RISKSHARD Public cyber-loss evidence

The source audit

What each public cyber-loss source actually publishes, asked one source at a time
sources registered75
read on all four properties64 of 75
answers verified against an artifact256 of 300
answers blocked44 — the artifact we hold is not the source
answers unread0 — a question, never counted as an absence

Cyber loss figures get quoted far past what they can support, and nobody checks. There is no name for that job and no one doing it, so this is us doing it: taking the public reports everyone cites, reading them one at a time, and writing down what each one actually publishes.

An answer may only say what a source publishes when a person read the stored document, and each one is pinned to that document’s SHA-256 rather than to a file path. A new edition has a different hash and inherits nothing.

The counts above are published beside every claim drawn from this page. A source not yet read is unread and is counted as unread. It is never reported as a source that publishes nothing.

The four questions

Asked of every source in the same words, so the answers can be compared.

PropertyQuestionPublishes
modeDoes it tell you the most likely loss — not the average, the most likely?
Does it publish a most-likely / modal value — the beta-PERT parameter?
0 of 64 read
distributionDoes it show the spread of losses, or only one number?
Does it publish a distribution or quantiles, or only point statistics?
14 of 64 read
exceedanceDoes it say how often losses go bigger than a given size?
Does it state how often a loss of a given size is exceeded, over a named population?
19 of 64 read
populationCan you tell who was measured — which countries, industries, sizes?
Can the measured population be named from the source itself?
51 of 64 read
What bounds every answer below

Stored PDFs are read as extracted text, so a property published only inside a chart image can be missed. Where that risk is live it is named in the answer rather than left for a reader to find. This is the audit’s own limitation, stated here rather than in a footnote.

Blocked is not unread. 44 answers are blocked because what we hold is a landing page or a summary rather than the document. Effort does not clear those; obtaining the document does.

Read one source · about twenty minutes

This is the only thing we are asking anyone for, and it is deliberately small. Take a public cyber-loss report you already know, answer the four questions above, and say where you saw each answer. You do not need to install anything, know this project, or agree with it.

“I could not tell” is a real answer, and on these questions it is usually the interesting one. So is telling us a question is badly framed.

Send back one source →   The form is the four questions, nothing else.

If instead you think an answer below is wrong, that is more valuable still: every record has a dispute link, and a source that publishes a most-likely loss would move the finding this whole audit rests on. We would rather have that than be right.

The matrix

One row per registered source. yes and no are answers a person verified against the document; blocked means the artifact we hold is not the source; unread means the question has not been put yet.

SourceModeDistributionExceedancePopulation
2026 Data Breach Investigations Report
Verizon Business
noyesnoyes
2025 Data Breach Investigations Report
Verizon Business
noyesnoyes
Cost of a Data Breach Report 2025
IBM
nononoyes
AI breaches are not just a scare story any more - they are happening in real life
ITPro
nononono
IBM Report: Canadians' Data Security Under Increased Threat, While Breach Costs Surge
IBM
blockedblockedblockedblocked
Rapport IBM 2025 : coût d'une violation de données en France
IBM
blockedblockedblockedblocked
Eurostat ISOC_CISCE_IC - ICT security incidents by size class (France)
Eurostat
nononoyes
CESIN 11e Barometre annuel de la cybersecurite des entreprises (2025)
CESIN
blockedblockedblockedblocked
Asteres - Le cout des cyberattaques reussies en France (2022)
Asteres
nononoyes
GDPR Article 83(5) maximum administrative fine (via CNIL)
CNIL
nononono
2025-2026 Annual Report to Parliament on the Privacy Act and PIPEDA
Office of the Privacy Commissioner of Canada
nononoyes
Cyber Security Breaches Survey 2025/2026
UK Department for Science, Innovation and Technology and Home Office
noyesyesyes
IBM UK Cost of a Data Breach 2025 release
IBM
blockedblockedblockedblocked
FCA fines Equifax Ltd over cyber security breach
Financial Conduct Authority
nononono
Counts of Australian Businesses, including Entries and Exits, July 2021 - June 2025
Australian Bureau of Statistics
nononoyes
Characteristics of Australian Business, 2024-25 financial year
Australian Bureau of Statistics
nononoyes
MYOB mid-sized business cyber attack survey 2024
MYOB (survey conducted by Dynata)
blockedblockedblockedblocked
Cybersecurity Insiders 2024 Insider Threat Report
Cybersecurity Insiders
nonoyesyes
Gurucul 2026 Insider Risk Report
Cybersecurity Insiders (sponsored by Gurucul)
nononoyes
BCI Supply Chain Resilience Report 2024
Business Continuity Institute
nononoyes
Interos Annual Global Supply Chain Report (Resilience 2022)
Interos
nononoyes
SPF Business Email Compromise scam interception case 2024
Singapore Police Force
nononono
Regula Deepfake Fraud Impact Survey 2024
Regula
nononoyes
Gartner deepfake attack survey (September 2025)
Gartner (reported via Adaptive Security)
nononoyes
Deepfake business fraud impact statistics 2024
Security.org (compilation of 2024 deepfake survey data)
nononono
Arup Hong Kong deepfake CFO fraud case 2024
CNN (reporting Hong Kong Police)
nononono
ICO self-reported personal data breach cases (2024/25)
Information Commissioner's Office
nononoyes
ICO monetary penalties 2024 (enforcement analysis)
Information Commissioner's Office (analysis via URM Consulting)
nononoyes
Statistics of U.S. Businesses (SUSB) 2022 Annual Data
U.S. Census Bureau
nononoyes
2025 AFP Payments Fraud and Control Survey Report
Association for Financial Professionals
blockedblockedblockedblocked
2026 AFP Payments Fraud and Control Survey Report
Association for Financial Professionals
blockedblockedblockedblocked
Coalition funds transfer fraud largest clawback case
Coalition
nononono
2025 IC3 Annual Report
Federal Bureau of Investigation Internet Crime Complaint Center
nononoyes
Targeting Scams Report 2025
Australian Competition and Consumer Commission National Anti-Scam Centre
nononoyes
Information Risk Insights Study 2025
Cyentia Institute
noyesyesyes
Information Risk Insights Study 2022
Cyentia Institute
noyesyesyes
IRIS Ransomware
Cyentia Institute
noyesyesyes
EPSS Data and Statistics
Forum of Incident Response and Security Teams
blockedblockedblockedblocked
Annual Cyber Threat Report 2024-2025
Australian Signals Directorate
nononoyes
Keeping your business cyber secure
Business Queensland
nononono
Notifiable Data Breaches Report July to December 2024
Office of the Australian Information Commissioner
nononoyes
Privacy Act 1988
Federal Register of Legislation
nononono
CPS 230 Operational Risk Management
Australian Prudential Regulation Authority
nononono
State of Ransomware in Financial Services 2024
Sophos
blockedblockedblockedblocked
Wirtschaftsschutz 2025
Bitkom e.V.
nononoyes
State of Ransomware in Manufacturing and Production 2025
Sophos
noyesyesyes
State of Ransomware in Manufacturing and Production 2024
Sophos
blockedblockedblockedblocked
Cost of Insider Risks Global Report 2023
Ponemon Institute and DTEX Systems
nononoyes
2025 Cyber Threat Situation Statistics Data
National Police Agency of Japan
noyesyesyes
NetDiligence Cyber Claims Study 2025 (Fifteenth Annual)
NetDiligence
nononoyes
SPF Annual Scam and Cybercrime Brief 2025
Singapore Police Force
noyesyesyes
ESAs 2025 Report on major ICT-related incidents (JC 2026 16)
Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA)
nononoyes
Statistics Canada Table 22-10-0076-01 - Types of cyber security incidents that impact enterprises, by industry and size
Statistics Canada
nononoyes
The State of Ransomware 2023 (whitepaper, archived snapshot)
Sophos
noyesyesyes
The State of Ransomware 2024 (whitepaper, archived snapshot)
Sophos
noyesyesyes
The State of Ransomware in Australia 2025 (whitepaper)
Sophos
blockedblockedblockedblocked
Latitude Group Holdings 1H23 Results Investor Presentation
Latitude Group Holdings Limited (ASX LFS)
nononono
SecurityBrief Australia coverage of IBM Cost of a Data Breach 2026 Australian figures
SecurityBrief Australia (TechDay)
nononono
SingStat Table M600981 - Enterprise Landscape By SMEs And Non-SMEs, Annual
Singapore Department of Statistics
nononoyes
CSA Singapore Cybersecurity Health Report 2023
Cyber Security Agency of Singapore
nononoyes
Business Email Compromise cost Australian victims more than $79 million in the past year
Australian Federal Police
nononono
The State of Ransomware in Financial Services 2025
Sophos
noyesyesyes
The State of Ransomware in Australia 2026
Sophos
nonoyesyes
The State of Ransomware in Germany 2026
Sophos
nonoyesyes
The State of Ransomware in France 2026
Sophos
nonoyesyes
The State of Ransomware in Japan 2026
Sophos
nonoyesyes
The State of Ransomware in United Kingdom 2026
Sophos
nonoyesyes
The State of Ransomware in United States 2026
Sophos
nonoyesyes
The State of Ransomware in Singapore 2026
Sophos
nononoyes
Cost of a Data Breach Report 2026
IBM
nononoyes
2026 Cost of Insider Risks Global Report
Ponemon Institute and DTEX Systems
nononoyes
The State of Ransomware in Enterprise 2025
Sophos
noyesyesyes
The State of Ransomware 2026 (global report)
Sophos
noyesyesyes
Singapore Cyber Landscape 2024/2025
Cyber Security Agency of Singapore
nononoyes
Singapore Cyber Landscape 2025/2026
Cyber Security Agency of Singapore
nononoyes

