Security event calendar
When the big threat reports land and when the research-heavy conferences run — the moments worth watching, with a note on why each matters.
Last updated: 12 August 2026 09:00 UTC
- 2 Sep – 28 Oct 2026
SOC-telemetry annual; mid September (2024 Sep 17, 2025 Sep 16). Arctic Wolf runs two other annuals (Threat Report in Feb, Human Risk Report in Oct); different lines.
- 20 Sep – 5 Nov 2026
The EU's annual threat landscape; 2025 landed Oct 1 (2024 Sep 19, 2023 Oct 19). Covers a mid-year-to-mid-year window, not calendar year.
- 2 Oct – 15 Nov 2026
Microsoft's telemetry-scale annual threat report; mid-October (2023 Oct 6, 2024 Oct 15, 2025 Oct 16).
- 30 Nov – 4 Dec 2026
Cloud-security announcement wave; watch identity/KMS/GuardDuty-family changes that ripple to every AWS shop.
- 4 Jan – 31 Mar 2027
Staged release: intro chapter early Jan (2026 Jan 8), consolidated report Feb-Mar (2026 Mar 17). Window covers the whole staging run.
- 7 Jan – 4 Mar 2027
January (2025 Jan 14, 2026 Jan 28). Title drifts between 'Security Report' and 'Cyber Security Report'; keywords cover both orders. Keywords carry the year so routine Check Point Research coverage stays unfloored.
- 29 Jan – 26 Mar 2027
Renamed from the Annual Report line, and year semantics flipped with it (old line named for year analysed, new line forward-year). 2026 edition Feb 12. No '2025' edition exists under either name.
- 3 Feb – 31 Mar 2027
Mid February (2025 Feb 11, 2026 Feb 17). Lean-IT relevant: Huntress telemetry skews to exactly our reader. State of Phishing / State of Ransomware cuts are derivatives of the same data.
- 3 Feb – 31 Mar 2027
February, stable (2026 Feb 17). Landing URL is ROLLING (always serves current edition). Themed spin-off editions off the same dataset are supplements, not separate reports.
- 4 Feb – 1 Apr 2027
First-party SOC telemetry across a full calendar year (2026 edition Feb 18: 2T events, ~600k alerts, 300k+ assets, ~53k triaged threats, YoY baselines). Barracuda's largest regular document (23pp).
- 10 Feb – 7 Apr 2027
Late February (2025 Feb 25, 2026 Feb 24). Renamed from 'Cost of Insider Threats' (Proofpoint era); DTEX sponsors now. Old-title strings cite a report that no longer publishes.
- 10 Feb – 14 Apr 2027
IR/MDR case data. Month has MOVED: Apr 2024, Apr 2025, then Feb 24 2026; window spans Feb-Apr until the new slot proves out. Now a single consolidated annual (half-year editions ended 2024).
- 11 Feb – 22 Apr 2027
Late February with real slip risk (2024 Feb 21, 2025 slipped to Apr 17, 2026 Feb 25); window carries the April tail.
- 13 Feb – 27 Mar 2027
Late Feb, the most stable date on this list (2024 Feb 21, 2025 Feb 27, 2026 Feb 24). Breakout-time metric and adversary naming the press repeats all year. Separate annual Threat Hunting Report is a different publication.
- 4 Mar – 15 Apr 2027
PROVISIONAL: one edition only (2026 Mar 18); predecessor Attack Intelligence line published May 2024 then skipped a year. Re-verify or drop if no 2027 edition lands in window.
- 4 Mar – 29 Apr 2027
March (2022, 2023, 2025 all March; 2026 edition live but undated). Red Canary is a Zscaler company now. Midyear update is not a separate annual.
- 9 Mar – 4 May 2027
Late March (2024 YiR out Mar 31 2025, 2025 YiR out Mar 23 2026). TITLE YEAR RUNS ONE BEHIND publication year, opposite of most vendors; the 2027 window ships the '2026' report.
- 9 Mar – 1 May 2027
Dwell-time and IR-derived trends. Moved a month earlier in 2026 (2024 Apr 23, 2025 Apr 23, 2026 Mar 23); window spans late Mar-Apr until the new slot proves out.
- 23 Mar – 18 May 2027
April (2024 report Apr 23 2025, 2025 report Apr 6 2026). Named for the year covered, not the year published. Loss-figure headlines the press quotes for a year; state and elder-fraud companions ship alongside.
- 1 Apr – 27 May 2027
Official Statistics, April (2024 Apr 9, 2025 Apr 10, 2025/26 edition Apr 30 2026). Split-year title since fieldwork moved to Aug-Dec. Strong Lean IT relevance (small-business incidence rates).
- 5–8 Apr 2027
Moscone SF, Apr 5-8. Product-announcement flood plus the year's densest report-launch window.
- 14 Apr – 9 Jun 2027
Late April (2025 Apr 28, 2026 Apr 30). Went annual after years as a semiannual. Shares the 'Global Threat Landscape' title with Rapid7's line; keywords carry the vendor to keep them apart.
- 15 Apr – 5 Jun 2027
The breach-pattern baseline everyone cites. Date drifts across a month (2024 May 1, 2025 Apr 23, 2026 May 19); window widened to cover late Apr through early Jun.
- 1 Jun – 15 Aug 2027
Sophos's annual vendor-agnostic ransomware survey. Month has drifted two years running (2024 Apr 30, 2025 Jun 24, 2026 Jul 15), so this window is wide — re-center once the cadence settles.
- 14–16 Jun 2027
Americas edition, National Harbor MD. Analyst summit; keynote predictions get press. Marginal — owner may kill if it doesn't earn its slot.
- 15 Jul – 9 Sep 2027
Very tight cadence (2024 Jul 30, 2025 Jul 30, 2026 Jul 29). Ponemon fieldwork, IBM analysis.