Affiliate disclosure

Book titles on this page link to Amazon. As an Amazon Associate, DataField.Dev earns from qualifying purchases — at no additional cost to you.

Bibliography

Sources are grouped by confidence tier, following the book's citation-honesty policy (see _style-bible.md §7). Tier 1 are works we are confident exist — NIST publications, MITRE ATT&CK, CIS Controls, OWASP, RFCs, vendor and government reports; Tier 2 are real ideas whose exact publication we have not pinned down; Tier 3 are constructed teaching examples, labeled where they appear.

Tier 1 — Verified canonical sources (standards, frameworks, primary docs)

Tier 2 — Attributed (specifics unverified)

  • (ISC)² / ISC2, Cybersecurity Workforce Study (published annually) — most-cited source for the security staffing gap; precise figures vary by year/methodology and are used here only as a range.
  • Altheide, C., & Carvey, H., Digital Forensics with Open Source Tools, Syngress.
  • Anderson, R., Security Engineering, 3rd ed., Wiley (book is verifiable; specific claims about under-patching economics should be checked against the text).
  • Anti-Phishing Working Group (APWG) trend reports — phishing-volume and technique data (exact figures Tier 2).
  • Bianco, D. J., "The Pyramid of Pain" (Enterprise Detection & Response blog, ~2013) — the canonical articulation of the pyramid-of-pain model; widely cited, exact figures/wording attributed to the blog post.
  • Bird, J., DevSecOps and related O'Reilly reports on integrating security into CI/CD (practitioner guidance; specifics and tool recommendations vary by edition).
  • BlueBorne Bluetooth vulnerability class (2017) — vendor and research retrospectives vary; treat exact details as attributed, not pinned.
  • Brotby, W. K., Information Security Governance: A Practical Development and Implementation Approach. (Practitioner text on aligning and governing a security program; treated as guidance, not authority.)
  • Carrier, B., File System Forensic Analysis, Addison-Wesley (filesystem internals, NTFS $MFT, deleted-file recovery).
  • Carvey, H., Windows Forensic Analysis and Windows Registry Forensics, Syngress (Windows artifacts: registry, event logs).
  • CISA/NCSC and partners, Guidelines for Secure AI System Development and related joint AI-security guidance (issuer/title pattern; verify the current document before citing).
  • Colonial Pipeline ~75 bitcoin ransom and partial DOJ recovery — widely reported; stated as reported, exact figures not over-specified.
  • Community Sysmon configuration files (widely used open configurations) for endpoint telemetry — referenced as a category; vet any specific config before deployment.
  • Conference talks and engineering retrospectives on the December 2021 Log4Shell response (timelines and specifics vary by account; cite reputable, well-sourced sessions).
  • Conference talks and write-ups on SAML service-provider validation flaws (signature/audience bypass class); specific talks vary by source — choose a reputable, well-sourced account.
  • Cross-industry MTTD/MTTR/coverage "benchmark" figures circulated by vendors and surveys — used in the chapter only as illustrative, directional comparisons (e.g., "~8-hour peer MTTD"). These are soft numbers; the chapter explicitly flags them as approximate and they should be verified against a named source before being presented as fact.
  • Current cloud-native security references (e.g., books on Kubernetes security) for workload-identity and service-account-token handling (pick a current, well-reviewed edition; the platform evolves quickly).
  • Davidoff, S., & Ham, J., Network Forensics: Tracking Hackers through Cyberspace, Prentice Hall.
  • Director-level cyber-oversight guidance of the kind issued by board associations (e.g., NACD/ISA cyber-risk handbooks for directors). (Attributed generally; the audience-side view of a board presentation. Emphases evolve by edition — not pinned to a specific figure.)
  • Discovering-firm public technical analyses of SUNBURST (the behavioral-detection / anomalous-MFA-enrollment discovery narrative) — read for the lesson; specific technical figures attributed, not pinned.
  • Ebbinghaus, H., foundational work on the forgetting curve and spaced repetition (1885); cited as the established memory-decay principle.
  • Eric Zimmerman's forensic tools and documentation (Windows artifact parsing) — widely used in the community.
  • Established CTF and hands-on practice platforms, and deliberately vulnerable practice VMs/applications published by security-training projects (specific platforms come and go; choose a reputable, currently active one that provides the targets).
  • Fogg, B. J., Tiny Habits and the Fogg Behavior Model (B = MAP); Tier 1 for the model itself, Tier 2 for its security-awareness application.
  • Freund, J., & Jones, J., Measuring and Managing Information Risk: A FAIR Approach, Butterworth-Heinemann — the book-length treatment of the FAIR model for quantifying risk; the rigorous version of the risk-vs-appetite / burn-down story. The FAIR Institute (fairinstitute.org) hosts related free material (vendor-adjacent community; read critically).
  • General business/product-analytics literature on "actionable vs. vanity metrics" (the distinction predates and is broader than security) — sharpens §36.1's core discriminator; the principle transfers cleanly though the sources are outside security.
  • General explanations of the base-rate fallacy as it applies to rare-event detection (standard probability result; many sources).