The records

Every answer in full, with what was read and the date it was read.

2026 Data Breach Investigations Report

Verizon Business
verizon_dbir_2026 · sources/raw/verizon_dbir_2026.pdf · sha256 4a2788bc5afb2ecd…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal or most-likely value is offered for any loss quantity. The report's central tendencies are medians and means; the single occurrence of the word "mode" in the text is "spectator mode", unrelated. Nothing in the report is presented as the most probable single value of a loss.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Yes, and this is the finding that complicates the simple version of our claim. Figure 45 is titled "Distribution of loss due to ransom payment in 2025" (n=1,494 for 2025; each dot is 7.47 events) and is a quantile dot plot. The methodology section states the report expresses confidence through "complementary cumulative density (slanted) bar charts, hypothetical outcome plot (spaghetti) line charts and quantile dot plots". So a loss distribution over a stated sample IS published here — it is simply not published as parameters a three-point model can consume.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
No exceedance probability is stated for any loss magnitude. Figure 45's quantile dot plot would let a reader derive one for ransom payments over that sample, which is more than most sources offer, but deriving is not stating and the distinction is the whole of ADR-0008. Recorded as not published, with the derivability noted rather than counted.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Sample sizes are given per figure and the contributor base, regions and industries are described. Note the population of the ransom-loss figure is actor-disclosed ransomware victims cross-referenced against known crypto-wallet payments — nameable, and not a general business population.
read 2026-08-15

2025 Data Breach Investigations Report

Verizon Business
verizon_dbir_2025 · sources/raw/verizon_dbir_2025.pdf · sha256 6e0affcc35112764…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value for any loss quantity, consistent with the 2026 edition. Central tendency is reported as medians.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Figure 46, "Distribution of loss due to ransom payment in USD (2022-2024)", a quantile dot plot with n=664/462/351 by year. The accompanying text gives the 2024 median ransom paid as $115,000, down from $150,000.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated. Figure 46 plots individual observations, so a reader could count an exceedance off it, but the report states none — the same call as the 2026 edition, and the reason the rule above distinguishes deriving from stating.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Sample sizes per figure and a methodology appendix. The ransom figure carries its own population caveat in the text: "the customers of ransomware negotiation companies tend to be larger enterprises."
read 2026-08-15

Cost of a Data Breach Report 2025

IBM
ibm_cost_data_breach_2025 · sources/raw/ibm_cost_data_breach_2025_report.pdf · sha256 e60c77ff14afe3d9…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Same construction as the 2026 edition: 60 occurrences of "average", zero of "median" or "percentile". Global average cost fell to USD 4.44 million, reported as a mean with no dispersion.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
The same benchmarked multi-country, multi-industry breached-organization sample as the 2026 edition, with demographics reported.
read 2026-08-16

AI breaches are not just a scare story any more - they are happening in real life

ITPro
itpro_ibm_data_breach_regional_costs_2025 · sources/raw/itpro_ibm_data_breach_regional_costs_2025.html · sha256 08a93ff04ee979b6…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. Trade-press coverage of IBM's regional breach cost figures.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None of its own. It relays averages measured by IBM.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No population of its own — it reports another study's figures, which is what its own limitations note in our records says. The population belongs to IBM, whose report we do not hold.
read 2026-08-15

IBM Report: Canadians' Data Security Under Increased Threat, While Breach Costs Surge

IBM
ibm_canada_cost_data_breach_2025 · sha256 20b282f563f722ca…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 901-word summary page, not Cost of a Data Breach 2025 (Canada cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 901-word summary page, not Cost of a Data Breach 2025 (Canada cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 901-word summary page, not Cost of a Data Breach 2025 (Canada cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 901-word summary page, not Cost of a Data Breach 2025 (Canada cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.

Rapport IBM 2025 : coût d'une violation de données en France

IBM
ibm_france_cost_data_breach_2025 · sha256 3024e63f0a4122a3…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 2,593-word IBM press release in French about the 2025 report, not the report. Same blocker as the global, UK and Canada cuts.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 2,593-word IBM press release in French about the 2025 report, not the report. Same blocker as the global, UK and Canada cuts.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 2,593-word IBM press release in French about the 2025 report, not the report. Same blocker as the global, UK and Canada cuts.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 2,593-word IBM press release in French about the 2025 report, not the report. Same blocker as the global, UK and Canada cuts.

Eurostat ISOC_CISCE_IC - ICT security incidents by size class (France)

Eurostat
eurostat_isoc_cisce_ic_2024 · sources/raw/eurostat_isoc_cisce_ic_2024.json · sha256 b87bb0fbc7fa8c88…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. A Eurostat JSON-stat query response, not a publication.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Percentages of enterprises experiencing security incidents by size class — prevalence by category, not a distribution over magnitude.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Titled in the response itself: "Security incidents and consequences by size class of enterprise" (ESTAT). The size classes are the population definition.
read 2026-08-15

CESIN 11e Barometre annuel de la cybersecurite des entreprises (2025)

CESIN
cesin_barometre_cybersecurite_2025 · sha256 c8b13e382d6e76a9…
Does it tell you the most likely loss — not the average, the most likely?
blocked
A 1,498-word press release (Communiqué de Presse) announcing the 10th CESIN barometer, not the barometer.
Does it show the spread of losses, or only one number?
blocked
A 1,498-word press release (Communiqué de Presse) announcing the 10th CESIN barometer, not the barometer.
Does it say how often losses go bigger than a given size?
blocked
A 1,498-word press release (Communiqué de Presse) announcing the 10th CESIN barometer, not the barometer.
Can you tell who was measured — which countries, industries, sizes?
blocked
A 1,498-word press release (Communiqué de Presse) announcing the 10th CESIN barometer, not the barometer.

Asteres - Le cout des cyberattaques reussies en France (2022)

Asteres
asteres_cout_cyberattaques_france_2022 · sources/raw/asteres_cout_cyberattaques_france_2022.pdf · sha256 475980a53f23d349…
Does it tell you the most likely loss — not the average, the most likely?
no
No mode. Read with French terms; zero occurrences of médiane in the study.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Averages only, and the study says so: it estimates "le coût moyen de la résolution de la crise, le coût moyen d'une rançon et les pertes moyennes de productivité". No médiane, no percentile, no répartition of cost.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
French organisations, built from a literature review plus a survey of CRiP members ("une enquête menée auprès des adhérents du CRiP"), with a methodology section — a named and self-selected professional population.
read 2026-08-15

GDPR Article 83(5) maximum administrative fine (via CNIL)

CNIL
gdpr_article_83_administrative_fines · sources/raw/gdpr_article_83_administrative_fines.html · sha256 5185d122837b1a71…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. The text of GDPR Article 83 as published by CNIL.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Legislation states penalty ceilings; it distributes nothing.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. A statutory ceiling is a legal bound, not an observed exceedance — the population_ceiling case in ADR-0008.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No measured population. Any figure taken from here is a legal maximum, not a measurement of anyone's losses.
read 2026-08-15

