Executive Overview: Readiness Is a Decision-Speed Discipline

Critical infrastructure cybersecurity is no longer measured only by whether an organization can prevent intrusion. It is measured by whether leaders can make safe, coordinated, and defensible decisions before a digital incident becomes a physical, regulatory, financial, or public-service crisis.

Verizon analyzed over 22,000 security incidents and 12,195 confirmed data breaches for its 2025 Data Breach Investigations Report. The research found that ransomware appeared in 44% of breaches, while third-party involvement doubled to 30%

For energy, water, healthcare, transportation, manufacturing, telecommunications, and public-sector organizations, those figures represent more than information loss. A cyber incident may interrupt patient care, affect industrial safety, stop production, constrain public services, undermine product quality, or require operations to continue without trusted digital systems.

The operating thesis of this playbook is straightforward: incident readiness reduces the distance between detection, judgment, containment, and safe recovery.

A mature critical infrastructure security strategy does not depend on a generic enterprise plan that assumes every system can be disconnected, reimaged, or restored through the same process. It defines how information technology, operational technology, engineering, safety, legal, risk, communications, suppliers, and executive teams will share evidence and exercise authority under pressure.

The scale of the threat environment increases the urgency for critical infrastructure operators. Microsoft processes more than 100 trillion security signals, blocks 4.5 million net-new malware files, and analyzes 38 million identity-risk detections on an average day, highlighting the volume and speed at which defenders must identify and contain threats.² 

IBM X-Force found that attacks exploiting public-facing applications increased by 44%, vulnerability exploitation contributed to 40% of observed incidents, active ransomware operators increased by nearly 49%, and publicly disclosed ransomware attacks rose 12%

The executive implication is not that critical infrastructure organizations need more alerts. They need a faster, better-governed path from evidence to authorized action.

Why Critical Infrastructure Incident Response Must Unite IT and OT

Traditional incident response planning often separates enterprise technology from industrial operations. That distinction is increasingly difficult to maintain.

Identity platforms, remote-access services, cloud environments, engineering workstations, historians, maintenance systems, original equipment manufacturers, business applications, and managed service providers create dependencies across IT and operational technology security.

When an attacker moves across those dependencies, two response cultures meet.

IT security teams generally prioritize containment, evidence preservation, credential revocation, and system restoration. Operations and engineering teams prioritize human safety, physical process stability, service continuity, equipment protection, and controlled change. Neither priority is wrong, but unmanaged conflict between them can create dangerous hesitation.

Disconnecting a corporate endpoint may be routine. Isolating an engineering workstation, historian, human-machine interface, or industrial network segment may interrupt process visibility, affect a safety dependency, or remove evidence required to understand what the physical process is doing.

The incident command structure must therefore answer three questions before a crisis begins:

  • Who can authorize containment?
  • Which actions are safe for each asset class?
  • What operational outcome must be preserved?

Table 1. Aligning IT and OT Incident Decisions

Decision Area

IT Priority

OT Priority

Readiness Requirement

Incident declaration

Confirm malicious activity

Understand the process and safety impact

Shared severity criteria

Containment

Stop lateral movement

Avoid unsafe operational changes

Preapproved isolation options

Evidence collection

Preserve logs and technical artifacts

Retain process and engineering context

Joint forensic collection plan

Recovery

Restore secure technology services

Return equipment to a safe operating state

Engineering-led validation

Communication

Inform legal, privacy, and customers

Inform operators, regulators, and safety teams

Sector-specific notification matrix

Executive authority

Manage cyber risk

Preserve mission and service continuity

Unified incident command

A unified command model does not remove specialist authority. It creates a defined process through which security, operations, engineering, legal, communications, suppliers, and executive leaders can make decisions without negotiating responsibilities during the incident. In critical infrastructure environments, the goal is not only fast containment. It is safe, authorized containment that protects essential services and operational outcomes. 

The Readiness Gap: Where Response Plans Break Under Pressure

The most damaging incident readiness gaps are rarely caused by the complete absence of a written plan. They emerge when the plan has not been converted into executable choices.

An organization may know whom to contact but not who can authorize an operational shutdown. It may have backups but no trusted method for restoring industrial configurations. It may collect threat intelligence but lack a process for turning external signals into hunt priorities, segmentation changes, supplier restrictions, or tabletop scenarios.

