Exhibits

What an exhibit is

An exhibit is a figure from outside this index. It is drawn from a primary source, reproduced as that source published it, held to the Exhibit Rule, and named for where it came from. It is evidence from the world.

For readings of this index’s own ledger, counts computed from the incidents tracked here and refreshed on every build, see the Live Cuts. The two are kept apart on purpose, so a reader always knows whether a number came from the world or from this record.

Exhibits

EXHIBIT · PRIMARY SOURCE · FBI IC3

Reported cyber loss outgrew the market by more than six to one

Indexed from year-end 2014 to year-end 2024: $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343.
6.05× the divergence over the decade, nominal against nominal
Series: reported losses to the FBI Internet Crime Complaint Center against the S&P 500 total return, each indexed to $100 at year-end 2014.

More breaches, fewer answers

America logged more data breaches than ever, but a shrinking share of the notices actually explained how the breach happened, even though every one of those breaches was disclosed.
100200300 202020212022202320242025 2020 = 100 U.S. breaches3,322 (record)Share of notices explaining how30%index
“Nearly 100 percent disclosed how a breach occurred in 2020; about 30 percent by 2025.”
Source: Identity Theft Resource Center
How this is measured
Two series from one source, indexed to 2020 = 100: U.S. data compromises (count), and the share of breach notices disclosing the attack vector, on the ALL-NOTICES basis. U.S. compromises tripled, from 1,107 in 2020 to 3,322 in 2025, while the share of notices disclosing how the breach happened fell from nearly 100 percent to about 30 percent. ITRC 2025 Annual Data Breach Report, twentieth edition, January 2026, Appendix A.

Denominator: all U.S. public breach notices ITRC tracked. ITRC also publishes a cyberattack-only basis (higher: about 58 percent lacking a vector in 2023, about 73 percent in 2025); it is a different denominator and is never merged with the all-notices series shown here. Counts use the audited 2020 to 2025 table, which supersedes originally-published figures (2022 is 720, not 716; 2023 is 1,449, not the 1,400-plus first reported) and the 2021 report’s broader-definition count. ITRC has since restated the 2025 compromise total to 3,321. This series is pinned to the twentieth edition throughout.

ITRC Annual Data Breach Report (2025, 20th ed.) ↗

Compliance rose. Effectiveness did not.

Federal agencies met more and more of the government's cybersecurity requirements, but the auditors who check whether those agencies are actually secure found no improvement at all.
23 = all agencies 05101520 201720182019202020212022fiscal year agencies FY2019 not reportedMeeting most targets20 of 23 (87%)12 of 23 (52%)Rated effective by IG8 of 23
“FISMA audit focuses on compliance, not effectiveness.”
Source: U.S. Government Accountability Office
How this is measured
Both lines count the same 23 civilian CFO Act agencies (the 24 CFO Act agencies less Defense, excluded for data sensitivity), on one shared 0 to 23 scale with identical units, no indexing and no dual axis. They are two different measures of those agencies, a process check set against the security outcome it is meant to signal. The rising line counts agencies meeting compliance targets: those reporting they met 7 to 10 of the 10 cybersecurity Cross-Agency Priority targets in GAO-22-104364, 12 of 23 in FY2018 and 20 of 23 in FY2020; GAO reports this composite only for those two years, so no FY2019 point is drawn and its connector is dashed. The flat line counts agencies rated effective: those whose information security program their Inspector General rated effective, an effective-or-not rating of 6, 6, 5, 7, 5, 8 across FY2017 to FY2022 (GAO-22-104364 for FY2017 to FY2020, GAO-24-106291 for FY2021 to FY2022). OMB redefined one of the ten CAP goal targets after FY2018 (exfiltration and enhanced defenses). The FY2018 and FY2020 counts therefore span a target set that changed by one target during the period. GAO states the resulting decline on that target is not evidence of regression. Source: GAO-22-104364, Table 3, footnote d.

The quoted line is GAO's own report section heading; GAO also documents officials at six agencies raising the same compliance-versus-effectiveness concern. No incident counts appear here; this exhibit does not use them.

GAO-22-104364, Cybersecurity: OMB Should Update IG Reporting Guidance (Mar 2022) ↗

GAO-24-106291, Cybersecurity: OMB Should Improve Information Security Performance Metrics (Jan 2024) ↗

Priced backwards.

The insurance industry, whose entire business is pricing risk correctly, cut the price of cyber coverage in the same year that cyber claims jumped by nearly half.
0%+20%+40% Year-over-year change, 2023 to 2024 0 = no change-5%Price of cover (Marsh)+40%Reported claims (NAIC)Both bars: year-over-year percent change for 2024. Marsh = price (rate change), NAIC = claim count.
Source: Marsh and the NAIC
How this is measured
Two measures, two sources, one shared unit: year-over-year percent change for 2024, drawn as two bars from a shared zero, nothing indexed. The price of cover is Marsh's US cyber renewal rate change (what buyers pay to renew, a price movement, not a price level); the volume of claims is the NAIC's reported-claim count. The 2024 cut was not a one-year blip: renewal rate changes had fallen from a 130 percent spike at the end of 2021 to outright cuts, turning negative in mid 2023, then fell about 5 percent further in 2024. This is a distinct finding from the premium-decline exhibit on this shelf: that card marks one series turning down; this one sets the price of risk against the claims in a single year, and finds the risk-pricers priced it backwards.

