References
# | Source | Used for |
¹ | Veracode, State of Software Security (2024); Snyk, State of Open Source Security (2024). Remediation timelines vary by study — 60 days is optimistic for critical vulnerabilities, 200+ days is common for medium-severity findings. | Exposure window estimates (§2.1) |
² | IBM Security & Ponemon Institute, Cost of a Data Breach Report (2024). Global average: $4.88M. | Breach cost figures |
³ | MITRE ATT&CK Framework — https://attack.mitre.org/ |
Additional resources:
Contrast ADR Documentation for SIEM integrations, agent deployment, and policy configuration
Contrast Support Portal for technical support and troubleshooting
CISA Federal Incident & Vulnerability Response Playbooks for structural reference for incident and vulnerability response processes
End of Handbook v2.0
This is a living document. Review quarterly against your maturity model (Chapter 4) and update scenarios (Chapter 5) as your ADR deployment matures.