  • General industry observation that boards fund risk-and-return narratives over technical detail, and that security leaders commonly fail at executive translation (widely reported in CISO practitioner literature and conference talks; not a single citable statistic).
  • General industry reporting that financial motivation dominates breaches and that credential theft/phishing are leading vectors (as summarized in successive DBIR editions).
  • General industry reporting that weak or unsalted password hashing (MD5/SHA-1) has amplified the impact of several large credential breaches (pattern summarized across multiple public post-mortems, not attributed to a single named incident here).
  • General pattern of large healthcare data breaches over the past decade (months-long undetected access, external discovery, logging gaps inflating notification scope, HHS "wall of shame" listings) — informs Case Study 2; not a single named event.
  • General project-management / GRC references on the RACI matrix and its anti-patterns (the concept is standard; exact source varies).
  • General reporting that open-source components constitute the large majority of code in typical applications and that transitive dependencies dominate dependency trees (widely cited in software-composition surveys; specifics vary).
  • Gilman, E., & Barth, D., Zero Trust Networks: Building Secure Systems in Untrusted Networks, O'Reilly (practitioner build reference; specifics vary by edition).
  • Google, CSP Evaluator (csp-evaluator.withgoogle.com) — tool that flags weak CSP directives such as 'unsafe-inline'.
  • Google/USENIX Site Reliability Engineering literature on blameless postmortems and sustainable on-call rotations — cross-disciplinary practice transferred to the SOC.
  • Hadnagy, C., Social Engineering: The Science of Human Hacking — defender-relevant treatment of human manipulation.
  • Hardy, N., "The Confused Deputy" — the classic articulation that a service must check the caller's authority, not its own (widely cited; multiple accessible retellings exist).
  • Have I Been Pwned (haveibeenpwned.com) as a public index illustrating the scale of leaked credentials and credential-stuffing exposure.
  • Hayden, L., IT Security Metrics. (Choosing and presenting metrics for an executive audience; supports the board-metrics slide.)
  • Hubbard, D., & Seiersen, R., How to Measure Anything in Cybersecurity Risk, Wiley (a widely cited argument for quantitative over qualitative risk; treat its specific claims as the authors' position).
  • Independent retrospectives and timelines of the SolarWinds campaign from major incident-response firms and the affected vendor; specifics vary by retelling, so anchored on the CISA account above.
  • Industry and press retrospectives on publicly exposed cloud storage ("open S3 bucket") data-exposure incidents (the general pattern behind Case Study 2; specifics vary by source and should be verified against the primary report before citing a figure).
  • Industry phishing-simulation benchmark reports (click-rate-by-sector studies) — used only for RANGES of realistic click/report rates; methodologies vary widely, so all specific percentages are treated as Tier 2 and never invented.
  • Industry reporting (as summarized in successive DBIR editions and similar surveys) that leaked credentials, misconfiguration, and exposed secrets are among the most common breach causes — described qualitatively; no precise figure invented here.
  • Industry reporting and incident analyses describing privilege escalation from a low-privilege foothold to domain admin via credential harvesting and lateral movement as a common ransomware pattern (specific efficacy and frequency figures vary by source; treat platform-mitigation efficacy claims as unverified specifics).
  • Industry reporting and successive DBIR editions indicating that exploitation of known, unpatched vulnerabilities on internet-facing assets remains a leading breach pattern (general finding; exact figures vary by year and source).
  • Industry reporting and vendor analyses that business email compromise produces greater aggregate financial losses than ransomware (as summarized in successive IC3 reports and industry surveys); do not cite a precise figure without the primary report.
  • Industry reporting on the 2022 MFA-fatigue ("push bombing") breaches of large technology firms (specifics vary by account; used to motivate number matching and phishing-resistant MFA).
  • Industry reporting that command-and-control beaconing and slow ("low-and-slow") exfiltration are common across major intrusions, and that DNS is a frequently abused covert channel (as summarized across vendor threat reports and ATT&CK technique documentation).
  • Industry reporting that default/weak credentials and unpatched edge devices are among the most common footholds for compromise (as summarized across successive DBIR editions and CISA advisories).
  • Industry reporting that expired certificates and TLS misconfigurations (not algorithm breaks) cause most real-world TLS outages and findings.
  • Industry reporting that high-impact intrusions increasingly involve "living off the land" — stolen credentials and built-in tools rather than malware — and so evade signature-only detection (as summarized across vendor and incident-response reports).
  • Industry reporting that injection and XSS classes have remained on successive OWASP Top 10 editions for ~two decades (general, as summarized across OWASP releases; no single precise statistic claimed).
  • Industry reporting that insider-driven financial fraud commonly exploits weak separation of duties and accumulated (creeping) privileges (general pattern, as summarized across fraud and audit literature).
  • Industry reporting that known, patchable vulnerabilities and default/weak configurations (rather than zero-days) account for a large share of real intrusions (as summarized across successive Verizon DBIR editions and CISA advisories) — no precise figure asserted.
  • Industry reporting that leaked credentials in source repositories and misconfigured cloud infrastructure are among the leading causes of cloud breaches (as summarized across successive DBIR editions and cloud-security reports).