It may also depend on a technology provider that controls logs, credentials, recovery media, or engineering support but has never participated in an exercise.

Verizon found that exploitation of vulnerabilities increased 34% year over year, while breaches involving third parties reached 30%.¹ These findings matter because critical infrastructure incident response frequently extends beyond the organization’s legal and technical boundaries.

A response plan that excludes original equipment manufacturers, cloud platforms, telecommunications providers, system integrators, managed security providers, and engineering partners may fail when the evidence or recovery dependency sits with one of those organizations.

CyberTech Intelligence Observation: Readiness Debt Grows Where Ownership Is Ambiguous

According to CyberTech Intelligence research and analysis, readiness debt accumulates wherever decision ownership remains unclear.

Every unmanaged remote connection, untested escalation route, unidentified dependency, undocumented recovery sequence, and unresolved exercise finding increases the number of decisions that must be made during a crisis.

The objective is not to predict every possible incident. It is to reduce the number of high-consequence choices that remain undefined when time, evidence, and operational options are limited.

Critical infrastructure leaders should evaluate every major scenario through four questions:

  1. Who owns the decision?
  2. What evidence is required before acting?
  3. Which action is safe, proportionate, and reversible?
  4. Which essential service or operational outcome must be preserved?

The CyberTech Intelligence Critical Infrastructure Incident Readiness Framework™

CyberTech Intelligence defines incident readiness as the organization’s ability to convert an uncertain cyber signal into a safe, authorized, and measurable operational response before essential services are materially disrupted.

The CyberTech Intelligence Critical Infrastructure Incident Readiness Framework™ assesses readiness across six connected dimensions: mission criticality, threat awareness, decision authority, containment safety, recovery assurance, and executive accountability.

The framework is designed for environments where enterprise IT, operational technology, industrial control systems, physical processes, identities, suppliers, and public-service obligations operate as one risk system.

The framework should be used as a repeatable CyberTech Intelligence model for evaluating readiness across critical infrastructure sectors. It helps leaders move beyond plan documentation and assess whether the organization can preserve mission-critical outcomes, authorize safe containment, validate recovery, and prove executive accountability under pressure. 

A weakness in one dimension can delay the entire response. Strong detection provides limited value when teams cannot authorize containment. A detailed recovery plan offers limited assurance when restored configurations cannot be trusted. Experienced security personnel may still struggle when operational leaders, legal teams, regulators, and suppliers have not agreed on decision rights.

Table 2. CyberTech Intelligence Critical Infrastructure Incident Readiness Framework™

Readiness Dimension

Core Leadership Question

Required Operating Capability

Evidence of Readiness

Mission Criticality

Which services and processes must remain available or fail safely?

Critical-service mapping and dependency analysis

Approved hierarchy of essential services and minimum operating conditions

Threat Awareness

Can teams recognize activity before it creates operational impact?

Integrated IT, OT, identity, cloud, and supplier telemetry

Detection coverage mapped to credible threat scenarios

Decision Authority

Who can declare, isolate, shut down, disclose, or restore?

Defined command structure, thresholds, and preauthorized rights

Named owners, deputies, approval paths, and alternate contacts

Containment Safety

Can attacker movement be restricted without creating unsafe conditions?

Asset-specific containment options designed by security and engineering

Tested isolation procedures and safety validation requirements

Recovery Assurance

Can services be restored from trusted systems, identities, data, and configurations?

Clean recovery environments, integrity checks, and dependency sequencing

Tested recovery procedures with operational sign-off

Executive Accountability

Can leadership demonstrate that readiness gaps are being reduced?

Metrics, exercises, after-action governance, and board reporting

Named owners, deadlines, closure evidence, and accepted residual risk

Recommended visual treatment: Convert this framework into a branded six-part CyberTech Intelligence visual showing Mission Criticality, Threat Awareness, Decision Authority, Containment Safety, Recovery Assurance, and Executive Accountability as connected readiness dimensions. 

How the Framework Operates

Identify mission-critical services

Map IT, OT, identity, supplier, and physical dependencies.

Define credible attack scenarios and operational consequences.

Assign decision authority and escalation thresholds.

Develop safe containment and recovery options.

Test decisions through cyber tabletop exercises

Measure gaps, assign ownership, and validate closure.

