Reference
Security calculators: the assumption is the answer
The multiplication is never the hard part. Every figure these things produce rests on one or two inputs nobody can verify, and the interesting question is which ones — because everything else on the form is decoration.
Last reviewed August 25, 2026
- Find the dominant input first. One field usually carries the answer; the rest are there to make the form look thorough.
- Defaults are the argument. Whoever set them decided the conclusion before you arrived.
- Estimate ranges, not points. Most decisions are insensitive to precision and sensitive to order of magnitude.
- A hidden input is a tell. If you cannot see or change the number that matters, you are reading a conclusion.
What is a calculator actually for?
Not for producing a figure. For making somebody state a belief out loud, at which point it becomes possible to disagree with them.
Consider the conversation these things replace. Somebody says an outage would be expensive, somebody else says the fix is expensive, and both are correct in a way that leads nowhere because neither has said a number. The calculator's real function is to force the first person to commit to a duration and the second to a cost, after which the disagreement is about something specific.
That reframing changes what a good one looks like. If the point were the output, precision would matter and hidden sophistication would be a virtue. If the point is the argument, then every input must be visible and adjustable, because the adjustment is the conversation. A tool that produces an impressive figure from fields you did not choose has removed the only useful thing it does.
It also explains why a calculator is worth building for a decision that has already been made emotionally. Writing down the assumption that made the answer obvious is how you find out whether it survives being written down — and a surprising proportion do not.
Which input carries the result
Vary each input of a typical incident cost model across a range you could defend, and see how far the answer moves.
One bar is wider than the three below it put together. In nearly every incident cost model the duration of disruption dominates, because it multiplies through everything else: lost trading, staff time, contractual penalties, the temporary arrangements that keep a business running. Change it from two days to five and the total does not rise by half, it more than doubles.
That bar is also, almost always, the field with the least discussion behind it. It arrives as a number somebody chose because it looked reasonable, sits between two fields that have been argued over, and carries the result. If a meeting has an hour for a cost model, fifty minutes belong to the top bar.
The narrow bars at the bottom deserve a word, because they attract effort out of proportion to their influence. Forensic engagement costs and notification expenses are knowable, quotable and satisfying to research, and getting them exactly right changes the total by a rounding error. Precision is worth spending where the sensitivity is, and almost nowhere else.
Why do vendor calculators always favour buying?
Not by cheating on the arithmetic, which is usually correct and checkable. The conclusion is set in the defaults.
Every field arrives pre-filled, because an empty form is abandoned. Somebody chose those values, that somebody works for the company selling the remedy, and research on every kind of form shows that most people submit the defaults with at most one or two changes. The output is therefore mostly a function of decisions made before you arrived, presented as a calculation you performed.
Two other mechanisms recur and are worth recognising by sight. Some inputs are absent altogether — the ongoing cost of operating the thing, the staff time to tune it, the migration off whatever it replaces — and an omitted cost is a cost set to zero. And the benefit side is frequently expressed as a percentage reduction in a loss you have not established you would have suffered, which multiplies an assumption by an assumption and reports the product as a saving.
None of this requires anybody to be acting badly, and the tools are often genuinely useful for structuring a first estimate. The correct use is to take the model, put your own numbers in every field including the ones nobody asked about, and notice how far the answer travels. If it still supports the purchase, that is now a real finding rather than a marketing artefact.
What does a breach actually cost?
There is no single figure, and quoting one without saying what it contains is the commonest error in this whole field.
Published averages differ by an order of magnitude, and the variation is almost entirely definitional rather than empirical. A narrow figure counts direct response: the responders, the overtime, the notification, the legal advice. A wide one adds lost business, reputational damage modelled from share price movements, customer churn attributed to the event, and staff time valued at salary. Both are defensible and they are not the same measurement.
The distribution is worse than the averages suggest. Most incidents cost very little and a small number cost enormously, so the mean sits well above what a typical organisation would experience and describes almost nobody. Quoting an average as though it were a forecast for your next incident is a statement about the tail dressed as a statement about you.
