Data Breach Cost Estimator
A breach cost estimator turns four inputs, records exposed, cost per record, detection time and downtime, into a rough total with a direct and indirect split. It is for budgeting security spend and sizing cyber insurance, and its numbers are order-of-magnitude, not forecasts.
Last reviewed by the Radiatus Cloud team
Want this done for your business?
Radiatus delivers cloud, security & automation for growing teams.
The formula
Base cost is records multiplied by cost per record. Detection time scales it: over 30 days adds 10 percent, over 100 days adds 30 percent, reflecting the consistent finding that breaches found late cost more because attackers have had time to move and exfiltrate. Downtime adds a flat 1,000 dollars per hour, a placeholder for a small business; replace it mentally with your own revenue per hour. The base is then split 60 percent direct, covering forensics, notification, legal and credit monitoring, and 40 percent indirect, covering churn and reputation, with downtime added to the indirect side.
Choosing a cost per record
IBM's annual Cost of a Data Breach study is the usual reference: the 2024 report put the global average total at 4.88 million dollars, and the most recent per-record figures cluster around 165 dollars, higher in healthcare and finance and in the United States. Two cautions. Per-record cost is not linear; mega-breaches of tens of millions of records cost far less per record than a 10,000-record incident, because fixed costs dominate small breaches. And the average hides a long tail, so a median-based number would be lower.
| Scenario | Records | Per record | Detection | Estimate |
|---|---|---|---|---|
| Small SaaS, customer emails | 20,000 | $150 | 45 days | about $3.3M plus downtime |
| Clinic, patient records | 5,000 | $400 | 120 days | about $2.6M plus downtime |
What is not in the model
- Regulatory fines, which under GDPR can reach 4 percent of global turnover and are set case by case.
- Ransom payments and the cost of rebuilding systems after ransomware, which can exceed the data costs entirely.
- Contractual penalties and increased cost of capital, which show up years later.
Using the number
Compare the estimate with the annual cost of the controls that would have shortened detection: logging, endpoint detection, a tested incident response plan. If detection time drops from 100 days to under 30 the model alone removes 20 percent of the cost, which is usually more than those controls cost.
Related tools
- Incident Downtime Cost Calculator — Estimate the cost of an incident across lost revenue, staff time and recovery, and build the case for prevention.
- Regulatory Penalty Estimator — Estimate potential fines for GDPR/CCPA violations.
- Incident Impact Calculator — Estimate the cost of a security incident from severity, affected users and downtime hours, with a compliance and trust rating and the response actions each severity level demands.
- Cyber Risk Scorecard — Generate a summary scorecard of your cyber risk posture.
Frequently Asked Questions
Where does the cost per record figure come from?
It is your input. The IBM Cost of a Data Breach report is the common source, with recent global averages around 165 dollars per record and roughly double that in healthcare. Use your sector's figure and remember it falls sharply for very large breaches.
Why does detection time increase the cost?
Attackers who remain undetected for months exfiltrate more, spread further, and leave a larger forensic scope. The IBM data shows breaches contained inside 200 days cost substantially less than those that ran longer; the 10 and 30 percent multipliers here are a simplification of that.
Is the 1,000 dollars per hour downtime cost realistic?
For a small business, roughly. An e-commerce site doing 10 million dollars a year loses about 1,150 dollars per hour of sales alone. Larger operations should substitute their own revenue and staff cost per hour.
Does the estimate include fines?
No. Regulatory penalties depend on jurisdiction, negligence and cooperation, and range from nothing to a percentage of turnover. Add them separately using the regulatory penalty estimator.
How accurate is this?
To within a factor of two or three at best. It is meant to justify security budgets and insurance limits, where being in the right order of magnitude is what matters.
Privacy & Security
Calculations local.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Incident Downtime Cost Calculator
BusinessEstimate the cost of an incident across lost revenue, staff time and recovery, and build the case for prevention.
Regulatory Penalty Estimator
BusinessEstimate potential fines for GDPR/CCPA violations.
Incident Impact Calculator
BusinessEstimate the cost of a security incident from severity, affected users and downtime hours, with a compliance and trust rating and the response actions each severity level demands.