Sample report · Cybersecurity

We re-derived a published figure from the public record.

A CISO has to brief the board on detection performance against the industry's most-cited benchmark — attacker dwell time. We typed in Mandiant's two published figures (16 days in 2022, 10 days in 2023) and withheld the rate of improvement. The app came back with a 37.5% reduction in mean time to detect — exactly the drop M-Trends describes, reconciled to Mandiant's published figures.

The situation

An industry benchmark, turned into a board-ready detection report.

A CISO has to brief the board on detection performance against the most-cited frontline benchmark in the industry: attacker dwell time — the number of days an intruder sits undetected. Mandiant's M-Trends report publishes the global median each year.

We used it as a reconcile test: feed the two years' dwell-time figures, withhold the improvement percentage, and see whether the app re-derives the drop the report describes — from arithmetic, not recall.

What we supplied

Only public inputs — each one sourced.

We fed the two dwell-time figures a reader would pull straight from M-Trends and omitted the improvement percentage, so the app had to derive it.

InputValueSource
Security domainNetwork & endpoint protectionDetection / dwell-time focus
Compliance frameworkNIST CSF 2.0
MTTD baseline (2022)384 hours (16 days)M-Trends 2024
MTTD current (2023)240 hours (10 days)M-Trends 2024
Internal detection share46% (up from 37%)M-Trends 2024

Source: Mandiant M-Trends 2024 · download the source document we used.

The report

The finished, board-ready output.

This is the actual rendered report — interactive charts and all. Nothing was edited after generation.

Open the report full-screen ↗

Reconcile

Our output vs. the published figures.

MetricPublishedOurs (computed)MatchNote
MTTD improvement % 37.5% (16→10 days) 37.5% ((384−240)/384) ✓ exact Withheld from the app — it derived it
MTTD baseline 16 days (384 hrs) 384 hrs Carried through
MTTD current 10 days (240 hrs) 240 hrs Carried through

Integrity check: the value 37.5 appears nowhere as a literal in the inputs — it's computed as (baseline − current) / baseline. MTTR improvement, vulnerability counts, and the composite risk score are modeled estimates (M-Trends reports detection dwell time, not containment times) and are labeled as such, distinct from the reconciled MTTD figure.

Build the same report from your own numbers.

You supply the figures you already have, and every number comes back labeled by where it came from — so you can put your name on it and show your work.

Generate your report — $20