An exhibit is a figure from outside this index. It is drawn from a primary source, reproduced as that source published it, held to the Exhibit Rule, and named for where it came from. It is evidence from the world.
A live cut is a reading of this index’s own ledger, computed from the incidents tracked here. It is a count, never a sum. It is evidence from this record.
The two are kept apart on purpose, so a reader always knows whether a number came from the world or from this ledger.
Exhibits
EXHIBIT · PRIMARY SOURCE · FBI IC3
Reported cyber loss outgrew the market by more than six to one
Indexed from year-end 2014 to year-end 2024: $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343.
6.05×the divergence over the decade, nominal against nominal
Series: reported losses to the FBI Internet Crime Complaint Center against the S&P 500 total return, each indexed to $100 at year-end 2014.
America logged more data breaches than ever, but a shrinking share of the notices actually explained how the breach happened, even though every one of those breaches was disclosed.
“Nearly 100 percent disclosed how a breach occurred in 2020; about 30 percent by 2025.”
Source: Identity Theft Resource Center
How this is measured
Two series from one source, indexed to 2020 = 100: U.S. data compromises (count), and the share of breach notices disclosing the attack vector, on the ALL-NOTICES basis. U.S. compromises tripled, from 1,107 in 2020 to 3,322 in 2025, while the share of notices disclosing how the breach happened fell from nearly 100 percent to about 30 percent. ITRC 2025 Annual Data Breach Report, twentieth edition, January 2026, Appendix A.
Denominator: all U.S. public breach notices ITRC tracked. ITRC also publishes a cyberattack-only basis (higher: about 58 percent lacking a vector in 2023, about 73 percent in 2025); it is a different denominator and is never merged with the all-notices series shown here. Counts use the audited 2020 to 2025 table, which supersedes originally-published figures (2022 is 720, not 716; 2023 is 1,449, not the 1,400-plus first reported) and the 2021 report’s broader-definition count. ITRC has since restated the 2025 compromise total to 3,321. This series is pinned to the twentieth edition throughout.
Federal agencies met more and more of the government's cybersecurity requirements, but the auditors who check whether those agencies are actually secure found no improvement at all.
“FISMA audit focuses on compliance, not effectiveness.”
Source: U.S. Government Accountability Office
How this is measured
Both lines count the same 23 civilian CFO Act agencies (the 24 CFO Act agencies less Defense, excluded for data sensitivity), on one shared 0 to 23 scale with identical units, no indexing and no dual axis. They are two different measures of those agencies, a process check set against the security outcome it is meant to signal. The rising line counts agencies meeting compliance targets: those reporting they met 7 to 10 of the 10 cybersecurity Cross-Agency Priority targets in GAO-22-104364, 12 of 23 in FY2018 and 20 of 23 in FY2020; GAO reports this composite only for those two years, so no FY2019 point is drawn and its connector is dashed. The flat line counts agencies rated effective: those whose information security program their Inspector General rated effective, an effective-or-not rating of 6, 6, 5, 7, 5, 8 across FY2017 to FY2022 (GAO-22-104364 for FY2017 to FY2020, GAO-24-106291 for FY2021 to FY2022). OMB redefined one of the ten CAP goal targets after FY2018 (exfiltration and enhanced defenses). The FY2018 and FY2020 counts therefore span a target set that changed by one target during the period. GAO states the resulting decline on that target is not evidence of regression. Source: GAO-22-104364, Table 3, footnote d.
The quoted line is GAO's own report section heading; GAO also documents officials at six agencies raising the same compliance-versus-effectiveness concern. No incident counts appear here; this exhibit does not use them.
The insurance industry, whose entire business is pricing risk correctly, cut the price of cyber coverage in the same year that cyber claims jumped by nearly half.
Source: Marsh and the NAIC
How this is measured
Two measures, two sources, one shared unit: year-over-year percent change for 2024, drawn as two bars from a shared zero, nothing indexed. The price of cover is Marsh's US cyber renewal rate change (what buyers pay to renew, a price movement, not a price level); the volume of claims is the NAIC's reported-claim count. The 2024 cut was not a one-year blip: renewal rate changes had fallen from a 130 percent spike at the end of 2021 to outright cuts, turning negative in mid 2023, then fell about 5 percent further in 2024. This is a distinct finding from the premium-decline exhibit on this shelf: that card marks one series turning down; this one sets the price of risk against the claims in a single year, and finds the risk-pricers priced it backwards.
Marsh is a broker rate-change index; the NAIC is regulator-filed statutory data. NAIC publishes an aggregate reported-claim count only for 2023 (33,561) and 2024 (nearly 50,000, a rise it states as almost 40 percent), so the claims figure is that single year-over-year change, not a multi-year line, and interpolates nothing. The 2024 Cyber Supplement changed from a two-way to a three-way split and dropped identity-theft reporting, which breaks sub-category comparability but not the aggregate count NAIC itself compares year over year. Because this claims-versus-price finding does not depend on premium composition, it is not held by the identity-theft reporting question that holds the premium-decline exhibit. No incident-count series appears here.
