Why this project exists
During workshops on threat modeling, security automation and offensive web application testing, I use real incidents to talk about business impact. The incident timeline fits on a slide. The longer-term outcome usually does not.
A serious cyber incident can be expensive and disruptive. That still does not automatically mean customers leave, the company loses lasting value or the business fails. Those are separate claims, and they need separate evidence.
I built Incident Impact as a teaching aid: open a documented case, compare the company with SPY over the same dates, and let the room inspect what happened. The site looks at one observable signal—public-market performance—not the whole business story.
What it can and cannot show
The tool makes a discussion more concrete. It does not prove that cyber incidents do or do not matter, measure customer behavior, score a company’s security or isolate the cause of a price move.
- Each case is qualified before its price results are checked.
- The company and SPY use the same dates.
- Sources, assumptions and limitations stay visible.
- The catalog is curated, not complete.
This site shows how share prices moved after an incident became public. It does not prove that the incident caused the move. Company news, sector moves and the wider market can affect every result. Educational only — not investment advice.