Security
A breach is a story within hours and a document within weeks, and only the document settles anything. This domain is about the distance between the two - and about what the distance is worth.
Cyber incidents look like the least researchable events on the board, because the facts arrive through attackers, journalists and lawyers rather than through a statistical agency. They are more researchable than they look. Disclosure is regulated with hard deadlines, incident base rates are published annually by named institutions, and the financial consequence is visible in a price series anyone can pull. What is missing is not data but a method for turning it into an estimate.
Each entry here answers a different part of the same question. One works a live case end to end - the GTA 6 leak, its cost to Take-Two, and what it changes for the developers who build the game. One sets out the disclosure rules that decide when an incident becomes an official fact. One supplies the base rates from ransomware economics. One covers the vendors who are paid when incidents rise, including the case where the vendor was the incident. And the last one hands over the method itself, step by step, so the analysis is something you run rather than something you read.
The recurring lesson across all five: the loudest number is usually the least durable one. A market-capitalisation loss quoted from the trough, a ransom demand quoted from the leak site, a breach quoted from an attacker's claim - each is the largest defensible figure available and the one least likely to survive a week.
A leak is not a delay, a lawsuit is not a loss, and a share price that falls on a Wednesday is not a verdict. This entry separates the three, because a market about any of them settles on a different thing.
Open entryA breach becomes tradeable at the moment it becomes a document. Everything before that is reporting, and reporting is not what a market settles on.
Open entryMost ransomware coverage reports the demand. The demand is the least informative number in the whole incident, and it is the only one the attacker chooses.
Open entryThe trade everyone reaches for after a breach - buy the security vendors - is the one with the least evidence behind it. What actually drives this sector is a budget cycle, not a news cycle.
Open entryA risk analysis is two estimates and one multiplication. Everything difficult about it is in deciding what exactly you are estimating - which is why the method starts with a definition and not with a number.
Open entry