Skip to main content

Standards

Methodology

How THE 24 defines incidents, evidence, confidence, and the daily reporting window.

THE 24 operates as a global cyber incident system of record. Every material publicly reported cyber incident receives a permanent identifier, structured provenance, and evidence-labeled technical data.

What counts as an incident

An incident is a publicly reported cyber compromise event involving unauthorized access, data exposure, ransomware deployment, or operational disruption attributed to a malicious actor or security failure.

Root vs downstream victims

Supply-chain and cascading events are modeled with root incidents and downstream affected organizations. Metrics differentiate independent attack events from downstream exposure.

Evidence states

  • Confirmed — Established by official disclosure or multiple credible sources
  • Reported — Stated in credible public reporting
  • Inferred — Analyst inference, clearly labeled
  • Claimed — Threat actor or unverified claim
  • Unknown — Not publicly confirmed

Confidence and severity

Confidence reflects how well-sourced our assessment is. Severity reflects impact potential. These are independent — high severity does not imply high confidence.

Daily report window

The World Cyber Clock tracks a rolling 24-hour UTC window. Daily reports aggregate eligible published incidents within each reporting period.

Unknown is acceptable. Unsourced certainty is not.

THE 24 — The World's Daily Cyber Exposure Report