Skip to main content

Cost Calculator - Data Breach

Estimate the total cost of a corporate data breach using IBM/CLUSIT 2024 model. Enter the number of records breached, industry and fixed costs to get an estimate and reference to GDPR article 83 sanction.

Configure

Number of potentially compromised personal data records

Forensic investigation, notification, incident response, crisis PR

Skip calculation of GDPR fine (Article 83) by entering 0

Result

No results

Enter values and press the button to calculate.

Frequently Asked Questions

How much does a typical data breach cost small and medium-sized enterprises (SMEs) in Italy?

According to the CLUSIT Report 2024 and IBM Cost of a Data Breach 2024, the global average cost of a data breach reached $4.88 million. For European SMEs, costs are proportionally lower but still significant: between €50,000 and €500,000 for companies with fewer than 500 employees. The most economically affected sectors are healthcare, finance, and technology.

What costs are included in the IBM/CLUSIT model for a data breach?

Model CLUSIT/IBM distinguishes between variable costs (proportional to the records violated: detection, forensic investigation, notification, loss of clients) and fixed costs (immediate response to the incident, crisis PR, legal consulting). These are supplemented by indirect costs such as reputational damage, long-term loss of clients, and increased insurance premiums.

What are the GDPR sanctions for a data breach?

GDPR (EU Regulation 2016/679) prescribes two levels of sanctions: Article 83, Part 4 up to €10 million or 2% global turnover (technical violations); Article 83, Part 5 up to €20 million or 4% global turnover (main violations, such as non-notification). This tool calculates the theoretical maximum of Article 83, Part 5 as a reference. Effective sanctions vary based on severity, cooperation, and preventive measures taken.

How many hours before notification is required for a GDPR data breach to the relevant authority?

Article 33 of the GDPR requires notification to the Data Protection Authority within 72 hours of discovering a data breach, unless it is unlikely to pose a risk to individuals' rights. In Italy, the Data Protection Authority is the Garante per la Protezione dei Dati Personali (garanteprivacy.it). Failure to notify within the prescribed timeframe increases penalties.

How can you reduce the cost of a potential data breach?

IBM 2024 reports that organizations with AI and security automation save an average of $2.22 million per breach. The most effective measures include: regular incident response plan testing, employee training (35% of breaches start from phishing), sensitive data encryption, network segmentation, continuous monitoring (SIEM/SOC), and verified offline backups.

How is it used?

  1. Insert number of records violated

    Indicate the estimated number of records (personal data) that may be compromised in an incident. Typical data breaches for small businesses involve between 1,000 and 100,000 records.

  2. Select your business sector

    The sector determines the average cost per violated record according to the IBM/CLUSIT 2024 model. Health has the highest costs (€150/record), education the lowest (€60/record).

  3. Add estimated fixed costs

    Insert fixed anticipated costs: forensic investigation, notification of interested parties, activation of the response team, crisis PR. Typically for SMEs between €10,000 and €100,000.

  4. Read GDPR Estimate and Reference

    The result shows estimated total cost, range of variability (-30% to +50%), and if revenue is entered, the maximum theoretical GDPR fine under article 83 as an informative measure.

What is a data breach and how to estimate its business cost?

A data breach is a security violation that involves the unauthorized disclosure, destruction, loss or modification of personal data. According to GDPR (EU Regulation 2016/679 art.4 par.12), any unauthorized access to personal data - even accidental - constitutes a data breach and triggers precise regulatory obligations, including notification to the Data Protection Authority within 72 hours.

The cost estimation model used by this tool is based on the IBM Cost of a Data Breach Report 2024 and the CLUSIT ICT Security Report in Italy 2024. The formula is: total cost = (number of records × average cost per record in the sector) + fixed costs. Record costs vary significantly by sector: healthcare reaches €150/record, manufacturing drops to €75/record, reflecting the varying sensitivity of data and complexity of regulations.

Fixed costs cover immediate response activities to the incident: forensic investigation (€5,000–€50,000 per PMI), notification of interested parties and the Guarantor, activation of the CSIRT team, crisis communication, and legal support. These costs are often under-estimated by organizations without a predefined response plan.

The GDPR prescribes administrative sanctions proportionate to the severity of the breach: Article 83, paragraph 5 allows for up to €20 million or 4% of global annual turnover (the highest value). This tool calculates the theoretical maximum threshold as a reference - actual fines imposed by the Italian Data Protection Authority depend on various factors, including cooperation, timeliness of notification, and preventive measures taken.

Range of variability (-30%/+50%) reflects the inherent uncertainty of pre-estimate predictions: organizations with tested response plans and data encryption tend to have real costs in the lower range; unprepared organizations, in the higher range or beyond. IBM 2024 estimates that the average cost of a breach reported within less than 200 days is approximately $1.3 million lower than those reported above this threshold.

Practical example

  1. Company: Retail SME with 50 employees, annual turnover €2 million.
  2. Incident: Ransomware exposing 5,000 customer records (name, email, address, order data)
  3. Variable cost: 5,000 records x €85/record (retail sector) = €425,000
  4. Fixed Costs: €30,000 (Forensic Investigation €15,000 + Notification €5,000 + Legal Support €10,000)
  5. Estimated Total Cost: $455,000 (Range: $318,500 - $682,500)
  6. GDPR fine cap at §83 max: min($20M, 4% of $2M) = $80,000 (only reference)
Estimated Total Cost455.000 €

Vocabulary Dictionary

Security Incident
Violation of security that involves accidental or unauthorized destruction, loss, modification, disclosure, or unauthorized access to personal data transmitted, stored, or otherwise processed (GDPR Article 4, Section 12).
Cost per track
Average cost sustained by the organization for each personally identifiable data breach, including detection, investigation, notification, loss of clients and reputational damage. Varies significantly by sector (IBM 2024).
General Data Protection Regulation Article 83
Article of EU Regulation 2016/679 defining administrative pecuniary sanctions. Paragraph 4: up to €10M or 2% of turnover. Paragraph 5: up to €20M or 4% of turnover (for main violations such as non-notification or lack of adequate measures).
Notification in 72 hours
GDPR Art.33: The data controller must notify the Supervisor within 72 hours of discovery, unless it is highly unlikely that a risk to individuals' rights and freedoms exists. Failure to comply increases penalties.
Cost Estimation Tool for IBM Cloud Services and On-Premises Environments
Cost Estimation Framework for Data Breach Based on IBM Cost of a Data Breach Report (Annual, Ponemon Institute Methodology) Adapted to the Italian Context by CLUSIT (Italian Association for Information Security). Confidence: Medium (Market Factors, Non-Regulatory).
Fixed costs of breach
Costs incurred regardless of the number of records violated: digital forensic investigation, activation of a CSIRT team, notification to affected parties and the Data Protection Authority, crisis communication, specialized legal support, any pre-emptive sanctions already imposed.

Do you need a custom analysis?

This tool is free and informative. For in-depth analysis with AI on-prem - private data, zero cloud - contact Federico.

Request a quote