  • Industry reporting that modern applications are predominantly assembled from third-party and transitive dependencies, making software composition analysis essential (as summarized across vendor and OWASP guidance).
  • Industry reporting that rogue access points and evil twins remain common physical-access vectors in retail and enterprise environments (as summarized in successive security reports).
  • Industry reporting that stolen credentials and phishing are among the most common breach causes (as summarized in successive DBIR editions).
  • Industry reporting that the majority of significant breaches involve lateral movement from an initial foothold (as summarized across successive incident-investigation reports such as the Verizon DBIR).
  • Industry reporting that the SolarWinds Orion compromise affected on the order of thousands of organizations and a number of U.S. agencies (exact counts vary by source).
  • Industry reporting that third-party/vendor access and stale credentials are recurring root causes of healthcare and enterprise ransomware (pattern summarized across public breach reporting; no single figure pinned).
  • Industry surveys reporting that non-human/machine identities outnumber human identities by roughly 10:1 to 50:1 in cloud-heavy environments (the exact multiple varies by source; the order of magnitude is consistent).
  • Industry workforce studies repeatedly reporting a persistent cybersecurity talent gap (more open roles than qualified people); direction is durable across years, but specific figures vary by source and should not be pinned to a single number.
  • Industry/practitioner literature on risk-based alerting (RBA) and detection engineering as a remedy for alert fatigue (widely discussed in vendor and SOC writing; treat specific figures as illustrative).
  • Jaquith, A., Security Metrics: Replacing Fear, Uncertainty, and Doubt, Addison-Wesley — the classic professional argument for measuring outcomes over activity and against vanity metrics; foundational to the modern discipline. A well-known practitioner text; treat specific figures as illustrative.
  • Kindervag, J., No More Chewy Centers: Introducing the Zero Trust Model of Information Security (originating analyst research, 2010 onward; exact publication details vary).
  • Luttgens, J. T., Pepe, M., & Mandia, K., Incident Response & Computer Forensics, McGraw-Hill.
  • Major-provider security "Learning Center" educational articles on DDoS, SYN floods, and reflection/amplification (e.g., Cloudflare/Akamai) — accurate on fundamentals; vendor educational material, read for concepts not product claims.
  • Malware-Traffic-Analysis.net — a community library of constructed/teaching PCAPs and exercises (excellent for lab skill-building; not a formal citation).
  • Mandiant / Google Cloud threat-intelligence reporting (e.g., the M-Trends annual report); named reputable source, but treat specific year-over-year figures as reported, not independently verified here.
  • Maslach, C., & Leiter, M. P., burnout research (e.g., The Truth About Burnout and the Areas of Worklife model) — the established framing of burnout as an organizational phenomenon; the SOC-specific application is the author's.
  • Microsoft Sysinternals Sysmon documentation — confident it exists; cited at the level of capability (process/network/image-load logging) without pinning a version.
  • MITRE, Caldera and the adversary-emulation/purple-teaming tooling ecosystem — open-source operationalization of the purple-team loop (use only in authorized environments).
  • MITRE, TTP-Based Hunting and ATT&CK-driven detection guidance (behavior-over-indicator detection; specifics vary by publication).
  • Murdoch, D., Blue Team Handbook: Incident Response Edition — a practitioner field reference.
  • Murdoch, D., Blue Team Handbook: SOC, SIEM, and Threat Hunting — widely used practical SOC field guide.
  • NIST and academic work on synthetic/AI-generated content detection and provenance (a fast-moving area; detailed claims should be treated as Tier 2 pending verification of the specific publication).
  • NIST guidance on network security and segmentation/zero-trust networking (e.g., the SP 800-series on virtualization/network security and SP 800-207 on zero trust) — cited for framing internal trust boundaries; specific document numbers to be confirmed before final compile.
  • Open FAIR / FAIR (Factor Analysis of Information Risk) as a named method for quantifying risk in dollars (Freund, J., & Jones, J., Measuring and Managing Information Risk: A FAIR Approach). (Cited as a real, named quantification approach that strengthens an ALE-based business case; specific figures not relied upon.)
  • Open-source PAM and secrets-management project documentation (e.g., HashiCorp Vault) as illustrations of vaulting, brokering, and short-lived credentials (one vendor's model among several).
  • OWASP, Security by Design Principles (community-maintained restatement of least privilege, fail-safe defaults, defense in depth; exact wording varies).
  • PortSwigger, Web Security Academy (portswigger.net/web-security) — free interactive labs on injection, XSS, CSRF, SSRF (teaches attacks for defensive understanding; use only in its sandbox).
  • Post-incident technical analyses of the SolarWinds / Sunburst compromise from multiple vendor and government sources (the public facts are well established; technical details and attribution specifics vary by report). The control-by-control "what would have prevented/detected it" framing in Case Study 2 is this chapter's defensive interpretation, not a claim about SolarWinds' internal decisions.
  • Public DMARC-report analyzers and "spoofability" checkers (reputable, well-reviewed services) used for hands-on practice on owned domains.
  • Public reporting of the first practical SHA-1 collision ("SHAttered", 2017) demonstrating that SHA-1 is unsafe for collision-dependent uses such as signatures (specifics per the published research and reputable accounts).