This sequence differs from a conventional incident response lifecycle because it begins before an alert is generated. Critical infrastructure readiness starts by defining what the organization must preserve, how essential services depend on digital and physical systems, and which actions remain safe when the technical picture is incomplete.

CyberTech Intelligence Observation: Readiness Fails at Operational Handoffs

The most consequential readiness failures often occur during the handoff between technical detection and operational authority.

A security operations center may detect suspicious access, but plant teams may not know whether isolation will interrupt a safety process. Engineering teams may recognize abnormal behavior, while executive and legal teams lack enough evidence to declare a reportable incident. Recovery teams may possess backups, but operations leaders may not trust the restored identities or configurations.

These are failures of decision architecture rather than failures of technology alone.

Table 3. High-Risk Operational Handoffs

Operational Handoff

Readiness Risk

Required Control

SOC to OT operations

Alert lacks process context

Joint validation criteria and escalation thresholds

OT operations to executive command

Technical impact is not translated into mission consequence

Shared incident severity model

Executive command to legal and regulatory teams

Reporting is delayed by incomplete evidence

Sector-specific notification matrix

Security team to supplier

Evidence or technical assistance is unavailable

Contractual response obligations and tested contacts

Recovery team to operations

Systems are restored without process validation

Engineering-led acceptance and return-to-service procedure

This handoff model should be treated as a readiness diagnostic. If a handoff lacks clear evidence, decision authority, supplier support, or operational validation, the organization may be forced to negotiate response responsibilities during the incident. That delay can increase safety, service continuity, regulatory, and public-trust risk. 

CyberTech Intelligence Perspective: Readiness Must Be Designed Around Consequence

CyberTech Intelligence’s perspective is that critical infrastructure incident readiness should not be judged by the length of the response plan, the number of security tools deployed, or the frequency of compliance reviews. It should be judged by whether the organization can preserve essential services while making safe, evidence-based decisions under pressure.

Most conventional incident response programs are organized around technical events. They begin with an alert, move through investigation and containment, and conclude with recovery. That sequence remains important, but it is incomplete for critical infrastructure because a technical action can create a physical, operational, or public-service consequence.

Readiness Is an Enterprise Decision Architecture

CyberTech Intelligence observes that the decisive control during a critical infrastructure incident is often not a product. It is the organization’s decision architecture: the people, authority, evidence, thresholds, and operational safeguards that determine how the organization acts.

A decision-ready organization can answer, before an incident occurs:

  • Which services must continue under degraded conditions?
  • Which systems can be isolated without creating an unsafe process state?
  • Who has the authority to interrupt production or suspend a public service?
  • What evidence is required before that decision?
  • How will teams operate when identities, communications, or monitoring systems cannot be trusted?
  • What conditions must be satisfied before a system returns to service?

When these questions remain unresolved, technical teams may detect an intrusion but still be unable to contain it confidently.

The Readiness Gap Is Usually Between Teams, Not Inside Tools

Critical infrastructure organizations have invested in endpoint protection, identity controls, network monitoring, backups, threat intelligence, and operational technology security. The persistent weakness is that these capabilities are frequently managed by separate teams with different priorities, terminology, and escalation models.

Table 4. Where Fragmentation Becomes Operational Risk

Readiness Gap

Incident Consequence

Leadership Impact

IT and OT use different severity models

The same activity is assessed differently

Declaration and containment are delayed

Security lacks process context

Technical anomalies cannot be connected to physical impact

Actions may be too aggressive or too cautious

Operations lack threat context

Suspicious behavior is treated as an equipment issue

Malicious activity remains active longer

Suppliers sit outside the response structure

Logs, credentials, or engineering support are unavailable

The organization loses control of response timing

Recovery ownership is fragmented

Systems return before integrity is validated

Operations may resume with an unresolved compromise

The strategic requirement is not simply greater visibility. It is coordinated operational judgment across cybersecurity, engineering, operations, legal, communications, procurement, suppliers, and executive leadership.

Four Outcomes Every Readiness Program Must Protect

Safety preservation: Containment and recovery actions must not introduce unacceptable risk to employees, patients, passengers, communities, equipment, or the environment.

Essential-service continuity: Leaders should know which services must continue, which can operate at reduced capacity, which can move to manual processes, and which must be stopped when trust is lost.

Decision integrity: Executives need reliable evidence even when the environment is partially compromised. Incident command must define how conflicting evidence will be evaluated and who can authorize action when complete certainty is impossible.

