When I started DysruptionHub, I wanted it to be more than a collection of individual stories. I wanted to follow what happened after the initial headlines and build a useful record of how cyber disruptions affect governments, schools, hospitals, utilities, businesses and the people who rely on them.
I began with a map that allowed readers to explore incidents geographically. It was useful, but it could not tell the whole story.
Articles have limitations, too. DysruptionHub updates its reporting as new information becomes available, but an article is still largely a record of what was known when it was written. An incident may continue for weeks, its effects may change, and important details may emerge long after the initial report.
As the reporting grew, I kept returning to the same questions:
Where else has this ransomware group appeared?
What other organizations have been affected?
Have we seen a similar disruption before?
Articles can help answer those questions, but they remain snapshots. Older coverage can also become difficult to find, compare and connect with later events.
That is what led me to begin building the Cyber Incident Registry nine months ago.
The registry is a research resource focused specifically on cyber disruptions. Each incident profile brings together what is publicly known about what happened, who was affected, the operational impact, the available evidence, and any connections to organizations, locations, ransomware groups or critical infrastructure sectors.
The records are meant to change as the incidents do. Active incidents will receive the most frequent updates, but older records can also be revised when new information becomes available. A report does not have to remain frozen at the point where the original article ended.
The registry also allows readers to approach the reporting from different directions. You can browse incidents, use an interactive map, look up organizations and ransomware groups, explore disruptions by location or critical infrastructure sector, and submit corrections or additional information directly from an incident page.
This is the first public version, and there is still a great deal of work ahead.
Over the coming months, I will be adding more than two years of incidents covered by DysruptionHub. Bringing that reporting into the registry will make older incidents easier to find, compare and follow as new details emerge.
Nobody likes paywalls, and DysruptionHub’s articles will remain free to read. The registry will, however, change how some incident intelligence reports are released.
Sustaining Members receive immediate access to complete incident intelligence reports when they are published. Supporters receive access after 14 days, and the reports become publicly available after 30 days.
The Cyber Incident Registry itself remains open to everyone. Memberships help support the research, follow-up reporting and ongoing work required to keep the records current.
This has been one of the largest projects I have taken on since starting DysruptionHub. It is not finished, and I do not expect it ever to be completely finished. There will always be more incidents to add, more records to improve and more connections to document.
For now, I am glad to finally make it available. I hope you will take a look, and I would genuinely appreciate hearing what works, what does not and what would make it more useful.