Breach Cost Estimation

Data breach cost estimation using IBM/Ponemon methodology — industry factors, cost modifiers, response readiness adjustments, and lawsuit probability.

The breach cost estimator uses a regression model based on the IBM/Ponemon Cost of a Data Breach methodology. It factors in industry, organization size, breach type, and response readiness to produce cost estimates with confidence intervals.

Input Parameters

| Parameter | Type | Description | |---|---|---| | Industry | String | Industry vertical (healthcare, financial services, technology, etc.) | | Employee Count | Number | Organization size by headcount | | Record Count | Number | Number of records at risk in the breach scenario | | Breach Type | Enum | malicious_outsider, malicious_insider, lost_device, accidental | | Has IR Plan | Boolean | Whether a documented incident response plan exists | | Has IR Team | Boolean | Whether a dedicated incident response team is in place | | Uses Encryption | Boolean | Whether extensive data encryption is deployed | | Has Security Training | Boolean | Whether employee security awareness training is active | | Time to Identify | Days | Estimated days to identify a breach | | Time to Contain | Days | Estimated days to contain a breach |

Cost Components

The model breaks down total breach cost into four categories:

Detection and Escalation

Costs associated with discovering and investigating the breach:

  • Forensic investigation
  • Assessment and audit services
  • Crisis management team activation
  • Internal investigation labor

Notification

Costs of notifying affected parties and regulators:

  • Regulatory notification compliance
  • Affected individual notification
  • Communication materials and call center setup

Post-Breach Response

Costs of responding to and managing the aftermath:

  • Help desk and customer support
  • Credit monitoring and identity protection services
  • Legal and regulatory compliance costs
  • Product discounts and customer retention efforts

Lost Business

Revenue and customer impact:

  • Customer turnover and acquisition cost increases
  • Reputation damage and brand impact
  • Business disruption and system downtime

Cost Modifiers

The model applies fixed modifiers based on organizational readiness. These are the exact constants the engine uses (estimateBreachCost in lib/risk-quantification.ts):

| Factor | Modifier | |---|---| | Has IR plan | −9.4% (its absence adds +9.4%) | | Has IR team | −14.0% | | Uses encryption | −7.0% | | Has security training | −5.0% | | Fast identification (under 100 days) | −10.0% | | Slow identification (over 200 days) | +23.0% | | Fast containment (under 30 days) | −8.0% | | Slow containment (over 90 days) | +12.0% |

Lawsuit Probability

The estimator also produces a class-action probability. This is a stated heuristic, not a fit to a historical lawsuit dataset — a 15% base rate plus fixed increments:

  • +15% for malicious-outsider breaches
  • +10% for breaches over 10K records, or +20% over 100K records
  • +10% for healthcare and financial-services organizations
  • Capped at 85%

Output

The model returns:

  • Median cost estimate with confidence interval
  • Cost breakdown by the four categories
  • Per-record cost for benchmarking
  • Modifier impact showing how each readiness factor affects the total
  • Lawsuit probability as a percentage

Integration with Exercises

After an exercise, the breach cost estimator can be run using the scenario parameters and readiness findings. This connects exercise outcomes directly to financial exposure, providing a tangible measure of why gap remediation matters.