Estimate data breach cost per record with lifecycle and control adjustments, following the published cost-of-a-breach structure.
The structure follows the published cost-of-a-breach model: a per-record base, a premium for long breach lifecycles, and percentage reductions for controls that studies consistently associate with lower costs. The fine and downtime are added afterwards, because neither scales with record count. Per-record arithmetic is how breach exposure gets translated into a number that sits alongside other enterprise risks — and the control discounts are the clearest available argument for funding an IR plan, encryption and automation before an incident rather than after.
Breach Cost
Total = records × cost per record × (1 + lifecycle premium) × (1 − control savings) + regulatory fine + downtime cost.
Effective per-record cost
Effective cost per record = total cost ÷ records exposed, which rises sharply for small breaches carrying a fixed fine.
Total = records × cost per record × (1 + lifecycle premium) × (1 − control savings) + regulatory fine + downtime cost. The structure follows the published cost-of-a-breach model: a per-record base, a premium for long breach lifecycles, and percentage reductions for controls that studies consistently associate with lower costs. The fine and downtime are added afterwards, because neither scales with record count.
Per-record arithmetic is how breach exposure gets translated into a number that sits alongside other enterprise risks — and the control discounts are the clearest available argument for funding an IR plan, encryption and automation before an incident rather than after.
This calculator takes 9 inputs: Records exposed, Cost per record, Breach lifecycle, Tested incident response plan and IR team, Affected data encrypted at rest, Extensive security AI and automation deployed, Expected regulatory fine or penalty, Hours of business disruption, Revenue or productivity per hour. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
They are drawn from the structure and direction of published breach-cost research, but every figure in this calculator — including the per-record cost and the discounts — is an assumption you should replace with your own or your insurer's numbers. Treat the output as a modelled estimate, not a prediction.
Fixed costs dominate small breaches. Forensics, legal review, notification tooling and a regulatory fine are largely the same whether ten thousand or fifty thousand records are exposed, so the per-record figure is much higher at the small end and flattens as volume grows.