2025-2026 Annual Report to Parliament on the Privacy Act and PIPEDA

Office of the Privacy Commissioner of Canada
opc_annual_report_2025_2026 · sources/raw/opc_annual_report_2025_2026.html · sha256 ff418539aa0aa504…
Does it tell you the most likely loss — not the average, the most likely?
no
No loss magnitudes of any kind, so no mode.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Counts and processing times, not loss. Complaints under PIPEDA rose from 1,458 to 3,044; files processed within an average of 66 days against a 28-day standard. No median, percentile or distribution over any magnitude a model would consume.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Complaints and breach reports made to the OPC under PIPEDA — a regulator's reporting population, clearly named.
read 2026-08-15

Cyber Security Breaches Survey 2025/2026

UK Department for Science, Innovation and Technology and Home Office
uk_dsit_cyber_breaches_2026 · sources/raw/uk_dsit_cyber_breaches_2026.html · sha256 780128a0e2a5daa2…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal cost. Central tendency is the median perceived cost.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Cost is reported as quantiles, not a single figure: median perceived cost of the most disruptive breach (£0 for businesses, £30 for medium and large), and "the range of perceived cost where most fell (25th to 75th percentile) was £0 to £200 for businesses and £0 to £80 for charities."
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Yes, and this is the clearest exceedance statement found in the corpus so far: "Looking at the perceived cost for the top 5% of cases (95th percentile) ... organisations can face high costs (£4,000 for all businesses and micro/small businesses, rising to £10,000 for medium/large businesses, and £1,000 for charities)." That is P(cost > £10,000) = 5% for UK medium/large businesses — a stated exceedance over a named population, split by size band.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
An official UK survey with a stated sample, reported separately for businesses and charities and split by size band (micro/small, medium/large).
read 2026-08-15

IBM UK Cost of a Data Breach 2025 release

IBM
ibm_cost_data_breach_uk_2025 · sha256 db034fcb5db2bd59…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 1,267-word summary page, not Cost of a Data Breach 2025 (UK cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 1,267-word summary page, not Cost of a Data Breach 2025 (UK cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 1,267-word summary page, not Cost of a Data Breach 2025 (UK cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 1,267-word summary page, not Cost of a Data Breach 2025 (UK cut). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.

FCA fines Equifax Ltd over cyber security breach

Financial Conduct Authority
fca_equifax_cyber_breach_fine_2023 · sources/raw/fca_equifax_cyber_breach_fine_2023.html · sha256 4474675d6ff6f598…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. The FCA's final notice, used as a regulatory-penalty anchor.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. An enforcement decision about one firm.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. A fine is an imposed amount, not an observed loss with an exceedance.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
One enforcement action against one firm; no population.
read 2026-08-15

Counts of Australian Businesses, including Entries and Exits, July 2021 - June 2025

Australian Bureau of Statistics
abs_counts_australian_businesses_2025 · sources/raw/abs_counts_australian_businesses_2025.html · sha256 2a04bc6f38721bc6…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. An official ABS business count, used as a denominator.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Counts of businesses by size and industry — a census breakdown, not a distribution over a loss or frequency magnitude.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None; it carries no loss magnitudes.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
The Australian business count itself. This is a denominator source, and the population is the whole point of it.
read 2026-08-15

Characteristics of Australian Business, 2024-25 financial year

Australian Bureau of Statistics
abs_characteristics_australian_business_2025 · sources/raw/abs_characteristics_australian_business_2025.html · sha256 b3246fbd7f32a4cb…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the release reports proportions of businesses, not loss magnitudes.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Prevalence by category — the share of businesses experiencing a cyber security incident, split by employment size range. A categorical breakdown of a rate, not a distribution over a magnitude.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None; the release carries no loss magnitudes to exceed.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
An official ABS statistical release covering Australian businesses with defined employment size ranges — the strongest population statement in the corpus so far, and the reason this source is used as a denominator.
read 2026-08-15

MYOB mid-sized business cyber attack survey 2024

MYOB (survey conducted by Dynata)
myob_business_monitor_cyber_2024 · sha256 237fbe8e3a2d7934…
Does it tell you the most likely loss — not the average, the most likely?
blocked
An 849-word CFOtech news article about the MYOB Business Monitor survey, not the survey.
Does it show the spread of losses, or only one number?
blocked
An 849-word CFOtech news article about the MYOB Business Monitor survey, not the survey.
Does it say how often losses go bigger than a given size?
blocked
An 849-word CFOtech news article about the MYOB Business Monitor survey, not the survey.
Can you tell who was measured — which countries, industries, sizes?
blocked
An 849-word CFOtech news article about the MYOB Business Monitor survey, not the survey.

Cybersecurity Insiders 2024 Insider Threat Report

Cybersecurity Insiders
cybersecurity_insiders_insider_threat_2024 · sources/raw/2024-Insider-Threat-Report-Gurucul.pdf · sha256 88b71b6bfeb54683…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Respondent percentages by category; no magnitude is distributed.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a threshold with a share: "the average cost of remediation exceeding $1 million for 29% of respondents". That is P(remediation cost > $1M) = 29% over the surveyed organizations - an exceedance statement, in a report that publishes no other magnitude.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Survey respondents, reported as percentages throughout; the population is self-selected security practitioners rather than a sampled organization frame.
read 2026-08-16

Gurucul 2026 Insider Risk Report

Cybersecurity Insiders (sponsored by Gurucul)
gurucul_insider_risk_report_2026 · sources/raw/gurucul_insider_risk_report_2026.html · sha256 ce24d06f198115b3…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A vendor survey of insider risk, reporting respondent percentages.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Prevalence and concern percentages by category only.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
A stated survey respondent population.
read 2026-08-15

BCI Supply Chain Resilience Report 2024

Business Continuity Institute
bci_supply_chain_resilience_2024 · sources/raw/bci_supply_chain_resilience_2024.html · sha256 92c9e8bab34b2fb3…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A BCI membership survey of supply-chain disruption.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Prevalence percentages only.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
BCI survey respondents — a self-selected professional membership population, which matters for how its prevalence figures travel.
read 2026-08-15

Interos Annual Global Supply Chain Report (Resilience 2022)

Interos
interos_global_supply_chain_2022 · sources/raw/interos_global_supply_chain_2022.pdf · sha256 eb2dc14d15d54959…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Survey point statistics — averages of reported annual cost of supply-chain disruption. No median, percentile or distribution.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
A stated survey respondent population of senior decision-makers.
read 2026-08-15

SPF Business Email Compromise scam interception case 2024

Singapore Police Force
spf_bec_interception_case_2024 · sources/raw/spf_bec_interception_case_2024.html · sha256 42681283b597f528…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A single documented BEC case used as a tail anchor.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. One event.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None — and this is why the shard anchored on it declares none_known.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
One documented case; no population.
read 2026-08-15

Regula Deepfake Fraud Impact Survey 2024

Regula
regula_deepfake_survey_2024 · sources/raw/regula_deepfake_survey_2024.html · sha256 4d697df12b66389b…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A vendor survey with respondent counts.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Percentages of respondents by experience and concern.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
A stated survey respondent population across named countries.
read 2026-08-15

Gartner deepfake attack survey (September 2025)

Gartner (reported via Adaptive Security)
gartner_deepfake_attack_survey_2025 · sources/raw/gartner_deepfake_attack_survey_2025.html · sha256 722032381d23aff9…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. Survey of prevalence; percentages of organisations experiencing attack types. No magnitude is distributed.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Percentages of respondents by attack type are a categorical breakdown, not a distribution over loss or frequency magnitude.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
A named survey population of respondent organisations.
read 2026-08-15

Deepfake business fraud impact statistics 2024

Security.org (compilation of 2024 deepfake survey data)
deepfake_business_impact_2024 · sources/raw/deepfake_business_impact_2024.html · sha256 a12249ceb1da4f33…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A Security.org guide that aggregates other parties' statistics.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None of its own.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
It aggregates figures measured by others rather than measuring a population itself, so there is no population belonging to this source. That is the property worth knowing about it.
read 2026-08-15

Arup Hong Kong deepfake CFO fraud case 2024

CNN (reporting Hong Kong Police)
arup_deepfake_case_2024 · sources/raw/arup_deepfake_case_2024.html · sha256 ca5bb68c91fe6052…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. CNN's report of the Hong Kong Police account of a single deepfake fraud.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. One event.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
One documented case reported by a news outlet; no population, and no methodology of its own.
read 2026-08-15

ICO self-reported personal data breach cases (2024/25)

