Gomes Security · Sources & attribution — the sixteen decisions

Where the numbers come from.

Compiled 2026-09-03 · Cited, never reproduced

How to read this page

Every dollar figure and every statistic in the sixteen decisions is an attributed figure, not a reproduced one. Nothing here is a chart, a table, or a passage lifted off a publisher's page — each entry below names the publication, the publisher, the year, and the kind of number the site draws from it, and stops there.

The industry-research families — CrowdStrike, Mandiant, IBM/Ponemon, Verizon, the Identity Theft Resource Center, Sophos, Coalition, and Hiscox — are cited at the report level: one bibliography entry per publication, not one per statistic, because that is the level at which each report is actually licensed to be read and quoted.

IBM/Ponemon's Cost of a Data Breach ships two entries because two separate editions are in play on this site: the 2025 edition's Figures 7, 9, 13–14, and 39 are shown as an industry reference beside each decision on the main instrument page, while story-copy dollars draw mostly from the 2026 edition; the per-story index below says which edition each decision uses.

Figures tied to a specific incident don't get their own bibliography entry — naming the report that covered one specific breach would start to re-identify the anonymized scenario it illustrates. They carry one collective line instead:

Figures tied to individual incidents are real and verified against primary records — securities filings, breach notices, court filings, and contemporaneous company statements — on file with Gomes Security. They are cited here at the publication level only, so the illustrative scenarios stay illustrative.

The FedRAMP 20x KSI and CIS Controls v8 chips shown on each story card are leading-practice cross-references, not evidence citations, and are not repeated in the bibliography below.

≈ marks a share read off the Fig. 9 scatter. Shared vectors counted once. Dollars are never guessed. Where no IBM/Ponemon vector applies, the card says so, and the rank never depends on it.

CR26 is optional today for Rev5 providers — its vulnerability rules bind 2026-12-07, the rest 2027-01-01. The platform tracks them now.

Deterministic by designThe math doesn't improvise.

The numbers on the instrument page are computed, not generated: forecasts, rankings, dollar figures, propagation counts. Same inputs, same answer, every time.

AI drafts paperwork on this platform. It never makes a decision, computes a number, or approves a change. The checks that guard your record run with no AI in them at all — and a named person signs every change.

Agents can hallucinate. Math can't. And when the data can't support an answer, the platform says so — it abstains instead of guessing.

Two kinds of numbers live on the instrument page: records and forecasts. Records are looked up — or marked “not assessed.” Never guessed. Forecasts are computed the same way every run, and always arrive as a range. We never dress one up as the other.

Carried over from the instrument page's own determinism strip when the landing went hero-only (2026-09-03); “here”/“this page” became “the instrument page” — no other word changed. The platform behind these pages is GS|ATO.

How the dollar bands are modeledSourced inputs, run through the platform's own engine

How the dollars on the sixteen decisions are made. Every dollar band is computed, not written: the platform's own risk and cost math (a FAIR loss-exposure simulation, 10,000 draws, seeded from the inputs so the same inputs give the same numbers) run on inputs that are sourced, not guessed. Every dollar is sized for a small SaaS team, the scale the platform uses throughout the sixteen decisions. The sixteen are ranked by that modeled figure, largest modeled dollar at risk first, and each card shows the modeled range before the rounded figure. The IBM/Ponemon per-vector figures on the cards sit next to it as an industry reference only — never the depth axis, never the rank. The four decisions with no matching IBM/Ponemon vector are ranked the same way as the other twelve, from their own modeled figure alone. Loss per event is anchored on Coalition's 2026 Cyber Claims Report figure for companies under $25 million in revenue, split into FAIR's loss forms by the IBM/Ponemon Cost of a Data Breach 2025 cost categories (response; fines and judgments; reputation, which includes lost business and notification); ransomware-class decisions use Coalition's ransomware claim average and Sophos's 2026 recovery cost. How often each loss event happens uses Hiscox's 2026 small-business attack rate times the decision's own vector share from the Verizon DBIR 2026, Mandiant M-Trends 2026, CrowdStrike, IBM/Ponemon, or OMB FISMA, as the card cites. Labor is priced at the BLS May 2024 wage for information security analysts times the loaded rate the cards state; tools at the vendors' own list prices, each page fetched and hashed. The stronger control's effect on frequency is the engine's own rule; where a published study measures a magnitude effect (intact backups, Sophos 2024) it is applied and named. Every band is modeled and unsigned: it is the platform's math on public inputs for a staged team, not a certified assessment for a real client, and the inputs, sources, and seeds are on file. As of 2026-09-04.

