**Introducing the HIH Index: A New Tool for Tracking Material Cyber Breaches**
In an age where data breaches dominate headlines but often lack reliable, centralized tracking, a former cybersecurity executive has taken matters into his own hands. Richard Bird, currently Chief Strategy and Chief Security Officer at Singulr AI—and previously a leader at JPMorgan Chase and multiple cybersecurity firms—has launched a unique public resource known as the “Hacker in a Hoodie (HIH) Index.” This project is designed to provide transparency and clarity in an area clouded by inconsistent reports and speculative figures.
The HIH Index is not another generic dashboard. It’s a meticulously curated, real-time reference built with the discipline of scientific methodology and the urgency of lived experience in cybersecurity. The tracker operates on two distinct ledgers, each with its own sourcing methodology and credibility indicators.
**The SEC 8-K Ledger: Enforcing a New Era of Disclosure**
One ledger pulls directly from the U.S. Securities and Exchange Commission’s (SEC) EDGAR database. Since 2023, public companies have been legally required to disclose material cyber incidents in a specific 8-K filing format. The HIH Index monitors these filings daily, capturing instances where companies formally acknowledge significant security breaches. This ledger is considered the most authoritative source—Bird labels these entries as “verified.”
**The News and Statement Ledger: Attesting to Transparency**
The second ledger relies on news articles and official company statements that report a breach but may not trigger an SEC filing. This includes press releases or public communications from the companies themselves. These entries are labeled “attested,” indicating a direct source, though one that exists outside the regulatory framework.
**Why Leadings Matter: The Problem with “Vague Math”**
A key feature of the HIH Index is its commitment to data integrity. Bird is deeply critical of the cybersecurity industry’s tendency to aggregate unverified numbers into massive, often-cited statistics—like the frequently referenced but elusive “trillion-dollar cybercrime” estimate.
He argues that summing unverified and verified data creates a “myth” rather than a measurement. “Summing the numbers creates a myth—it is no longer data; it becomes a prediction at best and a forecast at worst,” Bird explains. His index avoids this pitfall by refusing to combine disparate data types. Instead of producing a single, misleading total, the HIH Index presents a library of individual, source-graded incidents.
**Providing Context in a Cost-Increasing World**
Supplementing the ledgers is a reference section that provides crucial industry context. It highlights data from the FBI’s Internet Crime Complaint Center (IC3), which reported nearly $20.9 billion in losses in 2025, and IBM’s Cost of a Data Breet report, which notes an average cost of $4.44 million per incident. This data reveals a troubling trend: while the cost per breach has remained stagnant for a decade, the total financial losses are compounding at a rate of roughly 35% year-over-year.
Bird interprets this as a clear message: “The hackers aren’t making more money from the same number of victims. More companies are failing (way more) at cybersecurity every year.”
**A Solo Mission for Accountability**
Remarkably, Bird built and maintains the entire index alone, using custom pollers and tracers to gather and organize the raw text. He draws a parallel to Troy Hunt’s groundbreaking “Have I Been Pwned” service, which started small because there was no alternative. Bird sees his project filling a similar void.
His critique strikes at the heart of the industry’s culture. “Cybersecurity is the only business function that isn’t measured in dollars from a performance perspective,” he states. “It’s treated as a ‘cost of business’… We’ve built cybersecurity as a tax, not as a value-added business function.”
Ultimately, the HIH Index is more than a tracker; it’s a call for accountability. By providing a space to check claims against primary sources, it aims to shift the conversation from speculative forecasts to measurable outcomes.
***
### FAQ
**What is the HIH Index?**
The HIH Index, or Hacker in a Hoodie Index, is a public tracker created by Richard Bird to monitor and log disclosed material cybersecurity breaches. It provides a resource for cybersecurity professionals, journalists, and the public to verify the details of major incidents.
**What data sources does the HIH Index use?**
The index utilizes two main ledgers:
1. **The SEC 8-K Ledger:** This ledger tracks material cyber incidents disclosed in SEC filings, which is a regulatory requirement for public companies in the U.S. These entries are graded as “verified.”
2. **The News and Statement Ledger:** This ledger is based on news articles and direct company statements about breaches. These entries are graded as “attested.”
**What does it mean for an entry to be “verified” or “attested”?**
* **Verified:** The information comes directly from a formal SEC EDGAR 8-K filing, the highest tier of sourcing.
* **Attested:** The information comes from a company’s own official statement or a reputable news article.
**Why doesn’t the HIH Index show a total dollar loss?**
The index deliberately avoids summing all reported losses because the data is inconsistent. Many entries lack a dollar figure, and those that do come from different evidence tiers (e.g., a verified SEC filing vs. an inferred news report). Combining these into a single total would create a precise-looking number that is not backed by solid data, a practice Bird compares to “speculative forecasting.”
**Who is Richard Bird?**
Richard Bird is a longtime cybersecurity executive, currently serving as Chief Strategy and Chief Security Officer at Singulr AI. He has held leadership roles at JPMorgan Chase and several cybersecurity firms. He is also an author, and the HIH Index was created in preparation for his upcoming book, *Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It*.



