About the index

Who is behind this

The Hacker in a Hoodie Index is written by Richard William Bird, a seven-time C-level executive in technology and security, across both the corporate and start-up worlds.

He is the author of Built Wrong: Why Cybersecurity Keeps Failing and How We Can Rebuild It, a systemic diagnostic of the field: its historical foundations, and how those foundations have failed to evolve to meet the world’s digital threats. He wrote it as an insider with experience across every part of security, from regulatory demands and compliance to risk management, and from the operator’s seat. He is on LinkedIn.

Why this exists

Built Wrong argues that cybersecurity was built on foundations that never evolved. This index is that argument’s evidence: not a louder claim about what cybercrime costs, but a stricter record of what individual incidents actually cost, each figure read from the document that reported it.

The headline numbers put on cyber loss tend not to hold up when you follow them to their source. The response here is not a better estimate. It is a cleaner record: every figure traceable, graded by how well it is sourced, and never added to another.

How the record is made

Every figure is read from a primary source: an SEC 8-K filing, a state-regulator breach notification, or an attributed report. Each is graded by provenance, Verified, Attested, or Inferred, which says how well the number is sourced and nothing about how large the loss is. Figures from different incidents are never summed. The full standard, with the grades and the never-sum rule, is on the methodology page.

Corrections

If a figure here is wrong, that is a defect to fix, not to defend. Every figure links to the source it was read from, so the work can be checked rather than trusted. When a figure is corrected, its revision is shown in the open, not quietly swapped. Corrections and questions are welcome at the address in the footer.

The publisher

The Hacker in a Hoodie Index is published by Bird & Bird Media LLC. It is independent of the companies it tracks; every figure is reproduced from a public primary source and links back to it. The published incident record is open data under CC BY 4.0, available as CSV and JSON.

← Back to the index