Information Commissioner's Office
ico_self_reported_breach_cases_2024_25 · sources/raw/pdb-cases-q4-2025-26.csv · sha256 d8642b570d67d231…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the release carries no magnitudes at all.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
No magnitude is distributed because none is recorded. The dataset is case-level regulatory administration: case status, reference, legislation, received and completed dates, sector, sub-sector, the organisation named, the decision taken, and a cyber-incident flag. There is no cost, no record count and no severity field.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None, and none is possible from these fields.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
The strongest population statement in the corpus and the reason this source matters: every personal-data-breach case reported to the ICO under GDPR/DPA in the quarter, named to the organisation, classified by sector and sub-sector. 24,154 cases across the eight quarters held, of which 5,694 carry ISCyberIncident=Yes. For the cell we model it resolves to 1,970 Finance, insurance and credit cases with 707 flagged cyber - a genuine sector-and-country-specific numerator, over a mandatory-notification population rather than a survey sample.
read 2026-08-16

ICO monetary penalties 2024 (enforcement analysis)

Information Commissioner's Office (analysis via URM Consulting)
ico_monetary_penalties_2024 · sources/raw/ico_monetary_penalties_2024.html · sha256 1213aed005b8a04d…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. The ICO's register of monetary penalties issued.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
A list of penalties issued with amounts — an enumeration of actual decisions, not a distribution fitted or quantiled over them.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated. The register would let a reader compute one over issued penalties, which is not the same as the ICO stating it.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Penalties issued by the ICO in the period — a complete enumeration of a regulator's own actions rather than a sample.
read 2026-08-15

Statistics of U.S. Businesses (SUSB) 2022 Annual Data

U.S. Census Bureau
census_susb_2022 · sources/raw/census_susb_2022.xlsx · sha256 246200312e857ffe…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. A US Census Bureau SUSB workbook. Read as xlsx via the standard library.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Establishment and employment counts by enterprise size — a census breakdown, no magnitude distributed.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None; it carries no loss figures.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
US employer businesses by size band. A denominator source, and the population is the entire content.
read 2026-08-15

2025 AFP Payments Fraud and Control Survey Report

Association for Financial Professionals
afp_payments_fraud_2025 · sha256 b8eee369c360a402…
Does it tell you the most likely loss — not the average, the most likely?
blocked
A 1,443-word archived landing page for the AFP Payments Fraud and Control Survey Report, not the report.
Does it show the spread of losses, or only one number?
blocked
A 1,443-word archived landing page for the AFP Payments Fraud and Control Survey Report, not the report.
Does it say how often losses go bigger than a given size?
blocked
A 1,443-word archived landing page for the AFP Payments Fraud and Control Survey Report, not the report.
Can you tell who was measured — which countries, industries, sizes?
blocked
A 1,443-word archived landing page for the AFP Payments Fraud and Control Survey Report, not the report.

2026 AFP Payments Fraud and Control Survey Report

Association for Financial Professionals
afp_payments_fraud_2026 · sha256 c5db9fc0455a5a65…
Does it tell you the most likely loss — not the average, the most likely?
blocked
A 1,279-word archived landing page for the survey report, not the report.
Does it show the spread of losses, or only one number?
blocked
A 1,279-word archived landing page for the survey report, not the report.
Does it say how often losses go bigger than a given size?
blocked
A 1,279-word archived landing page for the survey report, not the report.
Can you tell who was measured — which countries, industries, sizes?
blocked
A 1,279-word archived landing page for the survey report, not the report.

Coalition funds transfer fraud largest clawback case

Coalition
coalition_ftf_largest_clawback_2023 · sources/raw/coalition_ftf_largest_clawback_2023.html · sha256 c98bd9541a5ddcac…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. An insurer's account of one funds-transfer-fraud recovery.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. One event.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
One documented case; no population.
read 2026-08-15

2025 IC3 Annual Report

Federal Bureau of Investigation Internet Crime Complaint Center
fbi_ic3_2025_report · sources/raw/fbi_ic3_2025_report.pdf · sha256 7d1fe453237654d2…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal loss value anywhere in the report.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Point statistics only. Complaint counts and total losses, an average loss of $20,699, and breakdowns by crime type, age group and state — categorical splits of a total, not a distribution over loss magnitude. No median, percentile or quantile appears.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. The word "exceed" appears only of aggregate totals passing a round number, e.g. losses to investment scams exceeding $8 billion, which is a sum rather than a statement about how often an individual loss is passed.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Nameable and important to name: the population is complaints reported to IC3 (1,008,597 in the year, $20.877bn in losses), which is a self-selected reporting population and not a business census.
read 2026-08-15

Targeting Scams Report 2025

Australian Competition and Consumer Commission National Anti-Scam Centre
accc_targeting_scams_2025 · sources/raw/accc_targeting_scams_2025.pdf · sha256 9d21086dedca93f0…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal loss value.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Point statistics only, though better chosen than most: a median loss (falling from $500 in 2024 to $400 in 2025) reported overall and broken out by demographic group. A median by category is not a distribution over magnitude — no percentile, quantile or banding appears.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated. The word appears only of aggregate reported-loss totals.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Scamwatch reports to the ACCC, plus partner reporting bodies — a self-selected reporting population, which the report itself discusses.
read 2026-08-15

Information Risk Insights Study 2025

Cyentia Institute
cyentia_iris_2025 · sources/raw/cyentia_iris_2025.pdf · sha256 00706bbbfefcc7b6…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value — and it is the one source that visibly reasons about the choice: "Prior IRIS used the geometric mean for a typical loss. Since the growing shoulder in lower part of the distribution pulls the geomean down, the median is better central measure." It deliberates over central tendency and still never reaches for a mode.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
The most complete in the corpus. Figure 9 is "Distribution of reported losses for security incidents from 2015 to 2024", plotted on a log scale, with "Loss percentile" used as an axis; the median incident costs about $600K.
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated: "The typical (median) incident costs about $600K, while more extreme (95th percentile) losses swell to $32 million", and "The top 5% of loss events continue to exceed the annual revenue of affected firms." It also documents where it uses the 90th rather than the 95th percentile and why, which is a care about tail estimation no other source here shows.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
A historical dataset of publicly reported cyber events drawn from Advisen's Cyber Loss Data, with the reporting-lag bias discussed rather than hidden.
read 2026-08-15

Information Risk Insights Study 2022

Cyentia Institute
cyentia_iris_2022 · sources/raw/cyentia_iris_2022.pdf · sha256 8cf45ef222a4375d…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; central tendency is a geometric mean and a median.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Loss percentiles throughout, including a 95th-percentile figure by sector (Transportation, $177M) and a largest observed loss of $12B.
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated in the form a modeller actually needs: "A little over a quarter of incidents fall in the span between 1% and 100% [of revenue], while 6% actually exceed the organization's yearly income." It then advises on use — "If you're looking to convey what a really bad cyber event might cost, we suggest using the 95th percentile value."
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
The most precisely stated population in the corpus: "over 77,000 cyber events experienced by 35,000 organizations over the last decade", drawn from Advisen's Cyber Loss Data.
read 2026-08-15

IRIS Ransomware

Cyentia Institute
cyentia_iris_ransomware · sources/raw/cyentia_iris_ransomware.pdf · sha256 d2bdaa1d7bf2a20c…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Loss percentiles reported and compared across incident types, including a 25th-percentile figure for 2023.
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated as a comparison of tails: "The 95th percentile loss balloons to about $50M, compared with $22M for non-ransomware" — $49.6M against $22.4M in the figures.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
The same Advisen-derived event dataset, filtered to ransomware.
read 2026-08-15

EPSS Data and Statistics

Forum of Incident Response and Security Teams
first_epss_data_stats
Does it tell you the most likely loss — not the average, the most likely?
blocked
Registered with no gathered artifact at all — `sources/manifest.json` holds no entry for it, so there is nothing to read. Distinct from the landing-page cases: those hold the wrong document, this holds none.
Does it show the spread of losses, or only one number?
blocked
Registered with no gathered artifact at all — `sources/manifest.json` holds no entry for it, so there is nothing to read. Distinct from the landing-page cases: those hold the wrong document, this holds none.
Does it say how often losses go bigger than a given size?
blocked
Registered with no gathered artifact at all — `sources/manifest.json` holds no entry for it, so there is nothing to read. Distinct from the landing-page cases: those hold the wrong document, this holds none.
Can you tell who was measured — which countries, industries, sizes?
blocked
Registered with no gathered artifact at all — `sources/manifest.json` holds no entry for it, so there is nothing to read. Distinct from the landing-page cases: those hold the wrong document, this holds none.