  • Public retrospectives on SaaS support-account / over-privileged-access breaches in which one compromised internal or support credential exposed many customers' data (the pattern behind Case Study 2; specifics vary by incident and reporting — attribute carefully and treat figures cautiously).
  • Public technical reporting on the Triton/Trisis malware targeting a safety instrumented system (2017) — vendor and researcher analyses; specifics treated carefully and at public-fact level only.
  • Published post-incident retrospectives of CI/CD secret-harvesting and leaked-cloud-key breaches, illustrating the secret-harvesting cascade pattern (the class of incident is well documented; specifics vary by retelling — favor primary vendor/CISA post-mortems).
  • Published regulatory enforcement actions and breach post-mortems (HHS OCR resolution summaries; EU data-protection-authority decisions; FTC actions) as sources of "compliant but breached" lessons — read the specific published case before citing any detail.
  • Red Canary, Atomic Red Team (github.com/redcanaryco/atomic-red-team) — ATT&CK-mapped safe test library.
  • Reference-monitor concept (always-invoked, tamper-proof, verifiable) — originating in the Anderson report on computer security (1972) and standard in security-architecture texts (used here at the level of the concept, not a specific edition/figure).
  • Regulatory moves to ban universal default passwords on consumer connected devices and require basic security properties before sale (several jurisdictions; specifics vary — attribute carefully and verify the regime before citing a particular law).
  • Reporting and retrospectives on the 2021 Colonial Pipeline ransomware incident, used as the generalized model behind the Meridian tabletop (specifics vary by source; the recovered-ransom detail and the single-credential initial access are widely reported).
  • Reporting on real deepfake-enabled fraud incidents, including the synthetic-CFO video-call wire-fraud cases (the mechanism is well established; specific amounts and companies vary by retelling — treat as illustrative unless independently verified).
  • Reporting on real deepfake-fraud incidents (2023–2024) in which finance employees were tricked by deepfaked voice/video calls into authorizing multi-million-dollar transfers (well-sourced press coverage; specifics vary by retelling).
  • Reporting on SIM-swap account-takeover cases against banking and cryptocurrency accounts (illustrates the weakness of phone-number-based possession).
  • Reporting that cloud-security and detection/blue-team skills are among the most in-demand in the field (durable industry direction, not a precise statistic).
  • Reputable post-incident analyses of identity-provider token-theft / token-forgery breaches illustrating that SSO concentrates risk at the IdP (treat single-source specifics cautiously; do not cite precise unverified figures).
  • Reputable retrospectives of the Target (2013, HVAC-vendor + flat-network) and NotPetya (2017, supply-chain + destructive blast radius) incidents — used as optional "Your Turn" cases.
  • Retrospective accounts of the 1988 Morris Worm as the first internet-scale security incident (specifics vary by source).
  • Retrospective accounts of the 2008 Kaminsky DNS cache-poisoning vulnerability disclosure and the resulting industry response (source-port randomization; accelerated DNSSEC adoption); specifics vary by source.
  • Retrospective accounts of the WannaCry and NotPetya (2017) outbreaks spreading via SMBv1 (specifics and attribution vary by source); used to motivate disabling SMBv1 / attack-surface reduction.
  • Retrospective accounts of TLS/SSL downgrade and padding-oracle attacks (POODLE, BEAST, FREAK, Logjam, Sweet32, ROBOT, Lucky 13) — read well-sourced write-ups; technical specifics vary by retelling.
  • SANS / E-ISAC analysis of the December 2015 Ukraine power-grid attack (widely cited public post-incident report; specifics summarized consistently across reputable accounts).
  • SANS DFIR posters and cheat sheets (Windows Forensic Analysis; Hunt Evil) — widely used quick references for artifacts and event IDs.
  • SANS Institute, annual SOC survey and SOC-management resources — practitioner data on SOC staffing, automation, tooling, and burnout (framework Tier 1; specific figures Tier 2).
  • SANS reading-room papers and SOC survey material on alert fatigue, false-positive rates, and SOC staffing (attributed; exact statistics vary by edition and year).
  • SANS Security Awareness, Security Awareness Maturity Model and the annual Security Awareness Report — framework Tier 1; specific benchmark figures Tier 2 (directional, not precise).
  • SANS security policy templates / policy library (useful as structural templates; some samples are mislabeled across tiers, which is itself instructive).
  • Sector information-sharing (ISAC) and vendor threat reports for financial services; quality varies by source, used as illustrative of sector-specific threat intelligence.
  • Sector ISAC threat-sharing reporting (e.g., a financial-services ISAC), membership-dependent.
  • Security Onion and SiLK/nfdump as widely used open-source NSM/flow tooling (project documentation; specifics vary by version).
  • Security-operations adage "two kinds of organizations: those that patch and those that get patched" (widely repeated; origin uncertain — used as an epigraph only, not a sourced claim).
  • Sommer, R., & Paxson, V., "Outside the Closed World: On Using Machine Learning for Network Intrusion Detection," IEEE Symposium on Security and Privacy, 2010 (venue/year as commonly cited; confirm before formal citation).
