Calculate Your Data Breach Cost

Estimate what a data breach would cost your organisation. Line-item breakdown of forensics, notification, legal, fines, downtime and churn. No signup.

Advertisement

Data Breach Cost Calculator for Security Budget Planning

This data breach cost calculator produces a line-item estimate of what a breach would cost your organisation, built from the inputs that actually move the number: industry, geography, record count, data types held, security maturity, and how long it takes you to detect and contain an incident. It is a planning model, not a prediction. Its purpose is to turn “we should probably spend more on security” into a defensible figure you can put in front of a CFO alongside the cost of the controls that would reduce it.

The calculator is aimed at IT directors, vCISOs, MSP account managers, and finance leads who need to size cyber risk in dollars. It runs entirely in your browser, keeps your inputs in the URL so you can bookmark or share a scenario, and exports the full breakdown to PDF for a board pack. There is no signup and nothing is uploaded.

What the Calculator Actually Computes

The model builds a total from seven cost components, then applies two multipliers. Every component is visible in the results breakdown, so you can argue with any single line rather than accepting a black-box number.

  • Per-record cost — a base per-record figure scaled by industry, region, and breach size.
  • Detection and forensics — forensic investigation, security analytics, incident response retainer, breach assessment, and evidence collection.
  • Notification — per-person notification and credit monitoring for the regulated share of records, plus regulatory filings, media management, call centre stand-up, and web updates.
  • Legal — outside counsel and regulatory defence, with class-action defence and a settlement reserve added once the breach crosses 50,000 regulated records.
  • Regulatory fines — GDPR, HIPAA, PCI DSS, US state privacy, and financial-sector exposure, applied only where your inputs make them applicable.
  • Business disruption — lost revenue during containment, customer churn valued at lifetime value, and downtime cost.
  • Post-breach — security upgrades, consulting, retraining, insurance premium increases, brand recovery, and executive time.

A second tab estimates cyber insurance recovery, assuming a policy absorbs a share of the total and leaves an out-of-pocket remainder plus a multi-year premium increase.

The Methodology, With the Formulas

The per-record cost is a product of four factors:

Cost per record = base rate × industry multiplier × region multiplier × scale factor

The base rate is $165 per record, the per-record figure from IBM’s Cost of a Data Breach research, which is what this model is calibrated against. Industry multipliers run from about 0.47 for government up to 2.24 for healthcare. Region multipliers run from 0.65 for Latin America to 1.92 for the United States. The scale factor encodes economies of scale: breaches under 10,000 records carry a 1.3× per-record penalty, breaches over 10 million records get 0.70× or lower, because fixed response costs are spread across more people.

Detection cost is a fixed base of roughly $660,000 multiplied by a detection-time factor: 1.5× above 180 days to detect, 1.2× above 90 days, 0.7× below 30 days. Business disruption is calculated as:

Revenue loss = (annual revenue ÷ 365) × days to contain × industry disruption rate

with disruption rates of 35% for retail and hospitality, 25% for healthcare and financial services, 20% for technology and manufacturing, and 15% elsewhere. Churn is modelled as records × churn rate (5%, rising to 8% above one million records) × a three-year customer lifetime value derived from your revenue and record count.

The subtotal is then multiplied twice. The maturity multiplier ranges from 1.50 at minimal maturity to 0.65 at optimised. The mitigation factor compounds separate effects: a tested incident response plan applies 0.75, extensive use of security AI applies 0.82, a total breach lifecycle under 200 days applies 0.76, and lifecycles over 300 days apply 1.23.

A worked example

Take a 100-person technology company in the United States, $5M annual revenue, 10,000 customer records, 30% of them regulated, basic security maturity, 196 days to detect and 68 days to contain.

  • Cost per record: $165 × 1.13 × 1.92 × 1.1 = $394. Record cost: $3,937,800.
  • Detection: $660,000 × 1.5 = $990,000 (detection exceeds 180 days).
  • Notification: 3,000 regulated records × $17.50, plus $390,000 fixed = $442,500.
  • Legal: $630,000 × 1.3 technology multiplier = $819,000. No class-action reserve, since the breach is under 50,000 records.
  • Business disruption: $186,300 revenue loss + $750,000 churn + $82,200 downtime = $1,018,500.
  • Post-breach: $1,470,000 fixed.

Subtotal: $8,677,800. Multiplied by 1.25 for basic maturity, then by 1.127 for the compounded mitigation factors, the estimate lands near $12.2M.

That number deserves a caveat, and it is the most useful thing on this page. The model carries roughly $3.5M of fixed response cost — detection, notification, legal, post-breach — before a single record is counted. Those figures are drawn from enterprise breach studies. For a company with $5M in revenue, the output is therefore a worst-case ceiling, not an expected value. Read small-organisation results as an upper bound and pay attention to the shape of the breakdown — which components dominate, and which of your inputs move them — rather than the headline total.

