401 Access Denied (opens in a new tab)
Why: Delinea bi-weekly podcast with Joseph Carson on identity security and InfoSec practice — official hub remapped from dead Libsyn path.
254 current resources. Refine by category, type, starting-point strength and last verified.
Showing 254 current resources
Why: Delinea bi-weekly podcast with Joseph Carson on identity security and InfoSec practice — official hub remapped from dead Libsyn path.
Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.
Why: Open library of portable, ATT&CK-mapped tests that security teams can run to check whether their detections actually catch real attacker behaviours.
Why: Curated collection of hunting tools, methods and references — a practical starting point when building or refreshing a threat-hunting programme.
Why: Lumen threat research arm; China-nexus IoT/proxy quartermaster enablement model — high value for edge/IoT defenders.
Why: Ready-to-use English incident response methodology playbooks covering common attack scenarios, so teams can rehearse and respond with shared steps rather than inventing process under pressure.
Why: Authoritative Carnegie Mellon CERT Coordination Centre vulnerability notes and advisories.
Why: Widely used secure-configuration baselines for operating systems, cloud and applications, helping teams harden systems to an agreed, repeatable standard.
Why: Prioritised, actionable safeguards that help teams sequence hardening work by impact.
Why: Voluntary CISA baseline protections for critical infrastructure (CPGs 2.0, aligned to NIST CSF 2.0) that help organisations prioritise practical safeguards when starting a maturity journey.
Why: Official US CISA cybersecurity advisory feed covering urgent vulnerabilities and threats, so organisations can act on authoritative government guidance quickly.
Why: CISA advisories focused on industrial control systems, helping OT teams track product risks and patch priorities that affect plant and field environments.
Why: CISA evergreen OT/ICS hub linking role-specific guidance, recommended practices, training and alerts for critical infrastructure defenders.
Why: Practical attack-surface guidance for getting unnecessary IT/OT exposure off the internet.
Why: CISA's catalogue of vulnerabilities known to be exploited in the wild — the practical must-patch list for teams prioritising fixes that attackers are already using.
Why: CISA buyer guidance that helps organisations demand secure products in procurement — a practical lever for reducing digital risk when acquiring software during change programmes.
Why: US CISA programme pushing software makers to ship products with security built in by default, reducing burden on defenders and buyers.
Why: CISA heightened-threat readiness hub with practical actions for organisations to harden, detect and respond when cyber risk is elevated.
Why: US whole-of-government ransomware hub consolidating prevention, response and recovery guidance plus #StopRansomware advisories.
Why: Ready-made CISA tabletop packages spanning cyber and physical scenarios, so teams can practise response without designing every exercise from scratch.
Why: High-yield detection engineering research including agentic post-compromise tradecraft.
Why: High-signal DDoS and internet-health view grounded in large-scale edge telemetry.
Why: Practical open-source incident response plan template that teams can adapt for policy, roles, escalation paths and documentation when building or refreshing their IR capability.
Why: Annual CrowdStrike threat landscape report — adversary trends, malware families, and industry risk themes for planners and responders.
Why: Olly Whitehouse (NCSC CTO) Substack — senior UK cyber perspective and pointers to useful practitioner resources.
Why: Home of the CVE programme that assigns the standard identifiers used worldwide for software flaws — the naming backbone behind most vulnerability tracking and advisories.
Why: Infotec Institute careers podcast with hiring managers and practitioners on skills, roles and how to progress in cyber security.
Why: The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
Why: Story-driven true-crime podcast about hacking incidents and underground culture — strong for awareness and lessons learned.
Why: Ipswitch/Progress technical podcast on file transfer, network and security operations — useful for IT and security teams sharing infrastructure concerns.
Why: Specialist OT and ICS threat research and practitioner resources for defenders protecting industrial and critical infrastructure environments.
Why: Standing EU ENISA hub for threat landscape and risk publications, helping teams track European threat trends and risk analysis without hunting across scattered releases.
Why: EU Agency for Cybersecurity catalogue of reports, guidance and sector studies — a primary source for EU policy context and practitioner research across member states.
