Security Report

Awesome Annual Security Reports

Source: Awesome Annual Security Reports
The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. https://github.com/jacobdjwilson/awesome-annual-security-reports/

Definition: The cybersecurity landscape is constantly evolving, making it hard for CIOs, CISOs, and security leaders to keep up. They’re flooded with annual reports from research consultancies, industry working groups, non-profits, and government agencies, and sifting through marketing material to find actionable insights is a major challenge. This list aims to cut through the noise by providing a vendor-neutral resource for the latest security trends, tools, and partnerships. It curates information from trusted sources, making it easier for security leaders to make informed decisions.

Disclaimer: The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. There are a variety of different business models and drivers that would cause information to be put behind a paywall, I would like to respect those companies and individuals. Consult the original authors for licensing of any report content.

Limitations: This is not a repository for project-specific documents such as white papers, intelligence reports, technical specifications, or standards. While all user-submitted uploads or report requests are welcome, we should draw a box around this awesome list.

Accessibility When possible, all reports will be sourced from their original authors and uploaded to Hybrid Analysis via GitHub action to provide an added level of confidence. The resulting analysis link will be included in the PDF commit notes. Additionally, all PDF reports will be converted to Markdown using AI, based on the AI Prompts defined in this repository.

Acknowledgement: I would like to give recognition for other works that inspired this collection. Richard Stiennon produces an annual, comprehensive industry analysis that surpasses the scope of this list and deserves attention. Additionally, Rick Howard‘s cyber cannon list of must-read books is an invaluable resource, catering to both leadership and practitioner levels within the field.


  • ATIS Enhanced 5G and Zero Trust Cloud 2025

    This ATIS report explains how zero trust architecture can secure 5G cloud and operational environments as networks shift from operator-owned infrastructure to complex multi-vendor and hyperscale cloud deployments. It emphasizes continuous monitoring, micro-segmentation, IAM, SIEM/SOAR, eBPF, AI/ML, and shared standards work across 3GPP, ETSI, O-RAN, CISA, NIST, MITRE FiGHT, and GSMA MoTIF to address threats…

  • ASD Cyber Threat Report 2025

    Australia’s Annual Cyber Threat Report 2024–25 shows a sharper threat environment, with more hotline calls, more incidents, rising financial losses, and a growing focus on state-sponsored activity against critical infrastructure, telecommunications, and logistics. The report also highlights escalating ransomware, credential theft, phishing, DDoS, and edge-device exploitation, while urging stronger resilience measures such as MFA, logging,…

  • Chainalysis Crypto Crime Report 2025

    Chainalysis’ 2025 Crypto Crime Report shows that crypto crime became more diversified and professionalized in 2024, with stablecoins dominating illicit volume while ransomware, scams, stolen funds, sanctions activity, and organized crime all shifted in response to enforcement and market changes. The report highlights major themes such as North Korean hacking, Huione Guarantee’s role in laundering…

  • Waterfall OT Cyber Threat Report 2025

    Waterfall’s OT Cyber Threat Report 2025 shows that physical-consequence OT attacks continued to rise in impact, with a 146% increase in affected sites and 76 incidents in 2024. The report highlights growing nation-state activity, persistent ransomware pressure, and new ICS-capable malware such as FrostyGoop, IOControl, and Fuxnet, with #Sandworm #VoltTyphoon #SaltTyphoon #FrostyGoop #IOControl #Fuxnet #CrowdStrike…

  • Vanta State of Trust Report 2025 Title

    Vanta’s third State of Trust report shows that AI is accelerating risk faster than most organizations can govern it, while budgets, staffing, and compliance time remain stuck. The report highlights rising vendor breaches, growing trust demands, and the rapid adoption of agentic AI—alongside major gaps in control, readiness, and oversight. #Vanta #agenticAI #AI

  • Bitsight Security Digitization and the Global Supply Chain 2025

    Bitsight’s 2025 report shows that global digital supply chains are vast, deeply interconnected, and concentrated around a relatively small set of critical providers that often sit behind major industries and markets. It also finds that provider organizations generally have a larger attack surface and weaker security posture than consumers, while some high-market-share providers still have…

  • Atbay InsurSec Report 2025

    At-Bay’s 2025 InsurSec Report shows that cyber claims rose sharply in 2024, driven by more ransomware, growing third-party losses, and persistent financial fraud. The report highlights major incidents such as the CDK Global outage, the expansion of ransomware groups, and the growing impact of email-based deception. #AtBay #CDKGlobal #MOVEit #LockBit #BlackBasta #BlackSuit

  • Truesec Threat Intelligence Report 2025

    Truesec’s 2025 Threat Intelligence Report shows that cybersecurity investments are helping some large Nordic enterprises reduce ransomware impact, while attackers shift toward smaller organizations, identity-based intrusions, data theft, and AI-assisted social engineering. The report also highlights major law-enforcement disruptions of criminal infrastructure, escalating geopolitical cyber sabotage, and the growing use of ransomware-as-a-service by groups such…

