# The Cybersecurity Industry Has a Number Problem. This Index Is Trying to Fix It.
For years, the go-to statistic in breach coverage has been some variation of a trillion-dollar cybercrime figure — a number so large it practically vibrates with urgency, and so poorly sourced that anyone who traces it back to its origin finds a single analyst projecting compounding curves into the void. The industry has used it anyway, because trillion dollars sounds like something worth paying attention to.
Richard Bird is tired of it.
Bird — longtime security executive, former JPMorgan Chase leader, current Chief Strategy and Security Officer at enterprise AI governance firm Singulr AI — has spent the past several months building something the security field has somehow not produced: a structured, graded, daily-updated index of material breaches, divorced from the addictive but corrosive habit of summing up losses that aren't actually comparable.
He calls it the Hacker in a Hoodie Index, and its most interesting feature is what it refuses to do.
## Built on the Only Honest Disclosure Requirement in Existence
The HIH Index draws from two sources. The first is SEC EDGAR — specifically the 8-K filings that public companies are required to submit when they experience a material cyber incident. That requirement is new. The SEC only formalized it in 2023, which means the pool of structured, legally obligated breach disclosures is barely three years deep. The second source is news articles and companies' own statements.
Bird built his own pollers and tracers to pull this data, and he runs them himself. At time of writing, the index covers more than 100 incidents, including recent entries on Fairlife (Coca-Cola's dairy brand), Centers Lab, Mount Royal University, and Accenture.
What makes the index genuinely useful rather than just another breach aggregator is the sourcing hierarchy Bird baked into every entry. An SEC filing is marked "verified." A company's own statement is "attested." A news report is "inferred." That three-tier grading means a researcher, journalist, or policymaker can look at a given entry and immediately understand how much epistemic weight it carries. Verified dollar losses aren't the same as estimated losses reported secondhand, and the index never pretends they are.
## The 35 Percent Problem
Separate from both ledgers, Bird includes a static reference chart built from FBI Internet Crime Complaint Center data and IBM's annual Cost of a Data Breach report. The juxtaposition is damning.
IBM's figure for average breach cost has barely moved in a decade — hovering around $4.44 million per incident. Meanwhile, FBI IC3 data shows total reported cybercrime losses hitting nearly $20.9 billion for 2025, compounding at roughly 35 percent annually.
If per-incident cost is flat and total losses are rising exponentially, there's only one conclusion: the number of successful attacks is growing fast. Companies aren't getting hit harder per breach — more companies are simply getting breached.
Bird's framing of this is blunt: "The hackers aren't making more money from the same number of victims. More companies are failing — way more — at cybersecurity every year and the bad guys are functionally printing money by capitalizing on how poorly cybersecurity is actually being executed at these companies."
That's not a comfortable message for an industry that has spent a decade arguing that better tools, bigger budgets, and more certifications are winning the fight. The flat per-breach cost masks a rising volume that suggests the opposite.
## Why He Won't Add It Up
The HIH Index's deliberate refusal to produce a headline total is its most counterintuitive and most defensible design choice.
Most entries in the index are marked "not yet quantified." The ones that do carry a dollar figure arrive from different evidence tiers — a verified SEC loss, an attested company statement, an inferred press report. Treating these as equivalent and producing a sum would create exactly the kind of number Bird is arguing against: something that looks precise, survives endless citation, and means nothing.
He's pointed at Cybersecurity Ventures' trillion-dollar cybercrime estimate as the archetype of this failure. That projection became ubiquitous not because it was well-sourced but because it was big enough to land in board decks and Senate hearings. It provided the industry with a number it wanted — a justification for spending — without providing anything it needed: a measurement of whether that spending was working.
"Summing the numbers creates a myth — it is no longer data," Bird told SecurityWeek. His book, *Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It*, extends this argument: the field has been optimizing for activity metrics — patches deployed, alerts reviewed, awareness training completed — rather than outcome metrics. The index is an attempt to establish the kind of outcome baseline that would make performance measurement possible.
---
## HackWire Analysis
The HIH Index arrives at a specific inflection point. The SEC 8-K disclosure rule, despite industry pushback, has quietly created the first mandatory, structured, public record of material breaches for public companies. Three years of filings now exist. That corpus is small, but it's growing and it's legally attested — which makes it categorically more reliable than anything the industry was working with before.
What Bird is doing is building infrastructure on top of that foundation before anyone else does it badly. The alternative — waiting for someone to scrape the same SEC filings and publish a headline number without the sourcing tiers — has happened repeatedly in adjacent spaces. Cybercrime estimates become talking points. Talking points become budget justifications. Budget justifications insulate bad programs from scrutiny.
The sourcing grading system is the critical differentiator here, and it deserves wider adoption. The security press routinely treats company statements, insurance estimates, and SEC filings as interchangeable when they're not. A CFO's estimate in a press release and a legal attestation to the SEC carry fundamentally different weight. That distinction shapes how defenders, regulators, and buyers should interpret breach reports.
The deeper critique — that the field measures activity rather than performance — has been made before, but rarely with this level of structural follow-through. Calling out the measurement problem is easy. Building the alternative ledger, running your own pollers, and maintaining a daily-updated index while also holding a CSO role is a different kind of commitment. Watch whether the index attracts peer review, regulatory interest, or academic collaboration; that would signal whether it develops into the field's first reliable baseline, or remains one executive's honest project.
Private companies remain outside the SEC disclosure umbrella entirely, which means a large fraction of material breaches still never surface in any structured form. The HIH Index's government and news ledger addresses this partially, but the inferred tier is exactly where the industry's bad habits live. That gap isn't a criticism of Bird's design — it's an argument for extending mandatory disclosure further.
— HackWire Editorial
---
## Related Coverage