Often, when we’re doing some data analysis, we come across small things that don’t fit into whatever project we’re working on, or they’re just small enough that they don’t merit much expansion into something larger. So we inevitably end up with a sort of “island of misfit data analysis nuggets” lying around, and this is probably as good a place as any to let them have their extremely modest moment in the sun. These nuggets aren’t necessarily groundbreaking, but they’re at least something that made us stop and say, “Huh, that’s kind of neat.”
One such misfit turned up while looking at the time gap between when an incident occurred and it was disclosed (referred to in our data as “notification”). Specifically, looking at the ECDFs (empirical cumulative distributions; don’t worry, an explanation is coming) of notification times by incident pattern, a fairly clear grouping emerged. ECDFs simply show the proportion of incidents that have been disclosed after a given period of time, as in the following plot.

Each line is a distinct incident pattern (intentionally unlabelled for now) but they immediately struck us as falling into three clear groups. The blue patterns are incidents that are typically disclosed almost immediately. The red patterns are disclosed much slower, with 50% of them being disclosed only after 1-2 months.
The “Huh, interesting” bit of this is that when we looked to see which patterns were in each group, they all made a certain amount of sense. Labelling the lines directly in the plot above gets a little messy with how much the lines overlap, so instead we’ll look at the median (50th percentile) and 95th percentile notification times by pattern, grouped by three:

Once we saw which line went with which incident pattern, this started to seem fairly obvious. System failures, DoS attacks and Defacements are sort of “self-disclosing”; it’s pretty obvious when they happen so those having by far the shortest notification times makes perfect sense.
The other groupings are a little less blatantly obvious, but it makes some sense that things like Insider misuse and Scam or fraud will often be discovered well after the fact and as a result disclosed well after the actual incident.
As we warned at the start, this isn’t a huge revelation, but it’s one of the many small, fun things that we run across from time to time.