A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Key points
- Richard Bird, a cybersecurity executive with decades of experience, launched a new public index tracking major reported data breaches.
- The index is designed for security professionals, journalists, policymakers, and ordinary members of the public.
- The tool records breaches that companies are legally required to disclose, known as "material" breaches, meaning incidents serious enough to affect investors or customers.
- The index deliberately does not aggregate or total up financial losses from those breaches.
- The project arrives as U.S. regulators are tightening disclosure rules for publicly listed companies.
A new public database is keeping score on corporate data breaches, and it has made one striking editorial choice: it will not add up the money lost.
Richard Bird, a longtime cybersecurity executive, built the index and opened it to anyone. Security experts, journalists, regulators, and ordinary citizens can use it. The premise is straightforward. When a company suffers a cyberattack serious enough to matter to its investors or customers, regulators now require that company to say so publicly. Bird's index collects those disclosures in one place.
Why does it refuse to show total losses?
The decision not to publish a running financial total is deliberate, not an oversight. Loss figures attached to breaches are frequently contested, often estimated, and almost always revised over time. Presenting a single large number risks misleading the public more than it informs them. The index instead focuses on the fact of each breach, who reported it, and when.
That choice sits inside a broader regulatory moment. The U.S. Securities and Exchange Commission, the federal agency that oversees publicly traded companies, adopted final rules in 2023 requiring those companies to disclose "material" cybersecurity incidents, meaning attacks that a reasonable investor would consider significant, within four business days of determining the incident is material. The relevant rule, Item 1.05 of Form 8-K, took effect for most companies on 18 December 2023.
The European Union's NIS2 Directive, short for the Network and Information Security Directive (version 2), sets parallel obligations for critical-infrastructure operators across member states, with most national deadlines falling in late 2024.
Bird's index draws on those mandatory disclosures, not voluntary announcements. That distinction matters. Companies do not choose whether to appear in it; the law decides.
For ordinary people, the practical meaning is this: if a company that holds your data reports a breach, that report should now end up in a searchable, public record.
What to watch for: if a company you use sends you a breach notification letter or email, search the index to see whether the company has also filed a formal regulatory disclosure. A notification letter without a corresponding regulatory filing can itself be a sign worth noting.
SecurityWeek first reported Bird's launch of the index.