How to Use It

  1. Set the organisation profile. Industry, region, headcount, and annual revenue. Changing industry auto-populates sensible defaults for data types and detection times, which you should then override with your real numbers.
  2. Describe the data. Record count and the categories you hold. Payment card data and protected health information both open regulatory fine paths that PII alone does not.
  3. Set the regulated share. This drives notification and credit-monitoring costs, which are per-person and scale linearly.
  4. Enter your real detection and containment times. If you do not know them, that is itself the finding. The defaults are industry averages adjusted for company size.
  5. Set maturity and controls. Toggle the tested incident response plan and cyber insurance to see the mitigation factors move the total.
  6. Export. The PDF carries the full breakdown and the prioritised recommendations, each with an investment figure and an implied return.

Where the Benchmarks Come From

The model’s constants are calibrated to IBM’s Cost of a Data Breach Report 2024 — a global average of $4.88M, $165 per record, and a 258-day mean breach lifecycle (194 days to identify, 64 to contain). Those are the numbers the arithmetic above uses.

The underlying research has moved since. IBM’s Cost of a Data Breach Report 2025 put the global average at $4.44M with a 241-day lifecycle (181 to identify, 60 to contain), and the Cost of a Data Breach Report 2026, covering 602 organisations breached between March 2025 and February 2026, reported a global average of $4.99M, a US average of $11.5M, and a 247-day average lifecycle. Healthcare remained the most expensive industry at $6.64M, down from $7.42M the year before. Treat the calculator’s output as directionally calibrated rather than current to the day, and sanity-check the total against the published average for your industry and region.

Frequently Asked Questions

Is this an estimate or a prediction?

An estimate, for planning. It answers “if a breach of this size happened, what would the cost structure look like?” It does not model the probability that a breach occurs. For probability-weighted figures, use annualised loss expectancy in the quantitative risk analysis tool.

Why is my estimate so much larger than my annual revenue?

Because the fixed response components — forensics, notification, legal, post-breach remediation — are drawn from enterprise breach studies and do not scale down with company size. For small organisations, read the result as a ceiling and focus on the relative size of each line.

What does changing detection time actually do?

Two things. It scales the detection cost bracket (1.5× above 180 days, 0.7× below 30), and it feeds the total lifecycle, which applies a 0.76 multiplier under 200 days and 1.23 over 300 days. IBM’s 2025 report found breaches with a lifecycle under 200 days averaged $3.87M against $5.01M for those over 200 days, which is the effect this multiplier represents.

How are regulatory fines calculated?

Conditionally, based on your inputs. GDPR exposure applies in UK, German, and French scenarios as the greater of 4% of revenue or a €20M-equivalent floor. HIPAA applies to US healthcare holding PHI, capped at $1.5M per year. PCI DSS applies wherever card data is selected. These are statutory maxima and typical settlement ranges, not predictions of what a regulator would actually levy.

Does cyber insurance really cover most of it?

The tool assumes a policy absorbs a substantial share and leaves an out-of-pocket remainder plus a multi-year premium increase. Real recovery depends entirely on your policy’s sublimits, exclusions, and whether you met its control warranties. Use the number as a prompt to read your policy, not as a coverage forecast.

Where does the per-record figure come from?

A $165 base rate, from IBM’s per-record breach cost research, adjusted by industry, region, and breach size. Per-record costs fall as breaches get larger, which is why a 10-million-record breach does not cost a thousand times a 10,000-record one.

Can I share or save a scenario?

Yes. Your inputs are encoded in the page URL, so bookmarking or sending the link reproduces the scenario exactly. The PDF export carries the full breakdown, the industry comparison, and the recommendation list.

What should I do with the result?

Compare it against the cost of the controls that would move it. Feed the total into the cybersecurity ROI calculator as your annualised loss figure, and use the cybersecurity budget calculator to size the spend that would reduce it.

Is my data sent anywhere?

No. The calculation runs in your browser. Inputs live in the URL and in local storage on your own device.

What Is a Data Breach Cost Calculator

A data breach cost calculator estimates the financial impact of a data breach based on factors like the number of records compromised, industry sector, geographic location, breach detection time, and response capabilities. Understanding potential breach costs helps organizations justify security investments, prioritize risk mitigation, and prepare realistic incident response budgets.

IBM's annual Cost of a Data Breach Report—the industry benchmark—found that the global average cost of a data breach reached $4.88 million in 2024, with costs varying dramatically by industry and region. Healthcare breaches averaged $9.77 million, while the public sector averaged $2.55 million. These figures include both direct costs (forensics, notification, legal fees) and indirect costs (customer churn, reputation damage, regulatory fines).

