The ransomware payment report must contain the prescribed information, including details of the incident, the demand, the payment made and the entity to which it was made.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.