Annual study on the total cost of data breaches by sector, geography, vector, and containment time. Source for our claims about average incident cost and the correlation between detection time and cost.
Cargando…
Cargando…
Sources / Fuentes
Every numeric or factual claim on simiriki.com that points at an external authority traces back to one of the entries below. The list is the contract: if a page on the site cites a number, the number comes from a source on this index. If we cite something not yet here, that is a bug — report it to hola@simiriki.com.
Sources are grouped by topic and ranked by editorial weight (most-cited first within each group). The "Cited on" line for each entry is a non-exhaustive sample — use the URL to grep the simiriki.com codebase for the full set if needed.
Annual study on the total cost of data breaches by sector, geography, vector, and containment time. Source for our claims about average incident cost and the correlation between detection time and cost.
Microsoft's annual threat-landscape report — identity as primary vector, MFA effectiveness, distribution of incidents by maturity tier. Supports simiriki claims on identity-based attack prevalence and incident concentration in low-maturity organisations.
Quarterly ransomware activity reports: average ransom, targeted sectors, payment and recovery rates. Source for every simiriki mention of mid-market ransomware trends.
Public catalog of vulnerabilities actively exploited in the wild. Supports simiriki decisions on remediation-playbook prioritisation.
Verizon's annual analysis of real data-breach patterns, based on thousands of investigated incidents. Complementary source to IBM / Microsoft DDR for our claims on attack vectors.
Mexican federal law governing personal-data processing by private parties. simiriki aligns its privacy policy, ARCO rights, breach-notification timelines, and security measures against LFPDPPP Articles 19, 20, and 22.
CNBV's general provisions applicable to credit institutions. simiriki cites the CISO-designation requirement, privileged-access segregation, and security master-plan obligations when relevant to the financial-services vertical.
Official SAT specification for the version 4.0 of Comprobantes Fiscales Digitales por Internet. simiriki cites issuance timelines, recipient tax regime, and cancellation rules when discussing automated tax compliance.
CFDI complement mandatory for goods-transport documentation. simiriki cites Carta Porte when discussing automation for logistics and transport.
Official text published in the DOF. Primary source for every normative LFPDPPP citation on simiriki — the INAI page is secondary.
NIST cybersecurity management framework. simiriki maps its Observe / Understand / Improve / Automate layers to NIST CSF 2.0's Identify / Protect / Detect / Respond / Recover functions.
International standard for information-security management systems. simiriki cites Annex A 8.2 (privileged-access rights) and other controls when the methodology requires it.
International standard for quality-management systems. Cited in the context of operational processes and continuous improvement.
Official Mexican GDP statistics by sector. simiriki cites INEGI to ground claims on the economic weight of manufacturing, retail, and services in the Mexican mid-market.
Monthly Mexican manufacturing-activity survey. Source for citations about the industrial sector in Nuevo León and the Monterrey metropolitan area.
National construction-industry-activity survey. Supports simiriki figures on the construction sector.
Annual studies on Mexican e-commerce and online sales. Source for simiriki citations on the Mexican retail / digital-commerce sector.
Official documentation for Power Automate, Power Apps, and connectors. simiriki cites platform limits, data regions, and available connectors when discussing process automation.
Sources are added when first cited on a public simiriki page. Each entry includes the publisher, the URL of the original document, the year (where the source has discrete editions), a one-paragraph description of why simiriki cites it, and a sample of pages where it appears. URLs are verified at every quarterly refresh; broken links surface as 404s in our internal link checker before they surface here.
simiriki does not paywall its citation graph. The full registry is available as a public-readable TypeScript file at github.com/jjdlr-simiriki/simiriki/blob/main/lib/citations.ts.