Why: Industry-standard Traffic Light Protocol for marking how far threat information may be shared, so responders and partners can exchange intelligence without accidental oversharing.
Why: Google Project Zero researches and discloses high-impact zero-day vulnerabilities with detailed technical write-ups that inform defence and vulnerability management.
Why: Unix living-off-the-land binaries companion to LOLBAS; essential for detection engineering and abuse-path review.
Why: Global ISMS requirements and control guidance underpinning certification and supplier assurance.
Why: Mandiant’s annual M-Trends report — real-world breach findings and frontline response lessons.
Why: Microsoft's weather-themed naming system for threat actors, essential for decoding Defender alerts and Microsoft threat reports into clear, consistent actor labels.
Why: Standing hub for identity/edge tradecraft (device-code phishing, TerminalFix, Unicode phishing).
Why: Living knowledge base of adversary tactics and techniques for threat-informed detection and defence.
Why: MITRE's catalogue of known adversary groups mapped to ATT&CK techniques, helping teams compare aliases, understand shared tactics and brief others with a common naming baseline.
Why: Interactive ATT&CK layer viewer for mapping techniques to detections and coverage, helping teams visualise gaps and brief stakeholders on adversary behaviour.
Why: Open-source automated adversary-emulation platform for running ATT&CK-mapped red-team and purple-team exercises safely in your own lab.
Why: UK National Cyber Security Centre hub of practical advice and guidance for organisations, covering everyday defence through to emerging topics such as AI and operational technology.
Why: Practical NCSC method for assessing supplier cyber assurance across procurement, legal and security — built for the organisational change needed to manage third-party digital risk.
Why: UK NCSC Cyber Assessment Framework for critical national infrastructure and essential services — a structured way to judge cyber resilience outcomes and where to improve.
Why: NCSC Cyber Aware public guidance: six practical actions (passwords, updates, 2SV, backups) for individuals and micro-businesses.
Why: UK government baseline certification scheme that sets practical controls for organisations of all sizes to guard against common internet threats.
Why: UK NCSC guidance that helps boards oversee cyber risk, culture and investment with clear questions and expectations for organisational leadership.
Why: NCSC board-toolkit guidance on building awareness programmes that shape organisational cyber culture.
Why: UK NCSC guidance on hardening Windows devices for enterprise use, giving clear platform settings that reduce everyday attack surface on endpoints.
Why: Free UK NCSC scenarios and facilitation packs for running cyber tabletop exercises, so organisations can practise decision-making without designing every drill from scratch.
Why: NCSC index of free 60–90 minute cyber tabletop discussion exercises. Facilitators pick a scenario (ransomware, supply chain, insider threat, BYOD, etc.), download the pack, and run structured injects with senior leaders, cyber engineers and communications.
Why: NCSC user-education hub on spotting phishing and reporting scam emails/websites (report@phishing.gov.uk) to take down abuse.
Why: NCSC guidance for embedding cyber risk into organisational decision-making — essential when programmes, technology choices and risk appetite shift during business change.
Why: NCSC principles for designing secure systems and services from the start, helping transformation teams reduce risk when building or changing digital capability.
Why: Widely adopted risk-based framework for organising cyber capability across Identify–Protect–Detect–Respond–Recover.
Why: The US National Vulnerability Database — the main public hub for searching CVEs with severity scores and references, essential for understanding and prioritising software flaws.
Why: Authoritative catalogue of security and privacy controls used to design and assess system safeguards.
Why: Practical application security verification standard that turns secure-design expectations into testable requirements for builders, reviewers and assurance teams.
Why: Concise, maintained secure-coding and configuration cheat sheets covering common risks, giving developers and defenders quick, trusted implementation guidance.
Why: Canonical web application risk ranking — the shared language practitioners and boards use for the biggest app risks.
Why: PortSwigger Research publishes practical web-security research papers, tools and techniques used by penetration testers and application defenders.
Why: Red Canary Threat Detection Report — annual study of detections, ATT&CK techniques, and SOC lessons.
