This file compares what this database records with what incident response data describes.
Four Points Of Comparison
Containment: 47% of attacks stopped before encryption, at 25-1216b. This corpus contains almost no such files — Pakistan Petroleum at 25-0807, Princeton at 25-1026, and Workday’s tenant boundary at 25-0815b.
Dwell: medians of two to fourteen days, at 25-1223b. This corpus records 102 days, five months, ten months, and 74 days before clients were told.
Detection: 52% internal, at 25-1224b. This corpus overwhelmingly records organisations learning from a ransom note, a researcher or a leak site.
Access: compromised credentials are the leading root cause at 41%, against 22% for exploited vulnerabilities, at 25-0421b. This corpus has far more files on exploitation than on credentials, because exploitation produces CVEs and advisories.
The Bias Is Consistent And Directional
On every measure, this database over-represents the worse outcome. Not because anything was selected for drama, but because the four filters at 25-0502 and the fifth at 25-0924b all favour incidents that got far enough to require disclosure.
The corpus estimated this at 25-0807 and 25-1225 and could not size it. It now can, at least in direction: fast detection is ordinary and appears here as remarkable; containment is close to half of cases and appears here almost not at all.
What Survives And What Does Not
Structural findings survive. Supplier concentration, the identity-led route, the availability gap, the absence of compensation — none depends on the sample being representative, per 25-1225.
Anything this desk has implied about typical organisational competence does not. Statements of the form "organisations do not detect intrusions" are false as a general claim and true of the population this database records.
And The Vendor Data Has The Opposite Bias
These figures come from customers of security vendors who engaged incident response or managed detection — organisations better defended than average, per 25-1216b and 25-0711.
So the corpus is a sample of failures and the caseload is a sample of the well-defended. The truth is between them, and neither source can locate it. Graded medium: this is a structural comparison, not a measurement.
It compares the composition of this database with published incident response data, principally the 2025 Sophos Active Adversary Report covering 413 cases from 2024. Neither population is representative and no corrected estimate is offered. Revised 2026: the access comparison previously read “56% logged in with valid credentials”, taken from a press release rather than the report. The corrected figures are 41% compromised credentials and 22% exploited vulnerabilities as root causes; see 25-0421b. The direction of the comparison is unchanged. Corrections: corrections@forensicpost.com.