  • Europool Internet Organized Crime Threat Assessment 2025

    Europol’s IOCTA 2025 shows how stolen data has become a core commodity in cybercrime, fueling fraud, account takeovers, extortion, and access brokering across dark web forums and encrypted channels. The report highlights the growing impact of infostealers, ClickFix, vishing, and generative AI, while also noting major law enforcement disruptions to Lumma, LabHost, Cracked, and Nulled.…

  • DigiCert UltraDDoS Biannual Report 2025

    DigiCert’s UltraDDoS Protect report shows a sharp decline in DDoS activity in the first half of 2025, with attackers increasingly favoring short, low-volume, single-target campaigns after enforcement actions such as Operation PowerOff disrupted major DDoS-for-hire services. Financial Services was the most targeted industry, while Saudi Arabia, the United States, and Sweden saw the highest attack…

  • White House Cybersecurity Posture of the United States 2025

    The 2025 Annual Threat Assessment describes a broad and intensifying threat environment in which cyber, criminal, terrorist, and state actors all pressure U.S. security, infrastructure, and economic stability. It highlights major risks from China, Russia, Iran, and North Korea, along with transnational criminal networks and terrorist groups such as ISIS and al-Qa‘ida, and notes how…

  • ContrastSecurity Software Under Siege 2025

    Contrast Security’s 2025 report shows application-layer attacks and exploitable vulnerabilities are growing faster than most organizations can defend against, with attackers exploiting flaws in just days while remediation often takes months. It highlights the need for runtime application defense and better vulnerability prioritization as traditional tools like WAF and EDR leave major blind spots. #ContrastSecurity…

  • Akamai Fraud and Abuse Report 2025

    Akamai’s Fraud and Abuse Report 2025 shows AI bots rapidly reshaping fraud, scraping, and abuse across industries, with traffic up 300% year over year and commerce, publishing, and healthcare among the most affected sectors. The report highlights how tools like FraudGPT, WormGPT, GPTBot, ChatGPT-User, Bytespider, and Meta-ExternalAgent are driving new detection and governance challenges, while…

  • Cyble Global Threat Landscape 2025

    Cyble’s H1 2025 report shows a sharp rise in ransomware, supply chain attacks, and more sophisticated hacktivism, with CL0P, Akira, and Qilin driving a large share of incidents. North America, especially the United States, remained the main target, while industrial and critical infrastructure sectors faced increasingly coordinated threats. #CL0P #Akira #Qilin #MOVEit #GoAnywhereMFT #NHS #ZPentest…

  • Censys State of the Internet 2025

    Censys’ 2025 State of the Internet Report analyzes adversary infrastructure at Internet scale, showing how malware, C2 services, open directories, and residential proxy networks persist, shift, and evade detection over time. The report highlights Cobalt Strike, Viper, Sliver, PlugX, and PolarEdge as major examples of how threat actors build and maintain infrastructure across global hosting…

  • Black Duck State of Embedded Software Quality and Safety 2025

    Black Duck’s 2025 embedded software report shows a sector being reshaped by rapid AI adoption, weak governance, and the rise of SBOMs as a commercial requirement. It also highlights a growing gap between management optimism and engineering reality, alongside a shift toward memory-safe languages and stricter supply-chain and compliance expectations. #BlackDuck #SBOM #Censuswide #MISRA #CERTC…

  • Cybersecurity Market Report Q4 2025

    The report projects the global cybersecurity market will reach $1 trillion annually by 2031, driven by expanding digital exposure across businesses, governments, IoT, industrial systems, and other connected platforms. It highlights major spending growth, the rising influence of AI, and the widening scope of cybersecurity beyond traditional IT to protect physical and cyber-physical environments. #CybersecurityVentures…

  • Salt Future of Agentic AI Report 2025

    Salt Security’s report shows that agentic AI adoption is rising quickly, but consumer trust has not kept pace, especially when personal data and chatbot interactions are involved. It emphasizes that APIs are the backbone of AI agent functionality and the main security weak point, making strong governance, monitoring, and access control essential for the future…

  • LastPass APAC Regional Report 2025

    LastPass’s 2025 APAC Regional Report shows the region facing high volumes of cyber espionage and financially motivated attacks, with manufacturing, Japan, stolen credentials, and Australia standing out as major targets. It also highlights the growing role of Akira, LUMMAC, Salt Typhoon, and credential-stuffing campaigns, alongside emerging risks from AI-driven scams and infrastructure abuse. #Lastpass #APAC…

  • Houlihan Lokey How AI Is Reshaping Digital Engineering 2025

    This report explains how AI is transforming digital engineering by reshaping software development, talent needs, pricing models, and delivery structures across global services firms. It also shows that buyers and providers are shifting toward outcome-based, AI-enabled, and consulting-led models as demand rises across key industries like financial services, healthcare, automotive, and life sciences. #HoulihanLokey #Globant…


More Report: https://www.hendryadrian.com/category/security-report