When the government flags a software flaw as under active attack and demands a fast fix, organizations are now taking longer to patch it, not shorter, and fixing fewer of them on time.
Source: CISA and the Verizon DBIR
How this is measured
Two elements, two sources, one shared unit (days). The fixed reference: the CISA BOD 22-01 remediation deadline, roughly 14 to 21 days for a recently-disclosed KEV, drawn as a band because it is a range. The rising actual: the median days to fully remediate a KEV from Verizon’s 2026 DBIR survival analysis, a normalized rate, 2024 and 2025 data years. The gap between the actual and the required band is the divergence, and it widens.
The band is BOD 22-01's recent-CVE window; the directive's full range runs from 14 days for recently-disclosed CVEs up to 6 months for older ones, with CISA assigning each KEV entry its own due date, often about three weeks. The actual clears even the band's most generous edge. BOD 22-01 was revoked in June 2026 by BOD 26-04, which keeps a 14-day accelerated tier for KEV, so the reference stands; framing is scoped to the 2021 to 2026 window. The DBIR figures are a survival metric (median time to full remediation, share fully remediated), not raw KEV counts, which the DBIR's growing contributor base would distort. Verizon draws the year-over-year change itself, reading both years off one multi-year survival curve computed on a single methodology built to make the years comparable, though it does not explicitly certify the metric against its changing contributor base. The plotted median-days figure is the 2024-vs-2025 readout of that curve: the median rose from 32 days for 2024 data to 43 for 2025, and over the same step the share fully remediated fell from 38 percent to 26. That share is the share fully remediated, not remediated within the deadline.
Direct written premium rose every year from 2020, then declined in 2024, the same year reported cyber loss set a record.
Source: NAIC 2025 Report on the Cybersecurity Insurance Market, direct written premium including alien surplus lines
How this is measured
Series plotted: total U.S. cyber direct written premium, including alien surplus lines, for each year from 2020 to 2024, read from NAIC 2025 report Figure 1. The line rises every year through 2023, then turns down in 2024, the first decline in the series and a fall of 7.11 percent, in the same year reported cyber loss set a record. The decline is a real movement in this series, not a reporting artifact. Effective for the 2024 annual statement filings NAIC removed identity-theft reporting from the Cyber Supplement, formerly the Cybersecurity and Identity Theft Supplement; identity theft was a separate reporting requirement, eliminated by the NAIC working group because many entities in that market are not insurers and the data did not provide meaningful information, and its removal did not change the cyber direct written premium total plotted here. The record-loss reference in the subtitle is the FBI Internet Crime Complaint Center. IC3 reported $16.6 billion in losses for 2024, the highest annual total in that series when it occurred, since surpassed by 2025. IC3 is not plotted here and no ratio is computed between the two. The bases differ: IC3 counts losses voluntarily reported by U.S. complainants, while this series is direct written premium including alien surplus lines. The supplement's other 2024 change, from a two-way stand-alone and packaged split to a three-way primary, excess, and endorsement split, affects only the comparability of policy-type sub-categories, not this aggregate direct written premium series. This is a distinct finding from the Priced backwards exhibit on this shelf: that card sets the price of cover against the volume of claims in a single year; this one follows premium's own multi-year trajectory and marks the year it first turned down. The two are different measures and are never combined.
Figure 2 (domestic direct written premium) and Figure 3 (domestic total) disagree by 0.4 to 0.75 percent in 2020 through 2022, up to about $31.5 million, with the sign flipping (Figure 3 higher in 2020, lower in 2021 and 2022), then agree to the dollar in 2023 and 2024. This is on the domestic basis, which this exhibit does not plot, so it changes no argument here.
A count of incidents, not dollars. Sectors are counted, never summed as loss; each bar is that sector’s share of the 157 tracked incidents.
Healthcare and Life Sciences38 · 24%
Financial Services28 · 18%
Manufacturing18 · 11%
Technology and Software18 · 11%
Retail and Consumer16 · 10%
Professional and Business Services12 · 8%
Transportation and Logistics8 · 5%
Wholesale and Distribution5 · 3%
Public Sector and Education4 · 3%
Telecommunications4 · 3%
Energy and Utilities3 · 2%
Other3 · 2%
157 incidents shown, tagged approved primaries. 1 more is pending a sector and is not yet placed. 15 corroborations nest under their primary incidents and are not counted separately. So 157 plus 1 pending is 158 primaries, and the corroborations are nested, not missing.
Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.
THE FLOOR · This count is a floor, the incidents tracked to date, not a census of all breaches.