Annual Cyber Threat Report 2024-2025

Australian Signals Directorate
asd_annual_cyber_threat_report_2024_2025 · sources/raw/Annual Cyber Threat Report 2024-2025 _ Cyber.gov.au.pdf · sha256 83a00aaf4390d405…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; 11 occurrences of "average" and none of "median".
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Averages broken down by business size, not distributed. Figure 3 gives the average self-reported cost of cybercrime to businesses at $80,850 per report overall, up 50%, with small business at $56,571 in 2024-25 against $49,615 in 2023-24. Size-banded means, no percentile or quantile anywhere.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Reports made to ReportCyber during the financial year - a self-reported, self-selected reporting population rather than a survey sample or a census, which is the caveat that must travel with any figure taken from it. Broken out by business size, which is why it is useful to us: size is bridged 44 of 66 times in the corpus.
read 2026-08-16

Keeping your business cyber secure

Business Queensland
business_qld_cyber_secure_guidance_2025 · sources/raw/business_qld_cyber_secure_guidance_2025.html · sha256 861376170008e250…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. Queensland government guidance for small business.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Guidance material citing indicative figures.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
Guidance rather than a study; no population is measured. Any figure taken from here is a citation of someone else's measurement.
read 2026-08-15

Notifiable Data Breaches Report July to December 2024

Office of the Australian Information Commissioner
oaic_ndb_jul_dec_2024 · sources/raw/oaic_ndb_jul_dec_2024.pdf · sha256 412c99ad35cd54c5…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Point statistics, but an unusually informative pair: Table 2 gives both the median AND the average number of affected individuals per breach source (cyber incident n=247, median 182, average 15,357). Reporting both exposes the skew, which most sources hide — it is still two point statistics rather than a distribution.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Breaches notified to the OAIC under the Notifiable Data Breaches scheme, with notification counts per category.
read 2026-08-15

Privacy Act 1988

Federal Register of Legislation
privacy_act_1988_latest · sources/raw/privacy_act_1988_latest.html · sha256 2993dd4de62fce20…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. The statute itself, used for a statutory penalty ceiling.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. Legislation states a maximum penalty; it distributes nothing.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. A statutory ceiling is a legal bound, not an observed exceedance — precisely the distinction ADR-0008 draws with population_ceiling.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No measured population. The relevant caveat for any figure taken from here is that it is a legal maximum, not a measurement of anyone.
read 2026-08-15

CPS 230 Operational Risk Management

Australian Prudential Regulation Authority
apra_cps_230 · sources/raw/apra_cps_230.html · sha256 8933f887d9600806…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A prudential standard. It sets obligations; it measures nothing.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. A regulatory instrument publishes requirements, not statistics.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. The maxima it mentions are tolerance settings an entity must define for itself, not observed magnitudes.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No measured population exists — this is a rule, not a study. Recorded as not published rather than as a gap, since the question does not apply to an instrument.
read 2026-08-15

State of Ransomware in Financial Services 2024

Sophos
sophos_state_ransomware_financial_services_2024 · sha256 77eed3acd2a9118b…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 1,387-word page, not State of Ransomware 2024 (financial services). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 1,387-word page, not State of Ransomware 2024 (financial services). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 1,387-word page, not State of Ransomware 2024 (financial services). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 1,387-word page, not State of Ransomware 2024 (financial services). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.

Wirtschaftsschutz 2025

Bitkom e.V.
bitkom_wirtschaftsschutz_2025 · sources/raw/bitkom_wirtschaftsschutz_2025.pdf · sha256 b7e68c140d9e6ddd…
Does it tell you the most likely loss — not the average, the most likely?
no
No Modalwert. Read with German terms after an English-only pass returned zero on every property — a false negative, since the report carries 4 "Durchschnitt", 2 "Verteilung" and 27 "Schaden".
read 2026-08-15
Does it show the spread of losses, or only one number?
no
The two "Verteilung" figures distribute the estimated IT-security budget share of total IT budget (Abbildung 19), not damage. Damage is reported as aggregate Milliarden-euro totals and averages. No Median or Perzentil anywhere.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
No überschreiten-type statement about damage magnitude.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Stated on every figure in the German convention: "Basis: Alle Unternehmen (n=1.002) | Quelle: Bitkom Research 2025"
read 2026-08-15

State of Ransomware in Manufacturing and Production 2025

Sophos
sophos_state_ransomware_manufacturing_2025 · sources/raw/sophos-state-of-ransomware-in-manufacturing-2025.pdf · sha256 c579c711f3004db6…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; "average (median)" again, used for the median.
read 2026-08-16
Does it show the spread of losses, or only one number?
yes
Chart 8, "Ransom payments in manufacturing and production | Distribution banding", with the same banding as the financial-services cut. Median ransom paid fell from $1.2M in 2024 to $1M in 2025; median demand from $1.5M to $1.2M.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated in prose, unambiguously, and this is the most directly usable exceedance found in the whole corpus: "extreme payments of $5 million or more — accounting for 18% of payments in 2025 — up from 15% last year", alongside "extreme demands of $5 million or more — accounting for a fifth (20%) of demands — up from 15% in 2024". P(payment >= $5M) = 18% over manufacturing and production organizations that paid.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Manufacturing and production organizations responding to the survey; root-cause base n=331 (2025), 375 (2024), 204 (2023). Same payer-denominator caveat as the financial-services cut.
read 2026-08-16

State of Ransomware in Manufacturing and Production 2024

Sophos
sophos_state_ransomware_manufacturing_2024 · sha256 874ecc440979cfc2…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 1,312-word page, not State of Ransomware 2024 (manufacturing). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 1,312-word page, not State of Ransomware 2024 (manufacturing). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 1,312-word page, not State of Ransomware 2024 (manufacturing). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 1,312-word page, not State of Ransomware 2024 (manufacturing). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.

Cost of Insider Risks Global Report 2023

Ponemon Institute and DTEX Systems
ponemon_dtex_cost_insider_risks_2023 · sources/raw/ponemon_dtex_cost_insider_risks_2023.pdf · sha256 1103b630847fa8f3…
Does it tell you the most likely loss — not the average, the most likely?
no
No. Every cost in the report is an average, and the report says so in its own words - 'the average cost per incident, the average number of incidents and the average annualized cost per year'. The total is given as 'the total average cost of activities to resolve insider risks over a 12-month period is $16.2 million'. The phrase 'most likely' appears repeatedly and never about a loss: it qualifies the most likely *cause* ('the most likely cause of insider risk is non-malicious'). No median, mode or most-likely loss value is published for any quantity. Read 2026-08-23 from the report itself, which had been recorded as blocked. See the artifact note below.
read 2026-08-23
Does it show the spread of losses, or only one number?
no
Not of loss, and this is the same shape as the CSA Singapore row: the report publishes real distributions, just not of a loss quantity. Figure 1 gives the 'Frequency of 7,343 incidents for three insider profiles' and Figure 2 the frequency per company; containment time is banded ('Only 13% of incidents were contained in less than 31 days', against an average of 86 days). Cost is then reported as a conditional mean across those bands and across industries - Technology $18.2M, Energy $16.9M - which is an average per stratum, not a spread over loss size. There is no distribution of cost.
read 2026-08-23
Does it say how often losses go bigger than a given size?
no
No. An exceedance statement needs a loss magnitude and a probability of passing it, and no cost figure here carries one. The nearest thing is time, not money: 13% of incidents contained in under 31 days, and organisations taking more than 91 days carrying higher average costs. That is a conditional mean by response time, and reading it as an exceedance probability over loss size would be exactly the error ADR-0008 exists to prevent.
read 2026-08-23
Can you tell who was measured — which countries, industries, sizes?
yes
Yes, and unusually precisely for a vendor-commissioned study. The benchmark sample is 309 separate organizations with 1,075 interviews, fieldwork concluding May 2023, over insider-related events in the prior 12 months, using an activity-based costing framework whose seven internal cost centres are named. Industry and headcount bands are broken out. The population is global and cross-industry, which is what makes every figure from it a bridge for any single country or sector - and that is a property of the source, stated, not a defect.
read 2026-08-23