What works better is asking a narrower question with a checkable answer. Not what a breach costs, but what a week without a specific system costs — which finance can estimate, which is about your organisation, and which feeds directly into the input that the chart above says carries everything.
How should a calculator be read?
Four steps, in order, and most tools fail before the third.
Find the dominant input. Change one field at a time and watch the output. The one that moves it most is the model; everything else is presentation. This takes two minutes and is the whole exercise.
Decide whether you believe that number. Not whether it is plausible — whether you would defend it in front of somebody who disagreed. If you would not, the output is not usable and no amount of care elsewhere rescues it.
Look for what is missing. Ongoing operation, staff time, the cost of leaving, what breaks during migration. An omitted field is not a neutral simplification; it is a value set to zero by somebody who benefits.
Run the range, not the point. Put in your low and high figures for the dominant input and read both answers. If the decision is the same at either end, you have finished and precision was never needed. If it flips, you have found the thing actually worth investigating, which is a better outcome than a single number would have given you.
Is return on investment the right frame?
Rarely, and the reason is structural rather than a matter of doing the sums better.
A return requires a gain, and the gain here is an absence: incidents that did not occur. Absences cannot be counted, and the standard workaround — multiply an industry loss figure by an assumed reduction percentage — chains two unverifiable numbers and presents the product as a saving. That is not a measurement with error bars; it is a construction whose output is determined by the inputs somebody chose.
The frame that survives contact with a finance function is exposure rather than return. What would this specific failure cost us, how often might it happen, and what does closing it cost. All three are estimable, the first two badly and the third precisely, and the comparison remains meaningful even when the first two are wide ranges.
There is also a category of spending where any financial frame is the wrong instrument and pretending otherwise wastes everybody's time. Regulatory obligations are not optional, and backups are not a return-generating investment — they are the condition under which the organisation continues to exist. Trying to justify those with a calculator produces bad arithmetic in service of a decision that was never going to turn on it.
Estimating when you have nothing to go on
The usual objection to all of this is that the organisation has no data, which is true and less disabling than it sounds.
Start with what somebody in the building already knows. Finance can estimate a day without the ordering system. Operations know how long the last unplanned outage lasted, whatever caused it. Support know how many people call when a particular thing breaks. None of that is a security metric and all of it feeds the input that matters most.
Then estimate in ranges wide enough to be honest. A confident interval that spans a factor of three is more useful than a point estimate that is precisely wrong, because it can be narrowed later and because it survives scrutiny. People consistently underestimate how wide their genuine uncertainty is, and a range that feels uncomfortably broad is usually about right.
Then check whether the width matters. Most decisions turn out to be insensitive to precision: you rarely need to know whether an outage costs two hundred thousand or six hundred thousand to know it exceeds the cost of the backup arrangement that would prevent it. Where the decision does flip inside the range, you have located the one thing worth measuring properly, and that is a far better use of a week than measuring everything.
The classic formula, and where it breaks
Almost every quantitative model in this field is a variation on one expression: expected annual loss equals what a single occurrence costs, multiplied by how often it happens. It is decades old, it appears in every syllabus, and it is worth understanding precisely — including its two failure modes, which are not the ones people usually name.
The first failure is not that the frequency is hard to estimate, though it is. It is that the expression returns an average, and averages describe populations rather than organisations. An event costing five million pounds once a decade has the same expected annual loss as one costing five hundred thousand every year, and those two situations demand completely different responses. One is a solvency question and the other is a budgeting question, and the formula flattens the difference.
The second failure is that both terms are usually estimated from the same source, which makes their errors correlate. If the figure you used for cost came from a report that also supplied the frequency, an optimistic methodology has moved both numbers in the same direction and the product is wrong by more than either input. Independent errors partly cancel; correlated errors compound.
What the expression is genuinely good for is comparison rather than prediction. Two risks estimated with the same flawed method, by the same person, on the same afternoon, can be ranked against each other with reasonable confidence even when neither absolute figure means much. Use it to decide which of two things to do first, and stop before using it to decide what the year will cost.
