Per health record breached
The single most expensive record type in the model. PII runs $180, payment cards $295, credentials $150. IBM Cost of a Data Breach 2024, healthcare segment.
Two calculators, one page, driven by the same answers. Risk Exposure prices the liability sitting in the records you hold — one breach, the annualised expectation, and the P95 tail your insurer asks about. ROI & Savings puts what your compliance programme costs today beside our published rates. Everything updates as you type.
The single most expensive record type in the model. PII runs $180, payment cards $295, credentials $150. IBM Cost of a Data Breach 2024, healthcare segment.
The industry incidence we multiply a single-breach loss by to get your expected annual loss. Shown as a 10–25% range. Verizon DBIR 2024 + IBM 2024, SMB incidence.
What the fractional CISO retainer includes — the figure the ROI side compares your current questionnaire, policy and advisory hours against. Our published rate card.
The easy way to build an ROI calculator is to claim a platform absorbs some percentage of your work, then multiply. We don't, because nobody can substantiate that number. Everything here is published research, your own inputs, or our own published price.
One breach is records you hold × a per-record cost from IBM's Cost of a Data Breach 2024 and the Verizon DBIR 2024 — PHI $408, PCI $295, PII $180, credentials $150. Multiply by a published breach base rate for expected annual loss; the severe, heavily-regulated end of the same model gives the P95 probable-maximum loss.
Questionnaire, policy and advisory hours at your own blended rate, against our published retainer and the 120–240 executive hours a year it includes. Plus the fractional CISO against the loaded cost of the full-time hire — base pay plus the ~25% employer burden the BLS reports.
We never multiply your workload by a claimed "platform absorbs 70% of this" figure to manufacture a saving. If the hours you buy exceed what a retainer covers, the calculator says so and points you at the larger scope — even though the smaller number would look better.
Single-breach exposure is what one incident touching those records would cost. Expected annual loss spreads that across a published breach base rate — the long-run average a board plans against. P95 is the bad year. Insurers and audit committees ask for all three.
No, and the distinction matters. The saving compares what the same capability costs two different ways — retained from us, or built in-house. It is not a claim that a programme removes some percentage of your exposure. Any vendor showing you that number should be asked where it came from.
Questionnaire effort (40–80 hours each) reflects the practitioner range for SIG Lite and CSA CAIQ completions; policy and advisory hours default to conservative mid-market figures. All are editable and labelled as assumptions rather than citations — your own numbers always win.
No. The calculator runs entirely in your browser and sends us nothing unless you ask for the summary by email. The full assessment — which does scan endpoints (Windows, macOS, Linux), Microsoft 365 and Google Workspace — only happens with your permission.