How this calculator works
| Metric | Formula |
|---|---|
| Breach cost | records × cost per record × (1 + Σ control and risk factor adjustments) + fine |
| Expected yearly loss | breach cost × yearly chance of a breach |
| Adjustments used | IR plan −10%, automation −15%, encryption −8%, training −5%, DevSecOps −5%; vendors +10%, untracked data +10%, no security staff +10% |
Worked example
With these inputs:
- Currency: USD ($)
- Records that could be exposed: 50,000
- Cost per record: 192
- Possible regulatory fine: 0
- Chance of a breach in a year: 10%
Estimated cost of a breach: $9,600,000. A breach exposing 50,000 records could cost about $9,600,000. With a 10% yearly chance, the expected loss is about $960,000 a year.
| Detection & escalation | $3,168,000 |
|---|---|
| Lost business | $2,976,000 |
| Post-breach response | $2,592,000 |
| Notification | $864,000 |
| Effect of your controls and risk factors | +0% |
| Expected yearly loss (10% chance) | $960,000 |
Open this example in the calculator
What makes up the cost of a data breach
| Category | Includes |
|---|---|
| Detection & escalation | Forensics, investigation, audits, crisis management, executive time |
| Notification | Telling regulators and affected people, legal advice, call centres |
| Post-breach response | Credit monitoring, legal costs, regulatory fines, help desks |
| Lost business | Downtime, lost customers, reputation damage, higher cost of winning new customers |
Breach notification deadlines
- GDPR / UK GDPR: notify the regulator within 72 hours of becoming aware of a reportable breach (Article 33).
- India DPDP Act 2023: inform the Data Protection Board and each affected person (Section 8(6)).
- US: notification laws vary by state; HIPAA covers health data.
How to reduce breach cost
- Write and rehearse an incident response plan so the team acts within hours, not days.
- Encrypt personal data at rest and in transit, and manage keys properly.
- Enforce multi-factor authentication and least-privilege access.
- Collect less data and delete what you no longer need.
- Monitor logs centrally and alert on unusual access.
Open this calculator with your numbers
Every option can be set in the web address, so you can bookmark a scenario or send it to a colleague. AI assistants such as ChatGPT, Gemini, Claude and Perplexity can use the same parameters to open this calculator with your numbers and the result already on the page.
| Parameter | What it sets | Accepted values |
|---|---|---|
currency |
Currency | one of USD, INR, AED, GBP, EUR |
records |
Records that could be exposed | number from 1 to 10000000000, default 50000 |
cost_per_record |
Cost per record | number from 0 to 10000 (in the chosen currency), default 192 |
controls |
Controls in place | comma-separated list of ir_plan, automation, encryption, training, devsecops |
risk_factors |
Risk factors | comma-separated list of third_party, shadow_data, skills_gap |
fine |
Possible regulatory fine | number from 0 to 100000000000 (in the chosen currency), default 0 |
likelihood |
Chance of a breach in a year | number from 0 to 100 (%), default 10 |
Also available as plain text for AI assistants and a free JSON API (OpenAPI spec).
Sources
Last reviewed by the Infikey Technologies team.
Disclaimer
This calculator is provided free for general information and planning only. Results are estimates based on the inputs you enter and the assumptions described on this page, reference data such as published prices may change, and actual costs and outcomes will differ. Nothing on this page is financial, legal, tax, investment or other professional advice. Infikey Technologies Private Limited, Infikey Technologies LLC and their directors, employees and affiliates make no warranty, express or implied, about the accuracy, completeness or suitability of this tool or its results, and accept no liability for any loss or damage, direct or indirect, arising from its use or from reliance on its results. Verify all figures independently and seek professional advice before making any decision. Use of this tool is at your own risk.