2025 Cyber Threat Situation Statistics Data

National Police Agency of Japan
npa_japan_cyber_threats_2025_statistics · sources/raw/npa_japan_cyber_threats_2025_statistics.xlsx · sha256 ca8c90022d470b94…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal or most-likely value is stated for any loss quantity, and the workbook contains no occurrence of 中央値 (median), 平均 (mean) or 最頻 (mode) in any of its 88 sheets. It does, however, come closer than any other source read so far: sheet 統計編P126 gives investigation cost as counts across six bands, and the heaviest band — ¥10M to ¥50M with 32 of 89 cases — is a modal CLASS a reader can identify. Recorded as not published, on the ADR-0008 rule that deriving is not stating, and flagged here because a modal class is the nearest thing this corpus has found to a published mode. Previously unread: the earlier reader extracted 461 words and no CJK text, so the workbook had never actually been seen.
read 2026-08-21
Does it show the spread of losses, or only one number?
yes
Yes. Sheet 統計編P126 (調査費用の総額, total investigation cost) publishes a full banded distribution with counts, n=89: under ¥1M, 16; ¥1M–5M, 18; ¥5M–10M, 9; ¥10M–50M, 32; ¥50M–100M, 9; ¥100M and above, 5. Sheets 図表9 and 統計編P127 cross-tabulate the same cost bands against recovery duration as proportions. Note the measurement basis: this is investigation cost (調査費用), not total event loss, so it is not interchangeable with the total-breach-cost figures elsewhere in this corpus.
read 2026-08-21
Does it say how often losses go bigger than a given size?
yes
Yes, and it is stated rather than derived: the top band of 統計編P126 is open-ended at ¥100M and above, holding 5 of 89 cases, so 5.6% of reported investigations exceeded ¥100 million. The ¥50M threshold is exceeded by 14 of 89, or 15.7%. This is a within-sample rate over organizations that reported to the NPA, which is a floor rather than a population rate — non-reporting is not measured.
read 2026-08-21
Can you tell who was measured — which countries, industries, sizes?
yes
Yes, and in unusual detail. Sheet 統計編P120 gives 226 ransomware damage reports received in R7; 統計編P122 splits them by organization size (large 64, SME 143, other bodies 19) and 統計編P123 by industry (manufacturing 91, wholesale/retail 34, services 24, IT 24, construction 18, education 11, other 24). The denominators differ by question and the source says so: the cost table is n=89 and the recovery-duration table n=107, both subsets of the 226. The population is organizations that reported to the National Police Agency, never all Japanese organizations.
read 2026-08-21

NetDiligence Cyber Claims Study 2025 (Fifteenth Annual)

NetDiligence
netdiligence_cyber_claims_2025 · sources/raw/netdiligence_cyber_claims_2025.pdf · sha256 4014f4e7a52c5512…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value for any cost. The report is built on averages — the word appears 177 times — with maxima and totals per category. The single "most likely" in the text describes an unknown cause being "most likely primary", not a loss value.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Charts titled "Distribution of Crisis Services Costs" (N=4,712 SMEs) break cost down by type of activity — a composition of what a claim is spent on, not a severity distribution over claims. No median, percentile or quantile appears anywhere in the report text. Bounded by the read method: a severity distribution shown only as an unlabelled image would not be captured.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
No percentile or quantile language anywhere in the text. Severity is conveyed as an average and a maximum per category — e.g. criminal-cause crisis services at 826K average against a 16.0M maximum — which bounds what was observed and says nothing about how often it is exceeded.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Yes, and unusually well: 10,402 incidents over 2020-2024, split SME versus large company, with revenue bands and sector breakdowns including average and maximum revenue per sector.
read 2026-08-15

SPF Annual Scam and Cybercrime Brief 2025

Singapore Police Force
spf_annual_scam_cybercrime_brief_2025 · sources/raw/spf_annual_scam_cybercrime_brief_2025.pdf · sha256 5422fa57299d72ed…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal loss. Central tendency is the median loss per case.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Banded, with both ends given: "about 67.1%, suffered less than $5,000 in losses, while 5.2% of scam cases suffered at least $100,000 in losses. The median loss per case was $1,644."
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated directly: 5.2% of scam cases suffered at least $100,000 in losses. That is P(loss >= S$100,000) = 5.2% over Singapore scam cases reported to the SPF — an exceedance statement in one sentence.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Scam and cybercrime cases reported to the Singapore Police Force in the year — a police reporting population, nameable and not a business census.
read 2026-08-15

ESAs 2025 Report on major ICT-related incidents (JC 2026 16)

Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA)
esas_dora_major_ict_incidents_2025 · sources/raw/esas_dora_major_ict_incidents_2025.pdf · sha256 aecab17720869aab…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. The Joint-ESA report under DORA Article 22, with its own methodology section.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Counts and shares of major ICT-related incidents reported in the EU, broken down by category. No distribution over a magnitude, and no cost figures to distribute.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Financial entities reporting major ICT incidents under DORA, with a stated methodology — a regulatory reporting population, and an unusually well-defined one.
read 2026-08-15

Statistics Canada Table 22-10-0076-01 - Types of cyber security incidents that impact enterprises, by industry and size

Statistics Canada
statcan_cscsc_incident_types_22100076 · sources/raw/statcan_cscsc_incident_types_22100076.zip · sha256 ca161dfcffc55dae…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. A Statistics Canada data table, not a report. Read with a standard-library zip/CSV reader.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Counts and rates of cyber security incidents by NAICS industry and size of enterprise — a categorical breakdown, not a distribution over a magnitude.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None. The table carries incident rates, not loss magnitudes to be exceeded.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Canadian enterprises, classified by NAICS and size of enterprise, with STATUS and quality symbols per cell. This is a population definition, which is why the shard uses it as a denominator.
read 2026-08-15

The State of Ransomware 2023 (whitepaper, archived snapshot)

Sophos
sophos_state_ransomware_2023 · sources/raw/sophos_state_ransomware_2023.pdf · sha256 9dfbe90fce1c870b…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the report reports averages and medians of payment and recovery cost.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
Described in the text as "a wide distribution of payments", reported in bands: 40% of paying organizations reported payments of $1 million or more, and 34% paid less than $100,000.
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated by the open top band: 40% of ransom payers paid $1 million or more, up from 11% in the prior study. P(payment >= $1M) = 40% over the surveyed payers.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Survey population with base numbers given per chart, including a cyber-insurance split.
read 2026-08-15

The State of Ransomware 2024 (whitepaper, archived snapshot)

Sophos
sophos_state_ransomware_2024 · sources/raw/sophos_state_ransomware_2024.pdf · sha256 bd4f07cb2940d3da…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. The report leads with averages and medians of ransom payment and recovery cost.
read 2026-08-15
Does it show the spread of losses, or only one number?
yes
A full bucketed severity histogram: "Distribution of ransom payments 2022-24" (n=1,097 for 2024), banded from "Less than $1,000" through "$1,000,000 and $4,999,999" to "$5 million or more", with a percentage in every band.
read 2026-08-15
Does it say how often losses go bigger than a given size?
yes
Stated, by construction of the histogram's open top band: 13% of paid ransoms were "$5 million or more" in 2024. An open-ended band with a percentage is a statement that a magnitude was exceeded that often, over a named sample — unlike a dot plot, which a reader would have to count.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
Base numbers given per chart (n=965/216/1,097 by year) and the survey's organisation population is described, with an industry breakdown in the appendix.
read 2026-08-15

The State of Ransomware in Australia 2025 (whitepaper)

Sophos
sophos_state_ransomware_australia_2025 · sha256 457e1469937da7aa…
Does it tell you the most likely loss — not the average, the most likely?
blocked
What we hold is a 1,032-word PDF summary, not State of Ransomware 2025 (Australia). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it show the spread of losses, or only one number?
blocked
What we hold is a 1,032-word PDF summary, not State of Ransomware 2025 (Australia). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Does it say how often losses go bigger than a given size?
blocked
What we hold is a 1,032-word PDF summary, not State of Ransomware 2025 (Australia). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.
Can you tell who was measured — which countries, industries, sizes?
blocked
What we hold is a 1,032-word PDF summary, not State of Ransomware 2025 (Australia). The report itself is gated. Unanswerable until the document is obtained — recorded as blocked rather than unread so it cannot be mistaken for a backlog that effort will clear.

