news.mlab.sh
Back to the feed
threat-intel

New Index Tracks Material Breaches — And Refuses to Add Up the Losses

Medium
Summary

Richard Bird, a former cybersecurity executive, has launched The Hacker in a Hoodie (HIH) Index, a project tracking disclosed material cyber incidents. The index compiles data from SEC filings and news reports, grading the reliability of each entry based on its source. Bird argues that aggregating these disparate loss figures – often lacking precise quantification – creates a misleading ‘trillion-dollar’ cybercrime myth, and that the industry has treated cybersecurity as a cost rather than a measurable business outcome. The index aims to provide a verifiable, source-graded reference for journalists and analysts to assess claims about cyber losses, addressing a gap in the industry’s reporting practices.

Richard Bird, a longtime cybersecurity executive, has created The Hacker in a Hoodie (HIH) Index, a new project designed to address a significant gap in how cyber loss data is reported and analyzed. The index consists of two ledgers: one drawing from SEC EDGAR filings – the agency’s public filing database – and tracking disclosures required since 2023 when the SEC mandated 8-K filings for material cyber incidents. The second ledger is built from news articles and company statements. Bird emphasizes that much of the data arrives as raw, inconsistent text, with some entries including dollar losses while most do not. He grades each entry based on its source reliability: a primary SEC filing is considered ‘verified,’ a company’s own statement is ‘attested,’ and a news report is ‘inferred.’

Bird’s core argument is that simply adding up these reported losses – which frequently rely on marketing-driven estimates – creates a misleading impression of the scale of cybercrime. He points to the Cybersecurity Ventures projection of a trillion-dollar cybercrime market as an example of a fabricated number. He believes that because cyber loss reporting is often based on estimates and lacks rigorous measurement, aggregating these figures produces a distorted picture.

The HIH Index isn’t about providing a total dollar amount of losses; it’s about offering a verifiable reference point. Journalists and analysts can examine the original SEC filings, understand the wording of company disclosures, and assess the evidence grade associated with each entry. This approach mirrors the functionality of Troy Hunt’s Have I Been Pwned service, which began as a small, manually-maintained database and grew over time due to a lack of alternative sources.

Bird highlights that cybersecurity is often treated as a ‘cost of business’ rather than a measurable business function, similar to taxes. He argues that the industry has created an ecosystem that emphasizes cost-cutting rather than performance and outcomes. He believes that by shifting the focus from simply tracking costs to measuring cybersecurity performance, the industry can move towards a more effective and accountable approach to protecting against cyber threats.

Read the full article at SecurityWeek