Marsh is a broker rate-change index; the NAIC is regulator-filed statutory data. NAIC publishes an aggregate reported-claim count only for 2023 (33,561) and 2024 (nearly 50,000, a rise it states as almost 40 percent), so the claims figure is that single year-over-year change, not a multi-year line, and interpolates nothing. The 2024 Cyber Supplement changed from a two-way to a three-way split and dropped identity-theft reporting, which breaks sub-category comparability but not the aggregate count NAIC itself compares year over year. Because this claims-versus-price finding does not depend on premium composition, it is not held by the identity-theft reporting question that holds the premium-decline exhibit. No incident-count series appears here.

Marsh Global Insurance Market Index, US cyber rate change ↗

NAIC Report on the Cybersecurity Insurance Market, 2024 data ↗

NAIC Report on the Cyber Insurance Market, 2023 data ↗

Flagged urgent, patched slower

When the government flags a software flaw as under active attack and demands a fast fix, organizations are now taking longer to patch it, not shorter, and fixing fewer of them on time.
02040 20242025 daysBOD 22-01 deadline, ~14 to 21 days32 days43 daysMedian days to remediate a KEV (DBIR)Deadline: CISA BOD 22-01 (a range). Actual: Verizon 2026 DBIR median days to full remediation, 2024 and 2025 data.
Source: CISA and the Verizon DBIR
How this is measured
Two elements, two sources, one shared unit (days). The fixed reference: the CISA BOD 22-01 remediation deadline, roughly 14 to 21 days for a recently-disclosed KEV, drawn as a band because it is a range. The rising actual: the median days to fully remediate a KEV from Verizon’s 2026 DBIR survival analysis, a normalized rate, 2024 and 2025 data years. The gap between the actual and the required band is the divergence, and it widens.

The band is BOD 22-01's recent-CVE window; the directive's full range runs from 14 days for recently-disclosed CVEs up to 6 months for older ones, with CISA assigning each KEV entry its own due date, often about three weeks. The actual clears even the band's most generous edge. BOD 22-01 was revoked in June 2026 by BOD 26-04, which keeps a 14-day accelerated tier for KEV, so the reference stands; framing is scoped to the 2021 to 2026 window. The DBIR figures are a survival metric (median time to full remediation, share fully remediated), not raw KEV counts, which the DBIR's growing contributor base would distort. Verizon draws the year-over-year change itself, reading both years off one multi-year survival curve computed on a single methodology built to make the years comparable, though it does not explicitly certify the metric against its changing contributor base. The plotted median-days figure is the 2024-vs-2025 readout of that curve: the median rose from 32 days for 2024 data to 43 for 2025, and over the same step the share fully remediated fell from 38 percent to 26. That share is the share fully remediated, not remediated within the deadline.

CISA BOD 22-01, KEV remediation deadline ↗

Verizon 2026 DBIR, KEV remediation survival analysis ↗

Premiums fell in the record-loss year

Direct written premium rose every year from 2020, then declined in 2024, the same year reported cyber loss set a record.
$2.00B$4.00B$6.00B$8.00B$10.0B 20202021202220232024 $9.14BFirst ever decline, down 7.11%$9.84B
Source: NAIC 2025 Report on the Cybersecurity Insurance Market, direct written premium including alien surplus lines
How this is measured
Series plotted: total U.S. cyber direct written premium, including alien surplus lines, for each year from 2020 to 2024, read from NAIC 2025 report Figure 1. The line rises every year through 2023, then turns down in 2024, the first decline in the series and a fall of 7.11 percent, in the same year reported cyber loss set a record. The decline is a real movement in this series, not a reporting artifact. Effective for the 2024 annual statement filings NAIC removed identity-theft reporting from the Cyber Supplement, formerly the Cybersecurity and Identity Theft Supplement; identity theft was a separate reporting requirement, eliminated by the NAIC working group because many entities in that market are not insurers and the data did not provide meaningful information, and its removal did not change the cyber direct written premium total plotted here. The record-loss reference in the subtitle is the FBI Internet Crime Complaint Center. IC3 reported $16.6 billion in losses for 2024, the highest annual total in that series when it occurred, since surpassed by 2025. IC3 is not plotted here and no ratio is computed between the two. The bases differ: IC3 counts losses voluntarily reported by U.S. complainants, while this series is direct written premium including alien surplus lines. The supplement's other 2024 change, from a two-way stand-alone and packaged split to a three-way primary, excess, and endorsement split, affects only the comparability of policy-type sub-categories, not this aggregate direct written premium series. This is a distinct finding from the Priced backwards exhibit on this shelf: that card sets the price of cover against the volume of claims in a single year; this one follows premium's own multi-year trajectory and marks the year it first turned down. The two are different measures and are never combined.

