Desk live·
ForensicPost
Breaches/Verification/File 25-0613b

This Database Is a Survey of Large Organisations

Four hundred and forty files, and the median subject is a multinational, a health system, a state government or a university. That is not what the incident population looks like.

Constructed geometry · not a chart of case data
TargetThis database
ActorUnattributed
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

This file records a limitation the corpus has been circling and has not stated directly.

The Five Filters All Select For Size

Mandatory notification thresholds are frequently volume-based. Collective redress requires a class large enough to be worth certifying. Research vendors write about organisations their customers recognise. Securities filings require a listing, per 25-0924b. And English-language coverage favours large firms in Anglophone markets.

Each filter independently favours large organisations. Together they produce a database in which a 4,541-person breach at 25-1005 is unusually small and was worth remarking on.

And The Techniques May Not Generalise Downward

This is the part that matters. The corpus’s central findings — supplier concentration, service-desk social engineering, connected-application abuse, long dwell times — were derived from organisations with suppliers, service desks, SaaS estates and detection capability.

A ten-person firm has none of those. Its exposure is more likely a compromised email account, a fraudulent invoice, or ransomware from a commodity phishing message — the business email compromise at 25-0602, the consumer-scale scams at 25-1122.

So this database may be an accurate account of how large organisations are compromised and a poor guide to how most compromises happen.

What Would Fix It, And Why Nobody Will

A reporting mechanism proportionate to small organisations: low-burden, anonymous, aggregated and published. Some national bodies collect fragments of this in survey form, per 25-0615b.

It would produce no named victims, no litigation and no vendor marketing material — which is precisely why the existing incentives have not produced it. Graded medium: this is a structural claim about the database, and the corpus cannot quantify the bias it describes.

This is an analysis file

It describes a size bias in this database and in the public record it draws on. Sources below support the small-business context. Corrections: corrections@forensicpost.com.

Sources
  1. Small business cybersecurity statistics and trendsStationX
  2. Must-know small business cybersecurity statisticsBD Emerson
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary