{
  "slug": "vendor-risk-exposure",
  "title": "Vendor Risk Exposure Calculator",
  "heading": "Third-Party Vendor Risk Exposure Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/vendor-risk-exposure",
  "summary": "Score and dollar-weight vendor risk from data access, criticality, and control maturity.",
  "description": "Third-party and supply chain incidents (think SolarWinds, MOVEit, or a compromised managed service provider) now account for a large and growing share of major breaches, yet most vendor risk programs still rely on a static questionnaire filed away and never revisited. This calculator produces a composite risk score by weighting data sensitivity the vendor can access, how critical the vendor is to your operations, and their control maturity (based on things like whether they hold a current SOC 2 report, use MFA, and have cyber insurance), then converts that score into an estimated annual exposure dollar figure by applying it against your typical breach cost. Use it to prioritize which vendors need deeper due diligence, contractual security requirements, or continuous monitoring versus which represent immaterial risk and don't need the same scrutiny, since treating every vendor identically wastes review capacity on low-risk relationships while under-scrutinizing the handful that actually carry your crown-jewel data.",
  "formula": "Risk score = (data sensitivity × 0.4 + operational criticality × 0.35 + (10 − control maturity) × 0.25) on a 1-10 scale. Estimated exposure = base breach cost × (risk score ÷ 10) × access scope factor.",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=vendor-risk-exposure",
  "inputs": [
    {
      "id": "dataSensitivity",
      "label": "Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial)",
      "kind": "number",
      "hint": null,
      "default": 7,
      "unit": null,
      "min": 1,
      "max": 10
    },
    {
      "id": "criticality",
      "label": "Operational criticality if vendor is disrupted (1-10)",
      "kind": "number",
      "hint": null,
      "default": 6,
      "unit": null,
      "min": 1,
      "max": 10
    },
    {
      "id": "controlMaturity",
      "label": "Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance)",
      "kind": "number",
      "hint": null,
      "default": 5,
      "unit": null,
      "min": 1,
      "max": 10
    },
    {
      "id": "baseBreachCost",
      "label": "Typical breach cost for your org",
      "kind": "number",
      "hint": null,
      "default": 2000000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "accessScope",
      "label": "Share of your data/systems vendor can reach",
      "kind": "number",
      "hint": null,
      "default": 25,
      "unit": null,
      "min": 1,
      "max": 100
    }
  ],
  "outputs": [
    {
      "id": "exposure",
      "label": "Estimated annual risk exposure",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "riskScore",
      "label": "Composite risk score (1-10)",
      "format": "decimal",
      "hint": null,
      "primary": false
    },
    {
      "id": "tier",
      "label": "Recommended oversight tier",
      "format": "raw",
      "hint": null,
      "primary": false
    },
    {
      "id": "sensitivity",
      "label": "Data sensitivity input",
      "format": "number",
      "hint": null,
      "primary": false
    },
    {
      "id": "maturity",
      "label": "Control maturity input",
      "format": "number",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial): 7",
      "Operational criticality if vendor is disrupted (1-10): 6",
      "Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance): 5",
      "Typical breach cost for your org: 2000000",
      "Share of your data/systems vendor can reach: 25"
    ],
    "outputs": [
      "Estimated annual risk exposure: $307,500",
      "Composite risk score (1-10): 6.2",
      "Recommended oversight tier: High — annual review + contractual controls",
      "Data sensitivity input: 7",
      "Control maturity input: 5"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter data sensitivity vendor can access (1=none, 10=crown jewel pii/financial).",
      "Enter operational criticality if vendor is disrupted (1-10).",
      "Enter vendor security control maturity (1=poor, 10=excellent — soc2, mfa, insurance).",
      "Enter typical breach cost for your org.",
      "Enter share of your data/systems vendor can reach.",
      "Read your estimated annual risk exposure on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "dataSensitivity": 4,
        "criticality": 4,
        "controlMaturity": 3,
        "baseBreachCost": 1200000,
        "accessScope": 15
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "dataSensitivity": 7,
        "criticality": 6,
        "controlMaturity": 5,
        "baseBreachCost": 2000000,
        "accessScope": 25
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "dataSensitivity": 10,
        "criticality": 10,
        "controlMaturity": 8,
        "baseBreachCost": 3200000,
        "accessScope": 40
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "What counts as 'control maturity' evidence?",
      "a": "A current SOC 2 Type II report (not just Type I, which only tests design, not operating effectiveness), evidence of MFA enforcement, a named security contact, incident notification commitments in the contract, and active cyber insurance coverage are the baseline items most vendor risk questionnaires should verify rather than just ask about."
    },
    {
      "q": "Why does access scope matter separately from data sensitivity?",
      "a": "A vendor could have access to extremely sensitive data but only for a narrow slice of your environment (like a benefits provider seeing SSNs for HR only), versus a vendor with broad infrastructure access but lower per-record sensitivity (like an MSP with admin rights across your whole network). Both create real risk, but the calculation needs to separately weight how much of your environment is actually reachable."
    },
    {
      "q": "How often should high-risk vendors be reassessed?",
      "a": "Annually at minimum for critical/high-tier vendors, with immediate reassessment triggered by any vendor security incident (even one that doesn't touch your data directly), significant vendor infrastructure changes, or contract renewal, since control maturity can degrade between review cycles without any visible warning sign."
    },
    {
      "q": "Should this replace a formal vendor risk questionnaire?",
      "a": "No, it's a prioritization and budget-justification tool that sits on top of your questionnaire process, helping you decide where to spend limited due-diligence time and whether to require additional contractual security terms, cyber insurance minimums, or right-to-audit clauses for your highest-exposure vendors."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy",
    "https://www.revenuelab.fyi/toolbox/breach-cost-per-record",
    "https://www.revenuelab.fyi/toolbox/pen-test-vs-bug-bounty"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Vendor Risk Exposure Calculator (https://www.revenuelab.fyi/toolbox/vendor-risk-exposure)"
}