Desk live·
ForensicPost
Ransomware/Verification/File 25-1225b

Incident Response Data Shows This Database Records Failures, Not Successes

This database has said three times that it records failures and not successes. Incident response data supplies the comparison, and the bias is worse than the corpus estimated.

Constructed geometry · not a chart of case data
TargetThis database
ActorUnattributed
D. Kennedy13 min readConfidence: medium2 sources reviewed

This file compares what this database records with what incident response data describes.

Four Points Of Comparison

Containment: 47% of attacks stopped before encryption, at 25-1216b. This corpus contains almost no such files — Pakistan Petroleum at 25-0807, Princeton at 25-1026, and Workday’s tenant boundary at 25-0815b.

Dwell: medians of two to fourteen days, at 25-1223b. This corpus records 102 days, five months, ten months, and 74 days before clients were told.

Detection: 52% internal, at 25-1224b. This corpus overwhelmingly records organisations learning from a ransom note, a researcher or a leak site.

Access: compromised credentials are the leading root cause at 41%, against 22% for exploited vulnerabilities, at 25-0421b. This corpus has far more files on exploitation than on credentials, because exploitation produces CVEs and advisories.

The Bias Is Consistent And Directional

On every measure, this database over-represents the worse outcome. Not because anything was selected for drama, but because the four filters at 25-0502 and the fifth at 25-0924b all favour incidents that got far enough to require disclosure.

The corpus estimated this at 25-0807 and 25-1225 and could not size it. It now can, at least in direction: fast detection is ordinary and appears here as remarkable; containment is close to half of cases and appears here almost not at all.

What Survives And What Does Not

Structural findings survive. Supplier concentration, the identity-led route, the availability gap, the absence of compensation — none depends on the sample being representative, per 25-1225.

Anything this desk has implied about typical organisational competence does not. Statements of the form "organisations do not detect intrusions" are false as a general claim and true of the population this database records.

And The Vendor Data Has The Opposite Bias

These figures come from customers of security vendors who engaged incident response or managed detection — organisations better defended than average, per 25-1216b and 25-0711.

So the corpus is a sample of failures and the caseload is a sample of the well-defended. The truth is between them, and neither source can locate it. Graded medium: this is a structural comparison, not a measurement.

This is an analysis file

It compares the composition of this database with published incident response data, principally the 2025 Sophos Active Adversary Report covering 413 cases from 2024. Neither population is representative and no corrected estimate is offered. Revised 2026: the access comparison previously read “56% logged in with valid credentials”, taken from a press release rather than the report. The corrected figures are 41% compromised credentials and 22% exploited vulnerabilities as root causes; see 25-0421b. The direction of the comparison is unchanged. Corrections: corrections@forensicpost.com.

Sources
  1. It takes two: The 2025 Sophos Active Adversary ReportSophos
  2. M-Trends: data, insights and recommendations from the frontlinesGoogle Cloud
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary