Skip to main content

Free estimator

Data breach cost calculator

What a breach would actually cost you, counting the response work and the downtime rather than just the fine.

Run it now

Answer the questions and you get the number, the working behind it and what we would do about it. The calculation itself runs in your browser, so your answers stay with you.

What you tell it

  • Records held and how sensitive they are
  • Sector, since notification duties and customer churn vary sharply
  • Whether you have an incident retainer and tested backups
  • Revenue per day, for the downtime element

What you get back

  • A cost range broken into detection, response, notification, legal, regulatory and lost business
  • Estimated days to contain, with and without a retainer in place
  • The share of cost that a tested recovery plan removes
  • What the same breach looks like if it is found in week one instead of month four

How the number is worked out

  1. 1

    Response effort is modelled on our own incident engagements, in hours by role.

  2. 2

    Notification cost uses Indian regulatory timelines, including the CERT-In six hour window where it applies.

  3. 3

    Lost business is the widest component and is shown as a band, driven by sector churn.

  4. 4

    Dwell time is the largest single lever in the model, which matches what we see in practice.

Where this stops being useful

Every breach cost model is built on averages, and no organisation is average. Use it to compare scenarios against each other rather than as a prediction of your own number.

Where breach cost actually lands

Organisations model breach cost as a fine plus some remediation. In practice the fine is frequently not the largest line, and the shape of the cost surprises people.

Incident response and forensics come first and are unavoidable. If you have no retainer, you are buying scarce expertise at the worst possible moment, which is more expensive than arranging it in advance.

Then business interruption, which for most organisations is the largest single line and is entirely determined by how long recovery takes. This is why backup and restore testing has a better return than nearly any detection investment.

Then notification and remediation for affected individuals, which scales with the number of records, which is why data you no longer need is a liability rather than a neutral asset.

Then regulatory penalty, legal cost and, over a longer horizon, customer churn and increased cost of sale. That last one is real and almost never modelled, because it lands in a different department's budget.

The variables that change the number by an order of magnitude

Time to detect. An intrusion caught in the quiet period, before the party that got in hands over to the party that will encrypt you, costs a fraction of one caught at impact. This is the single strongest argument for detection spend.

Whether recovery is tested. Organisations with untested backups discover during the incident that the restore takes days longer than assumed, or that the backups themselves were reachable from the compromised network and are now encrypted.

How much data you held. Records you deleted last year cost nothing to notify about.

Whether the incident process exists. The difference between a coordinated response and an improvised one is measured in days of business interruption, and days are the expensive unit here.

How to use this in a business case

Do not present the number alone. Present it against the cost of the control that reduces it, and be honest that the control reduces rather than eliminates the exposure.

The strongest business cases we see pair a specific control with the specific line it reduces. Tested restores reduce business interruption. Detection reduces dwell time. Retention reduces notification volume and penalty gravity. Segmentation reduces the affected scope.

Avoid using industry average figures as though they applied to you. They are drawn from populations that may look nothing like your estate, and a sceptical CFO will say so. Your own numbers, even rough ones, are more defensible.

The reporting clocks that run alongside the cost

Cost is not the only consequence, and the timelines are shorter than most organisations plan for. Reportable incidents go to CERT-In within six hours of noticing, under the 2022 Directions.

Where personal data is involved, the DPDP Act 2023 adds a separate obligation to the Data Protection Board and to affected data principals, with different triggers.

Regulated entities under RBI, SEBI or IRDAI supervision carry their own reporting expectations on top of both.

Build one detection and triage process with three reporting paths off it. Organisations that build one reporting process and assume it satisfies everyone notify the wrong body on the wrong timeline, which converts an incident into an enforcement matter.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.