The DBIR is not in the business of prediction, but it can go a long way to help you shape your response strategy in the face of an uncertain future.
We believe it is fair to say that one of the primary lessons that 2020 had to teach us was that it is often futile to attempt to predict the future. However, not trying to predict it is not the same thing as giving up on scenario planning and preparing your organization for probable outcomes to the best of your ability. The DBIR is not in the business of prediction,4 but it can go a long way to help you shape your response strategy in the face of an uncertain future.
For a potential entry to be eligible for the incident/breach corpus, a couple of requirements must be met. The entry must be a confirmed security incident defined as a loss of confidentiality, integrity or availability. In addition to meeting the baseline definition of “security incident” the entry is assessed for quality.