01 · Industry research · 2025 edition
IBM/Ponemon Cost of a Data Breach, 2025
IBM Security, research by Ponemon Institute
Cited for the per-vector cost-and-frequency breakdown (Figures 7, 9, 13–14, 39) shown as an industry reference beside each decision on the main instrument page, and for one decision's malicious-insider cost figure in its own cost line.
This is the earlier of the two Cost of a Data Breach editions cited on this site — see “How to read this page” above for which figures come from which edition.
Access — free to read; registration required.
02 · Industry research · 2026 edition
IBM/Ponemon Cost of a Data Breach, 2026
IBM Security, research by Ponemon Institute
Cited for headline breach-cost figures (global and U.S. averages, days to identify and contain) and vector-specific cost figures — phishing, supply chain, public-facing exploits, help-desk impersonation, business-partner compromise — used across nine of the sixteen decisions' cost lines.
Access — free to read; registration required.
03 · Industry research · 2026 edition
Verizon Data Breach Investigations Report (DBIR), 2026
Verizon Business
Cited for third-party involvement in breaches (48%), vulnerability exploitation as the leading initial-access vector (31%), and KEV remediation outcomes — about one in four fully remediated, forty-three-day median (report pp. 10, 17) — used in two decisions.
Access — access terms as published.
04 · Industry research · 2026 edition
Mandiant M-Trends, 2026
Mandiant (Google Cloud)
Cited for intrusion dwell-time and detection-method figures (median time to detection, externally notified vs. self-detected) and cloud-intrusion initial-access-vector prevalence (vishing, exploitation), used across three decisions.
Access — access terms as published.
05 · Industry research · 2026 edition
CrowdStrike Global Threat Report, 2026
CrowdStrike
Cited for the malware-free-intrusion share, the valid-account-abuse share of cloud incidents, attacker lateral-movement timing, and the count of organizations whose own AI assistants were talked into unauthorized actions, used across four decisions.
Access — access terms as published.
06 · Industry research · H1 2026 edition
Identity Theft Resource Center, H1 2026 Data Breach Report
Identity Theft Resource Center (ITRC)
Cited for the share of breach notices that disclosed how the attack happened, and a single-incident concentration figure for one breach-notice category, used across two decisions.
Access — access terms as published.
07 · Industry research · 2026 edition
Sophos, The State of Ransomware, 2026
Sophos
Cited for ransomware recovery cost, ransom payment rate, median ransom demand, and the added recovery cost when backups are also compromised, used across two decisions.
Access — access terms as published.
08 · U.S. government work
CISA Known Exploited Vulnerabilities (KEV) Catalog
Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security
Cited for the “actively exploited” vulnerability listing and its remediation-due-date mechanism (Binding Operational Directive 22-01), referenced in one decision's mechanism and cost line.
Access — U.S. government work, public domain (17 U.S.C. §105).
09 · U.S. government work · FY2023, latest published
OMB FISMA Fiscal Year 2023 Annual Report to Congress
Office of Management and Budget (OMB)
Cited for the federal-incident-category breakdown — improper usage as the leading category — used in one decision. FY2023 was the latest published edition as of this citation; it is the oldest-dated source in this bibliography.
Access — U.S. government work, public domain (17 U.S.C. §105).
10 · U.S. government work · May 2024 (edition pinned at engagement scoping)
BLS Occupational Employment and Wage Statistics — Information Security Analysts
U.S. Bureau of Labor Statistics (BLS)
Cited for the median hourly wage for information security analysts, scaled by 1.33 to the $80/hour loaded rate the cards use, underlying every one of the sixteen decisions' fix-cost estimate.
Access — U.S. government work, public domain (17 U.S.C. §105).
11 · Vendor threat-intelligence reporting
Google Threat Intelligence / Mandiant vendor-compromise reporting
Google Threat Intelligence / Mandiant (Google Cloud)
Cited for publication-level reporting on a vendor-credential compromise, alongside contemporaneous press coverage, used in one decision. Cited at the publication level only — no incident-specific article title or URL, consistent with this page's de-identification rule (see Licensing & Attribution below).
Access — access terms as published.
12 · U.S. government program documents
FedRAMP program documents — Consolidated Rules 2026 (CR26) and RFC-0031
FedRAMP Program Management Office, U.S. General Services Administration
Cited for the clocks that govern nine of the sixteen decisions: the one-hour incident report (current Incident Communications Procedures, which RFC-0031 revises), and from CR26 the 192-day accepted-vulnerability line, the monthly human-readable reporting MUST, the PAIN remediation clocks, the Corrective Action Plan / possible revocation consequence for a missed report, and the Class-C quarterly review requirement.