  • Sqrrl, "A Framework for Cyber Threat Hunting" and the associated Hunting Maturity Model — industry white paper popularizing hypothesis-driven hunting; specific maturity levels widely reproduced.
  • Stillions, R., "The DML (Detection Maturity Level) Model" (blog) — complementary model on the abstraction level of detections.
  • SwiftOnSecurity, sysmon-config (github.com/SwiftOnSecurity/sysmon-config) — widely used Sysmon configuration baseline.
  • The "diceware" passphrase method and its entropy rationale (widely described; word-list and per-word entropy figures referenced approximately).
  • The broader SANS 504/508 incident-handling and digital-forensics course body of knowledge (attributed; specific materials vary).
  • The Cryptopals Crypto Challenges (cryptopals.com) as a hands-on resource for understanding cryptographic misuse (ECB detection, bad randomness, missing integrity); community-maintained, technically sound.
  • The DFIR Report (thedfirreport.com) — public, ATT&CK-mapped intrusion analyses with detection guidance.
  • The Emerging Threats (ET) open Suricata/Snort ruleset (community-maintained; specific rules evolve over time).
  • The FAIR Institute (fairinstitute.org) — community articles and reference material on quantitative risk analysis.
  • The Mirai botnet (2016) and its record-setting DDoS attacks built from default-credentialed IoT devices — widely reported; the academic measurement study "Understanding the Mirai Botnet" (USENIX Security 2017) is the primary technical source. Treat any specific device-count or bandwidth figure as approximate and cite the study.
  • The Volatility Foundation documentation (memory forensics framework).
  • The widely repeated maxim "amateurs hack systems, professionals hack people" (used as the epigraph); attribution is uncertain and contested — treated as folklore, not a sourced quotation.
  • The ~76-day Equifax undetected-exfiltration window and the expired-certificate detail — from official investigations and reporting; stated at public-fact level.
  • U.S. CISA/FBI joint advisories and congressional testimony on the May 2021 Colonial Pipeline ransomware incident and the DarkSide ransomware-as-a-service operation (initial access via a VPN account lacking MFA; ransom paid, partially recovered; pipeline shut ~5 days). Public-record facts; some operational internals not public and flagged as such.
  • Vanhoef, M., & Ronen, E., "Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd" (2019) — read a well-sourced summary; implementation flaws were subsequently patched.
  • Vendor and CERT threat-intelligence reporting on ransomware-as-a-service affiliate models and initial access broker markets (ecosystem details vary by source; attribute carefully, do not treat one report's figures as canonical).
  • Vendor next-generation-firewall and NAC architecture guides (capabilities described generically; specific product claims vary and should be verified against NIST guidance).
  • Vendor security-blog guidance on specific cloud features (S3 Block Public Access, service control policies, IMDSv2); cloud features change, so any specific feature detail should be confirmed against current provider documentation.
  • Vendor WAF and web-security engineering blogs (e.g., Cloudflare, major cloud providers) — current web-attack and WAF-tuning writeups; vendor perspective, read critically.
  • Verizon, Data Breach Investigations Report (DBIR) — third-party and supply chain breach patterns (cite the pattern, not a precise figure that shifts year to year).
  • Widely reported figure of ~18,000 organizations downloading the trojanized SolarWinds Orion update (reported by SolarWinds) — stated as reported.
  • Widely reported observation that secrets pushed to public code repositories are scraped and abused by automated tooling within minutes (as summarized across security-vendor and platform reporting).
  • WireGuard protocol whitepaper and documentation (wireguard.com) — specific performance/design claims attributed to the project's own materials.
  • Zetter, K., Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon, Crown — a journalistic reconstruction of the Stuxnet operation (well-sourced narrative, not a primary technical document).

Tier 3 — Illustrative / constructed (labeled in text)

  • "BorderTrust Financial" (Exercise 32) — a constructed org for the CTF challenge.
  • "Folio" social platform and its 120-million-account password-dump analysis (Case Study 2) — a constructed composite, assembled from the documented general pattern of real megabreaches rather than any single named company.
  • Aldridge Robotics, "R. Vance," "Marcus Webb," and the insider data-theft investigation (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported insider/trade-secret cases.
  • All artifact excerpts, log lines, hashes (labeled illustrative placeholders), and timelines in this chapter — constructed for teaching.
  • All bluekit code outputs in this chapter (defender_checkpoint.py, example-01..03, exercise-solutions.py) — hand-traced, illustrative, never executed.
  • All configuration excerpts, audit outputs, IP addresses (documentation ranges only), and .example domains — illustrative.
  • All hashes, keys, certificates, IVs, nonces, and identifiers shown in code and figures — illustrative documentation placeholders, never real values or real computed digests.
  • All illustrative scan outputs, exception registers, CVSS/EPSS values in example tables (except the real CVE-2021-44228 figures), and SLA numbers — constructed for teaching.
  • All illustrative scanner findings, pipeline YAML, policy-as-code rules, CVE-in-context examples, and metrics in this chapter — constructed for teaching and labeled as illustrative (real CVE IDs such as CVE-2021-44228 / Log4Shell are cited only where confidently known and used illustratively in policy examples).
