{
  "slug": "cyber-liability-limit-sizing",
  "title": "Cyber Liability Limit Sizing Calculator",
  "heading": "Cyber Insurance Limit Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/cyber-liability-limit-sizing",
  "summary": "Size cyber liability limits from records held, breach cost benchmarks, and business interruption.",
  "description": "Cyber liability limits should be sized around a realistic worst-case breach scenario, not a round number pulled from a peer's policy. The core driver is the number of sensitive records you hold, multiplied by a per-record notification and remediation cost benchmark that industry breach reports put around $150–$180 per record on average, though healthcare and financial records run higher. On top of that, you need to add ransomware extortion exposure, business interruption from system downtime, and regulatory fine exposure if you handle regulated data like health or payment card information. This calculator combines those pieces into a total exposure estimate and compares it to a chosen limit so you can see your coverage gap in dollar terms.",
  "formula": "Breach cost = records × cost per record; total exposure = breach cost + ransom exposure + downtime cost + regulatory exposure; gap = total exposure − chosen limit.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=cyber-liability-limit-sizing",
  "inputs": [
    {
      "id": "records",
      "label": "Sensitive records held",
      "kind": "number",
      "hint": null,
      "default": 50000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "costPerRecord",
      "label": "Cost per record (notification, credit monitoring, legal)",
      "kind": "number",
      "hint": null,
      "default": 165,
      "unit": "$",
      "min": 0,
      "max": null
    },
    {
      "id": "ransomExposure",
      "label": "Ransomware extortion exposure",
      "kind": "number",
      "hint": null,
      "default": 250000,
      "unit": "$",
      "min": 0,
      "max": null
    },
    {
      "id": "downtimeDays",
      "label": "Expected downtime from an incident",
      "kind": "number",
      "hint": null,
      "default": 10,
      "unit": "days",
      "min": 0,
      "max": null
    },
    {
      "id": "dailyRevenueLoss",
      "label": "Daily revenue loss during downtime",
      "kind": "number",
      "hint": null,
      "default": 8000,
      "unit": "$",
      "min": 0,
      "max": null
    },
    {
      "id": "regulatoryExposure",
      "label": "Regulatory fine exposure (HIPAA, PCI, state law)",
      "kind": "number",
      "hint": null,
      "default": 100000,
      "unit": "$",
      "min": 0,
      "max": null
    },
    {
      "id": "chosenLimit",
      "label": "Cyber policy limit you're considering",
      "kind": "number",
      "hint": null,
      "default": 1000000,
      "unit": "$",
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "totalExposure",
      "label": "Total estimated breach exposure",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "breachCost",
      "label": "Notification & remediation cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "downtime",
      "label": "Business interruption from downtime",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "gap",
      "label": "Coverage gap vs. chosen limit",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "coverageRatio",
      "label": "Limit as % of total exposure",
      "format": "percent",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Sensitive records held: 50000",
      "Cost per record (notification, credit monitoring, legal): 165 $",
      "Ransomware extortion exposure: 250000 $",
      "Expected downtime from an incident: 10 days",
      "Daily revenue loss during downtime: 8000 $",
      "Regulatory fine exposure (HIPAA, PCI, state law): 100000 $",
      "Cyber policy limit you're considering: 1000000 $"
    ],
    "outputs": [
      "Total estimated breach exposure: $8,680,000",
      "Notification & remediation cost: $8,250,000",
      "Business interruption from downtime: $80,000",
      "Coverage gap vs. chosen limit: $7,680,000",
      "Limit as % of total exposure: 12%"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter sensitive records held.",
      "Enter cost per record (notification, credit monitoring, legal) ($).",
      "Enter ransomware extortion exposure ($).",
      "Enter expected downtime from an incident (days).",
      "Enter daily revenue loss during downtime ($).",
      "Enter regulatory fine exposure (hipaa, pci, state law) ($).",
      "Enter cyber policy limit you're considering ($).",
      "Read your total estimated breach exposure on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "records": 30000,
        "costPerRecord": 100,
        "ransomExposure": 150000,
        "downtimeDays": 6,
        "dailyRevenueLoss": 5000,
        "regulatoryExposure": 60000,
        "chosenLimit": 600000
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "records": 50000,
        "costPerRecord": 165,
        "ransomExposure": 250000,
        "downtimeDays": 10,
        "dailyRevenueLoss": 8000,
        "regulatoryExposure": 100000,
        "chosenLimit": 1000000
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "records": 80000,
        "costPerRecord": 265,
        "ransomExposure": 400000,
        "downtimeDays": 16,
        "dailyRevenueLoss": 13000,
        "regulatoryExposure": 160000,
        "chosenLimit": 1600000
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Where does the $150–$180 per-record cost benchmark come from?",
      "a": "It's a widely cited industry average combining forensic investigation, customer notification, credit monitoring, legal fees, and call center costs per compromised record, drawn from annual breach cost studies. Healthcare records tend to cost more per record due to regulatory complexity, while simple email/password breaches cost less, so adjust the input if your data sensitivity differs from the average."
    },
    {
      "q": "Should ransomware extortion be modeled separately from the per-record breach cost?",
      "a": "Yes. A pure ransomware event may not involve any data exfiltration or notification obligation at all — it's a business disruption and extortion payment problem, not a records-breach problem. Modeling it as its own line item avoids double-counting or under-counting depending on which type of incident actually occurs."
    },
    {
      "q": "Do I need cyber insurance if I use cloud vendors like AWS or Google Workspace?",
      "a": "Yes. Your cloud vendor's infrastructure security doesn't cover your liability for a breach of data you control, misconfigured access, phishing-based account compromise, or business interruption from your own systems being knocked offline. Vendor contracts almost always disclaim liability for your data handling practices."
    },
    {
      "q": "What's typically excluded from cyber policies?",
      "a": "Prior known incidents, acts of war (a growing point of dispute after major state-sponsored attacks), and betterment costs to upgrade security beyond restoring pre-incident state are common exclusions. Some policies also sublimit ransomware payments separately from the main limit, so read the ransomware sublimit carefully against your total exposure estimate."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/business-interruption-coverage",
    "https://www.revenuelab.fyi/toolbox/commercial-general-liability-rate"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Cyber Liability Limit Sizing Calculator (https://www.revenuelab.fyi/toolbox/cyber-liability-limit-sizing)"
}