Why: Red Canary threat intelligence resources — detection guidance, reports, and practitioner write-ups.
Why: Long-running news podcast covering cyber risk, breaches and industry developments for practitioners who need a weekly brief.
Why: Practitioner diary of active internet threats, scanning activity and opportunistic attacks.
Why: Open library of Sigma detection rules that translate to many SIEM and EDR backends, accelerating consistent hunting and detection engineering across tools.
Why: Industry-standard maturity model for Security Operations Centres, helping teams assess current SOC capability and plan clear improvements over time.
Why: Trusted-infrastructure and evidence-layer tradecraft (e.g. Fire Ant / TACACS).
Why: Community podcast interviewing cyber and software security leaders about real programme challenges, decisions and lessons from the field.
Why: Greg Schaffer Virtual CISO Moment on SMB security leadership — Apple hub remapped from dead CSO Online article URL.
Why: Daniel Miessler’s podcast on cyber security, AI and technology strategy — high-signal listening for thoughtful practitioners and leaders.
Why: Verizon DBIR — the industry-standard annual data-breach study used for risk conversations and planning.
Why: Interview-led podcast from two practitioners covering careers, community and day-to-day cyber practice for women and allies in the field.
Why: Short, practical episodes aimed at busy defenders — quick tips on Windows, Active Directory and hands-on security hygiene.
Why: Perry Carpenter podcast on the human (8th) layer of security — canonical hub remapped from dead Fortinet path.
Why: Community IP reputation database for checking whether an address has been reported for abuse before you block or investigate it.
Why: Light-touch storytelling podcast that makes cryptography and security concepts accessible for learners and non-specialist colleagues.
Why: ANY.RUN dashboard of malware trends from live sandboxes, showing which families and behaviours are circulating so teams can prioritise detection and awareness work.
Why: Classic DDoS visualisation still used for briefings on volumetric attack geography.
Why: Curated GitHub index of annual security and threat reports — a fast way to find this year’s major publications.
Why: Curated open list of threat-intelligence feeds, frameworks and research sources — a practical starting index for building a TI stack.
Why: Chris Glanden BarCode cybersecurity podcast — Apple hub remapped from dead barcode.com path.
Why: Scans websites and maps related attack infrastructure, helping analysts pivot from a single site to the wider hosting and threat landscape behind it.
Why: Mobile-app security search — find exposed endpoints, secrets and risky configurations across Android and iOS applications.
Why: Live Bitdefender map of malware and attack activity by region, giving practitioners a clear visual snapshot of where campaigns appear to be concentrating right now.
Why: Internet-wide asset search that helps teams discover exposed hosts, certificates and services on their attack surface.
Why: Security advisories from CERT-EU for EU institutions and public-sector defenders, helping European teams track urgent flaws and recommended mitigations.
Why: CERT-EU threat intelligence publications — EU institutional threat reporting and situational awareness.
Why: Standing CPR hub for nation-state and crimeware research (e.g. Lazarus / 0-day campaigns).
Why: Real-time ThreatCloud map of attack volume and destinations, helpful when you need a fast visual brief on where activity is concentrating.
Why: Joint CISA and G7 call for organisations to inventory cryptography and plan a phased move to post-quantum algorithms before quantum computers break today's encryption.
Why: Reusable CTEP planner/facilitator handbooks, invitation letter, slide deck, participant feedback and AAR-IP templates. Use alongside any situation manual so exercise teams can run and document a full HSEEP-style tabletop without building paperwork from scratch.
Why: Downloadable ransomware CTEP situation manual (DOCX, Sept 2023). Customisable objectives, injects and discussion questions for IR, leadership and communications to rehearse encryption/extortion response and recovery; pair with CTEP package documents.
Why: Cisco Talos podcasts and briefings on threats, malware and defensive research, giving practitioners timely context from one of the industry's major commercial threat teams.
Why: Cisco Talos live map linking spam and malware activity to geographic hotspots, helping teams connect email and malware pressure to places seeing the most traffic.
Why: Recorded Future’s geopolitics and threat-intel podcast — one place defenders can hear how nation-state and cybercrime context lands in practical intelligence work.
