Tracking Breaches Without the Guesswork
A new index aims to standardize how we monitor material cyber incidents by prioritizing verifiable data over industry-wide estimates.
In an industry often defined by opaque, high-level projections of cybercrime costs, a new resource has emerged to bring clarity to incident reporting. The Hacker in a Hoodie (HIH) Index, a project independently developed by Richard Bird, aims to catalog material cyber breaches by prioritizing source verification over aggregated, speculative totals.
A Dual-Ledger Approach
The architecture of the index relies on two distinct data streams. The first extracts information directly from SEC EDGAR, specifically tracking 8-K disclosures required of public companies since 2023. The second ledger compiles reports from corporate statements and external news coverage. By separating these inputs, the project attempts to resolve the issue of raw, inconsistent reporting that often plagues cybersecurity data.
Each entry in the index is assigned a grade based on the reliability of its source material:
- Verified: Primary SEC filing data
- Attested: Company-provided official statements
- Inferred: Data derived from news reporting
Prioritizing Accuracy Over Totals
Rather than attempting to calculate a definitive financial sum for industry losses, the index remains deliberately granular. Bird argues that combining data from different evidence tiers—such as a confirmed SEC filing versus a news-based estimate—creates a false sense of precision. His methodology rejects the common practice of generating massive, speculative figures that often lack foundational support.
“Summing the numbers creates a myth — it is no longer data; it becomes a prediction at best and a forecast at worst. The losses are so grossly underreported that if I took that sensationalist approach, I’d be creating another version of the same problem. A bunch of guessing that is perceived as being better but only because it has more citations.”
— Richard Bird, Chief Strategy and Chief Security Officer at Singulr AI
Contextualizing Industry Performance
The project includes reference charts comparing its data against broader industry benchmarks. These include reports from the FBI and IBM to illustrate the disconnect between rising incident frequency and stagnant per-incident costs. The data serves as a critique of how cybersecurity is currently measured within corporate governance, where it is often categorized as a fixed cost rather than an outcome-driven performance metric.
Implications for Security Analysis
For cybersecurity professionals, analysts, and policymakers, the index provides a verifiable audit trail for claims made about breach impacts. By exposing the reality that many incidents remain unquantified, the project highlights a gap in corporate reporting culture. This shift toward source-graded data may force a reevaluation of how businesses measure risk, moving away from marketing-driven estimates and toward a framework that treats cybersecurity as a measurable, value-added function within the enterprise.
Continue Reading
Critical Command Injection Flaw in AVideo
An incomplete patch in AVideo versions before 29.0 allows unauthenticated attackers to execute arbitrary OS commands via the Live plugin.
LightRAG Critical CORS Flaw Enables Data Theft
A critical vulnerability in LightRAG allows unauthorized cross-origin requests, potentially exposing sensitive documents and knowledge graph data.
LightRAG Critical Auth Bypass Vulnerability
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
Sources
- SecurityWeek Original source