Standards
Methodology
How THE 24 defines incidents, evidence, confidence, and the daily reporting window.
THE 24 operates as a global cyber incident system of record. Every material publicly reported cyber incident receives a permanent identifier, structured provenance, and evidence-labeled technical data.
What counts as an incident
An incident is a publicly reported cyber compromise event involving unauthorized access, data exposure, ransomware deployment, or operational disruption attributed to a malicious actor or security failure.
Root vs downstream victims
Supply-chain and cascading events are modeled with root incidents and downstream affected organizations. Metrics differentiate independent attack events from downstream exposure.
Evidence states
- Confirmed — Established by official disclosure or multiple credible sources
- Reported — Stated in credible public reporting
- Inferred — Analyst inference, clearly labeled
- Claimed — Threat actor or unverified claim
- Unknown — Not publicly confirmed
Confidence and severity
Confidence reflects how well-sourced our assessment is. Severity reflects impact potential. These are independent — high severity does not imply high confidence.
Daily report window
The World Cyber Clock tracks a rolling 24-hour UTC window. Daily reports aggregate eligible published incidents within each reporting period.
Unknown is acceptable. Unsourced certainty is not.