Applies to the ROI block and the dollar figure on all sixteen story cards, on the instrument page.

Your contract, your numberTyped once, kept on your device, never sent

The home page can take your federal contract's yearly value. Type it in and the “Late or lost ATO” line becomes your own number: a month of waiting on the ATO costs one twelfth of that value, the rule this site's own cost notes use for a month of delay. If the ATO is pulled, the whole value is on the line, plus a re-authorization. This is the platform's own rule, not a figure from an outside report.

The number stays in your browser's local storage, on your device. The page sends nothing. Clearing your browser's site data removes it.

How the control risk tier is coloredSourced mitigation coverage, run through a fixed cut rule

For each of the 31 controls behind the sixteen decisions, the platform reads every ATT&CK technique the CTID ATT&CK-to-NIST SP 800-53 mapping marks that control as mitigating, matches each technique (or its parent, for a sub-technique) against the ten techniques with the highest share of analyzed malware samples exhibiting them — the Picus Red Report 2026's own “Prevalence” column — and sums the prevalence percentages of the ones that match. A technique the mapping marks as detected but not mitigated is excluded from this headline score and instead counted at half weight in a separate sensitivity score, so a technique that is both mitigated and detected is never counted twice. The 31 controls are ranked by that score, descending, and cut into rough thirds — a tied score group sitting on the boundary is kept together in the higher tier — giving two rated tiers, stops the most common ways in and stops common ways in. Any control scoring exactly zero always falls outside those two tiers, not rated against the ten most common techniques, regardless of its rank: that is thirteen of the thirty-one controls, of which five do mitigate real techniques, just none among the ten most common, and eight have no mitigation mapping on record at all. Not rated is an absence, not a finding — never a claim that a control is weak or off the attacker's path. As of 2026-09-04.

Applies to the risk-tier color on every control icon shown on the instrument page.

The bibliographyTwenty publications, cited once each

01 · Industry research · 2025 edition

IBM/Ponemon Cost of a Data Breach, 2025

IBM Security, research by Ponemon Institute

Cited for the per-vector cost-and-frequency breakdown (Figures 7, 9, 13–14, 39) shown as an industry reference beside each decision on the main instrument page, and for one decision's malicious-insider cost figure in its own cost line.

This is the earlier of the two Cost of a Data Breach editions cited on this site — see “How to read this page” above for which figures come from which edition.

Access — free to read; registration required.
02 · Industry research · 2026 edition

IBM/Ponemon Cost of a Data Breach, 2026

IBM Security, research by Ponemon Institute

Cited for headline breach-cost figures (global and U.S. averages, days to identify and contain) and vector-specific cost figures — phishing, supply chain, public-facing exploits, help-desk impersonation, business-partner compromise — used across nine of the sixteen decisions' cost lines.

Access — free to read; registration required.
03 · Industry research · 2026 edition

Verizon Data Breach Investigations Report (DBIR), 2026

Verizon Business

Cited for third-party involvement in breaches (48%), vulnerability exploitation as the leading initial-access vector (31%), and KEV remediation outcomes — about one in four fully remediated, forty-three-day median (report pp. 10, 17) — used in two decisions.

