Breach Cost Calculator
Estimate data breach cost per record with lifecycle and control adjustments, following the published cost-of-a-breach structure.
Inputs
A user-supplied assumption; published studies put healthcare highest and public sector lowest.
Published studies consistently find a material cost premium beyond a 200-day lifecycle.
A user-supplied assumption.
Estimated Total Breach Cost
$38,176,250
Base Record Cost
$41,250,000
Lifecycle Premium
$9,487,500
Saving From Controls in Place
$15,221,250
Business Disruption Cost
$2,160,000
Effective Cost per Record
$152.71
Assumption Note
All monetary inputs are user-supplied assumptions. Base cost 41250000 USD, lifecycle premium 23%, control saving 30%.
Step by step
Values used
Records exposed = 250,000 records; Cost per record = 165 $/record; Breach lifecycle = Longer than 200 days to identify and contain; Tested incident response plan and IR team = Yes; Affected data encrypted at rest = No; Extensive security AI and automation deployed = Yes; Expected regulatory fine or penalty = 500,000 $; Hours of business disruption = 48 hours; Revenue or productivity per hour = 45,000 $/hour
Breach Cost
Total = records × cost per record × (1 + lifecycle premium) × (1 − control savings) + regulatory fine + downtime cost.
Effective per-record cost
Effective cost per record = total cost ÷ records exposed, which rises sharply for small breaches carrying a fixed fine.
Estimated Total Breach Cost
= 38,176,250
Base Record Cost
= 41,250,000
Lifecycle Premium
= 9,487,500
Saving From Controls in Place
= 15,221,250
Business Disruption Cost
= 2,160,000
Effective Cost per Record
= 152.71
How it works
The structure follows the published cost-of-a-breach model: a per-record base, a premium for long breach lifecycles, and percentage reductions for controls that studies consistently associate with lower costs. The fine and downtime are added afterwards, because neither scales with record count. Per-record arithmetic is how breach exposure gets translated into a number that sits alongside other enterprise risks — and the control discounts are the clearest available argument for funding an IR plan, encryption and automation before an incident rather than after.
Formulas
Breach Cost
Total = records × cost per record × (1 + lifecycle premium) × (1 − control savings) + regulatory fine + downtime cost.
- cost per record
- Per-record cost assumption for your sector
- lifecycle premium
- 23% uplift when the breach takes more than 200 days to identify and contain
- control savings
- 14% tested IR plan, 12% encryption, 16% security AI and automation
Effective per-record cost
Effective cost per record = total cost ÷ records exposed, which rises sharply for small breaches carrying a fixed fine.
- regulatory fine
- Expected penalty — a user-supplied assumption
- downtime cost
- Disruption hours × revenue per hour
Frequently Asked Questions
How is Breach Cost calculated?
Total = records × cost per record × (1 + lifecycle premium) × (1 − control savings) + regulatory fine + downtime cost. The structure follows the published cost-of-a-breach model: a per-record base, a premium for long breach lifecycles, and percentage reductions for controls that studies consistently associate with lower costs. The fine and downtime are added afterwards, because neither scales with record count.
Why does Breach Cost matter?
Per-record arithmetic is how breach exposure gets translated into a number that sits alongside other enterprise risks — and the control discounts are the clearest available argument for funding an IR plan, encryption and automation before an incident rather than after.
What values do I need to enter?
This calculator takes 9 inputs: Records exposed, Cost per record, Breach lifecycle, Tested incident response plan and IR team, Affected data encrypted at rest, Extensive security AI and automation deployed, Expected regulatory fine or penalty, Hours of business disruption, Revenue or productivity per hour. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Are the percentages here authoritative?
They are drawn from the structure and direction of published breach-cost research, but every figure in this calculator — including the per-record cost and the discounts — is an assumption you should replace with your own or your insurer's numbers. Treat the output as a modelled estimate, not a prediction.
Why does cost per record fall as breach size grows?
Fixed costs dominate small breaches. Forensics, legal review, notification tooling and a regulatory fine are largely the same whether ten thousand or fifty thousand records are exposed, so the per-record figure is much higher at the small end and flattens as volume grows.