A Breach Ledger That Tells the Truth
Most breach tracking resources fall into one of two failure modes: they either sum up losses into attention-grabbing headline figures that can't be substantiated, or they bury incidents in dense regulatory filings that only lawyers read. The Hacker in a Hoodie (HIH) Index is a deliberate attempt to avoid both traps.
Built by Richard Bird, Chief Strategy and Security Officer at Singulr AI, the HIH Index tracks material cybersecurity incidents through two independent ledgers — and it will never print a total losses figure.
Two Ledgers, One Standard
The index maintains two distinct data sources:
Ledger 1: SEC EDGAR
Tracks 8-K disclosures filed by public companies reporting material cyber incidents. Since the SEC's 2023 rule requiring timely cyber incident disclosure, this has become the closest thing to a ground truth for corporate breaches — because companies face legal liability for what they file.
Automated pollers check EDGAR on a daily or near-daily basis.
Ledger 2: News and Company Statements
Aggregates incidents from news reports and official company communications — a broader but less authoritative source.
Credibility Grading: Not All Evidence Is Equal
Every entry in the HIH Index carries a credibility grade:
| Grade | Source | Weight |
|---|---|---|
| Verified | Primary SEC 8-K filings | Highest |
| Attested | Company statements | Medium |
| Inferred | News reports | Lowest |
Current tracked incidents include breaches at Coca-Cola's Fairlife, Centers Lab, Mount Royal University, and Accenture, among 100+ total entries.
Why the Index Refuses to Sum Losses
This is the design choice that sets the HIH Index apart. Bird explains the reasoning plainly:
"Summing the numbers creates a myth — it is no longer data."
Most entries are marked "not yet quantified." Those that do carry a financial figure draw from different evidence tiers — meaning a Verified SEC disclosure and an Inferred news report might sit side-by-side in the ledger, but combining their figures would mix fundamentally incomparable data sources.
Adding them up produces a headline. It doesn't produce knowledge.
What the Data Actually Shows
The most revealing insight from the HIH Index isn't a single number — it's the pattern. Annual cybercrime losses compound at roughly 35% per year, yet per-incident costs remain stubbornly static at around $4.44 million.
If individual incidents cost about the same year over year, but total losses keep compounding, the conclusion is uncomfortable: organizations aren't being hit by increasingly destructive attacks. They're simply failing to learn. The systemic dysfunction isn't improving.
Context: The Book Behind the Index
The HIH Index supports Bird's forthcoming book: Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It. The index is designed to serve security professionals, journalists, policymakers, and members of the public who want a clear-eyed, evidence-graded view of the breach landscape without the mythology that typically surrounds cybercrime statistics.
Why This Matters
Cybersecurity decision-making is routinely distorted by inflated or unverifiable loss figures. When industry groups announce trillion-dollar annual cybercrime costs derived from surveys and extrapolations, security leaders can't translate those numbers into board-level decisions. The HIH Index takes a different stance: track what's actually disclosed, grade the evidence honestly, and refuse to manufacture precision where none exists.
For practitioners who need to brief executives or regulators, an evidence-graded, auditable breach ledger is more useful than any headline figure.