Richard Bird

The institution

The world has never spent more on cybersecurity, and organizations have never lost more to it.

That is not a technology problem.


This argument does not come from outside the cybersecurity profession. It comes from decades spent inside it. From building security programs, reporting to boards, navigating and entertaining regulators, responding to incidents, and watching organizations invest enormous effort in security while struggling to demonstrate whether those efforts reduced harm.

The titles don’t make me right. What they bought was thirty years of watching the same failure show up in every business I worked in, no matter what industry it was in.


A three-layer failure

One Narrative

The storytelling around attacks obscured the real causes of compromise.

The post-incident explanation describes a sophisticated attacker exploiting a novel technique. The narrative is accurate in its details and misleading in its structure. The attacker did not need novel techniques. They needed access, which the environment had already accumulated in ways no one was required to track.

Two Measurement

The profession built gauges that reward activity rather than protection.

Controls were in place. Present, documented, generating the expected operational signals. What they were not doing was preventing the attack pathway, because that pathway was not a vulnerability in any control. It was a trust relationship that grew across eighteen months of normal operations, never reviewed, never mapped.

Three Incentive

Those narratives and measurements shaped the architecture itself.

Boards, regulators, auditors, insurers, investors and vendors all adapted to incentives that rewarded the appearance of security more than its performance. The system was designed, entirely correctly by its own internal logic, to produce exactly this outcome.


One case, all three layers

In February 2024, attackers gained access to Change Healthcare, a UnitedHealth Group subsidiary that processes approximately forty percent of all medical claims in the United States.

Share of US medical claims
~40%
People whose data was compromised
~190,000,000
Proportion of Americans
Close to one in two
Initial access mechanism
A stolen credential
Multifactor on that portal
None

Compromised-records figure as stated by UnitedHealth Group.

The initial access mechanism was not sophisticated. Attackers used stolen credentials to log into a Citrix remote access portal that did not require multifactor authentication. That is not an exotic technique. It is one of the most commonly documented initial access vectors in incident reporting, cited in breach after breach across industries and years.

The disclosures that followed were extensive. Form 8-K notifications. Congressional testimony. HHS guidance. Viewed from inside the regulatory framework, the response was thorough. Notifications were timely. Disclosures were filed.

What the regulatory process did not produce was a structured account of how a platform processing forty percent of national medical claims came to operate a critical remote-access portal without multifactor authentication. Those findings emerged gradually, in investigative journalism and congressional questioning, months later. They were not a product of the disclosure system.


What this is actually about

When organizations collect personal data, operate critical systems, or provide services on which people depend, they accept a responsibility to protect what has been entrusted to them. Cybersecurity exists to honor that responsibility. The system described in this book was designed, instead, to demonstrate it.

Those are not the same thing, and the difference between demonstrating security and providing it is where most of the harm lives.

The patients who stood at those pharmacy counters had not chosen to entrust their healthcare data to Change Healthcare. They had not been asked. Their information had flowed there through a chain of institutional relationships they had no visibility into and no ability to influence. They were simply people who needed their medications.

And those are the people this is for.


The evidence

An argument this large should carry its evidence in public. The Hacker in a Hoodie Index is a live record of what individual cyber incidents actually cost, each figure read from the document that reported it, graded by how well it is attested, and never rolled into a headline total.

Summing them would conceal who truly carries the costs of a cybersecurity failure.

Read the index →


The book

Built Wrong cover

Built Wrong

Why Cybersecurity Keeps Failing and How We Can Rebuild It

October 2026

  1. Part IHow we built it wrong4 chapters
  2. Part IIWhy it keeps failing4 chapters
  3. Part IIIWhere the model breaks3 chapters
  4. Part IVRebuilding security6 chapters

Launch updates go out by email, and the evidence behind the argument is public in the index in the meantime.