The attacks that didn't have to succeed
Most incidents don't start with a sophisticated attack. They start with something basic that nobody fixed, nobody owned, or nobody thought to check.
State of the Defense takes real attack patterns and rebuilds them through fictional companies. Ridgeline Manufacturing. Clearwater Health Systems. Meridian Financial Group. The names aren't real. The attacks are. The gaps are the ones we see over and over.
Every case study breaks down the same way: what happened, then where the people failed, where the process failed, and where the technology failed. The three-legged stool. Most incidents don't happen because all three legs break at once. They happen because one leg was never there and the other two were expected to compensate.
The CEO impersonation email that led to a $400,000 wire transfer because nobody had a callback procedure. The shared admin credentials that were never rotated because no one owned the process. The phishing simulation the company ran once and never followed up on. The third-party integration that had full database access because it was easier than scoping permissions.
The companies are fictional because the point is the pattern, not the target. The same gap that cost Ridgeline $2.3 million is sitting in organizations that haven't been tested yet.
Who this is for
Anyone honest enough to look. The security leader who knows the org chart says one thing and the reality says another. The risk manager who inherited a program built on assumptions nobody has tested. The operations lead who suspects the tabletop exercise was too polite. The board member who wants to understand what "we have controls in place" actually means when it's Tuesday and the systems are down.
What to do with it
Read the case study. Find the leg of the stool that's missing in your organization. If you can't find it, you're not looking hard enough.
One intelligence shop. Three perspectives.
State of the Threat identifies the risk. State of the Attack shows the mechanism. State of the Defense shows why defenses fail.
Same intelligence pipeline. Same source list. Same author. The threat brief tells your board what's coming. The attack analysis shows your SOC what it looks like. The defense case study shows your team why the controls that should have been there weren't.