Breach Cost Estimation
Data breach cost estimation using IBM/Ponemon methodology — industry factors, cost modifiers, response readiness adjustments, and lawsuit probability.
The breach cost estimator uses a regression model based on the IBM/Ponemon Cost of a Data Breach methodology. It factors in industry, organization size, breach type, and response readiness to produce cost estimates with confidence intervals.
Input Parameters
| Parameter | Type | Description |
|---|---|---|
| Industry | String | Industry vertical (healthcare, financial services, technology, etc.) |
| Employee Count | Number | Organization size by headcount |
| Record Count | Number | Number of records at risk in the breach scenario |
| Breach Type | Enum | malicious_outsider, malicious_insider, lost_device, accidental |
| Has IR Plan | Boolean | Whether a documented incident response plan exists |
| Has IR Team | Boolean | Whether a dedicated incident response team is in place |
| Uses Encryption | Boolean | Whether extensive data encryption is deployed |
| Has Security Training | Boolean | Whether employee security awareness training is active |
| Time to Identify | Days | Estimated days to identify a breach |
| Time to Contain | Days | Estimated days to contain a breach |
Cost Components
The model breaks down total breach cost into four categories:
Detection and Escalation
Costs associated with discovering and investigating the breach:
- Forensic investigation
- Assessment and audit services
- Crisis management team activation
- Internal investigation labor
Notification
Costs of notifying affected parties and regulators:
- Regulatory notification compliance
- Affected individual notification
- Communication materials and call center setup
Post-Breach Response
Costs of responding to and managing the aftermath:
- Help desk and customer support
- Credit monitoring and identity protection services
- Legal and regulatory compliance costs
- Product discounts and customer retention efforts
Lost Business
Revenue and customer impact:
- Customer turnover and acquisition cost increases
- Reputation damage and brand impact
- Business disruption and system downtime
Cost Modifiers
The model applies fixed modifiers based on organizational readiness. These are the exact
constants the engine uses (estimateBreachCost in lib/risk-quantification.ts):
| Factor | Modifier | |---|---| | Has IR plan | −9.4% (its absence adds +9.4%) | | Has IR team | −14.0% | | Uses encryption | −7.0% | | Has security training | −5.0% | | Fast identification (under 100 days) | −10.0% | | Slow identification (over 200 days) | +23.0% | | Fast containment (under 30 days) | −8.0% | | Slow containment (over 90 days) | +12.0% |
Lawsuit Probability
The estimator also produces a class-action probability. This is a stated heuristic, not a fit to a historical lawsuit dataset — a 15% base rate plus fixed increments:
- +15% for malicious-outsider breaches
- +10% for breaches over 10K records, or +20% over 100K records
- +10% for healthcare and financial-services organizations
- Capped at 85%
Output
The model returns:
- Median cost estimate with confidence interval
- Cost breakdown by the four categories
- Per-record cost for benchmarking
- Modifier impact showing how each readiness factor affects the total
- Lawsuit probability as a percentage
Integration with Exercises
After an exercise, the breach cost estimator can be run using the scenario parameters and readiness findings. This connects exercise outcomes directly to financial exposure, providing a tangible measure of why gap remediation matters.