Why: Catalogue of named adversaries with aliases and campaign context, supporting research, briefings and consistent attribution language across teams.
Why: Certificate Transparency log search — enumerate domains and subdomains that have obtained TLS certificates.
Why: Bruce Schneier’s companion to the Crypto-Gram newsletter — clear takes on crypto, privacy and security policy for practitioners.
Why: Short daily headlines from the CISO Series that summarise the day's cyber news for leaders and practitioners who need a quick, reliable brief.
Why: WithSecure Cyber Security Sauna catalog hub (production ended 2024; F-Secure/WithSecure site paths 404) — still useful archive listening.
Why: Canadian ITWC daily brief covering major cyber news for practitioners who want a concise North American-oriented round-up.
Why: LMG Security Cyberside Chats with Sherri Davidoff and Matt Durrin — official hub remapped from dead CSO Online article URL.
Why: Concise daily briefing from The CyberWire covering major cyber news, so busy practitioners can keep pace without reading every headline themselves.
Why: The Cyber Security Body of Knowledge — structured academic and practitioner reference covering the core knowledge areas of the discipline.
Why: Search leaked credentials and related identity artefacts from known breaches — useful when checking exposure after phishing or account takeover.
Why: Annual DFIR year-in-review — practical incident response lessons and case themes from the DFIR Report team.
Why: Fast DNS reconnaissance that maps hosts, records and related infrastructure for a domain during investigations and attack-surface reviews.
Why: Generates lookalike domain variants so you can spot typosquatting and phishing infrastructure before attackers use it against your brand.
Why: Unit 42 podcast covering adversary behaviour, incident lessons and threat research for practitioners.
Why: Practitioner-facing discussions on dark-web tradecraft, OSINT and threat awareness for defenders tracking underground activity.
Why: ENISA foresight on cybersecurity threats out to 2030 — useful for long-range risk and strategy conversations.
Why: Curated archive of public exploits and proof-of-concept code for vulnerability research, detection writing and controlled testing.
Why: Global forum for incident response teams, sharing standards, community practice and CVSS context that underpins how responders collaborate worldwide.
Why: Cyberspace search engine (FOFA) for finding exposed assets and fingerprinting services on the public internet during OSINT and attack-surface reviews.
Why: Fortinet encyclopaedia of malware, vulnerabilities and threat intelligence for rapid lookup during research and response.
Why: Live Fortinet sensor feed useful for spotting surge patterns and regional pressure.
Why: FortiGuard Threat Signal Report — weekly Fortinet roundup of notable threats and exploit activity.
Why: Outbreak-oriented FortiGuard map for tracking active malware campaigns geographically.
Why: Standing hub behind G20 systemic cyber/AI-patch risk messaging.
Why: Attack-surface search that helps organisations discover internet-facing assets tied to their domains, supporting continuous external exposure monitoring and review.
Why: Open-source reverse-engineering suite (NSA-origin) for analysing binaries when dissecting malware or unknown software.
Why: Indexes publicly exposed cloud storage buckets so analysts can find accidental data spills and misconfigured object stores.
Why: Code search across hundreds of thousands of public git repositories — useful for finding secrets, vulnerable patterns and reuse of known code.
Why: Internet noise intelligence — tell scanner/benign mass probing apart from targeted attacks on your IPs.
Why: Independent podcast mixing news, interviews and community chat aimed at newcomers and hands-on hobbyist defenders.
Why: Career and culture interviews from Hacker Valley Studio — practical listening for people building cyber skills and professional networks.
Why: CyberWire series on social engineering and phishing case studies — concrete lessons for awareness programmes and human-risk teams.
Why: Free breach-notification service to check whether an email address or password has appeared in known data breaches.
Why: Finds publicly listed email addresses tied to a domain — useful for OSINT checks and phishing-defence awareness work.
Why: IBM X-Force Threat Intelligence Index — annual view of attack trends, industries hit, and attacker techniques.
Why: Real-time Imperva view of cyber attacks useful for application-threat briefings.
