How this is calculated
Cyber Incident Cost
Builds an illustrative incident cost from a fixed response cost plus a per-record element and the trading lost while systems are down, then sets it against what the cyber coverage in place would respond with.
Step by step
- Breach response = a fixed $25,000 floor plus $165 per exposed record, the whole of it uplifted 1.4× where card payments are taken.
- Downtime is illustrated at 12 days, or 24 days without tested offline backups.
- Trading lost = annual revenue ÷ 365 × those days. Revenue is a rough ceiling: a policy's business interruption cover pays net income plus continuing expenses rather than gross revenue.
- Illustrated incident cost = breach response + trading lost.
- What responds: a standalone policy responds up to the limit you enter (a stated $0 is a stated zero); a package endorsement responds up to a typical $50,000 sub-limit; none or unknown responds with nothing.
- A standalone policy with no limit entered leaves the gap open rather than showing it as zero — there is no figure to set the cost against.
- The gap is the illustrated cost minus what responds, never below zero.
The formula
Response = (fixed + records × per-record) × card multiplier. Downtime cost = revenue ÷ 365 × days. Gap = max(0, response + downtime − what responds).
Assumptions and their default values
Some of these change with the state you select.
Where the figures come from
- Broad published averages for breach response cost and incident downtime (illustrative, reviewed periodically).
What this method does not show
Nothing about the method is hidden. It deliberately does not attempt to estimate the likelihood of an incident, regulatory fines, or a ransom demand, which depend on jurisdiction and conduct rather than on business size.
Important disclosures
- This tool is educational only. It illustrates potential exposure using the assumptions shown — it is not insurance advice, a price, or an offer of coverage, and it does not determine whether any coverage amount is right for you. Policy language varies; review your actual policy and discuss your situation with a licensed insurance professional.
- Incident costs vary enormously with what was taken, which regulators are involved, whether a ransom is demanded, and how quickly the intrusion was found. The figures here are a rough illustration built from broad published averages, not an estimate of what any particular incident would cost.
- Cost-per-record averages are drawn largely from large breaches and mislead badly at small scale, because most of the cost of a small breach is fixed. This tool models that fixed cost first for exactly that reason, but it remains an illustration.
- Cyber policies differ more than almost any other line. Breach response, business interruption, extortion, funds-transfer fraud and third-party liability are frequently separate insuring agreements with separate sub-limits, so a single headline limit rarely applies to all of them.
- The trading figure uses annual revenue as a rough ceiling. Business interruption cover under a cyber policy generally pays lost net income plus continuing expenses, not gross revenue, so what a policy would actually pay for downtime is typically below the figure illustrated.
- Extortion and ransom payments are a separate insuring agreement, often with their own sub-limit and conditions, and are not modelled here at all.
- Coverage may be conditional on security controls stated in the application — multi-factor authentication and tested backups among them. Whether cover responds can turn on whether those were actually in place.
Now that you can see the method, the numbers are worth a conversation.
Back to Cyber Incident Cost