Latitude Group Holdings 1H23 Results Investor Presentation

Latitude Group Holdings Limited (ASX LFS)
latitude_1h23_results_2023 · sources/raw/latitude_1h23_results_2023.pdf · sha256 7fd0aeea79b580be…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; the document reports no loss magnitude in modal form. A single company's half-year results, used for one documented incident cost.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. It reports one company's own incurred and expected costs, which is an observation rather than a distribution.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No population. This is one entity's disclosure of one event — the reason a maximum drawn from it carries no exceedance under ADR-0008.
read 2026-08-15

SecurityBrief Australia coverage of IBM Cost of a Data Breach 2026 Australian figures

SecurityBrief Australia (TechDay)
securitybrief_ibm_au_breach_costs_2026 · sources/raw/securitybrief_ibm_au_breach_costs_2026.html · sha256 36018b189df6db8b…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Trade-press coverage of IBM's Australian breach-cost figure.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None of its own; it relays an average measured by IBM.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
No population of its own. The population belongs to IBM's study, which we hold only as a pointer — the record's own limitations already say the citation is secondary coverage rather than the gated primary.
read 2026-08-15

SingStat Table M600981 - Enterprise Landscape By SMEs And Non-SMEs, Annual

Singapore Department of Statistics
singstat_enterprise_landscape_m600981 · sources/raw/singstat_enterprise_landscape_m600981.json · sha256 4e2001c88b3abff4…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. A SingStat API response, not a publication.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
Enterprise counts by SME and non-SME — a denominator table.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None; no loss magnitudes.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
yes
"Enterprise Landscape By SMEs And Non-SMEs, Annual", Singapore Department of Statistics — a population count, which is its purpose here.
read 2026-08-15

CSA Singapore Cybersecurity Health Report 2023

Cyber Security Agency of Singapore
csa_cybersecurity_health_report_2023 · sources/raw/csa_cybersecurity_health_report_2023.pdf · sha256 f9eaf0af1de64d85…
Does it tell you the most likely loss — not the average, the most likely?
no
No. The report carries no monetary loss figure of any kind, so there is no most-likely loss value to publish. Business impact is reported entirely as the incidence of impact types - 48% business disruption, 46% data loss, 43% reputation damage, 31% financial loss for businesses (p6) - which says how often a kind of harm occurred and never how large it was. Read 2026-08-22 by rendering all 10 pages to images and reading them, after text extraction returned 791 words of headings; the substance is carried in images, and the earlier 'unverified' entry recorded that honestly rather than guessing.
read 2026-08-22
Does it show the spread of losses, or only one number?
no
Not of loss, and the distinction matters here more than usual because the report DOES publish a distribution - just not of a loss quantity. Page 5 gives incident frequency over the surveyed population: once 29%, several times a day 5%, a week 6%, a month 11%, a year 49%, not sure 1% (businesses; non-profits reported separately). That is a genuine spread over how OFTEN organisations were hit, and there is no spread over how MUCH any of it cost. Recorded false against the question as asked - does it show the spread of losses - with the frequency distribution named so it is not lost.
read 2026-08-22
Does it say how often losses go bigger than a given size?
no
No. Exceedance requires a loss magnitude to be exceeded and the report states none, so the question does not arise rather than being answered badly.
read 2026-08-22
Can you tell who was measured — which countries, industries, sizes?
yes
Yes, and specifically. More than 2,000 organisations across 23 industry sectors and 7 ITM clusters, with representation across small, medium and large organisations; 83% in operation 10 years or more; respondents at C-level, director and lead/manager. Non-profits are surveyed and reported separately (more than 7 charity sectors, 90% in operation 10 years or more). Surveyed May to August 2023 in Singapore. Every figure on the pages above is attributable to a named population, which is what this question asks.
read 2026-08-22

Business Email Compromise cost Australian victims more than $79 million in the past year

Australian Federal Police
afp_bec_australian_victim_case_2021 · sources/raw/afp_bec_australian_victim_case_2021.html · sha256 cfa1ec3ef363e312…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. An Australian Federal Police account of one BEC victim case.
read 2026-08-15
Does it show the spread of losses, or only one number?
no
None. One event.
read 2026-08-15
Does it say how often losses go bigger than a given size?
no
None — which is why the shard anchored on it declares none_known.
read 2026-08-15
Can you tell who was measured — which countries, industries, sizes?
no
One documented case; no population.
read 2026-08-15

The State of Ransomware in Financial Services 2025

Sophos
sophos_state_ransomware_financial_services_2025 · sources/raw/sophos-state-of-ransomware-in-financial-services-2025.pdf · sha256 92b2154b8f0cd2d5…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. The report writes "the average (median) ransom demand", using the two words interchangeably for the median, and never offers a most-likely figure.
read 2026-08-16
Does it show the spread of losses, or only one number?
yes
Chart 8, "Ransom payments in financial services | Distribution banding", n=147 (2025) and 90 (2024), banded from "Less than $1,000" through "Between $1,000,000 and $4,999,999" to "$5 million or more". Sector-specific, which is what makes it valuable here.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
By the open top band of Chart 8 — the same construction as the 2023 and 2024 editions, whose top bands state what share of payments passed $5M. The prose gives the medians rather than the top-band share for this cut, and the chart's percentages do not extract cleanly from the PDF columns, so the share itself is not quoted here: the exceedance is published, and reading its exact value needs the chart rather than the text.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Financial-services providers responding to the survey, n=147 for the 2025 payment question. The denominator is organizations that PAID a ransom, not all attacked — a caveat that travels with any figure taken from it.
read 2026-08-16

The State of Ransomware in Australia 2026

Sophos
sophos_state_ransomware_au_2026 · sources/raw/sophos-state-of-ransomware-in-australia-2026.pdf · sha256 b1e0e7a7eb29c7e8…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median Australian ransom demand $1.34 million; median Australian ransom payment $855,000; mean recovery cost excluding ransom $1.66 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "49% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 49% over Australia organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=119 for Australia, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in Germany 2026

Sophos
sophos_state_ransomware_de_2026 · sources/raw/sophos-state-of-ransomware-in-germany-2026.pdf · sha256 9bb9b4d4d4a8e0ae…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median German ransom demand $400,000; mean recovery cost excluding ransom $1.42 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "45% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 45% over Germany organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=139 for Germany, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in France 2026

Sophos
sophos_state_ransomware_fr_2026 · sources/raw/sophos-state-of-ransomware-in-france-2026.pdf · sha256 37bea34a3480d217…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median French ransom demand $500,000; mean recovery cost excluding ransom $2.02 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "39% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 39% over France organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=129 for France, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in Japan 2026

Sophos
sophos_state_ransomware_jp_2026 · sources/raw/sophos-state-of-ransomware-in-japan-2026.pdf · sha256 3782bad79f436282…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median Japanese ransom demand $1.75 million; median Japanese ransom payment $3 million; mean recovery cost excluding ransom $1.88 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "61% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 61% over Japan organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=152 for Japan, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in United Kingdom 2026

Sophos
sophos_state_ransomware_uk_2026 · sources/raw/sophos-state-of-ransomware-in-uk-2026.pdf · sha256 329fff7a941e6848…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median UK ransom demand $2.5 million; mean recovery cost excluding ransom $1.49 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "65% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 65% over United Kingdom organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=120 for United Kingdom, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in United States 2026

Sophos
sophos_state_ransomware_us_2026 · sources/raw/sophos-state-of-ransomware-in-us-2026.pdf · sha256 0b359dcb8acae726…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: median U.S. ransom payment $1 million; mean recovery cost excluding ransom $2.5 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
Stated as a single threshold: "55% of ransom demands were for $1 million or more". That is P(demand >= $1M) = 55% over United States organizations hit by ransomware. A threshold with a share is an exceedance statement; it is not a distribution, which is why distribution reads false for these country cuts and true for the sector cuts that carry a banded chart.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=377 for United States, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

The State of Ransomware in Singapore 2026

Sophos
sophos_state_ransomware_sg_2026 · sources/raw/sophos-state-of-ransomware-in-singapore-2026.pdf · sha256 c05f0be08438abbd…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value. Central tendency is reported as a median, and the recovery cost as a mean.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
Point statistics plus one threshold, not a distribution: mean recovery cost excluding ransom $1.14 million. No banding, percentile or quantile.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None. No ransom demand or payment figure is published for Singapore at all, which with n=33 reads as small-sample suppression rather than omission — the report gives Singapore recovery cost and impact percentages but stops before ransom levels.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Unusually precise and unusually useful: organizations with between 100 and 5,000 employees that were HIT by ransomware in the previous 12 months, n=33 for Singapore, surveyed January-March 2026, all figures in U.S. dollars. Note two constraints Sophos applies and states: the denominator is the hit population rather than all organizations, and outlier ransoms of $40 million or more were removed before publication.
read 2026-08-16

