The ransom payment report must include, to the extent applicable and available: a description of the ransomware attack including estimated date range; vulnerabilities/TTPs; actor identifying/contact information; the covered entity identity and contact; the date of payment; the ransom demand including virtual-currency type; payment instructions including the virtual-currency or physical address; and the amount paid.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.