Why: Infotec Institute live-style podcast covering current InfoSec topics and guest perspectives for working security professionals.
Why: Deep file-inspection laboratory for analysing suspicious samples and extracting indicators — useful when you need richer context than a quick multi-engine scan.
Why: Search engine for leaked data, dark-web content and historical internet records when investigating compromised accounts and domains.
Why: Global attack-distribution view with common vectors for quick situational awareness.
Why: Search engine for publicly indexed services and leak indicators — helps find exposed databases, panels and misconfigurations on the open internet.
Why: Dr Eric Cole Life of a CISO podcast on CISO practice and board communication — Libsyn hub remapped from dead Buzzsprout path.
Why: Living Off the Land Binaries and Scripts for Windows — essential reference for detection engineering and abuse-path reviews alongside GTFOBins.
Why: Story-driven history of hacking, malware and cyber conflict — strong background listening that puts today's threats in a longer historical context.
Why: Countermeasure knowledge graph that maps defensive techniques against attacker behaviours.
Why: MITRE active-defence framework for denial, deception and adversary engagement, mapped to ATT&CK for defender planning.
Why: Sophos Naked Security team podcast unpacking recent threats and research in plain language for IT and security staff.
Why: UK NCSC checklist of concrete steps organisations should take when the national cyber threat level rises — from hardening and monitoring to communications and recovery readiness.
Why: NCSC principles for building a security-supporting culture — useful when leading behaviour, leadership and process change alongside technical transformation.
Why: 60–90 minute NCSC tabletop for senior leaders, cyber engineers and communications. Walks phishing-delivered ransomware from detection through containment, recovery and external messaging; ZIP pack includes facilitator and participant PDFs.
Why: Internet-wide asset search and monitoring for hosts, services and related observables during OSINT and attack-surface work.
Why: NETSCOUT horizon view of DDoS and infrastructure threats at internet scale — strong for understanding volumetric attack patterns that hit networks and service providers.
Why: Mandatory UK health and care self-assessment of data security and information governance practice.
Why: NHS campaign materials that help staff handle information confidentially and build everyday data-security habits across clinical and administrative teams.
Why: US federal security baseline for protecting Controlled Unclassified Information on non-federal systems — a practical checklist for suppliers and partners handling sensitive US government data.
Why: Cyber threat intelligence search across IPs, domains and related observables — a practical OSINT and enrichment source when investigating hosts and infrastructure.
Why: Conversations on securing open-source software and supply chains — useful for teams that depend on OSS and need clearer risk thinking and community practice.
Why: Long-running feed of advisories, exploits and tools for staying current on disclosed vulnerabilities and attack techniques.
Why: Unit 42 research hub — threat reports, actor profiles, and vulnerability write-ups from Palo Alto Networks.
Why: Facial recognition search — find where a face appears online (use carefully; privacy-sensitive).
Why: Crowdsourced malware scanning for files and URLs, giving multi-engine verdicts useful in triage and indicator validation.
Why: Source-code search across public websites to find scripts, trackers and technology fingerprints at scale — useful for OSINT, brand protection and supply-chain checks.
Why: Threat intelligence search with community-scored risk context on indicators, helping analysts decide which IPs, domains and hashes deserve closer attention.
Why: Live application and network attack map for application-layer threat awareness.
Why: Edge persistence research plus Global Threat Landscape series.
Why: Standing Insikt research hub (Russia initial access, DPRK IT-worker pipelines, etc.).
Why: Short daily SANS Internet Storm Center briefing on active threats and defensive tips — a practical morning listen for hands-on defenders and analysts.
Why: Pairs Secure Controls Framework controls with a capability maturity model, so programmes can score security and privacy practice maturity against a common control set.
Why: Source-code search across millions of public projects — useful for finding leaked secrets, vulnerable patterns and library usage.
Why: Cross-maps many regulatory and security frameworks into one controls set for multi-obligation programmes.
Why: Kaspersky’s long-running research hub for malware analysis, APT reporting and threat insights used by defenders worldwide.