Cost of a Data Breach Report 2026

IBM
ibm_cost_data_breach_2026 · sources/raw/Cost-of-a-Data-Breach-Report-2026.pdf · sha256 0c7808f23134ff9e…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value.
read 2026-08-16
Does it show the spread of losses, or only one number?
no
None, and this is the finding. In 12,056 words about the cost of a data breach the word "average" appears 75 times and "median" does not appear once — nor does percentile, quartile, "50th" or "typical". The one heading containing "Distribution" is "Distribution by sample or region", which is the composition of the sample (ASEAN 4%, Australia 5%, US 10%), not a distribution of cost. The most-cited cyber loss figure in the field is a mean published without dispersion.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None. With no quantiles published there is nothing from which an exceedance could even be read.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Stated: organizations across 17 industries in 16 countries and regions that experienced a breach in the study window, with organization, geographic and industry demographics sections. It is a benchmarked cost study over a recruited sample, not a census — and Figure 4 gives average total cost by industry, USD 6.29M for Financial against 5.56M the prior year, which is the sector cut most relevant to our finance cells.
read 2026-08-16

2026 Cost of Insider Risks Global Report

Ponemon Institute and DTEX Systems
dtex_ponemon_cost_insider_risks_2026 · sources/raw/DTEX_Ponemon_2026.pdf · sha256 81752c526a630107…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; 50 occurrences of "average" and none of "median".
read 2026-08-16
Does it show the spread of losses, or only one number?
no
The three "distribution" mentions are categorical: the split of 7,490 analyzed attacks by insider type (53% negligence, 27% malicious, 20% outsmarted) and the industry composition of respondents. Cost is reported as means in Table 2, not distributed.
read 2026-08-16
Does it say how often losses go bigger than a given size?
no
None stated.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
A benchmark sample of 354 organizations, with 7,490 reported attacks analyzed and an industry composition given (financial services 14%, industrial 11%). Table 2 gives FY2025 average cost per incident of $747,107 for a negligent or mistaken insider, $742,125 for a criminal or malicious insider and $842,462 for an outsmarted insider, at 13.8, 6.3 and 5.3 incidents per organization per year. Note what the figure is: an activity-based remediation cost, not a total event loss.
read 2026-08-16

The State of Ransomware in Enterprise 2025

Sophos
sophos_state_ransomware_enterprise_2025 · sources/raw/sophos-state-of-ransomware-in-enterprise-2025.pdf · sha256 a6a860ff94795e70…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal value; "average (median)" again, used for the median.
read 2026-08-16
Does it show the spread of losses, or only one number?
yes
The same banded Chart 8 construction as the sector and country cuts. Median ransom demand for enterprise organizations fell 56% to $1.20 million in 2025 from $2.75 million; median paid fell to $1 million from $1.26 million.
read 2026-08-16
Does it say how often losses go bigger than a given size?
yes
By the open top band, and the movement is reported directly: a 24% decrease in the percentage of ransom demands of $5 million or more, and a 37% decrease in the percentage of payments at $5 million or more.
read 2026-08-16
Can you tell who was measured — which countries, industries, sizes?
yes
Enterprise organizations hit by ransomware, the size band ABOVE our mid-market cells. Recorded because a size contrast is evidence about size: the same survey family reports a different level for enterprises than for the 100-5,000 employee band its country cuts cover.
read 2026-08-16

The State of Ransomware 2026 (global report)

Sophos
sophos_state_ransomware_2026 · sources/raw/sophos_state_ransomware_2026.pdf · sha256 678a57d7ab358a10…
Does it tell you the most likely loss — not the average, the most likely?
no
No modal or most-likely value is offered for any loss quantity. The word "mode" appears three times and every occurrence is unrelated ("modest", "AI models"). Central tendencies are medians and means: median ransom demand USD 698,000, median ransom payment USD 769,000, mean recovery cost excluding ransom USD 1,700,200. The report goes further than most in naming the problem — it states that the widening gap between mean and median demands "signals a heavily skewed distribution" — and still publishes no most-likely value.
read 2026-08-21
Does it show the spread of losses, or only one number?
yes
Yes. A "Ransomware payment bands" chart gives the share of payers in each band (n=836), and the narrative reads the whole shape: the two highest bands, USD 1M–5M and USD 5M+, both declined while USD 20,000–99,999 and USD 500,000–999,999 grew. The bands are percentages of payers, so the denominator is organizations that paid, never organizations attacked.
read 2026-08-21
Does it say how often losses go bigger than a given size?
yes
Yes, stated rather than derived: "Just under half (48%) of payments were $1 million or more, down from 52% in the previous year." A year-on-year exceedance rate at a named threshold over a named sample. Same payer denominator as the bands — it is the share of PAYMENTS above USD 1M, not the share of incidents.
read 2026-08-21
Can you tell who was measured — which countries, industries, sizes?
yes
Yes. n=2,158 organizations surveyed January to March 2026 reporting on the previous 12 months, with prior-edition sizes given for comparison (n=3,400 in 2025, n=2,974 in 2024, n=1,974 in 2023). Sub-question denominators are stated where they differ, for example n=836 for the payment bands and n=1,022 for the attack-vector question. One gap is worth naming because it is unusual: printed page 11 carries the caption "Data split: In the last year, has your organization been hit by ransomware? n=5,000", and the answer appears nowhere in the report. The chart above that caption is three overlapping circles with no percentages and no counts. So a prevalence denominator of 5,000 was collected, the question is published in its own words, and the rate is not. Recorded here rather than only in FINDINGS because it changes what a reader may take from this source: it carries no attack rate, and not because one could not be measured.
read 2026-08-21

Singapore Cyber Landscape 2024/2025

Cyber Security Agency of Singapore
csa_singapore_cyber_landscape_2024_2025 · sources/raw/csa_singapore_cyber_landscape_2024_2025.pdf · sha256 6e58fcc4d59c26a9…
Does it tell you the most likely loss — not the average, the most likely?
no
No. The word "median" does not appear at all, and every occurrence of "mode" is "models" or "modern" rather than the statistic. Central tendencies where given are averages of operational counts — attacks blocked per hour, attack duration — not of loss.
read 2026-08-21
Does it show the spread of losses, or only one number?
no
No loss distribution, quantiles or bands. Monetary figures are national aggregates such as total scam losses, reported as single totals with year-on-year change.
read 2026-08-21
Does it say how often losses go bigger than a given size?
no
No. Nothing states how often a loss of a given size is exceeded. The report deals in national totals, which cannot yield an exceedance rate without a per-event denominator it does not publish.
read 2026-08-21
Can you tell who was measured — which countries, industries, sizes?
yes
Yes at national level — Singapore, for the reporting year, via CSA and police reporting channels. But the population that matters for a loss figure is absent: the aggregates carry no count of affected organizations, so no per-organization quantity can be recovered from them. Nameable, and not usable as an impact anchor.
read 2026-08-21

Singapore Cyber Landscape 2025/2026

Cyber Security Agency of Singapore
csa_singapore_cyber_landscape_2025_2026 · sources/raw/csa_singapore_cyber_landscape_2025_2026.pdf · sha256 1ad9d4c1e12803d6…
Does it tell you the most likely loss — not the average, the most likely?
no
No. "median" does not appear; all 53 occurrences of "mode" are "models" or "modern". The same pattern as the prior edition.
read 2026-08-21
Does it show the spread of losses, or only one number?
no
No loss distribution or bands. Scam losses are given as a national total, S$913.1 million, down 17.9% from S$1.1 billion in 2024 — a single figure with a change rate, not a spread.
read 2026-08-21
Does it say how often losses go bigger than a given size?
no
No. Individual case values appear (an operation "exceeding S$3.1 million", S$28.2 million seized) but these are instances, not statements about how often a loss of a given size is exceeded over a population.
read 2026-08-21
Can you tell who was measured — which countries, industries, sizes?
yes
Yes at national level, and with the same limitation as the prior edition: no count of affected organizations accompanies the loss totals, so the figures cannot be reduced to a per-event or per-organization quantity. This supersedes the CSA Cybersecurity Health Report 2023 as the current Singapore statistics source.
read 2026-08-21
Generated from raviaxo/RiskShard — nothing on this page is hand-written. The machine-readable form is sources/audit.yaml; the decision that created it is ADR-0015.