This file records a limitation the corpus has been circling and has not stated directly.
The Five Filters All Select For Size
Mandatory notification thresholds are frequently volume-based. Collective redress requires a class large enough to be worth certifying. Research vendors write about organisations their customers recognise. Securities filings require a listing, per 25-0924b. And English-language coverage favours large firms in Anglophone markets.
Each filter independently favours large organisations. Together they produce a database in which a 4,541-person breach at 25-1005 is unusually small and was worth remarking on.
And The Techniques May Not Generalise Downward
This is the part that matters. The corpus’s central findings — supplier concentration, service-desk social engineering, connected-application abuse, long dwell times — were derived from organisations with suppliers, service desks, SaaS estates and detection capability.
A ten-person firm has none of those. Its exposure is more likely a compromised email account, a fraudulent invoice, or ransomware from a commodity phishing message — the business email compromise at 25-0602, the consumer-scale scams at 25-1122.
So this database may be an accurate account of how large organisations are compromised and a poor guide to how most compromises happen.
What Would Fix It, And Why Nobody Will
A reporting mechanism proportionate to small organisations: low-burden, anonymous, aggregated and published. Some national bodies collect fragments of this in survey form, per 25-0615b.
It would produce no named victims, no litigation and no vendor marketing material — which is precisely why the existing incentives have not produced it. Graded medium: this is a structural claim about the database, and the corpus cannot quantify the bias it describes.
It describes a size bias in this database and in the public record it draws on. Sources below support the small-business context. Corrections: corrections@forensicpost.com.