  • All in-chapter campaign numbers (e.g., the 400-recipient retail-division simulation: 48 clicked, 96 reported) — illustrative figures for teaching the metrics.
  • All policy-decision logs, access requests, and microsegmentation flows shown in code and exercises — illustrative, using documentation IP ranges and example identities.
  • All sample authentication logs, hashes, IP addresses (documentation ranges), and the illustrative SHA-1 prefix ABF0F — constructed for teaching; the hash digest is fake and not verified.
  • All sample BSSIDs, SSIDs, passphrases, IP ranges (documentation/RFC1918/TEST-NET), and the wifiaudit.py output — constructed/illustrative, never real credentials or live targets.
  • All sample flow records, Zeek log lines, beacon timestamps, and storage figures throughout the chapter — illustrative values, hand-traced, not measured.
  • All sample IP addresses, log lines, signature IDs (9000xxx), and numeric figures throughout the chapter — illustrative values using documentation ranges only.
  • All sample logs, alerts, certificate inventories, and placeholder secret values (AKIA...EXAMPLE, ghp_EXAMPLE...) — illustrative and constructed; never real credentials.
  • All sample logs, detection rules, account inventories, and the bluekit/pam.py output — constructed and hand-traced; documentation values only.
  • All sample logs, IP addresses (documentation/RFC 1918 ranges), firewall rulesets, and traffic figures — illustrative and constructed.
  • All sample logs, the crypto-inventory tables, and the resilience-score figures throughout the chapter — illustrative, with documentation-range IPs (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24).
  • All sample/illustrative log lines, alert volumes, false-positive rates, and query results in this chapter — constructed for teaching.
  • All SBOM excerpts, questionnaire scores, log lines, and contract-clause text in the chapter — illustrative, using documentation values only.
  • All staffing/SLA, escalation-routing, build-vs-buy scoring, and purple-team coverage figures in the code/ examples — illustrative and hand-traced; never executed.
  • Brightwater Health Systems and the eighteen-day double-extortion campaign, all logs, timelines, and the deepfake-CFO call (Case Study 2) — a constructed teaching scenario whose patterns mirror widely reported real-world ransomware tradecraft.
  • Brightwater Logistics and the deepfake-CFO incident (Case Study 2) — a constructed teaching scenario, grounded in the general pattern of widely reported deepfake-fraud cases.
  • Cedar Hollow Water District (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported small-utility incidents.
  • CIS Controls v8 control NUMBERS (4, 7, 2, 10, 8) are mapped from memory of the v8 control set — high confidence but spot-check the exact numbering before publishing the crosswalk in key-takeaways.md.
  • Colonial Pipeline initial access via a single legacy VPN account without MFA, password in a breach dataset; ransomware affected IT (not OT) and Colonial proactively shut the pipeline — stated per public reporting; confirm phrasing against CISA/company statements.
  • CorePoint Systems (Case Study 1) — a constructed core-banking vendor for teaching.
  • CVE-2017-5638 is the Apache Struts 2 RCE associated with the Equifax breach (CONFIDENT at public-fact level); confirm the exact disclosure month (March 2017) against NVD.
  • CVE-2021-44228 (Log4Shell): CVSS 10.0 Critical, disclosed December 2021 (CONFIDENT). The CSRB report title/year ("Review of the December 2021 Log4j Event", 2022) should be confirmed.
  • Eastfield State University (Case Study 2) — a constructed teaching scenario; the breach shape (stale federated account plus loose SAML assertion validation) reflects a real, recurring class of incident, but all specifics, logs, names, and figures are invented for teaching.
  • Equifax exposure figure (~147 million people) and the ~76-day undetected window: widely reported and in official reports; confirm exact numbers against the GAO/congressional reports.
  • Harborview Construction and Coastal Steel, the $1.2M BEC wire-fraud incident, and all associated figures and headers — a constructed teaching scenario informed by the general pattern of reported BEC incidents (Case Study 2).
  • HelixCare (Case Study 2) — a constructed health-tech SaaS teaching scenario; the tenant counts, log excerpts, and figures are illustrative, informed by the general pattern of reported over-privileged-access breaches but tied to no specific real company.
  • Lakeshore Regional Health (Case Study 2) and its 600,000-patient data breach — a constructed teaching scenario, informed by the general pattern of reported healthcare breaches.
  • Lakeshore Regional Health (Case Study 2) and its account-takeover incident — a constructed teaching scenario, informed by the general pattern of reported healthcare account-takeover incidents.
  • Lakeshore Regional Health and its full-disk-encryption rollout, device counts, wave metrics, and incidents (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported lost-device health-data breaches.
  • Lakeshore Regional Health System (Case Study 2) — a constructed teaching scenario depicting a silent risk-acceptance failure, informed by the general pattern of reported healthcare PHI breaches; no real institution or incident is depicted.
  • Lakeside Health Network (Case Study 2) — a constructed teaching scenario informed by the general, widely-reported pattern of healthcare ransomware via unowned/stale vendor access; all figures (9-day outage, costs) are illustrative.
