Top Research & Reports
Original research, quarterly benchmarks, and analyst reports that define the cybersecurity marketing conversation.
22 curated entries · Last updated
Verizon Data Breach Investigations Report (DBIR)
New York, USA
The Verizon DBIR analyzes thousands of confirmed breaches and security incidents contributed by law enforcement, forensic firms, and cyber insurers to map how breaches happen and who is behind them. Published annually, it is the most widely cited breach benchmark in the industry.
IBM Cost of a Data Breach Report
Armonk, USA
IBM's Cost of a Data Breach Report surveys hundreds of breached organizations across more than a dozen countries to quantify average breach cost, time to identify and contain, and cost factors such as AI governance and shadow AI. Research is conducted independently by the Ponemon Institute.
Mandiant M-Trends
Reston, USA
Mandiant's M-Trends draws on hundreds of thousands of hours of incident-response engagements to report on dwell time, initial infection vectors, and threat-actor tactics. A 17+ year staple for defenders, now published under Google Cloud.
CrowdStrike Global Threat Report
Austin, USA
The CrowdStrike Global Threat Report summarizes the Counter Adversary Operations team's analysis of eCrime and nation-state activity, popularizing metrics such as 'breakout time' and named adversary groups. Published annually and widely referenced by SOC and CISO audiences.
ENISA Threat Landscape (ETL)
Athens, Greece
The ENISA Threat Landscape identifies prime threats, threat actors, and attack techniques across the EU, with mitigation guidance for technical and policy audiences. Published annually, it is the authoritative European public-sector threat reference.
Red Canary Threat Detection Report
Denver, USA
Red Canary's Threat Detection Report ranks the most prevalent threats and techniques observed across customer environments via human-led investigation, mapped to MITRE ATT&CK. A practitioner-favored, detection-engineering-oriented benchmark published annually.
ISC2 Cybersecurity Workforce Study
Alexandria, USA
The ISC2 Cybersecurity Workforce Study surveys 14,000+ practitioners worldwide to size the workforce, quantify the talent and skills shortage, and gauge job sentiment and budget pressures. Published annually, it is the most-cited source on the cybersecurity skills gap.
Coalition Cyber Claims Report
San Francisco, USA
Coalition's Cyber Claims Report analyzes actual claims across more than 100,000 policyholders to report on ransom demands, business email compromise and funds-transfer-fraud frequency, claims severity by company size, and recovery outcomes.
Picus Red Report
San Francisco, USA
The Picus Red Report analyzes over a million malware samples annually, mapping millions of observed behaviors to MITRE ATT&CK to rank the techniques attackers use most, such as process injection and defense evasion. A focused, actionable prioritization reference for defenders.
Chainalysis Crypto Crime Report
New York, USA
The Chainalysis Crypto Crime Report uses blockchain analytics to quantify funds flowing to illicit and sanctioned crypto addresses, scams, ransomware, and stolen funds. Published annually, it is the standard reference for crypto-crime figures.
Microsoft Digital Defense Report
Redmond, USA
The Microsoft Digital Defense Report synthesizes insights from the trillions of daily security signals Microsoft processes to map nation-state activity, cybercrime, and emerging AI-era threats. Published annually, it is one of the broadest threat assessments available.
IBM X-Force Threat Intelligence Index
Armonk, USA
The IBM X-Force Threat Intelligence Index reports on the most common attack vectors, top actions on objective, and industry targeting based on IBM's incident response and threat intelligence data. Published annually, it is a key benchmark for how attackers gain and use access.
Palo Alto Unit 42 Global Incident Response Report
Santa Clara, USA
The Unit 42 Global Incident Response Report analyzes hundreds of incident response cases to surface trends in ransomware, extortion, initial access, and attacker dwell time. It is a practitioner-focused view grounded in real engagements.
Fortinet Global Threat Landscape Report
Sunnyvale, USA
The Fortinet Global Threat Landscape Report from FortiGuard Labs analyzes exploit, malware, and botnet activity across Fortinet's global sensor network to highlight the most active threats and attacker behaviors.
Sophos State of Ransomware
Abingdon, UK
Sophos's State of Ransomware surveys thousands of IT and security leaders worldwide to quantify ransomware frequency, root causes, ransom payments, and recovery costs. Published annually, it is one of the most-cited ransomware benchmarks.
Verizon Mobile Security Index
New York, USA
The Verizon Mobile Security Index assesses the state of mobile and IoT security, surveying organizations on threats, incidents, and the maturity of their mobile defenses. It is a leading reference for mobile-specific risk.
Sonatype State of the Software Supply Chain
Fulton, USA
Sonatype's State of the Software Supply Chain analyzes open-source consumption, malicious package trends, and dependency risk across millions of projects. Published annually, it is the leading benchmark for software supply chain security.
Veracode State of Software Security
Burlington, USA
Veracode's State of Software Security analyzes scan data from hundreds of thousands of applications to report on flaw prevalence, security debt, and remediation rates. It is one of the longest-running data-driven AppSec reports.
Orca State of Cloud Security Report
Portland, USA
Orca Security's State of Cloud Security Report analyzes real cloud environments to surface the most common misconfigurations, exposures, and risky attack paths across AWS, Azure, and Google Cloud.
Google Cloud Threat Horizons Report
Mountain View, USA
The Google Cloud Threat Horizons Report delivers cloud-focused threat intelligence and forecasts from Google's security teams, covering credential abuse, misconfigurations, and emerging cloud attack trends.
Europol Internet Organised Crime Threat Assessment (IOCTA)
The Hague, Netherlands
Europol's IOCTA is the European Union's flagship law-enforcement assessment of the cybercrime landscape, covering ransomware, online fraud, child sexual exploitation, and the criminal ecosystem enabling them.
Imperva Bad Bot Report
San Mateo, USA
The Imperva Bad Bot Report (by Thales) analyzes global web traffic to quantify the share of traffic driven by automated bots, including credential stuffing, scraping, and account takeover. It is the leading benchmark on bot activity.