Because cloud and SaaS providers become targets once customer data moves to them, they should publish statistics on their own internal controls, such as the deployment of phishing-resistant MFA like FIDO; ideally no staff member can reach customer or other sensitive data without it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.