Data breach cost calculator
Your estimated breach cost range
Where the cost of a typical breach goes
How your industry compares
How is this calculated?
Step 1: we start from real breach sizes. Our corpus contains 38,233 breaches where the number of affected records was disclosed. Line them all up from smallest to largest, and your four scenarios are four points on that line:
Smaller incident (4 records): 3 in 4 real breaches were bigger than this.
Typical (250 records): half of real breaches were bigger than this.
Severe (152,022 records): only 1 in 10 real breaches was bigger than this.
Worst case (598,400 records): only 1 in 100 was bigger.
Every real breach falls somewhere on that line. We show these four points because they answer the two questions that actually get asked: what should we expect, and how bad could it realistically get.
Step 2: we price each record. The cost per record starts from the most sensitive data type you hold. Health records cost more per record than email addresses. Holding more than one data type adds 5% per extra type, because each type adds its own notification duties and regulatory exposure.
Step 3: we adjust for your profile. Your industry and country each raise or lower the estimate, based on how often organizations like yours appear in our incident data and how hard regulators there fine. More vendors raises it too, because third parties are the leading way breaches start.
One honest caveat: for the severe and worst-case scenarios, the per-record price is stretched beyond the breach sizes where it is best validated. Read those two as "how bad could it get" indicators, not forecasts. The model was last calibrated on August 13, 2026 from 196,365 incidents and recalibrates as the corpus grows.
These estimates are informational aggregates from public breach data. They are not financial, legal, or insurance advice, and no figure here is a prediction about any specific organization.
How does this compare to the platform's calculator?
This is the full model: the same calibrated formula and the same inputs as the platform's estimator, nothing held back. The platform version adds the full audit trail, with every factor in the calculation shown alongside the exact dataset behind it, and your estimate benchmarked live against the organizations we track in your industry.
Beyond the calculator, the platform points this same model at your actual suppliers: upload your vendor list and it prices a breach of each specific vendor, follows the cost through their parents and subsidiaries on the ownership graph, and shows the corroborated breach records behind every number. The calculator answers "how big is a breach for a company like mine". The platform answers "which of my vendors causes it, and what does that cascade cost me".
Point this model at your own suppliers
We are running a small number of pilot demos. Email us, bring your supplier list, and we will walk you through your real exposure.
Request a pilot demoOr write to us directly: [email protected]