New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Richard Bird launched the "Hacker in a Hoodie (HIH) Index," a transparent tracker for disclosed material cyber breaches aimed at providing a reliable resource for professionals and the public. The tool utilizes two distinct ledgers: one aggregating SEC 8-K filings (mandatory since 2023) and another compiling news reports and company statements, updated via custom-built scrapers. Entries are graded by evidence quality ('verified', 'attested', 'inferred') to prevent misleading aggregation, rejecti
Analysis
TL;DR
- Richard Bird launched the "Hacker in a Hoodie (HIH) Index," a transparent tracker for disclosed material cyber breaches aimed at providing a reliable resource for professionals and the public.
- The tool utilizes two distinct ledgers: one aggregating SEC 8-K filings (mandatory since 2023) and another compiling news reports and company statements, updated via custom-built scrapers.
- Entries are graded by evidence quality ('verified', 'attested', 'inferred') to prevent misleading aggregation, rejecting the industry's tendency to sum unverified estimates into sensationalized totals.
- Bird argues that cybersecurity is structurally treated as a fixed "tax" or overhead cost rather than a measurable performance metric, leading to systemic failures despite stable per-incident costs.
Why It Matters
This initiative addresses a critical transparency gap in the cybersecurity industry by moving beyond speculative financial projections to verifiable, source-graded data. For AI practitioners and security researchers, it highlights the importance of data provenance and the dangers of aggregating heterogeneous data sources without rigorous quality control. Furthermore, it underscores a strategic shift in how organizations might need to evaluate cybersecurity investments, moving from compliance-based metrics to outcome-based performance indicators.
Technical Details
- Data Sources: The primary ledger ingests data from the SEC EDGAR database (specifically Form 8-K filings regarding material cyber incidents), while the secondary ledger aggregates unstructured data from news articles and corporate press releases.
- Automation Infrastructure: The system relies on custom-built web scrapers ("pollers and tracers") maintained by Bird to update the ledgers on a daily or near-daily basis, eliminating reliance on third-party data vendors.
- Evidence Grading System: Each breach entry is assigned a credibility tier: 'Verified' for primary SEC filings, 'Attested' for official company statements, and 'Inferred' for journalistic reports, allowing users to assess data reliability.
- Reference Metrics: The platform integrates static comparative data from the FBI’s Internet Crime Complaint Center (e.g., $20.9 billion in reported losses for 2025) and IBM’s Cost of a Data Breach report ($4.44 million average per breach) to contextualize trends.
Industry Insight
- Shift from Activity to Outcome: Organizations should reconsider cybersecurity budgeting by adopting measurable performance outcomes rather than treating security as a static overhead cost, potentially aligning it more closely with ROI-driven business functions.
- Data Integrity in Reporting: The rejection of summed, unverified loss estimates serves as a cautionary tale for the broader tech industry; stakeholders must prioritize data provenance and transparency over sensationalized aggregate statistics to maintain trust.
- Regulatory Impact: With mandatory disclosure rules like the SEC 8-K requirement becoming standard, companies must enhance their internal incident reporting mechanisms to ensure accurate, timely, and compliant public disclosures, reducing the burden on external tracking efforts.
Disclaimer: The above content is generated by AI and is for reference only.