Access — U.S. government work, public domain (17 U.S.C. §105).
13 · U.S. government work · Control authority
NIST SP 800-53 Revision 5 + SP 800-53A
National Institute of Standards and Technology (NIST)
No statistic is drawn from these documents directly. They are the control-language and assessment-procedure authority behind every one of the sixteen decisions' anchor controls and the FedRAMP High baseline itself — constant across all sixteen, so it is listed once here rather than repeated on every row of the index below.
Access — U.S. government work, public domain (17 U.S.C. §105).
14 · Consultancy & tool-vendor estimates
Moderate re-authorization cost and timeline estimates
Secureframe, Vanta, Paramify, Knox Systems, CISGuard
Cited for the $250,000 to $2 million and 12 to 24 months range used for a late-or-lost Moderate re-authorization, referenced in two decisions. FedRAMP publishes no official figure for this; these are consultancy and tool-vendor estimates, attributed at the publication level, directional only.
Access — publicly published estimates, access terms as published.
15 · Industry research · 2026 edition
Coalition Cyber Claims Report, 2026
Coalition, Inc. (via Risk & Insurance coverage)
Cited for the loss-per-event anchor behind the modeled ROI band on every one of the sixteen decisions: the average claim severity for policyholders under $25 million in revenue, and the ransomware-claim average used for the three destructive-class decisions. See “How the dollar bands are modeled” above.
Access — accessed via secondary trade-press coverage (Risk & Insurance); Coalition's own report was not directly fetched this pass.
16 · Industry research · 2026 edition
Hiscox Cyber Readiness Report, 2026
Hiscox
Cited for the share of small businesses attacked in the past twelve months (56%), used as the loss-event-frequency base rate for the modeled ROI band on every one of the sixteen decisions. See “How the dollar bands are modeled” above.
Access — free to read (PDF).
17 · Industry research · 2024 fielding
Sophos, The Impact of Compromised Backups on Ransomware Outcomes, 2024
Sophos, fielded by Vanson Bourne (2,974 organizations hit by ransomware) — a distinct study from the 2026 State of Ransomware report cited separately above
Cited for the recovery-cost magnitude effect of compromised vs. intact backups (eight times higher: $3M vs. $375K) applied to one decision's modeled ROI band. See “How the dollar bands are modeled” above.
Access — free to read (vendor blog).
18 · Vendor list prices · fetched 2026-09-04
Vendor list-price pages, fetched and hashed on 2026-09-04
Multiple named-brand identity, secrets-management, SIEM, breach-and-attack-simulation, continuous-monitoring, and penetration-testing tool vendors
Cited for the cost of the stronger control in each decision's modeled ROI band: hardware security keys, identity and lifecycle-management licensing, secrets-manager and SIEM infrastructure, breach-and-attack-simulation and continuous-monitoring platform licensing, object-lock backup storage, penetration-testing engagements, and similar control-specific line items — each priced at the vendor's own published list price, marketplace listing, or product documentation. See “How the dollar bands are modeled” above. Held as one collective entry rather than naming each vendor, so a story's cost line stays about the control, not the product behind it.
Access — eleven pages fetched directly and hashed, 2026-09-04; publicly published, no registration required.
19 · Mapping data · commit 5998957f
ATT&CK 16.1 to NIST SP 800-53 Revision 5 mapping (enterprise), CTID Mappings Explorer
Center for Threat-Informed Defense (CTID)
Cited for the control-to-technique mitigates mapping behind the risk-tier color shown on each control icon on the instrument page: 2,782 mitigates-type mapping rows across the 31 scored controls, collapsing to 1,055 after de-duplication (5,264 mitigates-type rows exist across the full 443-control crosswalk table; a separately-sourced GSA .govCAR strength-score dataset sharing that same table is not used here). See “How the control risk tier is colored” above.
Access — license: see the project's repository.
20 · Industry research · Red Report 2026
Picus Red Report 2026
Picus Security (Picus Labs) — 1,084,718 malware samples analyzed in 2025; 13,321,128 total TTP observations mapped to ATT&CK
Cited for ATT&CK technique-prevalence percentages used as attributed inputs to the risk-tier color shown on each control icon on the instrument page — matched against the mapping above, never reproduced as a table. See “How the control risk tier is colored” above.
Access — access terms as published; the ten prevalence figures used here were retrieved 2026-09-04 by an automated text fetch of the publisher's page (self-dated 2026-02-24), not a byte-level capture, so the sha256 on file covers the extracted figures only, not the page's raw bytes.