Security Resources

Curated links to authoritative security frameworks, guidelines, and tools

These are the resources I actually use and recommend. Official frameworks, government guidelines, and trusted industry standards — no affiliate links, no sponsors, just useful stuff.

Frameworks & Standards

NIST Cybersecurity Framework (CSF)

The gold standard for organizing security programs. Covers Identify, Protect, Detect, Respond, and Recover. Works for any organization size.

Free Framework Enterprise

NIST SP 800-63B — Digital Identity Guidelines

The definitive source on password policy. If your organization still requires 90-day password changes, show them this document.

Free Passwords Authentication

CIS Critical Security Controls

18 prioritized security controls. Implementation Groups (IGs) help you focus on what matters for your organization's size and risk level.

Free Controls Prioritized

CIS Benchmarks

Detailed hardening guides for operating systems, cloud platforms, network devices, and applications. Specific, actionable, and widely respected.

Free (registration) Hardening Configuration

NIST SP 800-207 — Zero Trust Architecture

The authoritative guide to Zero Trust. Essential reading as organizations move beyond perimeter-based security.

Free Zero Trust Architecture

Government Resources

CISA Cybersecurity Best Practices

Practical guidance from the U.S. Cybersecurity and Infrastructure Security Agency. Great starting point for SMBs.

Free Best Practices SMB-friendly

CISA Known Exploited Vulnerabilities (KEV)

The vulnerabilities actually being exploited in the wild. If you can only patch some things, patch these first.

Free Vulnerabilities Patching Priority

FBI Internet Crime Complaint Center (IC3)

Annual reports with real data on cybercrime trends, losses by attack type, and emerging threats. Eye-opening statistics for awareness training.

Free Reports Statistics

ENISA (EU Agency for Cybersecurity)

European perspective on cybersecurity. Threat landscapes, good practices, and sector-specific guidance.

Free EU Reports

ENISA Threat Landscape

Annual report on the top cyber threats in the EU. Data-driven analysis of attack trends, threat actors, and emerging risks. Essential for risk assessments.

Free Threat Intel Annual Report

ENISA Supply Chain Security

Guidelines for securing software and hardware supply chains. Increasingly critical after SolarWinds, Log4j, and similar incidents.

Free Supply Chain Third-Party Risk

ENISA Cloud Security Guide for SMEs

Practical cloud security guidance tailored for small and medium enterprises. Risk assessment, provider selection, and security controls.

Free Cloud SMB-friendly

NIS2 Directive Resources

EU's updated Network and Information Security directive. Broader scope than NIS1, stricter requirements. Mandatory for many sectors by October 2024.

Free Compliance EU Law

ENISA Incident Management Guide

Step-by-step guidance for building incident response capabilities. Detection, analysis, containment, and lessons learned.

Free Incident Response CSIRT

Tools & References

Have I Been Pwned

Check if your email or password has appeared in data breaches. Also offers an API for checking passwords during registration.

Free Breach Check API Available

FIDO Alliance — Passkeys

Everything about passkeys — the passwordless future. Implementation guides, user experience research, and adoption resources.

Free Passkeys FIDO2

MITRE ATT&CK

Knowledge base of adversary tactics and techniques. Essential for threat modeling, detection engineering, and red team exercises.

Free Threat Intel Detection

OWASP (Open Web Application Security Project)

Web and application security resources. The OWASP Top 10 is essential knowledge for anyone building or securing web apps.

Free Web Security AppSec

Learning & Training

SANS Reading Room & Resources

Thousands of free whitepapers, research, and practical guides. The paid training is excellent too, but the free resources are gold.

Free (resources) Research Training

CISA Secure Our World

Simple, clear guidance for basic security hygiene. Perfect for sharing with non-technical users and small businesses.

Free Awareness Basic

TryHackMe

Hands-on cybersecurity training through browser-based labs. Great for learning offensive and defensive security skills.

Freemium Hands-on Labs

Staying Current

Krebs on Security

Brian Krebs does deep investigative journalism on cybercrime. Thorough, well-researched, and often breaks major stories.

Free News Investigation

Schneier on Security

Bruce Schneier's blog on security, privacy, and technology policy. Thoughtful analysis from a security legend.

Free Analysis Policy

The Hacker News

Daily cybersecurity news. Good for staying current on vulnerabilities, breaches, and industry developments.

Free Daily News Vulnerabilities