Why: Consistent vendor threat profiles that summarise actor behaviour and naming, useful when preparing briefings or aligning research across sources.
Why: Long-form weekly show explaining security news, crypto and privacy topics in depth for technically curious listeners.
Why: Long-running family of shows covering security news, research and interviews — a reliable weekly listen for staying current across the industry.
Why: Historical DNS, WHOIS and domain intelligence that helps investigators reconstruct past infrastructure and related assets during domain and host research.
Why: Free Shadowserver network-reporting subscriptions that notify organisations about exposed services, malware and other risks on their address space.
Why: Search engine for internet-connected devices and services — classic attack-surface reconnaissance.
Why: Gerald Auger’s community-focused show on cyber careers, certifications and practical skill-building for early and mid-career practitioners.
Why: Graham Cluley and friends weekly news show — irreverent but informative briefings on breaches and industry stories.
Why: Keeps current and target SOC operating models aligned to SOC-CMM, MITRE Inform and SIM3 with living evidence — product hub remapped from retired GitHub path (soft wall).
Why: Sophos annual threat report — ransomware, malware, and attacker behaviour trends for defenders.
Why: Spamhaus map of botnet and spam-source concentrations, useful when you need a reputation-led view of where abusive infrastructure is clustering worldwide.
Why: Structured threat-hunting methodology that folds threat intelligence into hunt cycles, giving analysts a repeatable way to pursue targeted leads.
Why: Interview-led cyber security radio for broad situational awareness — official hub remapped from dead VoiceAmerica path (soft wall).
Why: WatchGuard 443 Security Simplified weekly threat and research podcast — Podbean hub remapped from dead Fortinet path.
Why: Women-led cyber podcast highlighting careers, leadership and community — useful listening for practitioners seeking diverse voices in the field.
Why: Purdue cyberTAP centre hub for cyber awareness and education content — remapped from invalid Podbean site (podcast path retired).
Why: Stewart Baker Cyberlaw Podcast on cyber law, regulation and policy — Libsyn hub remapped from dead Steptoe path.
Why: Detailed real-world intrusion case write-ups with timelines, tooling and lessons that help responders and hunters improve practice.
Why: Robert Vamosi interviews hackers and researchers about mindset and method — background listening that sharpens threat understanding.
Why: Privacy and security interviews focused on practical controls and policy for teams balancing usability with protection.
Why: Chris Hadnagy’s long-running show on social-engineering research and defence — essential for awareness and red-team human-risk work.
Why: Trellix Advanced Research Center threat reports — regular analysis of malware, campaigns, and emerging threats.
Why: Trellix Advanced Threat Research white-paper library covering laboratory techniques (function hooking, patch diffing, ICS simulation, Android SSL pinning, and related methods) for practitioners reducing attack surfaces.
Why: Converts Sigma detection rules into formats used by common SIEM and EDR platforms, speeding up detection engineering when the same logic must run across tools.
Why: abuse.ch malware URL blocklist publishing known-bad links for blocking, hunting and research — a trusted free feed for defenders tracking malicious URLs.
Why: Sandbox a suspicious URL — see page behaviour, redirects, and related indicators without opening it yourself.
Why: Multi-engine file and URL scanner that helps analysts quickly see whether a sample or link is widely flagged as malicious.
Why: Large vulnerability knowledge base spanning CVEs, advisories and related artefacts for prioritisation and research.
Why: Internet Archive web history — recover deleted or changed pages and track how sites evolved during investigations.
Why: News and interview podcast covering cyber threats and industry developments for a broad practitioner audience.
Why: Community wireless-network map and database for locating Wi-Fi and cellular observations during physical and RF investigations.
Why: Cyberspace search for hosts, services and exposures across the public internet — useful for OSINT, red-team reconnaissance and attack-surface checks. Canonical hub remapped from zoomeye.org (HTTP 521) to zoomeye.ai.
Why: Public malware analysis submissions from the ANY.RUN sandbox — useful for spotting what’s circulating and reviewing related indicators.
Why: BAE Systems threat intelligence newsletter — regular insights from their TI team.
