Exhibits
An exhibit is a figure from outside this index. It is drawn from a primary source, reproduced as that source published it, held to the Exhibit Rule, and named for where it came from. It is evidence from the world.
For readings of this index’s own ledger, counts computed from the incidents tracked here and refreshed on every build, see the Live Cuts. The two are kept apart on purpose, so a reader always knows whether a number came from the world or from this record.
Exhibits
Reported cyber loss outgrew the market by more than six to one
More breaches, fewer answers
“Nearly 100 percent disclosed how a breach occurred in 2020; about 30 percent by 2025.”
How this is measured
Denominator: all U.S. public breach notices ITRC tracked. ITRC also publishes a cyberattack-only basis (higher: about 58 percent lacking a vector in 2023, about 73 percent in 2025); it is a different denominator and is never merged with the all-notices series shown here. Counts use the audited 2020 to 2025 table, which supersedes originally-published figures (2022 is 720, not 716; 2023 is 1,449, not the 1,400-plus first reported) and the 2021 report’s broader-definition count. ITRC has since restated the 2025 compromise total to 3,321. This series is pinned to the twentieth edition throughout.
Compliance rose. Effectiveness did not.
“FISMA audit focuses on compliance, not effectiveness.”
How this is measured
The quoted line is GAO's own report section heading; GAO also documents officials at six agencies raising the same compliance-versus-effectiveness concern. No incident counts appear here; this exhibit does not use them.
GAO-22-104364, Cybersecurity: OMB Should Update IG Reporting Guidance (Mar 2022) ↗
Priced backwards.
How this is measured
Marsh is a broker rate-change index; the NAIC is regulator-filed statutory data. NAIC publishes an aggregate reported-claim count only for 2023 (33,561) and 2024 (nearly 50,000, a rise it states as almost 40 percent), so the claims figure is that single year-over-year change, not a multi-year line, and interpolates nothing. The 2024 Cyber Supplement changed from a two-way to a three-way split and dropped identity-theft reporting, which breaks sub-category comparability but not the aggregate count NAIC itself compares year over year. Because this claims-versus-price finding does not depend on premium composition, it is not held by the identity-theft reporting question that holds the premium-decline exhibit. No incident-count series appears here.
Marsh Global Insurance Market Index, US cyber rate change ↗
NAIC Report on the Cybersecurity Insurance Market, 2024 data ↗
Flagged urgent, patched slower
How this is measured
The band is BOD 22-01's recent-CVE window; the directive's full range runs from 14 days for recently-disclosed CVEs up to 6 months for older ones, with CISA assigning each KEV entry its own due date, often about three weeks. The actual clears even the band's most generous edge. BOD 22-01 was revoked in June 2026 by BOD 26-04, which keeps a 14-day accelerated tier for KEV, so the reference stands; framing is scoped to the 2021 to 2026 window. The DBIR figures are a survival metric (median time to full remediation, share fully remediated), not raw KEV counts, which the DBIR's growing contributor base would distort. Verizon draws the year-over-year change itself, reading both years off one multi-year survival curve computed on a single methodology built to make the years comparable, though it does not explicitly certify the metric against its changing contributor base. The plotted median-days figure is the 2024-vs-2025 readout of that curve: the median rose from 32 days for 2024 data to 43 for 2025, and over the same step the share fully remediated fell from 38 percent to 26. That share is the share fully remediated, not remediated within the deadline.
The priced record is a rounding error of the reported one
“IC3 received 859,532 complaints in 2024, with losses exceeding $16 billion.”
How this is measured
Scope differs by source and is stated on purpose: IC3 counts all cyber-enabled crime complaints, including individual victims, so it is not a count of organizational breaches; HHS counts only health-sector breaches of 500 or more individuals; this ledger counts organizational cyber incidents on the U.S. public disclosure record across all sectors. Because the populations are not nested, the bars compare magnitudes, they are not a funnel. The 2024 figures are pinned: IC3 and HHS are closed-year annual reports, and this ledger's 2024 counts are a snapshot as tracked, which can only rise as older 2024 incidents are added. The HHS figure is on the reported-in-2024 basis (742), to match how this ledger and IC3 both date by report, not occurrence; 663 of those 742 relate to breaches that occurred in 2024, a subset given for completeness. The OCR breach portal, which lists every 500-or-more breach and can be exported in full, independently carries about 735 breaches submitted in 2024, corroborating the report.
FBI IC3 2024 Internet Crime Report ↗
HHS OCR Annual Report to Congress on Breaches (2024) ↗
The health-data breach became a hack
“By 2024, hacking and IT incidents accounted for more than four in five large health-data breaches.”
How this is measured
Counts are breaches of 500 or more individuals on the reported-in-year (submission-date) basis, tallied from the OCR breach portal public export by the Type of Breach field. Theft and Loss are combined as physical-media loss; Hacking/IT Incident is OCR's category for electronic intrusion. Unauthorized Access or Disclosure, Improper Disposal, and Other are real categories but are not plotted, so the two series do not sum to the annual total. A record may list more than one breach type; it is classified once, counting Hacking/IT Incident where present. This is a distinct finding from the disclosure-gap and enforcement questions on this shelf: it is about how breaches happen, not how many reach the record.