Access — access terms as published.
04 · Industry research · 2026 edition

Mandiant M-Trends, 2026

Mandiant (Google Cloud)

Cited for intrusion dwell-time and detection-method figures (median time to detection, externally notified vs. self-detected) and cloud-intrusion initial-access-vector prevalence (vishing, exploitation), used across three decisions.

Access — access terms as published.
05 · Industry research · 2026 edition

CrowdStrike Global Threat Report, 2026

CrowdStrike

Cited for the malware-free-intrusion share, the valid-account-abuse share of cloud incidents, attacker lateral-movement timing, and the count of organizations whose own AI assistants were talked into unauthorized actions, used across four decisions.

Access — access terms as published.
06 · Industry research · H1 2026 edition

Identity Theft Resource Center, H1 2026 Data Breach Report

Identity Theft Resource Center (ITRC)

Cited for the share of breach notices that disclosed how the attack happened, and a single-incident concentration figure for one breach-notice category, used across two decisions.

Access — access terms as published.
07 · Industry research · 2026 edition

Sophos, The State of Ransomware, 2026

Sophos

Cited for ransomware recovery cost, ransom payment rate, median ransom demand, and the added recovery cost when backups are also compromised, used across two decisions.

Access — access terms as published.
08 · U.S. government work

CISA Known Exploited Vulnerabilities (KEV) Catalog

Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security

Cited for the “actively exploited” vulnerability listing and its remediation-due-date mechanism (Binding Operational Directive 22-01), referenced in one decision's mechanism and cost line.

Access — U.S. government work, public domain (17 U.S.C. §105).
09 · U.S. government work · FY2023, latest published

OMB FISMA Fiscal Year 2023 Annual Report to Congress

Office of Management and Budget (OMB)

Cited for the federal-incident-category breakdown — improper usage as the leading category — used in one decision. FY2023 was the latest published edition as of this citation; it is the oldest-dated source in this bibliography.

Access — U.S. government work, public domain (17 U.S.C. §105).
10 · U.S. government work · May 2024 (edition pinned at engagement scoping)

BLS Occupational Employment and Wage Statistics — Information Security Analysts

U.S. Bureau of Labor Statistics (BLS)

Cited for the median hourly wage for information security analysts, scaled by 1.33 to the $80/hour loaded rate the cards use, underlying every one of the sixteen decisions' fix-cost estimate.

Access — U.S. government work, public domain (17 U.S.C. §105).
11 · Vendor threat-intelligence reporting

Google Threat Intelligence / Mandiant vendor-compromise reporting

Google Threat Intelligence / Mandiant (Google Cloud)

Cited for publication-level reporting on a vendor-credential compromise, alongside contemporaneous press coverage, used in one decision. Cited at the publication level only — no incident-specific article title or URL, consistent with this page's de-identification rule (see Licensing & Attribution below).

Access — access terms as published.
12 · U.S. government program documents

FedRAMP program documents — Consolidated Rules 2026 (CR26) and RFC-0031

FedRAMP Program Management Office, U.S. General Services Administration

Cited for the clocks that govern nine of the sixteen decisions: the one-hour incident report (current Incident Communications Procedures, which RFC-0031 revises), and from CR26 the 192-day accepted-vulnerability line, the monthly human-readable reporting MUST, the PAIN remediation clocks, the Corrective Action Plan / possible revocation consequence for a missed report, and the Class-C quarterly review requirement.

Access — U.S. government work, public domain (17 U.S.C. §105).
13 · U.S. government work · Control authority

NIST SP 800-53 Revision 5 + SP 800-53A

National Institute of Standards and Technology (NIST)

No statistic is drawn from these documents directly. They are the control-language and assessment-procedure authority behind every one of the sixteen decisions' anchor controls and the FedRAMP High baseline itself — constant across all sixteen, so it is listed once here rather than repeated on every row of the index below.