  • Lakeside Regional Health (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported insider accounts-payable fraud.
  • Lakeside State University (Case Study 2) and its credential-based intrusion, anomaly alert, and detection telemetry — a constructed teaching scenario, informed by the general pattern of reported research-network intrusions.
  • Lumadyn Health (Case Study 2) and its public-bucket exposure, escalation chain, and figures — a constructed teaching scenario informed by the general pattern of reported public-storage incidents.
  • Lumen Forge and its 200 GB exfiltration via cloud bucket and DNS tunneling, all hosts, baselines, and figures (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported IP-theft and low-and-slow exfiltration incidents.
  • Meridian Regional Bank and all its personnel, figures, and incidents — a constructed teaching scenario.
  • Meridian Regional Bank branch-wireless redesign (Case Study 1) — a constructed teaching scenario; all configurations, branch counts, and figures are illustrative.
  • Meridian Regional Bank online-banking portal review and all its findings, code, logs, and personnel — a constructed teaching scenario.
  • Meridian Regional Bank — its AD/Entra hybrid environment, the orphaned-contractor finding, the eight-week identity-governance cleanup, and all account names, counts, and access-review reports — a constructed teaching scenario.
  • Meridian Regional Bank — its enterprise risk assessment, register, appetite statement, personnel, and all SLE/ARO/ALE figures (DDoS, credential attack, etc.) are constructed teaching scenarios with illustrative numbers.
  • Meridian Regional Bank — its network, addresses, firewall rulesets, IDS signatures, the branch-jack penetration-test finding, and all personnel — a constructed teaching scenario.
  • Meridian Regional Bank — the hard-coded AWS backup key discovered on a contractor's laptop, the svc-statements over-privileged service account, the secrets-management discovery scan, and the nine-rule secrets-management standard — all a constructed teaching scenario.
  • Meridian Regional Bank's AWS footprint, the posture review, all CSPM figures, ACLs, IAM policies, security-group rules, and CloudTrail events in this chapter and Case Study 1 — a constructed teaching scenario.
  • Meridian Regional Bank's network-monitoring deployment, the C2 beaconing hunt, all addresses, beacon scores, and the cdn-sync.example C2 (Case Study 1) — a constructed teaching scenario.
  • Meridian Regional Bank's security awareness program, personnel, simulation results, and all figures (Case Study 1) — a constructed teaching scenario.
  • Meridian Regional Bank's TLS estate, the forgotten marketing microsite, the audit, and all figures/grades (Case Study 1) — a constructed teaching scenario.
  • Meridian Regional Bank, its board Audit Committee, the Q1 metrics pack, the four named incidents (phishing/creds, malware, data egress, admin login) with their timestamps, the coverage counts (220 servers / 48 admin accounts / 60 critical systems), the maturity table, and all figures in this chapter and Case Study 1 — a constructed teaching scenario; the MTTD/MTTR/coverage/maturity numbers are illustrative.
  • Meridian Regional Bank, its branch IoT, its ~200 ATMs, the lobby-camera incident, and all per-device logs, IP addresses, and figures in this chapter and Case Study 1 — a constructed teaching scenario.
  • Meridian Regional Bank, its building management system (BuildControl controllers, the facilities HMI/SCADA, the vendor remote-access path), Sam Whitfield's engagement, and all associated figures — a constructed teaching scenario.
  • Meridian Regional Bank, its encryption standard, cardholder-data-environment design, and all personnel and figures (Case Study 1) — a constructed teaching scenario.
  • Meridian Regional Bank, its loan-origination pipeline, security team (Okafor/Whitfield/Vasquez et al.), figures, and the secure-pipeline build narrative (Case Study 1) — a constructed teaching scenario.
  • Meridian Regional Bank, its personnel (Okafor, Vasquez, Whitfield, Reyes, etc.), and all its vendor scenarios, figures, and findings — a constructed teaching scenario.
  • Meridian Regional Bank, its team, documents, policy set, RACI, and the examination scenario — a constructed teaching scenario.
  • Meridian Regional Bank, the "LoanFlow" loan-origination application, and all associated personnel, code, figures, and findings — a constructed teaching scenario.
  • MidStream Credit Union (Exercise 12) — a constructed organization for the build-vs-buy analysis exercise.
  • No CVE IDs asserted in this chapter (WannaCry/NotPetya referenced by name/behavior, not by CVE). All standard document numbers above are real to the best of the author's knowledge; where uncertain, the chapter text describes them generically.
  • No precise dollar amounts, exact victim lists, or exploit details fabricated. Where a number is approximate it is labeled "~" / "reported".
  • Northbridge State University and the graduate-student "Dani" server compromise (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported unhardened-host/internet-exposed-SSH compromises; no real institution depicted.
  • NorthField Outfitters retail rogue-AP incident (Case Study 2) — a constructed teaching scenario, informed by the documented pattern of real retail wireless intrusions; all logs, addresses, and figures are illustrative.
  • NorthFlow Analytics (Case Study 2) and its Log4Shell incident specifics — a constructed teaching scenario built on the real, widely-documented shape of the global Log4Shell response.