Taking a range to people who wanted a number
The usual objection to everything above is practical: a board asked for a figure and will not accept an interval. That objection is real and mostly solvable by presentation rather than by abandoning the honesty.
Lead with the decision, not the estimate. The sentence that lands is we recommend spending this, because the alternative costs somewhere between these two figures. The range appears as support for a recommendation rather than as a request for somebody else to interpret it.
Name the input that decides it. One sentence: this turns on how long we would be down, we have assumed four days, and here is why. That invites the challenge you want and forecloses the challenge you do not, which is a general question about where any of the numbers came from.
Show that the decision holds at both ends. Where it does, say so and the range stops being a weakness. Where it flips, that is genuinely the most important thing in the paper, and burying it under a point estimate is the failure the whole exercise exists to prevent.
Bring the arithmetic and offer it. Nobody will check, and having it changes the register of the conversation from persuasion to examination. The willingness to be checked is doing the work, not the checking.
Directors are, in general, considerably more comfortable with uncertainty than security teams expect. They spend their working lives making decisions on estimates with wide intervals. What they react badly to is not a range but a figure that turns out to have been a range wearing a disguise, discovered later — which is the outcome the single confident number reliably produces.
The tools on this site
32 of them, 29 producing a figure. Each states what it assumes, produces the same answer from the same inputs, and serves its full argument without scripting.
“Can I tell from the log where an agent's instruction came from?”
- You set
- Six logged actions, three possible origins each
- It assumes
- Log lines deliberately reduced to their common shape — timestamp, credential, operation, result. Real telemetry carries more, and none of the extra fields answers the question either, which is the assertion being made rather than an accident of the example
In AI agents
“Should we buy this or hire somebody?”
- You set
- Pick buy or hire for each of four ordinary needs
- It assumes
- A silhouette rather than a survey. Scores were calibrated deliberately so the ordering reverses between the twelfth month and the thirty-sixth, since that reversal constitutes the whole claim; no individual figure deserves more credence than that
In People & skills
“When should a leaver's access actually be removed?”
- You set
- Slide the revocation date across ninety days around a departure
- It assumes
- That the handover and the pilfering inhabit one identical fortnight, whence no position triumphs. An actual resignation might prise them apart, whereupon the dilemma dissolves and the page overstates its difficulty
In Insider risk
“Why does waiting defeat almost every scam?”
- You set
- Choose a script; the check that undoes it appears after a delay
- It assumes
- That six seconds feel bearable while reading quietly. Sustaining an identical interval with somebody impersonating your bank on the telephone is incomparably harder, which is precisely the assertion and precisely what no webpage can stage
In Scams against people
“What happens when I answer an insurance questionnaire honestly?”
- You set
- Five controls, three answers each
- It assumes
- Interrogatories modelled on prevailing market proposal forms, never transcribed from an individual contract. Whichever concessions your carrier tolerates hinge upon wording you already signed, and upon nothing whatsoever assembled here
In Cyber insurance
“What breaks if I remove a credential nobody claims?”
- You set
- Decide on seven credentials before seeing the outcome
- It assumes
- That candour occasionally requires admitting ignorance, and it does. Any drill wherein every repercussion proves foreseeable depicts a tidier estate than any organisation genuinely operates
In Machine identity
“Would knowing who did it change what I do?”
- You set
- Switch the label on a fixed set of observed facts
- It assumes
- Completeness of the observed facts. Genuine attribution normally arrives bearing fresh forensic material; this drill isolates the awkward remainder, where the label shifts and the evidence does not
In State actors & espionage
“How far does one supplier's outage actually reach?”
- You set
- Follow a dependency outward, one level at a time
- It assumes
- A believable chain, certainly not your own. Depth carries the argument: the tier beyond which nobody can even name the supplier sits nearer the surface than intuition allows
In Availability & resilience
“How do I put this so it gets a decision?”
- You set
- Translate the same finding between four registers
- It assumes
- Soundness of the underlying finding. Rephrasing improves the reception of an accurate statement and confers precisely nothing upon an erroneous one
In Security leadership
“What do we do before anybody has decided anything?”
