A new online resource has been developed to track material breaches in cybersecurity, providing a unique tool for professionals, journalists, and policymakers. This index fills a critical gap by offering a centralized platform for monitoring disclosed incidents without aggregating financial losses.
Background of the Cybersecurity Index
The creator behind this tool is Richard Bird, who currently serves as the Chief Strategy and Security Officer at Singulr AI, an enterprise AI governance firm. With past leadership roles at JPMorgan Chase and other cybersecurity organizations, Bird brings a wealth of experience to this initiative. The project, named The Hacker in a Hoodie (HIH) Index, is part of the preparation for his forthcoming book, ‘Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It’.
The index features two main ledgers, updated almost daily by Bird himself using custom-built pollers and tracers. The first ledger pulls data from the SEC’s EDGAR system, focusing on 8-K disclosures that public companies must file after significant cyber incidents — a requirement in place since 2023. The second ledger compiles information from news articles and official company statements.
Data Organization and Grading System
The information gathered is often in raw form, with few entries providing exact financial losses. Bird’s ledger organizes these disparate records into a coherent, ongoing list. As of now, the index includes over 100 incidents, with recent entries about breaches at companies like Coca-Cola’s Fairlife and Accenture.
Each entry in the HIH Index is graded based on the reliability of its source: SEC filings are deemed ‘verified’, company statements are ‘attested’, and news reports are ‘inferred’. This grading system allows users to quickly assess the credibility of the information presented.
Impact and Future of Cybersecurity Reporting
Beyond the ledgers, the site offers a reference chart with annual data from the FBI’s Internet Crime Complaint Center and IBM’s Cost of a Data Breach report. These figures suggest that while the per-incident cost has remained stable over the past decade, the total financial impact of breaches has surged.
Bird emphasizes that the index’s purpose is not to assign blame but to highlight flaws in the current cybersecurity model. He argues that cybersecurity has been treated as a financial burden rather than a performance metric, likening it to business taxes. This approach, he suggests, is a fundamental reason behind the industry’s ongoing challenges.
Bird’s decision not to total the ledger data is intentional, aimed at avoiding misleading figures. He criticizes industry estimates like Cybersecurity Ventures’ trillion-dollar projection, which he views as speculative. The true value of the ledgers lies in their ability to verify claims through solid, sourced data.
Maintained solely by Bird, the project is still in its infancy but mirrors the growth trajectory of services like Troy Hunt’s Have I Been Pwned. Bird’s ultimate goal is to shift how cybersecurity performance is measured, advocating for a framework that recognizes it as a value-added business function rather than an unavoidable expense.
