Why this project exists
During workshops on threat modeling, security automation and offensive web application testing, I use real incidents to talk about business impact. The incident timeline fits on a slide. The longer-term outcome usually does not.
CrowdStrike is the obvious example for many people in IT. Buying after its 2024 outage and holding would have worked well. But one memorable case is a poor basis for a general rule, so I wanted a broader list that made the intuition easier to test.
I built Incident Impact as a practical tool for my workshops and my own curiosity: open a case, compare the company with SPY over the same dates, and see what happened. It looks at one observable signal—public-market performance—not the whole business story.
How it was made
The underlying idea is straightforward. The time cost was in finding incident dates, structuring the cases and building a consistent comparison. For a long time, that opportunity cost was higher than the value of having the tool.
Working with GPT-5.6 and Codex changed the trade-off. I defined the question, scope and rules, and used AI agents for most of the implementation and data-assembly work. That made a project I had postponed for years practical to finish.
What it can and cannot show
The tool makes a discussion more concrete. It does not prove that cyber incidents do or do not matter, measure customer behavior, score a company’s security or isolate the cause of a price move. Historical outcomes are not an investment recommendation.
- Each case is qualified before its price results are checked.
- The company and SPY use the same dates.
- Sources, assumptions and limitations stay visible.
- The catalog is curated, not complete.
This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.