Why: Discovery hub for bug bounty programmes — helps researchers and programme owners find active scopes and opportunities.
Why: US CISA catalogue of free resources and tools spanning guidance, playbooks and programmes for defenders and critical infrastructure operators.
Why: Widely known process-maturity framework that organisations still reference when comparing capability levels alongside cyber-specific maturity models.
Why: Official EU network linking national CSIRTs and CERT-EU — the coordination hub for cross-border incident response, information sharing and mutual support across Europe.
Why: Shared hunting framework that helps teams design detection and hunt workflows in a structured way, useful when building a repeatable threat-hunting practice.
Why: Industry news and analysis that surfaces vulnerability and threat developments for practitioners.
Why: e2e-assure Recon Review — LinkedIn newsletter covering reconnaissance themes and open-source intel.
Why: HP Wolf Security Threat Insights — annual report on malware delivery, browser threats, and endpoint risk themes.
Why: IBM Security video channel for advisories, research briefings and product security updates — remapped from legacy /user/ path.
Why: Companion index of global cyber-threat statistics and trends alongside the live map.
Why: International criteria for evaluating IT product security claims in procurement and assurance.
Why: Live attack dashboard that turns global sensor hits into a simple picture of where activity is rising — handy for quick situational awareness without wading through raw logs.
Why: NCSC listings of verified suppliers and secure products that help buyers choose assured cyber security offerings with clearer confidence in quality and provenance.
Why: NETSCOUT annual threat intelligence report — DDoS, botnet, and network-attack trends from global telemetry.
Why: NSHC ThreatRecon Team on Medium — regular threat research posts and campaign write-ups.
Why: Podcast and resource brand on the human skills of cyber security — communication, leadership and culture for practitioners and leaders.
Why: Live worldwide attack view from SonicWall sensors, useful for spotting surge patterns and giving leaders a quick sense of global threat pressure.
Why: SophosLabs video channel covering malware research, vulnerabilities and defensive tips — a practical watch-list for teams who prefer briefings in short video form.
Why: Deutsche Telekom's European security radar showing live attack traffic, useful when you want a continental view of threat pressure alongside the major US vendor maps.
Why: Community-minded internet security organisation offering threat intelligence, reputation data and research for defenders.
Why: Deutsche Telekom Security’s open-source repositories — tools and detection content useful for SOC and security engineering teams.
Why: Fast-moving cyber news hub useful for situational awareness of newly disclosed vulnerabilities.
Why: Independent tech news covering security incidents and vulnerability disclosures with practical context.
Why: Elections-infrastructure cyber tabletop package (StopRansomware hub). State/local election officials and cyber partners discuss threats to election systems with template objectives, scenario and discussion questions; editable Word version via CISA Exercises email.
Why: Hub for CTEPs that explore physical impacts from cyber vectors (and vice versa). Useful for OT/ICS and critical-infrastructure exercise planners designing convergence discussions beyond pure IT scenarios; contact CISA Exercises for packages.
Why: CISA download library of cybersecurity CTEP situation manuals (ransomware, insider threat, ICS, sector packs for healthcare, water, maritime, local government, etc.). Planners download a DOCX scenario then pair it with CTEP package documents for facilitator/AAR templates.
Why: Electricity-subsector cyber CTEP situation manual (DOCX, July 2024). Grid/utility cyber and operations leads can exercise OT impacts, reliability obligations and multi-party coordination after a cyber attack on electric systems.
Why: Executive/senior-leadership cyber CTEP situation manual (DOCX, Aug 2024). Board-facing discussion injects for decision-making, risk acceptance, external communications and oversight during a major cyber incident—not a technical deep-dive.
Why: Federal DDoS CTEP situation manual (DOCX, Nov 2023). Network defenders and service owners rehearse detection, scrubbing/mitigation choices, public messaging and restoration under sustained denial-of-service pressure.
Why: Sector CTEP for healthcare/public health cyber scenarios (DOCX, Oct 2023). Useful for hospital CISOs and clinical ops to exercise patient-care continuity, clinical system downtime and regulatory notification under cyber attack.
