CYBER RISK CALCULATOR

How much risk do you have in dollars?

Estimate your annual expected loss (ALE), VaR P90, and exposure to regulatory fines with the FAIR methodology, calibrated by the IBM Cost of a Data Breach 2025 (United States). Each result comes compared to your sector's benchmark. No email gate, no registration.

Annualized loss expectancy (ALE)

$0

How much, on average annually, we expect it to cost — combining probability × impact.

12-month probability

0%

Single loss expectancy (SLE)

$0

Industry benchmark — IBM 2025

$0

P90 VaR

$0

P99 VaR

$0

GDPR fine exposure

$0

4% of revenue, capped at the €20M statutory reference, adjusted by probability and sector sensitivity.

Estimate based on the United States cut of the IBM Cost of a Data Breach 2025 ($10.22 million average) and on sector multipliers from the same report. Methodology FAIR adapted. For CSURFACE platform customers, the methodology incorporates additional proprietary data — fine-tuning probability based on observed business context, critical processes identified, and assets effectively mapped by the platform.

METHODOLOGY

How We Calculate It

What Each Number Means

  • ALE — Annualized Loss Expectancy (Expected Annual Loss): the average value expected to be lost per year due to cyber incidents, combining the probability of an incident with its cost (probability × impact). It is the "average" of the loss distribution — and alone hides the atypical years.
  • SLE — Single Loss Expectancy: the estimated cost of a single material incident if it occurs. ALE, in essence, is SLE weighted by the probability of the incident happening in the year.
  • 12-Month Probability: the estimated chance of at least one material incident in the next 12 months, given by the sector baseline, security maturity, and scale of exposed assets.
  • VaR P90 — Value at Risk (Percentile 90): the level of loss that is exceeded on average once every ten years — the "bad year." Cyber loss is asymmetric; VaR shows the tail of rare and severe events that the average (ALE) does not reveal.
  • VaR P99 (Percentile 99): the level of loss exceeded on average once every hundred years — the catastrophic scenario. It is the worst-case reading to size reserves and insurance coverage.
  • GDPR fine exposure: the portion of risk tied to an administrative sanction, taken as 4% of revenue and held at the €20 million statutory reference, then adjusted by the probability of an incident and the sensitivity of sector data. GDPR itself applies the greater of the two, so this reading is deliberately the conservative one.
  • Sector benchmark: your country base cost multiplied by your sector factor, both from IBM Cost of a Data Breach 2025. It is the market reference that situates your single-loss estimate.

How the Calculation is Done

  • Base breach cost: $10.22 million, the United States cut of the IBM Cost of a Data Breach Report 2025.
  • Sector multiplier: the sector's average cost divided by the global average, both from IBM 2025 (healthcare $7.42M, financial $5.56M, retail $3.54M, public $2.86M, global average $4.44M). Being a ratio, it carries across currencies unchanged.
  • Sector Benchmark: the average breach cost published by IBM 2025 for your sector, displayed alongside your estimate.
  • Probability: sector baseline × maturity (basic/intermediate/advanced) × asset scale. Saturates at 95%.
  • SLE: adjusted by revenue (fractional powers avoid naive linearity).
  • VaR P90/P99: lognormal approximation (1.85× and 3.6× of ALE).
  • GDPR fine: 4% of revenue, held at the €20M statutory reference, × probability × sector sensitivity.

Calibration for Platform Customers

The public calculator applies the parameters described above — derived from sector baseline and IBM benchmarking. For CSURFACE platform customers, the methodology incorporates additional proprietary data collected by the operation: calibrated probability based on observed exposure, business context inferred by the agentic layer, critical processes identified in external surfaces, and actual assets mapped out. The number delivered to the customer's board is calculated per asset and process — not estimated by sector.

⚠️ This is an executive guidance calculator — does not replace formal quantitative risk analysis conducted by actuaries or specialized consultants.