  • Northgate Industrial and its breach timeline (Case Study 2) — a constructed teaching scenario whose pattern (a known, KEV-listed, internet-facing vulnerability left unpatched under a drifted exception) mirrors several well-documented real breaches, but whose specific figures and entities are invented.
  • NorthLine Commerce (Case Study 2) and all its facts, certificates, and the 4.2-million-record breach — a constructed teaching scenario, informed by the general pattern of reported compliant-but-breached incidents and leaked-API-key breaches.
  • NorthRiver Logistics, its all-green pre-breach dashboard, its breach narrative, and the reconstructed "honest scorecard" in Case Study 2 — a fully constructed teaching scenario; the company is fictional, while the failure mode (activity-only dashboards hiding real risk) is a real, recurring pattern.
  • Northvale Health System (Case Study 2), its SOC, advisory AA-2026-HC-09, and all indicators/figures — a constructed teaching scenario informed by the general pattern of reported healthcare ransomware intrusions.
  • Northwind Analytics (Case Study 2) — a constructed SaaS company and CI/CD secret-harvesting incident, a composite informed by the general (well-documented) pattern of pipeline/secret breaches.
  • Northwind Health Systems (Case Study 2), CISO Ravi Desai, the two board presentations, and the ransomware outcome — a constructed teaching scenario, informed by the general pattern of reported healthcare ransomware incidents and unsegmented medical-device risk; not a specific real organization or breach.
  • Northwind Logistics (Case Study 2) and its breach timeline — a constructed teaching scenario, informed by the general pattern of reported lateral-movement breaches.
  • Northwind Logistics (Case Study 2) — a constructed Orion-customer defender for analyzing SolarWinds from the blue-team seat; all internal telemetry, scores, and timelines are illustrative.
  • Pinewood Regional Medical Center (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported healthcare/flat-network intrusions; no specific real incident is depicted.
  • Pinnacle Ridge Construction and the $312,000 BEC/vishing incident (Case Study 2) — a constructed teaching scenario, informed by the general pattern of widely reported BEC losses; no specific real incident.
  • Renata Cabrera and her career-change path (Case Study 2) — a constructed teaching scenario informed by the general pattern of reported career-changer entries into GRC.
  • ShopVerse (Case Study 2) e-commerce SQL-injection breach — a constructed teaching scenario, informed by the general pattern of reported web-application breaches; no real company, data, or exploit reproduced.
  • SolarWinds attribution to a Russian state-sponsored group (publicly associated with the SVR) and the ~18,000 download figure — stated as publicly reported/attributed, not as independently verified here.
  • SP 800-167 title is given as "Guide to Application Whitelisting" — confident the SP number and topic are correct; the historical title uses "whitelisting." Verify exact current title/revision.
  • SP 800-40 cited as Rev. 4 with the patch-management-planning title — confident; confirm the revision number at compile.
  • StreamHarbor (Case Study 2) — a constructed consumer-streaming-service scenario, informed by the general pattern of reported credential-stuffing/account-takeover waves.
  • Tellaro Components (Case Study 2) — a constructed teaching scenario, informed by the general pattern of reported manufacturing-sector ransomware intrusions; all hosts, accounts, timestamps, and events are illustrative.
  • The "misattributed intrusion" CTF scenario (Exercise 29) — constructed for teaching.
  • The "two intrusions at a manufacturer" War Story (§2.2) — a constructed composite illustrating how motivation shapes behavior.
  • The "war story" of the CISO whose all-green deck collapsed after a third-party breach (§36.5) — a constructed, representative vignette, labeled illustrative.
  • The CISSP_MIN_YEARS = 5 threshold and all CPE credit values in the code examples — illustrative numbers, not official requirements; confirm with the issuing body.
  • The constructed war stories in §40.2 and §40.4 (the vendor-agent telemetry near-miss; the "stop trying to fix it, tell me where we have it" Log4Shell moment) — illustrative, labeled.
  • The defender's reading of SolarWinds in Case Study 2 presents the campaign analytically; the high-level facts are from public reporting (Tier 1/2 above), but the framing, tables, and any rounded characterizations are constructed for teaching and avoid claiming non-public detail.
  • The insurer war story in §10.3 — a constructed, representative vignette.
  • The peer-institution breach referenced in Case Study 1 — a constructed composite.
  • The reconstructed Mirai per-device egress logs and target/edge telemetry in Case Study 2 — illustrative reconstructions for teaching; the underlying event is real (see Tier 1/2), the specific log lines are not.
  • The SolarWinds/Sunburst behavioral details used in worked examples are described generically and at a defensive level; specific Meridian instantiations are constructed.
  • The water-utility scan/RTU-crash "War Story" (§33.4) and the small-utility flat-network scenario (Exercise 23) — constructed composites informed by the general pattern of reported small-utility OT incidents.
  • Theo Brandt, Marcus Reyes, and all Meridian Regional Bank personnel, dialogue, and figures (Case Study 1) — a constructed teaching scenario.
  • Vantage Logistics (Case Study 2) — a constructed analytical failure case; the burnout-to-breach pattern reflects a common reported failure mode but the company, people, and incident are invented for teaching.