This file connects the small-business argument at 25-0610b to 25-0616b with the supply-chain files above.
None Of These Firms Passed A Single Filter
The five filters at 25-0502 and 25-0924b: mandatory notification, collective redress, research industry coverage, English-language publication, securities listing.
A ninety-person component maker that halved its workforce, at 25-1001b, passed none of them. It suffered no data breach, has no class, is not listed, and no vendor sells anything to firms its size.
It reached the public record because a company large enough to pass every filter was attacked upstream of it, and the resulting attention swept the chain into view.
Which Is A Sixth Route, And A Bad One
Proximity to a large incident. It is not a mechanism — it is an accident, and it produces coverage only when the upstream event is enormous.
The corpus recorded small-firm harm three other times: a nursery group at 25-0926, forty-partner law firms at 25-0910, a research association at 25-0408. Each entered through a different accident.
Four accidents in 454 files is not coverage of a population that, per 25-0610b, is reportedly the target of 43% of attacks.
And The Harm Profile Is Genuinely Different
The corpus’s large-organisation files end in notification, remediation, litigation and a settlement of a few dollars per head, per 25-1227.
These files end in redundancy, a week of runway, and a state considering buying inventory to prevent insolvency. Different consequence, different remedy, different policy question — and the corpus reached them only by following a large incident downhill.
Graded medium: this is a structural argument about the database, and the corpus cannot quantify what it is missing.
It connects the small-organisation files in this database to the supply-chain incidents recorded above. Sources support the underlying cases. Corrections: corrections@forensicpost.com.