Quantify PII breach exposure: records at risk, field sensitivity, identity-theft potential, notification cost and regulatory fines.
What makes a breach expensive is the field combination, not the record count alone: a name and email is a nuisance, while a name with a government identifier is a durable identity-theft kit that cannot be reissued like a card number. Credential exposure is discounted by how well the secrets were protected, which is the one field where prior engineering decisions materially change the outcome. Fine exposure is modelled well below the statutory maximum because enforcement rarely reaches it. Cost per record is the figure that survives contact with a board: it converts an abstract breach into a number that can be compared against the cost of the control that would have prevented it.
PII Exposure
sensitivityIndex = 0.9 × (1 for names/email + 3 for government ID + 3 for financial + 2.5 for health + 2 for credentials); costs scale notification and remediation by record count and sensitivity.
Modelled regulatory exposure
expectedFine = maxFine × min(0.15, sensitivityIndex ÷ 10 × 0.15) — enforcement rarely reaches the statutory maximum, so the model caps the modelled exposure at 15% of it.
sensitivityIndex = 0.9 × (1 for names/email + 3 for government ID + 3 for financial + 2.5 for health + 2 for credentials); costs scale notification and remediation by record count and sensitivity. What makes a breach expensive is the field combination, not the record count alone: a name and email is a nuisance, while a name with a government identifier is a durable identity-theft kit that cannot be reissued like a card number. Credential exposure is discounted by how well the secrets were protected, which is the one field where prior engineering decisions materially change the outcome. Fine exposure is modelled well below the statutory maximum because enforcement rarely reaches it.
Cost per record is the figure that survives contact with a board: it converts an abstract breach into a number that can be compared against the cost of the control that would have prevented it.
This calculator takes 10 inputs: Records exposed, Names and email addresses included, Government identifiers included, Payment or bank details included, Health data included, Passwords or authentication secrets included, Protection applied to the exposed data, Notification and support cost per record, Credit monitoring and remediation per record, Annual revenue. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because it cannot be reissued. A compromised card is cancelled in a day; a national identifier follows the person for life and underpins account opening everywhere, which is why remediation costs run for years.
They are planning figures, not actuals. Published averages hide enormous variation by sector and jurisdiction, so replace the defaults with your own legal and notification quotes as soon as you have them.