global ransomware payments, 2025 ~$820M on-chain (−8%) Chainalysis Crypto Crime Report 2026 A traceable floor, not a total
Ransomware payment rate ~28% overall; 15% for exfiltration-only Chainalysis; Coveware Q2 2026 Caseload-based
Median attacker dwell time 14 days (up from 11); 122 days for espionage/DPRK IT-worker cases Mandiant M-Trends 2026 IR-engagement casework, not population data
eCrime breakout time ~29 minutes average; fastest observed 27 seconds CrowdStrike 2026 Global Threat Report Vendor telemetry
Record DDoS 31.4 Tbps (Nov 2025, Aisuru/Kimwolf) Cloudflare via The Hacker News Vendor-mitigated peak
Worldwide security spending ~$213B (2025), ~$244B (2026 est.) Gartner End-user spending forecast
Security as % of IT budget 10.9% average; ~26% for sub-$50M-revenue firms IANS/Artico 2025 CISO self-reported

4. Positioning recommendation for the site

The cybersecurity content market is saturated with two kinds of material: vendor content marketing dressed as research, and SEO listicles with no sourcing. The gap — and the defensible position — is dated, sourced, uncertainty-honest, and safety-disciplined practical guidance. Concretely, that means:

Every statistic carries a source link and a publication date, and the distinction between a confirmed incident, a vendor telemetry claim, a threat-intelligence assessment, and a modeled estimate is stated on the page rather than flattened into "studies show." Every framework and regulation page carries a version and a status line ("current as of," "final rule pending"). Every product page states that results depend on configuration and staffing, names the open-source alternative, and declines to call anything secure. Every offensive-security page is anchored to written authorization and lawful labs.

That editorial discipline is also the site's safety architecture: the same rules that make the content trustworthy are the rules that keep it from becoming an attack manual. 15-editorial-and-safety-policy.md turns this into publishable policy.


Launch with five pillars that can be maintained by a small team and that compound: a beginner learning path (free, structured, honest about the job market), a small-business and personal security checklist set anchored to CISA CPGs and CIS IG1, a security tool directory with comparison pages built on the pricing and evidence tables in 05-security-tool-comparison.md, a framework and regulation tracker with date-stamped status lines, and an incident-response playbook library derived from 07-incident-response-playbooks.md. Add the threat and breach database, the lab and training directory, and the career guides in phase two. The 90-day plan in 14-website-strategy-and-ia.md sequences this.


Compiled September 15, 2026. Items flagged for re-verification before publication are consolidated in 16-data-methodology-and-sources.md.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval