Field Manual · Ed. 2026
The 2026InfoSecPlaybook
Building, running and proving a security program in the year the old playbook stopped working.
Daniel Ramos
Daniel Ramos · CTO, Intelligent Automation
Building, running and proving a security program in the year the attackers stopped breaking in and started logging in. Twenty-one chapters, fourteen scenario playbooks a stranger can execute at 3 a.m., and 489 tiered controls mapped to NIST CSF 2.0, CIS v8.1 and ISO 27001. Every claim cited to a primary source — and where sources disagree, it says so instead of picking a favourite.
Free, in full, no email wall. No registration, no gated download, nothing withheld.
Every one written to be opened on its own, by someone who has not read the rest.
Written so somebody who has never read the book can pick one up mid-incident and run it. Ransomware, business email compromise, account takeover, identity provider compromise, supply chain, insider, data breach, DDoS, deepfake fraud, Kubernetes, AI systems, edge devices, web applications and OT.
The whole program, sequenced into a first 180 days.
Fourteen playbooks and a severity model that survives contact.
The IG1 tier is the honest minimum, and it is achievable.
489 controls, each answerable true or false by someone who is not you.
The companion volume, written entirely for managed service providers.
If it is useful, use it. Quote it, print it, hand it to your team.