- You set
- Order the actions of the opening hour
- It assumes
- Somebody being awake and authorised. A plan's three habitual collapses — adjudication, spokesmanship, custody of the telephone numbers — precede every step enumerated below
In Incident response
“What is the harm when a hospital system stops?”
- You set
- Compare an outage against ordinary clinical timings
- It assumes
- Published averages for therapeutic windows. Whichever diversion protocol a particular hospital maintains perturbs the outcome further than any slider offered
In Healthcare
“Why does normal security advice fail on industrial equipment?”
- You set
- Apply an ordinary control to an operational system
- It assumes
- Availability outranking confidentiality — dependable across most operational technology, mistaken for a universal law rather more often than it should be
In Critical infrastructure
“What does encryption actually hide, and from whom?”
- You set
- Choose an observer and see what remains visible
- It assumes
- A faultlessly configured connection. Authentic exposure originates overwhelmingly in misconfiguration rather than in the underlying mathematics, and none of that misconfiguration appears below
In Encryption & privacy
The instruction, not the network
“Why does the best-defended sector lose the most money?”
- You set
- Follow a payment against the controls it passes
- It assumes
- Every control behaving exactly as specified. Losses depicted below accrue while all of them function impeccably, which supplies the discomfort
In Financial services
“Do I actually know what I think I know?”
- You set
- Answer with a confidence range rather than a number
- It assumes
- Erring generously beating erring narrowly. It gauges calibration rather than erudition, and those two qualities diverge far oftener than practitioners anticipate
In Home
“What would an incident actually cost us?”
- You set
- Headcount, downtime days, whether backups are usable
- It assumes
- Published per-employee and per-day averages, which vary widely by sector and say nothing about your own recovery speed
In Ransomware
“Who do we have to tell, and how fast?”
- You set
- Which regimes apply to you
- It assumes
- That you have already decided the event is notifiable, which is the hard part and happens before the clock
In Data breaches
“What should somebody actually look at in a message?”
- You set
- Reveal each signal in turn
- It assumes
- A message built to be teachable. Real lures increasingly carry none of these signals
In Phishing
“What happens between the click and the encryption?”
- You set
- Step forwards and back through six stages
- It assumes
- One representative sequence. Real intrusions skip stages and repeat others
In Malware
“Where should this connected device be allowed to sit?”
- You set
- Four questions about exposure, updates and credentials
- It assumes
- That you can answer question two honestly — whether the vendor still ships firmware, not whether the device has an update mechanism
In IoT
“How many components are really in our build?”
- You set
- Expand one level at a time
- It assumes
- A mid-sized application's shape. Your graph differs, and the order of magnitude is the point
In Supply chain risk
“How many people click at least once in a year?”
- You set
- Click rate per campaign, campaigns per year
- It assumes
- That attempts are independent and everybody is equally targeted, which is generous to the training
In Security awareness
“Why does our vulnerability queue never shrink?”
- You set
- Findings arriving per month, share repaired per month
- It assumes
- A constant proportional fix rate, which is the assumption that produces the fixed point
In Application security
“What can one leaked key reach?”
- You set
- Which credential leaked
- It assumes
- An illustrative permission graph. Yours has different edges and the same shape
In Cloud security
“What does tightening our checks cost in customers?”
- You set
- How strict the check is
- It assumes
- Two exponential curves fitted to the shape of the problem, not to any vendor's measurements
In Fraud & identity theft
“This happened to us — which clocks start?”
- You set
- What happened, and what kind of organisation you are
- It assumes
- The texts as they stood in August 2026. National transpositions and contracts add more
In Compliance & regulation
“Is this assistant safe to give tools to?”
- You set
- Which capabilities you grant
- It assumes
- Nothing numeric. The result is structural and does not depend on any figure
In AI & security
“Can we ever patch an edge device in time?”
- You set
- Hours to notice, confirm, schedule and apply
- It assumes
- That mass exploitation begins on day zero for this class of equipment, which is the published median
In Network & infrastructure
“How much actually happens to one work phone?”
