Where Our Figures Come From

We sell courses that teach people to check things before they believe them. It would be poor form to then ask you to take our own numbers on faith.

So this page lists every organisation whose data appears anywhere on this site, what we use it for, and the rules we apply before a figure goes on a product page. Every statistic we publish also carries its own source note at the foot of the page it appears on.

The organisations we cite

Office for National Statistics. Crime in England and Wales, published quarterly. We use it for fraud prevalence and for recorded theft from the person. Course 01 and Course 03.

National Cyber Security Centre. The NCSC's Annual Review and its published analysis of breached passwords. We use it for phishing report volumes, takedown activity, and password reuse. Courses 02, 06 and 09.

Ofcom. Children's Online Experiences research. We use it for what children actually encounter online and how they encounter it. Course 15.

UK Finance. The Annual Fraud Report. We use it for payment fraud losses and the breakdown of authorised push payment cases. Course 14.

Department for Science, Innovation and Technology, and the Home Office. The Cyber Security Breaches Survey, and Cyber security skills in the UK labour market. We use them for ransomware prevalence and for cyber employment and salary data. Courses 07 and 20.

Google. The published Pixel software update commitment. We use it for the security update window on the GhostNet Wraith.

The GrapheneOS project. Its own documentation at grapheneos.org. We use it for what GrapheneOS does and does not provide.

What we are not claiming

None of the organisations above endorse GhostNet Solutions, approve our courses, or have any relationship with us of any kind. We are not affiliated with, accredited by, partnered with or certified by any of them.

We cite them for one reason. They publish good data, in public, for free, and it is better than anything we could produce ourselves. Naming them lets you go and check us.

GrapheneOS in particular is an independent open source project. We install it on the hardware we sell. That is the entire extent of the connection, and the project would be no worse off if you flashed it yourself.

The rules we apply

  • A figure has to trace to a named organisation and a dated publication. If we cannot attribute it, we do not use it, however good it sounds.
  • We name the report and the period it covers, not just the organisation, so you can find the specific document rather than searching a whole website.
  • If a figure is old, we say so on the page rather than presenting it as current. The oldest number on this site is from 2019 and is labelled as such.
  • If a number is falling rather than rising, we say that too, even where it weakens the point we are making.
  • We do not use a statistic to say more than it actually says. A finding about businesses is not presented as a finding about households.

What we removed

Applying those rules to our own material cost us several figures we had been using.

Claims like "90% of breaches begin with a phishing message" and "70 million phones are lost or stolen each year worldwide" circulate very widely and appear authoritative. Neither traces back to a credible primary source. Both were in our material. Both are gone, replaced with attributed data from the organisations listed above.

We mention this because unverifiable statistics presented as fact are precisely what Course 09 teaches people to spot, and we would rather tell you we found some in our own work than hope nobody noticed.

If we have got something wrong

Tell us. If a figure on this site is wrong, out of date, or does not say what we claim it says, email us and we will correct it. If it turns out we cannot attribute it, we will remove it rather than defend it.

That is not a courtesy. It is the only version of this that is worth anything.