It just seems the either no one is measuring realized risk exposure numbers for their firms, or mums the word on their findings. The information that I collect is strongly covered by Non-Disclosure Agreements. To help with this, I want to start publishing de-identified statistical abstracts.
I included some of these statistical abstracts in the financial section of a paper published by ANSI. I am a coauthor on, "The Financial Impact of Breach Health Information, A Business Case for Enhanced