Access — U.S. government work, public domain (17 U.S.C. §105).
14 · Consultancy & tool-vendor estimates

Moderate re-authorization cost and timeline estimates

Secureframe, Vanta, Paramify, Knox Systems, CISGuard

Cited for the $250,000 to $2 million and 12 to 24 months range used for a late-or-lost Moderate re-authorization, referenced in two decisions. FedRAMP publishes no official figure for this; these are consultancy and tool-vendor estimates, attributed at the publication level, directional only.

Access — publicly published estimates, access terms as published.
15 · Industry research · 2026 edition

Coalition Cyber Claims Report, 2026

Coalition, Inc. (via Risk & Insurance coverage)

Cited for the loss-per-event anchor behind the modeled ROI band on every one of the sixteen decisions: the average claim severity for policyholders under $25 million in revenue, and the ransomware-claim average used for the three destructive-class decisions. See “How the dollar bands are modeled” above.

Access — accessed via secondary trade-press coverage (Risk & Insurance); Coalition's own report was not directly fetched this pass.
16 · Industry research · 2026 edition

Hiscox Cyber Readiness Report, 2026

Hiscox

Cited for the share of small businesses attacked in the past twelve months (56%), used as the loss-event-frequency base rate for the modeled ROI band on every one of the sixteen decisions. See “How the dollar bands are modeled” above.

Access — free to read (PDF).
17 · Industry research · 2024 fielding

Sophos, The Impact of Compromised Backups on Ransomware Outcomes, 2024

Sophos, fielded by Vanson Bourne (2,974 organizations hit by ransomware) — a distinct study from the 2026 State of Ransomware report cited separately above

Cited for the recovery-cost magnitude effect of compromised vs. intact backups (eight times higher: $3M vs. $375K) applied to one decision's modeled ROI band. See “How the dollar bands are modeled” above.

Access — free to read (vendor blog).
18 · Vendor list prices · fetched 2026-09-04

Vendor list-price pages, fetched and hashed on 2026-09-04

Multiple named-brand identity, secrets-management, SIEM, breach-and-attack-simulation, continuous-monitoring, and penetration-testing tool vendors

Cited for the cost of the stronger control in each decision's modeled ROI band: hardware security keys, identity and lifecycle-management licensing, secrets-manager and SIEM infrastructure, breach-and-attack-simulation and continuous-monitoring platform licensing, object-lock backup storage, penetration-testing engagements, and similar control-specific line items — each priced at the vendor's own published list price, marketplace listing, or product documentation. See “How the dollar bands are modeled” above. Held as one collective entry rather than naming each vendor, so a story's cost line stays about the control, not the product behind it.

Access — eleven pages fetched directly and hashed, 2026-09-04; publicly published, no registration required.
19 · Mapping data · commit 5998957f

ATT&CK 16.1 to NIST SP 800-53 Revision 5 mapping (enterprise), CTID Mappings Explorer

Center for Threat-Informed Defense (CTID)

Cited for the control-to-technique mitigates mapping behind the risk-tier color shown on each control icon on the instrument page: 2,782 mitigates-type mapping rows across the 31 scored controls, collapsing to 1,055 after de-duplication (5,264 mitigates-type rows exist across the full 443-control crosswalk table; a separately-sourced GSA .govCAR strength-score dataset sharing that same table is not used here). See “How the control risk tier is colored” above.

Access — license: see the project's repository.
20 · Industry research · Red Report 2026

Picus Red Report 2026

Picus Security (Picus Labs) — 1,084,718 malware samples analyzed in 2025; 13,321,128 total TTP observations mapped to ATT&CK

Cited for ATT&CK technique-prevalence percentages used as attributed inputs to the risk-tier color shown on each control icon on the instrument page — matched against the mapping above, never reproduced as a table. See “How the control risk tier is colored” above.