- You set
- Your own guess, before the measured figure
- It assumes
- Published figures for professionally managed handsets, given as orders of magnitude
In Endpoint & mobile
“How many security tools do we run?”
- You set
- Which counting rules you accept
- It assumes
- An illustrative estate. What is not illustrative is that the published answers range threefold
In Industry & market
“What does this word mean to the other party?”
- You set
- Type a term, or show only the contested ones
- It assumes
- Nothing. The entries are definitions and disputes, not calculations
In Glossary
“What do suppliers say they do, and how many say the same?”
- You set
- Press a claimed capability to see who claimed it
- It assumes
- Nothing. The terms are the suppliers' own words from recovered listings, split and counted
In Directory
Building one that is worth using
Five properties, and the last is the one most tools miss.
Start from the decision, not the data. A calculator exists to inform a choice somebody is about to make. If you cannot name the choice, you are building a dashboard.
Expose the input that dominates, prominently. If duration decides the answer, duration belongs at the top with room to argue about it, not buried between two fields that change nothing.
Refuse fields that do not move the output. Every additional input makes the thing look more rigorous and less usable, and a field that changes the answer by one per cent is there to impress rather than to inform.
Make it deterministic. The same inputs must always give the same answer. Anything with randomness cannot be checked by the person reading it, and a figure nobody can reproduce is not a figure.
Write down what you assumed, where the reader can see it. Not in a methodology note nobody opens — beside the result. This is the property that separates a model from a claim, and it is the one almost universally omitted, because stating an assumption invites disagreement and disagreement is what the thing was built to avoid.
Common questions
What is a security calculator actually for?
Making an assumption visible and arguable. The arithmetic is trivial; the value is that a number forces somebody to state what they believe about downtime, probability or cost, at which point it can be disagreed with. A calculator that hides its inputs has removed the only useful thing it does.
Why do vendor calculators always favour buying?
Because the defaults were chosen by somebody with an interest in the result, and defaults are what most people submit. The arithmetic is usually sound and the conclusion is set before you arrive, in fields you were not invited to think about.
Which input carries the result?
In almost every incident cost model, the duration of disruption. Vary it across a defensible range and the answer moves further than every other input combined, which is why it deserves the argument and rarely gets it.
What does a breach actually cost?
There is no single number, and quoting one without saying what it includes is the commonest error in this field. Published averages vary by an order of magnitude depending on whether they count only direct response or add lost business, modelled reputational damage and staff time at salary.
How should a calculator be read?
Find the input that moves the answer most, decide whether you believe that number, and treat everything else as decoration. If that input is not visible or not adjustable, the tool is an argument rather than a model.
Is return on investment the right frame for security?
Rarely, because the return is an absence and absences cannot be measured. Cost of exposure works better: what would this specific failure cost, how likely is it, and what does removing it cost. That reframing keeps the argument about things somebody can actually estimate.
What do you do when you have no data?
Estimate ranges rather than points, state them, and act on the ones where the range does not change the decision. Most choices are insensitive to precision — you rarely need to know whether something costs £200,000 or £600,000 to know it costs more than the fix.
What makes a calculator trustworthy?
Every input visible and adjustable, the formula stated, the assumptions named, and the same inputs always producing the same answer. Anything with hidden fields, undisclosed multipliers or randomised outputs is presenting an opinion with a decimal point.
Should these numbers go in a board paper?
With the range and the driving assumption alongside, yes. A single figure invites the question of where it came from, and the honest answer is a better conversation than the figure was. Present the range and name the input that decides it.
Do the tools on this site need JavaScript?
No. Each one serves its full argument as text and tables, and the interaction adds a shortcut rather than the content. Anything that only works with scripting is unavailable to a reader, a search engine and an archive at the same time.
Are any of these figures measurements of your organisation?
None of them. Each tool states what it assumes, and several are explicitly illustrative of a shape rather than derived from a survey. They are instruments for thinking about a problem, not for reporting on your estate.
How do you build one that is worth using?
Start from the decision it should inform, expose the input that dominates, refuse to add fields that do not change the answer, and write down what you assumed where the reader can see it. Most calculators fail on the last of those.