Recovery trust: Availability does not prove that recovery is complete. Restored systems must be validated for identity integrity, configuration accuracy, software trust, data consistency, and safe process behavior.

CyberTech Intelligence Observation: Response Options Narrow Before the Crisis Becomes Visible

The most dangerous stage of a critical infrastructure intrusion may occur before the organization experiences an obvious outage.

During this period, an attacker may be collecting credentials, studying process dependencies, accessing remote-management pathways, testing privileges, or compromising recovery systems. The organization may still appear operational, but its future response options are already narrowing.

Threat intelligence, identity security, operational technology monitoring, third-party access governance, and incident response planning should therefore operate as one readiness system. Together, they determine whether hostile activity can be identified while safe containment options remain available.

CyberTech Intelligence Position

CyberTech Intelligence’s position is that incident readiness is becoming an executive measure of operational endurance.

The strongest organizations will be those that can detect early, decide quickly, contain safely, communicate credibly, and recover with evidence that the operating environment can be trusted.

Building a Sector-Specific Incident Response Plan

A critical infrastructure incident response plan should be organized around service consequences rather than malware categories.

The first step is to identify the services that create safety, economic, regulatory, or public-trust consequences. The organization should then map the systems, identities, suppliers, communications channels, industrial processes, and physical dependencies supporting each service.

For every critical service, the plan should define the conditions under which the organization will:

  • Isolate an asset or network segment
  • Disable external or third-party access
  • Move to manual operations
  • Degrade or suspend a service
  • Activate alternate communications
  • Invoke crisis management
  • Notify regulators or government agencies
  • Request external technical support
  • Begin recovery and return-to-service validation

Table 5. Sector-Specific Incident Readiness Priorities

Sector

Primary Operational Concern

Readiness Priority

Energy and Utilities

Grid stability and uninterrupted service

Safe isolation, manual operations, and supplier coordination

Water and Wastewater

Treatment integrity and public safety

Remote-access control and process validation

Healthcare

Patient care and clinical continuity

Downtime procedures, identity recovery, and data assessment

Manufacturing

Worker safety, production, and product quality

Engineering recovery and production-line segmentation

Transportation

Passenger safety and service continuity

Resilient communications and dependency mapping

Government

Public services and citizen trust

Cross-agency coordination and evidence preservation

Telecommunications

Network availability and cascading customer impact

Redundant command routes and supplier escalation

A sector-specific plan should connect operational consequences with decision ownership, evidence requirements, containment choices, communications responsibilities, and restoration conditions.

Turning Threat Intelligence into Operational Decisions

Threat intelligence creates value only when it changes a decision.

Critical infrastructure teams may receive sector alerts, vulnerability information, adversary profiles, government advisories, and vendor intelligence. Those inputs do not automatically improve cyber resilience.

Decision-ready threat intelligence should produce at least one of four outcomes:

  1. A new or revised detection hypothesis
  2. A review of exposed access, assets, or privileges
  3. A containment or hardening decision
  4. A scenario for a cyber tabletop exercise

Threat Intelligence Decision Flow

External intelligence signal

Relevant asset, identity, supplier, or process identified.

Potential operational consequence assessed.

Detection, control, or response action assigned

Implementation verified through monitoring or exercise.

The strategic question is not how many reports the organization receives. It is whether leadership can show which intelligence signals changed a hunt, control, supplier decision, segmentation rule, patching priority, or exercise.

Intelligence that remains inside a portal improves awareness. Intelligence connected to named assets, operational processes, identities, suppliers, owners, and response actions improves readiness. Critical infrastructure leaders should measure threat intelligence by the decisions it changes, not by the volume of reports received. 

Identity Security as a Critical Infrastructure Control

Identity is the connective tissue between enterprise systems and industrial operations.

Engineers, operators, administrators, contractors, original equipment manufacturers, service accounts, machine identities, and remote-support platforms can all create trusted pathways into critical systems.

CrowdStrike reported thatAI-enabled adversary activity rose by 89%, cloud-conscious intrusions increased 37%, and state-nexus activity rose 266% in its 2026 Global Threat Report.⁴

This pattern shows why operational technology security cannot rely only on malware detection. An attacker using legitimate credentials, administrative utilities, cloud sessions, remote-management tools, or trusted supplier access may not introduce conventional malware during the early stages of an intrusion.