Access — access terms as published; the ten prevalence figures used here were retrieved 2026-09-04 by an automated text fetch of the publisher's page (self-dated 2026-02-24), not a byte-level capture, so the sha256 on file covers the extracted figures only, not the page's raw bytes.

Per-story reference indexWhich sources each decision draws on

The BLS wage table backs every decision's fix-cost line, so it appears in every row below; the other entries vary by decision. NIST SP 800-53 anchors every decision's control but isn't repeated per row — see entry 13 above.

#DecisionDraws on
01Their Own RoomITRC H1 2026·BLS OES 2024
02Never RestoredIBM CoDB 2025·Sophos SoR 2026·Sophos 2024·BLS OES 2024
03Fire DrillFedRAMP CR26/RFC-0031·Sophos SoR 2026·BLS OES 2024
04Who Can Copy?CrowdStrike GTR 2026·IBM CoDB 2026·BLS OES 2024
05Takes TwoCrowdStrike GTR 2026·BLS OES 2024
06Nobody LookedMandiant M-Trends 2026·IBM CoDB 2026·FedRAMP CR26·BLS OES 2024
07Tell Them FirstMandiant M-Trends 2026·FedRAMP CR26·BLS OES 2024·Consultancy est.
08Allow AllVerizon DBIR 2026·FedRAMP CR26·BLS OES 2024
09Where Data LivesOMB FISMA FY23·IBM CoDB 2025·BLS OES 2024
10Fixed by Wednesday *Verizon DBIR 2026·IBM CoDB 2026·CISA KEV·FedRAMP CR26·BLS OES 2024
11Twelve MinutesITRC H1 2026·IBM CoDB 2026·FedRAMP CR26·BLS OES 2024·Consultancy est.
12One Weak DoorMandiant M-Trends 2026·IBM CoDB 2026·FedRAMP CR26·BLS OES 2024
13Wait a WeekIBM CoDB 2026·FedRAMP CR26·BLS OES 2024
14Leftover AccessCrowdStrike GTR 2026·IBM CoDB 2026·BLS OES 2024
15Forgotten KeyGoogle TI/Mandiant reporting·IBM CoDB 2026·FedRAMP CR26·BLS OES 2024
16Sorry, No ResetCrowdStrike GTR 2026·IBM CoDB 2026·BLS OES 2024

* Fixed by Wednesday's exposure line cites the 2025 edition's vulnerability-exploitation vector ($4.24M) — the exposure basis stays on the 2025 table by policy. Its cost line cites the 2026 edition's public-facing-application exploit vector ($4.68M) (IBM CoDB 2026). Different editions, adjacent categories; neither supersedes the other.

What the names meanThe NIST SP 800-53 Rev 5 name for each control on the instrument

On the instrument every control is shown by its NIST SP 800-53 Rev 5 name. This table maps each name to its control identifier. The instrument's reach counts are out of 1,014 — every active control and enhancement in the platform's NIST SP 800-53 Rev 5 control map; the stack page's 410, 323 and 156 are the FedRAMP High, Moderate and Low baselines drawn from that map.

Name shown on the instrumentNIST SP 800-53 Rev 5 control (ID)
Account ManagementAC-2
Access EnforcementAC-3
Information Flow EnforcementAC-4
Separation of DutiesAC-5
Least PrivilegeAC-6
Use of External SystemsAC-20
Role-based TrainingAT-3
Audit Record Review, Analysis, and ReportingAU-6
Information ExchangeCA-3
Continuous MonitoringCA-7
Least FunctionalityCM-7
User-installed SoftwareCM-11
Information LocationCM-12
Signed ComponentsCM-14
Contingency Plan TestingCP-4
System BackupCP-9
System Recovery and ReconstitutionCP-10
Identification and Authentication (Organizational Users)IA-2
Authenticator ManagementIA-5
Identification and Authentication (Non-organizational Users)IA-8
Incident Response TestingIR-3
Incident HandlingIR-4
Incident ReportingIR-6
Personnel TerminationPS-4
Vulnerability Monitoring and ScanningRA-5
External System ServicesSA-9
Developer Testing and EvaluationSA-11
Information in Shared System ResourcesSC-4
Flaw RemediationSI-2
System MonitoringSI-4
Software, Firmware, and Information IntegritySI-7
Notification AgreementsSR-8
Name shown on the instrumentFamily
Access ControlAC
Awareness and TrainingAT
Audit and AccountabilityAU
Assessment, Authorization, and MonitoringCA
Configuration ManagementCM
Contingency PlanningCP
Identification and AuthenticationIA
Incident ResponseIR
Personnel SecurityPS
Risk AssessmentRA
System and Services AcquisitionSA
System and Communications ProtectionSC
System and Information IntegritySI
Supply Chain Risk ManagementSR

