The United States marked the 25th anniversary of the September 11 attacks on September 11, 2026, with a commemoration at Ground Zero where victims’ relatives read aloud the names of the dead, honored first responders and urged the nation to unite.
The observance held to the form that has long set it apart from other national remembrances. Political speeches are traditionally absent from Ground Zero. The program belongs instead to the families, who take turns at the microphone reading names, and to the firefighters, police officers and medical crews honored alongside them.
A Ceremony Without Political Speeches
That restraint is the point. Where anniversaries elsewhere in American public life have become platforms for officeholders, the plaza where the twin towers stood has kept to a narrower script: the names, the first responders and an appeal for the country to pull together. Those three elements defined the 25th anniversary ceremony as they have defined the ones before it.
A quarter-century is a long enough span that the attacks now sit at the edge of living memory for a substantial share of the population.
Separately, the security industry’s own agenda in 2026 has centered on a threat surface that barely existed in its current form when the towers fell: the encrypted web, the third-party software supply chain and the machine-speed tooling now available to attackers.
Why HTTPS Still Anchors Web Security
HTTPS — Hypertext Transfer Protocol Secure — is the secure version of HTTP, and it relies on Transport Layer Security (TLS) to encrypt whatever passes between a browser and the server it is talking to. It is the plumbing behind every padlock icon, and it remains the baseline expectation for any organization shifting workloads onto cloud-based infrastructure.
The mechanics are worth spelling out, because the details are where defenses succeed or fail. Secure HTTPS connections typically run over port 443, while unsecured HTTP traffic uses port 80. Before any page content loads, a TLS handshake verifies the server’s identity, negotiates encryption parameters, establishes session keys and determines the cipher suite that will protect the exchange. Done correctly, that sequence helps prevent man-in-the-middle attacks and session hijacking — two long-standing techniques in the attacker’s catalog.
Done carelessly, it is an invitation. Settings left wrong, certificates left to lapse and protocol versions left in service long past their retirement all hand attackers a way in, according to an HTTPS explainer posted November 25, 2025. The uncomfortable implication for security teams is that widespread HTTPS adoption is not the same thing as widespread HTTPS hygiene. A certificate nobody renewed and a protocol version nobody retired will still show a padlock to a user who is not looking closely.
The company behind that guidance, SecurityScorecard, has built its pitch around the same premise at scale, marketing TITAN AI as a threat-informed third-party risk management platform — the idea being that an organization’s exposure increasingly runs through the vendors, suppliers and partners connected to its network rather than through its own front door.
Fortinet’s 2026 Recognitions and Reports
Among the vendors competing for that budget, Fortinet has collected a set of analyst placements across 2025 and 2026. Gartner placed the company in the Leader category of its 2026 Magic Quadrant covering hybrid mesh firewalls, in the Challenger category of the 2026 Magic Quadrant for SASE Platforms, and again among Challengers in the 2025 Magic Quadrant devoted to security information and event management (SIEM).
Its research output points in a similar direction. Fortinet’s 2026 State of Operational Technology and Cybersecurity report draws on a global survey of more than 700 operational technology (OT) professionals — the engineers and managers responsible for the industrial systems that run factories, utilities and pipelines.
The company’s other flagship study makes the point more bluntly: Fortinet’s 2026 Global Threat Landscape Report states that artificial intelligence is accelerating attacks. That is the line tying the technical housekeeping to the strategic picture. If adversaries are automating reconnaissance, phishing and exploitation, then the expired certificate and the deprecated protocol get found faster than they used to — and the window between a misconfiguration and an intrusion narrows accordingly.
None of that machinery figured at the plaza. The observance there required no platform, no analyst report and no product — only the names, read aloud by the people who knew them, a salute to the first responders, a plea for the country to hold together, and, as tradition dictates at Ground Zero, no politician at the microphone.