Critical infrastructure identity security should include:

  • Privileged access management
  • Multifactor authentication
  • Time-bound access
  • Remote-session approval and recording
  • Shared-account elimination
  • Service-account governance
  • Emergency access procedures
  • Third-party identity lifecycle management
  • Machine and nonhuman identity oversight
  • Rapid identity recovery after compromise

Identity security is not only about preventing stolen credentials. It is about reducing the business and operational impact of trusted-access abuse, protecting maintenance workflows, limiting ransomware entry paths, and ensuring that response teams retain trusted administrative access during a crisis. For critical infrastructure operators, identity recovery is also an incident readiness requirement because containment and restoration depend on trusted access. 

Designing Cyber Tabletop Exercises That Expose Real Gaps

A cyber tabletop exercise should expose decision friction rather than demonstrate that participants can follow a prepared script.

An effective exercise begins with an uncertain signal. It introduces incomplete evidence, conflicting priorities, third-party dependencies, operational impact, regulatory pressure, and executive communication requirements.

Participants should decide when to:

  • Declare a significant incident
  • Isolate enterprise or industrial assets
  • Suspend remote access
  • Move to manual operations
  • Engage specialist suppliers
  • Notify regulators
  • Communicate with customers or the public
  • Begin recovery
  • Accept residual operational risk

Table 6. Critical Infrastructure Tabletop Exercise Design

Exercise Stage

Scenario Inject

Decision Tested

Evidence Captured

Detection

Unusual remote access and abnormal process activity

When to declare an incident

Threshold and decision owner

Escalation

Engineering visibility becomes unreliable

Who controls containment

IT-OT authority and safety review

Operational Impact

Service degradation or production interruption

Which services take priority

Mission impact criteria

External Pressure

Regulator, customer, or media inquiry

What can be disclosed and when

Notification workflow

Supplier Dependency

Critical provider cannot supply logs or support

How dependencies are managed

Contractual and escalation route

Recovery

Backups exist, but configuration integrity is uncertain

When restoration is safe

Validation and executive sign-off

Each exercise should produce named owners, due dates, and evidence of closure. A high-risk finding should remain visible to leadership until it is remediated, transferred, accepted, or replaced by a compensating control.

The better measure is not how many exercises were conducted. It is whether those exercises changed authority structures, technical controls, supplier obligations, recovery procedures, and executive understanding.

Measuring Incident Readiness at the Executive Level

Executive reporting should show whether the organization can make and execute high-consequence decisions. It should not focus mainly on the number of tools deployed, plans written, or exercises completed.

Table 7. CyberTech Intelligence Executive Incident Readiness Measures

Measure

What It Evaluates

Leadership Relevance

Decision Cycle Time

Time from validated signal to authorized action

Shows whether command structures operate under pressure

Safe Containment Coverage

Critical assets with approved isolation options

Indicates whether teams can act without creating unsafe conditions

Identity Recovery Readiness

Ability to restore trusted administrative access

Shows whether the response can continue after identity compromise

Third-Party Response Coverage

Critical suppliers with tested contacts and obligations

Exposes dependence on external organizations

Recovery Validation Coverage

Critical services restored through tested procedures

Demonstrates whether backups translate into safe operations

Exercise Issue Closure

High-risk findings resolved by the agreed deadline

Shows whether exercises produce operational improvements

Regulatory Evidence Readiness

Availability of validated incident records and reporting inputs

Supports CIRCIA compliance and sector-specific disclosure

Manual Operations Readiness

Essential functions with tested degraded procedures

Measures the ability to preserve services during digital disruption

These measures should be interpreted together.

A short detection time provides limited assurance if leaders still require hours to approve containment. High backup completion rates offer limited confidence when engineering teams have not validated configurations. A completed exercise provides little value when findings remain unresolved.

The purpose of executive measurement is to reveal where uncertainty is concentrated and where investment can reduce delayed, unsafe, or inconsistent decisions. The strongest readiness scorecards do not simply report activity. They show whether the organization can decide, contain, recover, communicate, and prove progress under pressure. 

Strategic Priorities for Critical Infrastructure Leaders

Establish One Incident Command Structure

Define one command structure across IT, OT, engineering, safety, legal, communications, and executive leadership. Specialist teams retain technical authority, but escalation and decision ownership should be shared and documented.

