Estimate what a data breach would cost your organisation. Line-item breakdown of forensics, notification, legal, fines, downtime and churn. No signup.
This data breach cost calculator produces a line-item estimate of what a breach would cost your organisation, built from the inputs that actually move the number: industry, geography, record count, data types held, security maturity, and how long it takes you to detect and contain an incident. It is a planning model, not a prediction. Its purpose is to turn “we should probably spend more on security” into a defensible figure you can put in front of a CFO alongside the cost of the controls that would reduce it.
The calculator is aimed at IT directors, vCISOs, MSP account managers, and finance leads who need to size cyber risk in dollars. It runs entirely in your browser, keeps your inputs in the URL so you can bookmark or share a scenario, and exports the full breakdown to PDF for a board pack. There is no signup and nothing is uploaded.
The model builds a total from seven cost components, then applies two multipliers. Every component is visible in the results breakdown, so you can argue with any single line rather than accepting a black-box number.
A second tab estimates cyber insurance recovery, assuming a policy absorbs a share of the total and leaves an out-of-pocket remainder plus a multi-year premium increase.
The per-record cost is a product of four factors:
Cost per record = base rate × industry multiplier × region multiplier × scale factor
The base rate is $165 per record, the per-record figure from IBM’s Cost of a Data Breach research, which is what this model is calibrated against. Industry multipliers run from about 0.47 for government up to 2.24 for healthcare. Region multipliers run from 0.65 for Latin America to 1.92 for the United States. The scale factor encodes economies of scale: breaches under 10,000 records carry a 1.3× per-record penalty, breaches over 10 million records get 0.70× or lower, because fixed response costs are spread across more people.
Detection cost is a fixed base of roughly $660,000 multiplied by a detection-time factor: 1.5× above 180 days to detect, 1.2× above 90 days, 0.7× below 30 days. Business disruption is calculated as:
Revenue loss = (annual revenue ÷ 365) × days to contain × industry disruption rate
with disruption rates of 35% for retail and hospitality, 25% for healthcare and financial services, 20% for technology and manufacturing, and 15% elsewhere. Churn is modelled as records × churn rate (5%, rising to 8% above one million records) × a three-year customer lifetime value derived from your revenue and record count.
The subtotal is then multiplied twice. The maturity multiplier ranges from 1.50 at minimal maturity to 0.65 at optimised. The mitigation factor compounds separate effects: a tested incident response plan applies 0.75, extensive use of security AI applies 0.82, a total breach lifecycle under 200 days applies 0.76, and lifecycles over 300 days apply 1.23.
Take a 100-person technology company in the United States, $5M annual revenue, 10,000 customer records, 30% of them regulated, basic security maturity, 196 days to detect and 68 days to contain.
Subtotal: $8,677,800. Multiplied by 1.25 for basic maturity, then by 1.127 for the compounded mitigation factors, the estimate lands near $12.2M.
That number deserves a caveat, and it is the most useful thing on this page. The model carries roughly $3.5M of fixed response cost — detection, notification, legal, post-breach — before a single record is counted. Those figures are drawn from enterprise breach studies. For a company with $5M in revenue, the output is therefore a worst-case ceiling, not an expected value. Read small-organisation results as an upper bound and pay attention to the shape of the breakdown — which components dominate, and which of your inputs move them — rather than the headline total.
The model’s constants are calibrated to IBM’s Cost of a Data Breach Report 2024 — a global average of $4.88M, $165 per record, and a 258-day mean breach lifecycle (194 days to identify, 64 to contain). Those are the numbers the arithmetic above uses.
The underlying research has moved since. IBM’s Cost of a Data Breach Report 2025 put the global average at $4.44M with a 241-day lifecycle (181 to identify, 60 to contain), and the Cost of a Data Breach Report 2026, covering 602 organisations breached between March 2025 and February 2026, reported a global average of $4.99M, a US average of $11.5M, and a 247-day average lifecycle. Healthcare remained the most expensive industry at $6.64M, down from $7.42M the year before. Treat the calculator’s output as directionally calibrated rather than current to the day, and sanity-check the total against the published average for your industry and region.
An estimate, for planning. It answers “if a breach of this size happened, what would the cost structure look like?” It does not model the probability that a breach occurs. For probability-weighted figures, use annualised loss expectancy in the quantitative risk analysis tool.
Because the fixed response components — forensics, notification, legal, post-breach remediation — are drawn from enterprise breach studies and do not scale down with company size. For small organisations, read the result as a ceiling and focus on the relative size of each line.
Two things. It scales the detection cost bracket (1.5× above 180 days, 0.7× below 30), and it feeds the total lifecycle, which applies a 0.76 multiplier under 200 days and 1.23 over 300 days. IBM’s 2025 report found breaches with a lifecycle under 200 days averaged $3.87M against $5.01M for those over 200 days, which is the effect this multiplier represents.