Figure 2 (domestic direct written premium) and Figure 3 (domestic total) disagree by 0.4 to 0.75 percent in 2020 through 2022, up to about $31.5 million, with the sign flipping (Figure 3 higher in 2020, lower in 2021 and 2022), then agree to the dollar in 2023 and 2024. This is on the domestic basis, which this exhibit does not plot, so it changes no argument here.

NAIC 2025 Report on the Cybersecurity Insurance Market, Figure 1 ↗

The priced record is a rounding error of the reported one

In 2024, U.S. public records counted cyber incidents by the hundreds of thousands. The corporate disclosure record this index tracks logged 59, and put a dollar figure on nine.
101001k10k100k1Mcount, log scale (each line = 10x) Cyber-crime complaints to the FBI (IC3 2024)859,532Health-data breaches of 500+ (reported to HHS, 2024)742Incidents on this disclosure ledger (this index, 2024)59Of those, carrying a dollar figure (this index, 2024)9
“IC3 received 859,532 complaints in 2024, with losses exceeding $16 billion.”
Source: FBI IC3, HHS OCR, and this ledger
How this is measured
Four public counts of cyber incidents for calendar year 2024, on a shared logarithmic scale. Cyber-enabled crime complaints to the FBI Internet Crime Complaint Center: 859,532 (all victims, individuals and organizations; IC3 2024 Internet Crime Report). Breaches of 500 or more individuals reported to HHS OCR in 2024: 742 (health-sector organizations only; HHS OCR Annual Report to Congress on Breaches, 2024; corroborated at about 735 by counting 2024 submission dates in the OCR breach portal active and archive exports). Cyber incidents on this index's public disclosure ledger, all sectors: 59. Of those, the number carrying any stated dollar figure: 9. The four counts measure different, non-nested populations; each is labeled with its scope, and none is a subset of another. The point is scale, not containment: even the narrowest mandatory breach registry, one sector, dwarfs the whole priced record.

Scope differs by source and is stated on purpose: IC3 counts all cyber-enabled crime complaints, including individual victims, so it is not a count of organizational breaches; HHS counts only health-sector breaches of 500 or more individuals; this ledger counts organizational cyber incidents on the U.S. public disclosure record across all sectors. Because the populations are not nested, the bars compare magnitudes, they are not a funnel. The 2024 figures are pinned: IC3 and HHS are closed-year annual reports, and this ledger's 2024 counts are a snapshot as tracked, which can only rise as older 2024 incidents are added. The HHS figure is on the reported-in-2024 basis (742), to match how this ledger and IC3 both date by report, not occurrence; 663 of those 742 relate to breaches that occurred in 2024, a subset given for completeness. The OCR breach portal, which lists every 500-or-more breach and can be exported in full, independently carries about 735 breaches submitted in 2024, corroborating the report.

FBI IC3 2024 Internet Crime Report ↗

HHS OCR Annual Report to Congress on Breaches (2024) ↗

HHS OCR breach portal (the underlying 500-or-more record) ↗

This index: the government-record ledger ↗

The health-data breach became a hack

A decade ago, most large health-data breaches were stolen or lost physical media. Theft and loss then fell by ninety percent while hacking and IT intrusions rose more than fifteenfold, and the hooded intruder became the breach.
0200400600 20142015201620172018201920202021202220232024 breaches Hacking / IT intrusion612Theft & loss of physical media15
“By 2024, hacking and IT incidents accounted for more than four in five large health-data breaches.”
Source: HHS OCR breach portal
How this is measured
Two breach-cause counts on one axis, 2014 to 2024, from the HHS OCR breach portal (active and archive exports, breaches of 500 or more individuals). Hacking/IT Incident, per year: 39, 56, 114, 149, 165, 314, 457, 546, 568, 608, 612. Theft plus Loss of physical media, per year: 154, 105, 77, 71, 54, 53, 52, 34, 30, 16, 15. The lines cross around 2015 to 2016: hacking overtook theft and loss and kept climbing, while theft and loss fell in absolute terms even as total breaches doubled. These are two of OCR's cause categories; the remainder, chiefly Unauthorized Access or Disclosure, is not plotted, so the two lines do not sum to all breaches. The window starts at 2014 to sit clear of the 2009-2010 HITECH reporting ramp.

Counts are breaches of 500 or more individuals on the reported-in-year (submission-date) basis, tallied from the OCR breach portal public export by the Type of Breach field. Theft and Loss are combined as physical-media loss; Hacking/IT Incident is OCR's category for electronic intrusion. Unauthorized Access or Disclosure, Improper Disposal, and Other are real categories but are not plotted, so the two series do not sum to the annual total. A record may list more than one breach type; it is classified once, counting Hacking/IT Incident where present. This is a distinct finding from the disclosure-gap and enforcement questions on this shelf: it is about how breaches happen, not how many reach the record.

HHS OCR breach portal (500-or-more record) ↗

Live Cuts, from this index’s own ledger →  ·  ← Back to the index