Prioritize Mission Consequences

The response program should begin with the services the organization must preserve, not the security tools it owns. Critical-service mapping should guide detection priorities, segmentation, supplier reviews, tabletop exercises, and recovery sequencing.

Build Safe Containment Options

Every critical asset class should have preapproved containment choices. These may include account suspension, remote-access termination, network isolation, application restriction, manual operation, or controlled shutdown.

Govern Third-Party Dependencies

Contracts should clarify the availability of evidence, notification timing, technical support, forensic cooperation, credential revocation, recovery assistance, and participation in exercises. Contact routes should be tested rather than assumed.

Treat Recovery as an Integrity Problem

Recovery is not complete when a system becomes available. Identities, software, configurations, data, controllers, and engineering files must be trusted before the service returns to normal operation.

Connect CIRCIA Compliance to Incident Operations

CIRCIA compliance preparation should be integrated into incident classification, evidence collection, legal review, communications, and executive escalation. Regulatory reporting should be an output of disciplined response operations rather than a separate administrative process.

Strategic Takeaway: From Preparedness to Operational Endurance

Cyber resilience is not the ability to absorb unlimited disruption. It is the ability to preserve essential outcomes while detecting, containing, investigating, communicating, and recovering from an incident.

That requires:

  • One incident command structure across IT and OT
  • Sector-specific incident response planning
  • Threat intelligence connected to decisions
  • Identity security that limits trusted-access abuse
  • Cyber tabletop exercises that test operational reality
  • Recovery validation based on safe operating conditions
  • Executive metrics that reveal unresolved readiness gaps

CyberTech Intelligence’s position is that incident readiness should be funded and managed as an enterprise operating capability.

The most prepared organizations will not necessarily be those with the longest incident response plans. They will be those that have reduced uncertainty around authority, dependencies, containment, recovery, disclosure, and executive accountability before an adversary forces those decisions. That is the shift from documented preparedness to operational endurance. 

Use the Research Scoreboard to Strengthen Critical Infrastructure Cybersecurity Investment

The scoreboard in Critical Infrastructure Cybersecurity 2026: Incident Readiness, Threat Intelligence, and Cyber Resilience, published on CyberTech Intelligence, translates incident response planning, operational technology security, threat intelligence maturity, identity security gaps, recovery validation, regulatory preparedness, supplier dependencies, and cyber exercise performance into measurable executive security signals.

It gives CISOs, CIOs, operational technology leaders, incident response teams, security operations teams, infrastructure operators, compliance leaders, and board-facing risk teams a clearer way to connect incident readiness, OT security, threat intelligence, identity security, supplier preparedness, recovery validation, cyber tabletop exercises, and regulatory evidence with service continuity, operational risk reduction, and board-level accountability. 

Read the full research report: Critical Infrastructure Cybersecurity 2026: Incident Readiness, Operational Resilience, and Threat Intelligence

Request a Critical Infrastructure Incident Readiness Assessment

Critical infrastructure leaders need more than a static incident response plan. They need confidence that technical teams, operational leaders, suppliers, legal stakeholders, and executives can make coordinated decisions when evidence is incomplete and essential services are at risk.

CyberTech Intelligence helps organizations assess incident readiness gaps, align IT and OT decision authority, develop sector-specific cyber tabletop exercises, strengthen executive measurement, and turn threat intelligence into practical response priorities.

A Critical Infrastructure Incident Readiness Assessment can help leadership evaluate mission-critical service dependencies, IT-OT escalation paths, safe containment options, supplier response coverage, recovery validation, regulatory evidence readiness, and executive decision authority.

Request a Critical Infrastructure Incident Readiness Assessment to understand where readiness gaps remain, which decisions need clearer ownership, and what evidence supports operational endurance during a high-consequence cyber incident.

References

  1. Verizon, 2025 Data Breach Investigations Report, May 2025
    https://www.verizon.com/about/news/2025-data-breach-investigations-report
  2. Microsoft, Microsoft Digital Defense Report 2025, October 2025
    https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/bade/documents/products-and-services/en-us/security/Microsoft-Digital-Defense-Report-2025-v5-21Nov25.pdf
  3. IBM, X-Force Threat Intelligence Index 2026, February 2026
    https://uk.newsroom.ibm.com/ibm-2026-x-force-threat-index
  4. CrowdStrike, 2026 Global Threat Report, February 2026
    https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/