The containment figure at 25-1216b measures attacks halted before encryption. This file sets out what that leaves open.
The Adversary Was Already Inside
Stopping an attack before encryption means detecting it after initial access, after whatever lateral movement occurred, and after any data was taken.
The corpus filed at 25-1125 that the 102 days before deployment at Nevada were the operation, and that the deployment is the last act. A metric measuring the last act rewards catching an adversary at the final step.
And In Half Of Cases There Is No Final Step To Catch
The encryption rate fell to 50% at 25-1217b. Where an operation never intended to encrypt, "stopped before encryption" describes nothing — the data was taken and the extortion proceeds on publication.
A containment rate defined against encryption therefore improves partly because encryption is becoming less common. Some of the 22-to-47-point movement may be the denominator changing rather than the defence improving.
This desk applied the same objection at 25-1204 to manufacturers blocking more attempts while adversaries shifted to data theft: the industry measures progress against the technique it defeated.
What Would Measure The Right Thing
Attacks stopped before exfiltration. That is the point after which the corpus establishes nothing can be undone — no takedown at 25-1018, no verifiable deletion at 25-0507, no recovery from a backup.
It is harder to measure, because exfiltration resembles normal traffic and the absence of evidence is not evidence of absence. That difficulty is exactly why the industry reports the easier number.
Graded medium: this is a critique of a metric, not a dispute about the underlying research.
It examines the limits of a containment metric used in published research. It does not dispute the underlying measurements. Corrections: corrections@forensicpost.com.