New Index Tracks Material Breaches — And Refuses to Add Up the Losses

A New Index Tracks Material Breaches – But Refuses to Add Up the Losses

In a groundbreaking move, cybersecurity expert Richard Bird has launched The Hacker in a Hoodie (HIH) Index, a website that tracks disclosed material breaches and shines a light on the limitations of current cyber loss reporting. As Chief Strategy and Chief Security Officer at Singulr AI, Bird brings a wealth of experience to this project, which is also tied to his upcoming book, “Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It”.

The HIH Index is built on two main ledgers that update daily or near-daily, pulling data from SEC EDGAR filings and news articles. These ledgers contain over 100 entries, including recent incidents reported by Coca-Cola’s Fairlife, Centers Lab, Mount Royal University, and Accenture. Each entry is graded according to its sourcing: primary SEC filings are “verified”, company statements are “attested”, and news reports are “inferred”. This grading system allows users to quickly assess the credibility of each entry.

One of the key criticisms Bird makes about current cyber loss reporting is that it relies too heavily on sensationalized estimates. He argues that summing up the losses, as many reports do, creates a myth rather than providing accurate data. The trillion-dollar cybercrime estimate, popularized by Cybersecurity Ventures, is a prime example of this issue. By refusing to add up the numbers, Bird’s project provides a much-needed resource for journalists, policymakers, and cybersecurity professionals alike.

The HIH Index also includes a static reference chart that pulls annual figures from the FBI’s Internet Crime Complaint Center and IBM’s Cost of a Data Breach report. These reports show that while total reported losses have increased by 35% annually over the past decade, per-incident cost has remained relatively stable. Bird interprets this as evidence that companies are failing at cybersecurity more frequently each year, allowing hackers to capitalize on these vulnerabilities.

Bird emphasizes that his project is not about pointing fingers of blame, but rather about rethinking the way we measure and report cyber loss. He argues that current methods focus too much on activity metrics, such as the number of breaches or malware detected, rather than actual performance and outcomes. By shifting the focus to verifiable data and credible sources, Bird’s project aims to provide a more accurate picture of the cybersecurity landscape.

For those interested in staying up-to-date with material breaches and understanding the limitations of current reporting methods, The Hacker in a Hoodie Index is an invaluable resource. It provides a citable, source-graded reference that can be used to check claims against, helping to separate fact from fiction in the world of cyber loss reporting.

In conclusion, Bird’s project highlights the need for more accurate and transparent reporting in the cybersecurity industry. By refusing to add up the losses and instead focusing on verifiable data, The Hacker in a Hoodie Index is an important step towards rebuilding our understanding of cyber loss and driving meaningful change. As Bird himself says, “The HIH Index is not about sensationalizing numbers; it’s about providing a fact-based reference that can be used to make informed decisions.”


Source: SecurityWeek — 2026-07-20