The stack pageWhere the stack page's numbers come from.

The baselines are FedRAMP Rev 5 as published in OSCAL by the OSCAL Foundation's fedramp-resources repository: 156 controls at Low, 323 at Moderate, 410 at High. Control and family names are the official NIST SP 800-53 Rev 5 titles.

The cloud underlay is the shared-responsibility split common to AWS GovCloud, Azure Government and Google Cloud, anchored to the Cloud Security Alliance's CCM v4: 31 controls the provider owns outright (physical, environmental, maintenance, media, provider personnel, alternate sites) and 37 it shares with you.

AWS service citations come from AWS's published OSCAL component definitions, joined to the Security Hub → NIST 800-53 mapping derived from the guard rules AWS publishes (Apache-2.0). They are shared, never provider-complete.

cloud.gov rows come from cloud.gov's published control-family policies, public domain under CC0. Red Hat OpenShift rows come from the ComplianceAsCode OSCAL component definition at the Moderate baseline — which is why OpenShift stops counting at High.

Vendor rows are what each vendor's public FedRAMP package or trust documentation asserts, one citation per control, with its FedRAMP Marketplace listing and reference link where the vendor's page still answers. At FedRAMP High, a vendor we hold at the Moderate baseline does not count until we map its High package. A vendor we have not mapped yet counts as yours to write until we map it — which happens at onboarding, from the vendor's own package.

A control is provider-covered when at least one of your picks' packages asserts full responsibility for it, shared when they assert a split, and yours when no pick speaks to it.

The speed strip's numbers are measured, not estimated: on the package we keep on our own platform at the High baseline, a batch of 203 implementation statements was drafted in 14 minutes and reviewed in 15 — both figures are ceilings, poll-stamped by the same cron that checks batch completion.

stack.html carries a copy of the platform's inheritance data as of the snapshot date shown in its masthead; the platform recomputes on every change.

The ATO pageWhere the ATO page's numbers come from.

The ATO page's package figures are a read-only export of the platform's own database, never typed in by hand: a build script reads the same tables the product itself reads, and records a sha256 hash of every file it reads so a later change upstream is detectable. The export's snapshot date is shown in the ATO page's own masthead.

Every speed figure on the ATO page is a timed batch, not an estimate:

RunWhatMinutesDate
NarrativeBatch cmphen86c006e04kthf9krr1d203 control statements drafted14.02026-05-22
AssessmentBatch cmphf5jmf01pu04l7uhj553va203 statements reviewed in an assessor's voice14.82026-05-22
NarrativeBatch cmr9i876c005msb3g24z2s79o50 control statements drafted8.32026-07-06
ProcedureDocument createdAt window108 procedure documents drafted70.32026-06-12

Every figure above is a ceiling: completion is stamped by a scheduled check that finds the batch already finished, not by the batch's own clock.

Of the package's 410 control implementations, 202 are approved and 208 are still drafted. 18 policy documents exist, one for each control family that has implementations in this package (two families carry none), with 110 procedure documents beneath them; none of either kind has been promoted out of draft status yet.

