Starting ranges for cyber loss estimates, where every number states where it came from and what it will not support. Each shard gives an annual event frequency and a per-event loss, as three-point estimates you can drop straight into a Monte Carlo.
The point is not that these numbers are right. It is that a range carrying six citations and a range someone typed from memory should not look equally authoritative — so here the sources travel with the numbers.
The notes below are the honest limits. If a number from here reaches a board deck, its limitation belongs on the same slide.
Filter to the population nearest the thing you are modelling, then open a shard's sources before quoting any of its numbers.
Read each shard's status. Most are governed starters, meaning the evidence is real but the shard has not cleared human benchmark review.
Where no local per-firm rate is published, a shard may bridge from another country that has one — the US data-breach frequency comes from a UK survey. Each such parameter says so in its own limitation.
Four currencies across the shards. Do not add them together without converting first, and state the rate and date when you do.
If a number from here reaches a board deck, its limitation belongs on the same slide.