This page is generated from the open repository — nothing on it is hand-written. Each item covers one jurisdiction / industry / threat cell and lists the public evidence found for it: the source, the exact line cited, the quantity it measures, the population it was measured on, and its limitation. Any line can be disputed as a GitHub issue.
58 of 72 registered sources have been read end to end and asked four questions. Zero publish a mode. That is the “likely” in every min / likely / max estimate, and the anchor the output moves with most. Not the statistics offices, not the police reporting bodies, not the national surveys, not the regulators, not the insurers, not the vendor studies. IBM’s Cost of a Data Breach says “average” 75 times and “median” zero. What goes in the slot instead, here and everywhere, is a published mean.
The other three questions went the other way. Distributions, exceedance statements and named populations turn up more often than the field assumes. The gap is the mode.
The four questions, in plain words: does it tell you the most likely loss (not the average)? Does it show the spread, or only one number? Does it say how often losses go bigger than a given size? Can you tell who was measured? Across 58 sources the answers are 0, 12, 17 and 45.
Read the audit itself — all 72 sources, every answer carrying what it was checked against and disputable one row at a time. Or read one source and send back four answers: about twenty minutes, nothing to install, and “I could not tell” is a real answer.
All eight findings,
including what we got wrong — two figures retracted for citing no primary source and two
claims withdrawn after measurement contradicted them. Every answer is pinned to a document hash
with the passage quoted, in
sources/audit.yaml.
A cyber loss figure travels a long way from the report that produced it. By the time it lands in a board deck it has usually lost what it measured, who it measured, and what it cannot bear. Nobody puts those back, because that means reading the source. So the gap gets filled with the nearest available number.
Not a prediction, not a benchmark to adopt unread, not a methodology. An item describes a cell, never a company. Where this is going.
Most readers won't break one — the easier ways in count just as much: request the cell you need (requests decide what gets built next) · name a closer source (naming it is a full contribution — extraction is on us) · argue with an open judgment call (no source-hunting required).
Numbers broken so far are counted above and recorded in Findings.
One row per jurisdiction / industry / threat cell. The rendered figures are a reference simulation over each item’s anchors, not the exhibit — click an item for its evidence record.
Monte Carlo, 10,000 trials, seed 42, machine-independent seeding — a modeled range from public evidence, not a prediction. A parameter marked estimate is an interpretive value whose limitation is stated on its face; all others cite a named public source. A parameter marked bridged is source-backed by evidence not drawn from this item’s own cell, and the dimensions borrowed across are named on its fit line. Grades follow the maturity ladder: governed_starter → benchmark_review_candidate → benchmark-grade; no item here holds the last.
Two things to carry while reading. A maximum on this page is not a bound — most
impact.max values carry no exceedance statement, so read them as the largest
loss found, never the largest that can happen. And because the model composes
minimum, likely and maximum into one distribution, the maximum drives the modeled average
rather than capping it: it is simultaneously the least evidenced anchor and the one the result
is most sensitive to. Where its share exceeds half, the item says so under its loss figure.
The cell-matched count above fell 31 → 7 on 2026-08-15, and that is the correction rather than a decline. Fit used to be a field an author kept by hand; measured against the declarations it was supposed to describe, it disagreed on 45 of 66 parameters. It was retired for a computed rule. No published figure moved — every value, source, caveat and simulated total is unchanged, and 7 is what the number always was. One consequence while reading: a statutory penalty cap, a documented single-event loss and a same-survey adjacent band are all measured over some other population, so they read bridged too.
The full basis — how fit is computed, what a mixed range is, and how exceedance is read — is in docs/BASIS_OF_PREPARATION.md.
Why these figures changed. Every correction ever made, newest first; none was silent.