Conditionally, based on your inputs. GDPR exposure applies in UK, German, and French scenarios as the greater of 4% of revenue or a €20M-equivalent floor. HIPAA applies to US healthcare holding PHI, capped at $1.5M per year. PCI DSS applies wherever card data is selected. These are statutory maxima and typical settlement ranges, not predictions of what a regulator would actually levy.
The tool assumes a policy absorbs a substantial share and leaves an out-of-pocket remainder plus a multi-year premium increase. Real recovery depends entirely on your policy’s sublimits, exclusions, and whether you met its control warranties. Use the number as a prompt to read your policy, not as a coverage forecast.
A $165 base rate, from IBM’s per-record breach cost research, adjusted by industry, region, and breach size. Per-record costs fall as breaches get larger, which is why a 10-million-record breach does not cost a thousand times a 10,000-record one.
Yes. Your inputs are encoded in the page URL, so bookmarking or sending the link reproduces the scenario exactly. The PDF export carries the full breakdown, the industry comparison, and the recommendation list.
Compare it against the cost of the controls that would move it. Feed the total into the cybersecurity ROI calculator as your annualised loss figure, and use the cybersecurity budget calculator to size the spend that would reduce it.
No. The calculation runs in your browser. Inputs live in the URL and in local storage on your own device.
A data breach cost calculator estimates the financial impact of a data breach based on factors like the number of records compromised, industry sector, geographic location, breach detection time, and response capabilities. Understanding potential breach costs helps organizations justify security investments, prioritize risk mitigation, and prepare realistic incident response budgets.
IBM's annual Cost of a Data Breach Report—the industry benchmark—found that the global average cost of a data breach reached $4.88 million in 2024, with costs varying dramatically by industry and region. Healthcare breaches averaged $9.77 million, while the public sector averaged $2.55 million. These figures include both direct costs (forensics, notification, legal fees) and indirect costs (customer churn, reputation damage, regulatory fines).
Breach costs are calculated across four major categories:
| Cost Category | Includes | Avg. % of Total |
|---|---|---|
| Detection & escalation | Forensic investigation, audit services, crisis management | 31% |
| Notification | Letters, emails, credit monitoring, call center setup | 6% |
| Post-breach response | Help desk, identity protection, legal fees, regulatory fines | 28% |
| Lost business | Customer churn, reputation damage, opportunity cost, system downtime | 35% |
Key cost multipliers:
According to IBM-Ponemon 2024 research, global average is $4.45 million per breach ($165 per compromised record). Healthcare averages $10.93M, financial services $5.97M, pharmaceuticals $5.01M. Costs include detection and escalation (29%), notification (7%), post-breach response (28%), and lost business (36%). U.S. breaches cost significantly more than global average due to regulatory environment.
Direct costs include forensic investigation, legal counsel, crisis management, customer notification, credit monitoring, regulatory fines, and remediation. Indirect costs include lost business, customer churn, reputation damage, increased insurance premiums, stock price impact, and class action settlements. Hidden costs include employee time, system downtime, and opportunity costs from diverted resources.
GDPR fines reach €20M or 4% of global revenue (whichever is higher) for serious violations. Average GDPR fine is €3.6M but can exceed €100M for major breaches. Add costs for notification (72 hours), DPO investigation, remediation, and customer compensation. EU breaches often cost 20-40% more than non-EU due to stringent requirements. U.S. state laws add further complexity.
Cost multipliers include: delayed detection (over 200 days adds $1.12M), lack of incident response plan (adds $1.49M), third-party involvement (adds $370K), cloud misconfigurations (vs. malicious attacks), high employee turnover, complex regulatory environment, system complexity, and sensitive data types. Healthcare PHI and financial PII cost significantly more per record than general information.
Global average is 277 days to identify and contain a breach (204 days to identify, 73 days to contain). Faster detection significantly reduces costs: breaches contained in under 200 days cost $3.93M vs. $5.46M for over 200 days. AI and automation reduce detection time by 28% and lower costs by $2.22M. Mature security programs detect 60-80% faster.
Lost business represents 36% of total breach cost ($1.6M average), including customer turnover, reputation damage, and diminished goodwill. Customer churn averages 7-10% post-breach, with 65% of victims losing trust. Revenue impact persists 2-3 years. High-profile breaches cause stock price drops of 5-7% in immediate aftermath. B2B companies lose contracts and partnerships.
Cost reducers include: incident response plan and testing (saves $1.49M), AI and automation (saves $2.22M), encryption (saves $360K), employee training (saves $232K), DevSecOps approach (saves $249K), zero trust architecture (saves $1.76M), and cyber insurance. Organizations with high security maturity experience 50-60% lower breach costs than immature programs.
Notification costs average 7% of total breach ($312K), including legal review, regulatory filing, mail/email distribution, call center setup, credit monitoring subscriptions, and public relations. Large breaches affecting millions cost $5-20M for notification alone. U.S. state laws require individual notification; GDPR requires supervisory authority notification within 72 hours. Factor $50-150 per affected individual.