Security Resources

Curated links to authoritative security frameworks, guidelines, and tools

These are the resources I actually use and recommend. Official frameworks, government guidelines, and trusted industry standards โ€” no affiliate links, no sponsors, just useful stuff.

๐Ÿ›๏ธ Frameworks & Standards

๐Ÿ“˜

NIST Cybersecurity Framework (CSF)

The gold standard for organizing security programs. Covers Identify, Protect, Detect, Respond, and Recover. Works for any organization size.

Free Framework Enterprise
๐Ÿ“—

NIST SP 800-63B โ€” Digital Identity Guidelines

The definitive source on password policy. If your organization still requires 90-day password changes, show them this document.

Free Passwords Authentication
๐Ÿ›ก๏ธ

CIS Critical Security Controls

18 prioritized security controls. Implementation Groups (IGs) help you focus on what matters for your organization's size and risk level.

Free Controls Prioritized
๐Ÿ”ง

CIS Benchmarks

Detailed hardening guides for operating systems, cloud platforms, network devices, and applications. Specific, actionable, and widely respected.

Free (registration) Hardening Configuration
๐ŸŽฏ

NIST SP 800-207 โ€” Zero Trust Architecture

The authoritative guide to Zero Trust. Essential reading as organizations move beyond perimeter-based security.

Free Zero Trust Architecture

๐Ÿข Government Resources

๐Ÿ‡บ๐Ÿ‡ธ

CISA Cybersecurity Best Practices

Practical guidance from the U.S. Cybersecurity and Infrastructure Security Agency. Great starting point for SMBs.

Free Best Practices SMB-friendly
โš ๏ธ

CISA Known Exploited Vulnerabilities (KEV)

The vulnerabilities actually being exploited in the wild. If you can only patch some things, patch these first.

Free Vulnerabilities Patching Priority
๐Ÿ“Š

FBI Internet Crime Complaint Center (IC3)

Annual reports with real data on cybercrime trends, losses by attack type, and emerging threats. Eye-opening statistics for awareness training.

Free Reports Statistics
๐Ÿ‡ช๐Ÿ‡บ

ENISA (EU Agency for Cybersecurity)

European perspective on cybersecurity. Threat landscapes, good practices, and sector-specific guidance.

Free EU Reports
๐Ÿ“Š

ENISA Threat Landscape

Annual report on the top cyber threats in the EU. Data-driven analysis of attack trends, threat actors, and emerging risks. Essential for risk assessments.

Free Threat Intel Annual Report
๐Ÿข

ENISA Supply Chain Security

Guidelines for securing software and hardware supply chains. Increasingly critical after SolarWinds, Log4j, and similar incidents.

Free Supply Chain Third-Party Risk
โ˜๏ธ

ENISA Cloud Security Guide for SMEs

Practical cloud security guidance tailored for small and medium enterprises. Risk assessment, provider selection, and security controls.

Free Cloud SMB-friendly
โš–๏ธ

NIS2 Directive Resources

EU's updated Network and Information Security directive. Broader scope than NIS1, stricter requirements. Mandatory for many sectors by October 2024.

Free Compliance EU Law
๐Ÿšจ

ENISA Incident Management Guide

Step-by-step guidance for building incident response capabilities. Detection, analysis, containment, and lessons learned.

Free Incident Response CSIRT

๐Ÿ” Tools & References

๐Ÿ”

Have I Been Pwned

Check if your email or password has appeared in data breaches. Also offers an API for checking passwords during registration.

Free Breach Check API Available
๐Ÿ”‘

FIDO Alliance โ€” Passkeys

Everything about passkeys โ€” the passwordless future. Implementation guides, user experience research, and adoption resources.

Free Passkeys FIDO2
๐Ÿ“

MITRE ATT&CK

Knowledge base of adversary tactics and techniques. Essential for threat modeling, detection engineering, and red team exercises.

Free Threat Intel Detection
๐Ÿ“š

OWASP (Open Web Application Security Project)

Web and application security resources. The OWASP Top 10 is essential knowledge for anyone building or securing web apps.

Free Web Security AppSec

๐Ÿ“– Learning & Training

๐ŸŽ“

SANS Reading Room & Resources

Thousands of free whitepapers, research, and practical guides. The paid training is excellent too, but the free resources are gold.

Free (resources) Research Training
๐Ÿ›ก๏ธ

CISA Secure Our World

Simple, clear guidance for basic security hygiene. Perfect for sharing with non-technical users and small businesses.

Free Awareness Basic
๐ŸŽฎ

TryHackMe

Hands-on cybersecurity training through browser-based labs. Great for learning offensive and defensive security skills.

Freemium Hands-on Labs

๐Ÿ“ฐ Staying Current

๐Ÿ“ก

Krebs on Security

Brian Krebs does deep investigative journalism on cybercrime. Thorough, well-researched, and often breaks major stories.

Free News Investigation
๐Ÿ”ฌ

Schneier on Security

Bruce Schneier's blog on security, privacy, and technology policy. Thoughtful analysis from a security legend.

Free Analysis Policy
๐Ÿ—ž๏ธ

The Hacker News

Daily cybersecurity news. Good for staying current on vulnerabilities, breaches, and industry developments.

Free Daily News Vulnerabilities