RISKSHARD

Public cyber-loss evidence
and what each figure can and cannot support

Every figure traces to a named public source, states the quantity it actually measures, names the population it was measured on, and declares what it cannot bear. The loss simulation further down each item is a reference rendering of that evidence — not the product.

This page is generated from the open repository — nothing on it is hand-written. Each item covers one jurisdiction / industry / threat cell and lists the public evidence found for it: the source, the exact line cited, the quantity it measures, the population it was measured on, and its limitation. Any line can be disputed as a GitHub issue.

What reading these sources found

58 of 72 registered sources have been read end to end and asked four questions. Zero publish a mode. That is the “likely” in every min / likely / max estimate, and the anchor the output moves with most. Not the statistics offices, not the police reporting bodies, not the national surveys, not the regulators, not the insurers, not the vendor studies. IBM’s Cost of a Data Breach says “average” 75 times and “median” zero. What goes in the slot instead, here and everywhere, is a published mean.

The other three questions went the other way. Distributions, exceedance statements and named populations turn up more often than the field assumes. The gap is the mode.

The four questions, in plain words: does it tell you the most likely loss (not the average)? Does it show the spread, or only one number? Does it say how often losses go bigger than a given size? Can you tell who was measured? Across 58 sources the answers are 0, 12, 17 and 45.

Read the audit itself — all 72 sources, every answer carrying what it was checked against and disputable one row at a time. Or read one source and send back four answers: about twenty minutes, nothing to install, and “I could not tell” is a real answer.

All eight findings, including what we got wrong — two figures retracted for citing no primary source and two claims withdrawn after measurement contradicted them. Every answer is pinned to a document hash with the passage quoted, in sources/audit.yaml.

Why a label matters more than a number

A cyber loss figure travels a long way from the report that produced it. By the time it lands in a board deck it has usually lost what it measured, who it measured, and what it cannot bear. Nobody puts those back, because that means reading the source. So the gap gets filled with the nearest available number.

  1. Before you cite one. Is “average breach cost” an average of your kind of company, and does it bound anything? Written down here with the sentence quoted, including when the answer is that the source does not say.
  2. When you have to defend one. Every figure has an identifier pinned to a fixed release, and the citation carries the caveat, so the limitation turns up in the room at the same time as the number.
  3. When you buy or build risk tooling. It will ask for min, likely and max, and compose them as a beta-PERT where “likely” is the mode. No public source publishes a mode. Worth asking any vendor where theirs came from.
  4. When you publish loss figures yourself. The four questions are a labelling standard. Answer them and your figure can be used in someone else’s model. Do not, and it can only be quoted.

Not a prediction, not a benchmark to adopt unread, not a methodology. An item describes a cell, never a company. Where this is going.

Notice to readers — how to break a number
  1. Pick any figure in any item below.
  2. Follow it to the named source and the exact cited line — both are printed on the parameter's row.
  3. If the value, the source, or the caveat is wrong, use the [dispute] link on that row. It opens a pre-filled issue; state what is wrong and the public source that shows it.

Most readers won't break one — the easier ways in count just as much: request the cell you need (requests decide what gets built next) · name a closer source (naming it is a full contribution — extraction is on us) · argue with an open judgment call (no source-hunting required).

Numbers broken so far are counted above and recorded in Findings.

Index of items

One row per jurisdiction / industry / threat cell. The rendered figures are a reference simulation over each item’s anchors, not the exhibit — click an item for its evidence record.

Note 1 — Basis of preparation

Monte Carlo, 10,000 trials, seed 42, machine-independent seeding — a modeled range from public evidence, not a prediction. A parameter marked estimate is an interpretive value whose limitation is stated on its face; all others cite a named public source. A parameter marked bridged is source-backed by evidence not drawn from this item’s own cell, and the dimensions borrowed across are named on its fit line. Grades follow the maturity ladder: governed_starter → benchmark_review_candidate → benchmark-grade; no item here holds the last.

Two things to carry while reading. A maximum on this page is not a bound — most impact.max values carry no exceedance statement, so read them as the largest loss found, never the largest that can happen. And because the model composes minimum, likely and maximum into one distribution, the maximum drives the modeled average rather than capping it: it is simultaneously the least evidenced anchor and the one the result is most sensitive to. Where its share exceeds half, the item says so under its loss figure.

The cell-matched count above fell 31 → 7 on 2026-08-15, and that is the correction rather than a decline. Fit used to be a field an author kept by hand; measured against the declarations it was supposed to describe, it disagreed on 45 of 66 parameters. It was retired for a computed rule. No published figure moved — every value, source, caveat and simulated total is unchanged, and 7 is what the number always was. One consequence while reading: a statutory penalty cap, a documented single-event loss and a same-survey adjacent band are all measured over some other population, so they read bridged too.

The full basis — how fit is computed, what a mixed range is, and how exceedance is read — is in docs/BASIS_OF_PREPARATION.md.

Note 2 — The correction record

Why these figures changed. Every correction ever made, newest first; none was silent.