New Index Tracks Material Breaches — And Refuses to Add Up the Losses

A longtime cybersecurity executive has built a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist.
The tracker was created by Richard Bird, who is currently Chief Strategy and Chief Security Officer at enterprise AI governance company Singulr AI. He previously held leadership roles at JPMorgan Chase and several cybersecurity companies.
Unrelated to his role at Singulr AI, Bird is an author, and in preparation for his upcoming book — Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It — he has launched a new project named The Hacker in a Hoodie (HIH) Index.
The core of the site is a pair of ledgers that update on what Bird describes as a daily or near-daily basis, pulled by pollers and tracers he built and runs himself.
The first ledger draws from SEC EDGAR, the agency’s public filing database, tracking the 8-K disclosures that public companies are required to file when they experience a material cyber incident — a requirement that has existed only since 2023. The second ledger is based on news articles and companies’ own statements.
The data arrives as raw, inconsistent text, with some entries naming a dollar loss while most don’t. Bird’s ledger organizes those scattered records into one running list.
At the time of writing, the index contains information on more than 100 incidents. The most current entries cover data breaches reported by Coca-Cola’s Fairlife, Centers Lab, Mount Royal University, and Accenture.
The HIH Index grades every entry by how solid its sourcing is: a primary SEC filing counts as ‘verified’, a company’s own statement as ‘attested’, and a news report as ‘inferred’. That grading lets a reader tell at a glance how much weight a given entry can actually carry.
Separate from both ledgers, the site includes a static reference chart that pulls annual figures from the FBI’s Internet Crime Complaint Center (which shows nearly $20.9 billion in reported losses for 2025) and IBM’s Cost of a Data Breach report (which shows an average of $4.44 million per breach).
These reports provide context for the project’s argument. They show that per-incident cost has barely moved in a decade, even as total reported losses have compounded at roughly 35% a year.
“This means only one thing — the hackers aren’t making more money from the same number of victims,” Bird told SecurityWeek. “More companies are failing (way more) at cybersecurity every year and the bad guys are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed at these companies.”
He added, “The [upcoming] book, and the index, are not pointing fingers of blame. What we’ve built in cybersecurity is rational. But it is rational based on the wrong data and inputs — we measure activity, we don’t measure performance and outcomes.”
Bird’s case against summing the HIH Index data is straightforward: most of the ledger’s entries are marked ‘not yet quantified,’ and the ones that do carry a figure come from different evidence tiers — a verified dollar loss in an SEC filing isn’t the same as an inferred estimate drawn from a news report. Treating those as interchangeable and adding them together would produce a number that looks precise but is not backed by anything solid.
He points to the industry’s favorite trillion-dollar cybercrime estimate, a controversial Cybersecurity Ventures projection, as exactly the kind of number his project aims to avoid manufacturing.
“Summing the numbers creates a myth — it is no longer data; it becomes a prediction at best and a forecast at worst,” Bird explained. “The losses are so grossly underreported that if I took that sensationalist approach, I’d be creating another version of the same problem. A bunch of guessing that is perceived as being better but only because it has more citations.”
What makes the ledgers useful isn’t the total — it’s the ability to check. A reporter or analyst can look up what a specific company actually disclosed, how the filing was worded, and what evidence grade it carries. In an industry where cyber loss reporting leans heavily on marketing-driven estimates, having a citable, source-graded reference to check claims against fills a gap that has largely gone unfilled.
Bird maintains the entire project alone — no editorial team, no outside data vendor, just the scrapers he built to keep both ledgers current. He is also upfront about the dataset being young: the SEC requirement it’s built on is relatively new, and he draws a direct comparison to Troy Hunt’s Have I Been Pwned data breach notification service, which also started small and grew because there was nowhere else to look.
That absence is the point he’s really making. Everything else in a company gets measured in dollars, except cybersecurity, which Bird says has been treated as overhead instead of a tracked outcome. In his words:
“Business keeps score in dollars, governments keep score in dollars, consumers keep score in dollars — cybersecurity is the only business function that isn’t measured in dollars from a performance perspective. It’s treated as a ‘cost of business’. There is only one other corporate ‘cost of business’ in the enterprise world — whether it is large, medium or small businesses. And that is taxes. We built cybersecurity as a tax, not as a value-added business function. The entire industry and practice has created an ecosystem over the last 30 years that not only emphasizes that truth, it actually rewards the continuation of the flawed model.”
Related: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk
Related: New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications
https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/