Why: ICS/OT-focused CTEP situation manual (DOCX, Aug 2024). Designed for operators and cyber teams to discuss ICS compromise, safety/process impacts and IT–OT coordination; strong fit for critical-infrastructure tabletops.
Why: IT-sector CTEP situation manual (DOCX, June 2024). Suited to MSPs, cloud and enterprise IT teams exercising cyber incident coordination, customer impact and sector information-sharing during an unfolding attack.
Why: Insider-threat CTEP situation manual (DOCX, Sept 2023). Helps security, HR and legal practise detection, investigation boundaries and containment when a trusted insider abuses access; customisable modules for pre-incident sharing through recovery.
Why: Local-government cyber CTEP situation manual (DOCX, Nov 2023). Built for municipal IT/security and emergency management to exercise ransomware and service disruption against citizen-facing systems and mutual-aid coordination.
Why: Maritime ports cyber CTEP situation manual (DOCX, Nov 2023). Port operators and cyber teams can rehearse OT/IT impacts on cargo operations, vessel scheduling and multi-agency response after a cyber incident.
Why: Open-source software risk CTEP situation manual (DOCX, April 2024). Teams discuss dependency inventory, disclosure of vulnerable components and remediation when open-source libraries or tooling become the incident vector.
Why: Vendor/supply-chain compromise CTEP situation manual (DOCX, Aug 2024). Exercises response when a trusted vendor is the intrusion path—vendor isolation, software integrity checks and customer notification for cyber practitioners.
Why: Water/wastewater cyber CTEP situation manual (DOCX, Nov 2023). Utility operators and ICS security leads practise process disruption, public health messaging and recovery when treatment/SCADA systems are targeted.
Why: Scenario of compromise via unknown Wi-Fi and outdated software. Validates travel/remote working controls, endpoint patch posture and user guidance; short NCSC facilitated discussion with downloadable materials.
Why: Tabletop covering compromised personal devices and business data leakage under BYOD. Helps security, IT and policy owners rehearse MDM/conditional access decisions, wipe vs contain choices and staff communications; NCSC pack for facilitators.
Why: Exercise for periods of elevated national or sector cyber threat. Leadership and cyber teams practise stepping up monitoring, change freezes, remote-access hardening and crisis comms without waiting for an active breach; free NCSC materials.
Why: Tests controls and response when remote/home working drives data compromise risk. Good for validating VPN/zero-trust assumptions, endpoint hygiene and HR/comms playbooks; 60–90 minute NCSC facilitated discussion with downloadable pack.
Why: Scenario where a user grants unauthorised third parties access to sensitive information. Involves cyber, HR and legal in detection, account disablement, evidence handling and breach notification decisions; NCSC tabletop pack.
Why: Practises receiving and handling a vulnerability disclosure on an online system. Security, engineering and comms rehearse triage, patch/mitigation timelines, researcher engagement and public messaging; NCSC facilitator pack.
Why: Tabletop on a stolen mobile used to extract confidential information. Tests device encryption, remote wipe, MFA/session revocation and insider-risk follow-up; suitable for IT, security and staff who handle sensitive data on phones.
Why: Broader supply-chain risk tabletop for products, systems and services from suppliers. Procurement, cyber and business continuity owners discuss assurance, contractual levers and fallback when a critical supplier fails or is attacked.
Why: Exercises organisational response when ransomware hits a supplier and cascades into your operations. Useful for IR leads and business owners to test dependency maps, alternate providers and crisis communications; NCSC pack.
Why: Focused on software suppliers in the estate. Teams walk a supply-chain software attack: inventory of critical components, detection signals, isolation, rebuild and customer impact; NCSC downloadable discussion pack.
Why: NCSC discussion exercise on responding when a third-party software supplier is compromised. Useful for CISOs and IT leads to stress-test vendor dependency, isolation options and customer/stakeholder communications; downloadable exercise pack.
Why: Tabletop on preventing, detecting and responding to threats to leak sensitive information (extortion-style pressure). Brings together cyber, legal, privacy and communications on containment, engagement strategy and notification duties.