NIST's SP 800-53 Revision 5 catalog comes in as OSCAL 1.2.2 (catalog release 5.2.0); every package the platform generates goes out as OSCAL 1.2.1: System Security Plan · Security Assessment Plan · Security Assessment Report · Plan of Action & Milestones · Continuous Monitoring Package · Complete Package. The FedRAMP baseline and ODP files are digests derived from the OSCAL Foundation's fedramp-resources repository. Every package export is checked for structure before it leaves the platform; the full FedRAMP schema check runs in the build pipeline, not on every export.

FedRAMP's own machine-readable indicators, used for the FedRAMP 20x figures, are pulled from FRMR.documentation.json in FedRAMP's docs repository (the repository has since been renamed docs-legacy and the file did not answer at that path on 16 September 2026; the platform holds the corpus it retrieved earlier): 11 themes, 62 indicators, 474 links from indicators to controls, and 351 mappings from those indicators onto NIST SP 800-53 Rev 5 controls.

On 2026-09-16, FedRAMP's current machine-readable rules file — fedramp-consolidated-rules.json in the FedRAMP/rules repository on GitHub, version 2026.09.13.02 — listed 46 indicators in 10 themes; 16 of the 62 indicators in the platform's corpus, loaded 2026-06-23, do not appear in it.

The ATO page's Why ATO comparison describes what our own review found across the 26 platforms we looked at on 16 September 2026 — a scope, not a ranking, and no platform is named on either page.

The Fix Engine can check 28 vulnerability classes end to end, in isolation, before a fix ever reaches you; nothing is applied without your approval, and a finding closes only when a later, comparable scan confirms it.

Licensing & attributionThe legal basis for citing this way

Cited, never reproduced: IBM/Ponemon Cost of a Data Breach 2025 (Figs. 7, 9, 13–14, 39) & 2026 · Verizon DBIR · Mandiant M-Trends · CrowdStrike GTR · ITRC · CISA KEV · OMB FISMA report. Industry reports are free to read (registration) and appear here as attributed figures only — no charts or text reproduced. NIST, FedRAMP, CISA, and OMB materials are U.S. government works — public domain (17 U.S.C. §105).

This is the same licensing language that runs in the instrument page's own footer, carried over intact rather than paraphrased: the “cited, never reproduced” framing is the operative practice: figures are cited with attribution; expression, charts, and text are never reproduced — drawn from registration-gated industry reports, and the public-domain carve-out for U.S. government works is a separate legal basis that stands on its own — the two are not the same claim and shouldn't be blurred together.

Several sources in the bibliography above aren't named in that original line, because this page's bibliography is wider than what a one-line footer could carry — among them Sophos's State of Ransomware, the Bureau of Labor Statistics wage table behind every fix-cost estimate, the FedRAMP program documents behind the platform's clocks, and the sources behind the modeled ROI band described above: Coalition's Cyber Claims Report, Hiscox's Cyber Readiness Report, Sophos's 2024 backup-compromise study, and the vendor list-price pages. BLS and FedRAMP program documents are U.S. government works under the identical public-domain rule as NIST, CISA, and OMB above. Sophos's access terms are stated as published here, not independently re-verified this session in either direction.

Per-case figures — the real companies and incidents behind each anonymized scenario — are not disclosed on this page by design; see “How to read this page” for their collective attribution line. The internal mapping between a staged scenario and the real case behind it is held separately and does not render on any public page.

Recent incidents -- sources

GOMESSECURITY™, GS|ATO™ and Compliance-as-Architecture™ are trademarks of Gomes Security LLC. FedRAMP is a mark of the U.S. General Services Administration; ATT&CK is a mark of The MITRE Corporation; all other names belong to their owners. Gomes Security LLC is not affiliated with or endorsed by any of them. For information only — dollar figures, likelihoods and forecasts are computed estimates from the cited public sources, not guarantees and not legal, audit or compliance advice.