How Breach Cost Estimation Works

Breach costs are calculated across four major categories:

Cost CategoryIncludesAvg. % of Total
Detection & escalationForensic investigation, audit services, crisis management31%
NotificationLetters, emails, credit monitoring, call center setup6%
Post-breach responseHelp desk, identity protection, legal fees, regulatory fines28%
Lost businessCustomer churn, reputation damage, opportunity cost, system downtime35%

Key cost multipliers:

  • Per-record cost: The average cost per compromised record is $165 globally, but ranges from $93 (public sector) to $541 (healthcare)
  • Detection time: Breaches identified within 200 days cost an average of $1 million less than those taking longer to detect
  • AI and automation: Organizations with fully deployed security AI saved $2.22 million compared to those without
  • Incident response planning: Having a tested IR plan reduces costs by an average of $473,706
  • Regulatory environment: GDPR fines can reach 4% of annual global revenue; HIPAA penalties up to $2.13 million per violation category

Common Use Cases

  • Security budget justification: Quantify the cost of a potential breach to justify investments in preventive controls
  • Risk assessment: Compare estimated breach costs against the cost of implementing specific security measures
  • Cyber insurance planning: Determine appropriate coverage levels based on realistic breach cost estimates
  • Board reporting: Present breach risk in financial terms that executives and board members understand
  • Vendor risk management: Estimate the cost impact of a breach at a third-party vendor handling your data

Best Practices

  1. Use industry-specific cost factors — Healthcare, financial services, and technology sectors have significantly higher per-record costs than average
  2. Factor in detection time — Invest in detection capabilities; every day a breach goes undetected increases total cost
  3. Include opportunity costs — Lost business typically represents 35% of total breach cost and is often underestimated
  4. Account for regulatory penalties — GDPR, CCPA, HIPAA, and PCI-DSS fines can dwarf direct remediation costs
  5. Update estimates annually — Breach costs increase year over year; recalculate using the latest industry benchmarks

Frequently Asked Questions

What is the average cost of a data breach?+

According to IBM-Ponemon 2024 research, global average is $4.45 million per breach ($165 per compromised record). Healthcare averages $10.93M, financial services $5.97M, pharmaceuticals $5.01M. Costs include detection and escalation (29%), notification (7%), post-breach response (28%), and lost business (36%). U.S. breaches cost significantly more than global average due to regulatory environment.

What costs are included in data breach calculations?+

Direct costs include forensic investigation, legal counsel, crisis management, customer notification, credit monitoring, regulatory fines, and remediation. Indirect costs include lost business, customer churn, reputation damage, increased insurance premiums, stock price impact, and class action settlements. Hidden costs include employee time, system downtime, and opportunity costs from diverted resources.

How do GDPR fines affect breach costs?+

GDPR fines reach €20M or 4% of global revenue (whichever is higher) for serious violations. Average GDPR fine is €3.6M but can exceed €100M for major breaches. Add costs for notification (72 hours), DPO investigation, remediation, and customer compensation. EU breaches often cost 20-40% more than non-EU due to stringent requirements. U.S. state laws add further complexity.

What factors increase data breach costs?+

Cost multipliers include: delayed detection (over 200 days adds $1.12M), lack of incident response plan (adds $1.49M), third-party involvement (adds $370K), cloud misconfigurations (vs. malicious attacks), high employee turnover, complex regulatory environment, system complexity, and sensitive data types. Healthcare PHI and financial PII cost significantly more per record than general information.

How long does it take to detect a data breach?+

Global average is 277 days to identify and contain a breach (204 days to identify, 73 days to contain). Faster detection significantly reduces costs: breaches contained in under 200 days cost $3.93M vs. $5.46M for over 200 days. AI and automation reduce detection time by 28% and lower costs by $2.22M. Mature security programs detect 60-80% faster.

What is the cost of lost business from breaches?+

Lost business represents 36% of total breach cost ($1.6M average), including customer turnover, reputation damage, and diminished goodwill. Customer churn averages 7-10% post-breach, with 65% of victims losing trust. Revenue impact persists 2-3 years. High-profile breaches cause stock price drops of 5-7% in immediate aftermath. B2B companies lose contracts and partnerships.

How do you reduce data breach costs?+

Cost reducers include: incident response plan and testing (saves $1.49M), AI and automation (saves $2.22M), encryption (saves $360K), employee training (saves $232K), DevSecOps approach (saves $249K), zero trust architecture (saves $1.76M), and cyber insurance. Organizations with high security maturity experience 50-60% lower breach costs than immature programs.

What are typical breach notification costs?+

Notification costs average 7% of total breach ($312K), including legal review, regulatory filing, mail/email distribution, call center setup, credit monitoring subscriptions, and public relations. Large breaches affecting millions cost $5-20M for notification alone. U.S. state laws require individual notification; GDPR requires supervisory authority notification within 72 hours. Factor $50-150 per affected individual.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.