← BACK TO FEED
cybersecuritydata breachesSEC disclosurebreach trackingcyber risk

This Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand Total

Richard Bird, a cybersecurity executive and author, has launched the Hacker in a Hoodie (HIH) Index — a website that tracks disclosed material cyber breaches by drawing on SEC EDGAR filings and news sources, grading each entry by the reliability of its sourcing. Unlike industry estimates that aggregate losses into headline figures, Bird deliberately avoids summing the data, arguing that combining inconsistently evidenced entries produces misleading numbers that resemble the marketing-driven projections already plaguing the field. The project's broader argument is that cybersecurity has long been measured by activity rather than outcomes, and that treating it as a business cost rather than a performance-tracked function is the root cause of the industry's persistent failure to reduce breaches.

Cybersecurity has a data problem. Not a shortage of numbers — there's no shortage of those — but a shortage of numbers that actually mean anything. Trillion-dollar estimates get laundered into conference keynotes and vendor whitepapers until they take on the weight of fact. Richard Bird, a former JPMorgan Chase executive and current CSO at enterprise AI governance firm Singulr AI, has decided to do something about it.

Bird has built and launched the Hacker in a Hoodie (HIH) Index, a publicly accessible tracker of disclosed material cyber breaches. The project sits outside his day job and is tied to an upcoming book, Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It. He runs the whole thing himself.

The index is built around two running ledgers. The first pulls from SEC EDGAR, specifically the 8-K filings that US public companies have been required to submit following material cyber incidents since 2023. The second is built from news reporting and companies' own public statements. Both are updated daily or close to it, using scrapers and tracers Bird wrote himself. At the time of writing, the index covers more than 100 incidents, with recent entries including breaches reported by Coca-Cola's Fairlife, Mount Royal University, and Accenture.

Because the source material is inconsistent, some entries include a named dollar figure and most do not, Bird applies a sourcing grade to every entry. An SEC filing gets marked 'verified'. A company statement is 'attested'. A news report is 'inferred'. That single distinction matters more than it might sound. It means anyone using the index as a reference can immediately tell how solid the underlying evidence actually is.

The site also includes a static reference chart pulling headline figures from the FBI's Internet Crime Complaint Center (nearly $20.9 billion in reported losses for 2025) and IBM's annual Cost of a Data Breach report ($4.44 million average per breach). Those figures provide context rather than endorsement. What Bird finds interesting is the gap between them: per-incident costs have barely shifted in a decade, while total reported losses have compounded at around 35% per year.

His conclusion is blunt. "This means only one thing — the hackers aren't making more money from the same number of victims. More companies are failing at cybersecurity every year and the bad guys are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed."

Notably, Bird refuses to sum the HIH Index totals. Most entries carry no dollar figure at all, and the ones that do come from different evidence tiers. Adding a verified SEC loss alongside an inferred news estimate would produce a number that looks authoritative but rests on nothing. He's specifically taking aim at the industry habit of publishing impressively round figures with thin methodology underneath them.

"Summing the numbers creates a myth," he said. "It is no longer data; it becomes a prediction at best and a forecast at worst. The losses are so grossly underreported that if I took that sensationalist approach, I'd be creating another version of the same problem."

The practical value of the ledger is not a headline total. It's granularity and citability. A journalist or analyst can look up exactly what a specific company disclosed, read how the filing was worded, and know what confidence level to attach to it. That kind of traceable, graded reference is largely absent from the existing landscape.

Bird draws a deliberate comparison to Troy Hunt's Have I Been Pwned, which started as a one-person project filling a gap nobody else had bothered to fill. The SEC disclosure requirement the index relies on is still relatively new, so the dataset is young. But that's partly the point.

The deeper argument Bird is making is structural. Every other business function gets measured in money. Cybersecurity doesn't. It's treated as overhead, a cost of doing business alongside taxes, with no meaningful performance tracking against outcomes.

"Business keeps score in dollars, governments keep score in dollars, consumers keep score in dollars," he said. "Cybersecurity is the only business function that isn't measured in dollars from a performance perspective. We built cybersecurity as a tax, not as a value-added business function. The entire industry has created an ecosystem over the last 30 years that not only emphasizes that truth, it actually rewards the continuation of the flawed model."

That's a fairly damning verdict from someone who has spent decades inside the industry. Whether the HIH Index grows into the reference he's aiming for will depend on uptake. But the underlying argument, that the sector has been measuring activity instead of outcomes and mistaking noise for data, is hard to dismiss.

READ NEXT
Ransomware Knocks Out Fairlife Milk Production Across the USRussian Intel Is Using Your CCTV Camera to Watch NATO Weapons ShipmentsRansomware Knocks Fairlife's US Dairy Plants Offline