← The Hacker in a Hoodie Index  ·  methodology & standards
Methodology & Standards
What this page is

Every figure this index publishes is held to a standard. This page states those standards plainly, so a reader can check the work rather than take it on trust.

The index exists because the headline numbers put on cyber loss do not hold up when you follow them to their source. The answer here is not a better estimate. It is a stricter record. Two rules govern everything below: a figure is only as good as the document behind it, and figures from different incidents are never added together.

The never-sum rule
The rule

This index never sums dollar losses across incidents. Add them together and you get a number that means nothing: the figures come from different companies, periods, definitions, and standards of proof, and a total silently treats them as one measurement.

So the index counts incidents and shows each figure on its own, next to the source that stated it. Where you see a count, it is a count of events. Where you see a dollar figure, it belongs to one incident. There is no grand total on this site, and there never will be.

How a figure is graded

Every figure carries one of three grades, shown as a badge beside it. The grade is about provenance, not size: it says how well the number is sourced, and nothing about how large or how severe the loss is.

VVerified
The linked primary document states this figure. On this index, Verified is reserved for the government record: SEC filings, and state-regulator enforcement and breach notifications. The strongest grade, and the only one that appears On the Government Record.
AAttested
A published report credits an identifiable source for the figure: a company results statement, or an official on the record. Strong, but one step removed from a primary filing.
IInferred
No direct confirmation. An outside estimate or a news figure, held as a lead, not asserted as fact.

Verified figures live On the Government Record. Attested and Inferred figures live Beyond the Filings, and never borrow the Verified grade: that grade is reserved for the primary filings and enforcement records, and is not extended to a company statement or a news report.

What counts as a loss
One incident, one figure at a time

A figure on a card is one incident’s own disclosed number, read from the source and linked to it. When a company later states a typed cost (a direct expense, a business-interruption loss, remediation spend, or a stated total), that figure enriches the card; it never replaces the disclosure with a guess. A single incident may carry more than one figure, for instance a direct cost and a revenue impact. They are shown side by side, each labeled, and never summed into one.

The revision trail

Numbers move. A cost figure arrives after an incident is disclosed and changes as stronger sources report it; early estimates usually run below the figure a company eventually files. Each card shows its most recent figure, and beneath it, on the ledger, the full revision trail: every prior claim in order, each with its date, its source, and its grade. Nothing is quietly overwritten.

What the record does not claim
The floor

This ledger is a floor, not a census. Where there is no measurement, there is no number here, only its absence: an incident with no disclosed figure reads “Not yet quantified,” never a filled-in estimate. Most cyber incidents never reach a public filing or notice at all. What is tracked here is a lower bound on the record, not a count of everything that happened.

Two shelves, two standards

Beyond the incident ledger, the index shows charts. They come in two kinds, kept apart on purpose and each labeled so a reader always knows which is which. One carries evidence from the world; the other carries readings of this record.

Exhibits · the Exhibit Rule

An exhibit is a figure from outside this index: a public, primary-source number a reader can verify against the original document, chosen because it shows an instrument that should track loss failing to. Every exhibit must pass four tests, all four required.

  1. Public. Openly available. Not licensed, paywalled, or obtained through a relationship.
  2. Primary. From the body that produced it, not from anyone reporting on it (IC3 from the FBI, not a vendor report about IC3). Vendor threat reports are excluded: they are marketing with a methodology section.
  3. Verifiable. A reader can open the cited document, find the figure, and reconstruct the arithmetic unaided. If you have to trust rather than check, it is not an exhibit yet.
  4. Divergence. It shows a measure that should move with loss failing to, or moving against it. Merely large or alarming is not enough. The divergence is the argument.

Two conditions ride on every exhibit: the basis is pinned before publication (where a source has more than one version of a figure, the canonical one is named on the card), and any known discrepancy is footnoted, not hidden. And one disqualifier overrides a pass on all four: if a figure’s movement could be a reporting-method change rather than a real-world change, it is held until that is resolved with the source directly.

Live cuts · the never-sum standard

A live cut is a reading of this index’s own ledger, such as the breakdown of tracked incidents by sector. It is labeled “From the ledger,” and it answers to one rule above all: the never-sum rule. A live cut may count incidents, or show their share, but it may never add up dollar losses. It shows what the ledger holds, a floor, and never reads as covering the whole. A live cut draws only on records that already cleared grading and provenance; the standard is never relaxed to fill a slice.

Sources

Aggregate figures are reproduced as single, attributed data points, and each links to its originating report: the FBI Internet Crime Complaint Center (IC3), Chainalysis, the NAIC cybersecurity-insurance supplement, and the IBM / Ponemon Cost of a Data Breach. Source figures remain the property of their publishers and are shown here as attributed data points for commentary and research.

Forward projections are noted, never charted as measured loss. The widely cited “$10.5 trillion by 2025,” for one, is a projection compounded from a base whose methodology is not disclosed. A projection is not evidence, and this index does not draw it on the same axis as measured figures.

The record, open

The full incident record is published as open data: one row per distinct incident, the same records and the same order as the ledgers, each with a link back to its card and to its primary source. Reuse it for reporting or research. Attribution to The Hacker in a Hoodie Index is appreciated.

Keeping the record current, and corrections

New incidents enter the record from SEC 8-K filings and from state-regulator and federal breach notifications, each reviewed before it is published. The per-feed ledgers are the complete, uncapped record; the front page shows only the most recent few of each.

Every figure links to the source it was read from. If we have read one wrong, that is worth knowing: tell us at info@hackerinahoodie.com. An index whose argument is that published numbers do not hold up should invite scrutiny of its own.

← Back to the index