
A secondary archive of reference material — adversary profiles, defensive gap analyses, and the primary sources that shaped modern security practice.
Curated reference lists and scoring frameworks distilled from decades of defensive practice.
A reordering of the original DSD Top 35 strategies, elevated for the 2026 threat landscape: identity-first attacks, AI-automated exploits, and supply chain fragility.
A practical framework covering the five essential principles of data security — from understanding your data's value to assessing how well it's protected.
An executive dashboard consolidating resilience scorecard results across configuration, protection, and response into a single operational view.
Map your current controls against the MITRE ATT&CK framework to identify the defensive gaps an adversary would exploit first.
Threat actor profiles, ATT&CK technique mappings, and adversary heatmaps for sector-specific intelligence.
Map threat actors to their MITRE ATT&CK techniques and filter by your industry to see which adversaries target your sector and exactly how they operate.
A six-tier adversary capability framework with profiled threat groups — including Talbot (Level 6 nation-state) and Jakemann (Level 5 supply chain) — covering TTPs, targeting sectors, and operational characteristics.
A visual heatmap of adversary activity across tactics and techniques, highlighting the most frequently observed attack patterns by sector.
Build a tailored threat profile by selecting your sector, assets, and risk appetite — generating a prioritised adversary shortlist with recommended mitigations.
Select your industry sector to visualise active threat actors, their MITRE ATT&CK TTPs, and the ISM controls most effective against the adversaries targeting your sector.
ASD/ACSC Privileged User Training — June 2026. Step-by-step walkthrough of attacker tooling including Metasploit exploitation, Pass-the-Hash with Mimikatz, Golden Ticket creation, network propagation, and log analysis.
Primary sources, timelines, and breach post-mortems that shaped modern security practice.
The seminal 2002 memo from Bill Gates to all Microsoft employees, establishing Trustworthy Computing as the company's highest priority.
An interactive timeline tracing the evolution of cybersecurity standards and practice from 1990 to 2024 — from foundational frameworks to adversarial simulation.
Interactive case study of the 2014–2015 Deep Panda nation-state attack on Anthem — 78.8 million records stolen. Explore the full timeline, what was taken, security failures, and the controls that would have stopped them.
A collection of security incident and breach case studies with lessons-learned analysis across critical infrastructure, financial services, and government sectors.