
Reordered for the Modern Threat Landscape
A reordering of the original DSD Top 35 strategies, elevated to address the 2026 threat landscape: identity-first attacks, AI-automated exploits, and supply chain fragility.
Specifically phishing-resistant (FIDO2/Passkeys). Identity is the new perimeter.
Must be Immutable and Offline. Resilience is measured by your ability to restore, not just protect.
The 48-hour rule is now the standard for critical vulnerabilities.
Includes network devices and "edge" hardware which are now primary targets.
Essential for stopping AI-generated malicious payloads.
Minimising the "blast radius" of a single credential compromise.
Crucial for containing lateral movement in an "Assume Compromise" world.
You cannot defend what you cannot see. SIEM/XDR integration is mandatory here.
Disabling unneeded features (Java, OLE) to shrink the attack surface.
Blocking all macros by default unless digitally signed and vetted.
Assess your current resilience score
Use our 2026 Resilience Scorecard to rate your organisation against the critical controls.