Back to Resources
Framework

2026 Top 35

Reordered for the Modern Threat Landscape

A reordering of the original DSD Top 35 strategies, elevated to address the 2026 threat landscape: identity-first attacks, AI-automated exploits, and supply chain fragility.

1

Multi-factor Authentication

Elevated

Specifically phishing-resistant (FIDO2/Passkeys). Identity is the new perimeter.

2

Regular Backups

Elevated

Must be Immutable and Offline. Resilience is measured by your ability to restore, not just protect.

3

Patch Applications

Extreme Risk

The 48-hour rule is now the standard for critical vulnerabilities.

4

Patch Operating Systems

Extreme Risk

Includes network devices and "edge" hardware which are now primary targets.

5

Application Control / Whitelisting

Essential for stopping AI-generated malicious payloads.

6

Restrict Administrative Privileges

Minimising the "blast radius" of a single credential compromise.

7

Network Segmentation and Segregation

Elevated

Crucial for containing lateral movement in an "Assume Compromise" world.

8

Centralised & Time-Synchronised Logging (Computer Events)

You cannot defend what you cannot see. SIEM/XDR integration is mandatory here.

9

User Application Hardening

Disabling unneeded features (Java, OLE) to shrink the attack surface.

10

Microsoft Office Macro Settings

Blocking all macros by default unless digitally signed and vetted.

Assess your current resilience score

Use our 2026 Resilience Scorecard to rate your organisation against the critical controls.

Open Scorecard
Feisty Fox Logo
Feisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.