Threat reports
Long-form research written by the analysts who ran the engagements it draws on. Headline findings are published in full on each report page — the download is the detail, the working and the data.
- 2
- 3
Annual review48 pages
Threat Landscape 2026
Twelve months of observed activity across the six regions we cover — who is operating, what they want, and how they get in.
Business email compromise overtook ransomware as the highest-loss incident category for the first time.
Median dwell time before detection fell year on year, but time-to-containment did not — the constraint has moved from detection to response capacity.
Written for
CISOs, fraud leads and risk committees at multi-market organisations
Why the findings are public
A report whose conclusions sit entirely behind a form cannot be cited, cannot be linked to and cannot be judged before you hand over an address. Ours are published in full; the download is the methodology, the sample and the data behind them.
Field notes
Shorter pieces on a single technique, written between reports.
Detecting thread hijacking without reading anyone's mail
Header and graph signals that identify an injected reply, without content inspection or the privacy problems it brings.
7 min
What we preserve first, and why the order matters
The evidence acquisition sequence our responders follow in the first hour, and the reasoning behind it.
6 min
p=quarantine is not enforcement
Why a partial DMARC policy provides far less protection than the dashboard suggests, and what the percentage tag actually does.
5 min
How we publish
Everything on this page is written by the analysts who ran the engagements it draws on. Nothing is commissioned, ghostwritten or assembled from other people’s telemetry.
That is the reason there is not more of it. We publish when we have something we have actually observed and are willing to be held to — which is a slower cadence than a content calendar, and a better one for anyone deciding whether to trust the conclusions.
Client data never appears in a report, in aggregate or otherwise, without written sign-off on the exact wording. Where a finding would identify an organisation even in anonymised form, it does not go in.
Corrections
If you find an error in a published report, tell us and we will correct it in place with a dated note. We would rather be right late than wrong quietly.
Get the next one first
Platform customers receive research ahead of publication, with the underlying indicators attached. Everyone else gets it here on the day it ships.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.