
Rex says
Money math without the spreadsheet headache. Plug in your numbers and I'll show you exactly where the dollars land.
Try a scenario
Click to load — tweak from there.Inputs
Result
Total estimated breach exposure
$8,680,000
Notification & remediation cost
$8,250,000
Business interruption from downtime
$80,000
Coverage gap vs. chosen limit
$7,680,000
Limit as % of total exposure
12%

Psst — share this and help Rex grow
One click, a permanent link with your numbers baked in.
How to use this
- 1Enter sensitive records held.
- 2Enter cost per record (notification, credit monitoring, legal) ($).
- 3Enter ransomware extortion exposure ($).
- 4Enter expected downtime from an incident (days).
- 5Enter daily revenue loss during downtime ($).
- 6Enter regulatory fine exposure (hipaa, pci, state law) ($).
- 7Enter cyber policy limit you're considering ($).
- 8Read your total estimated breach exposure on the right — it updates as you type.
- 9Hit Share to keep the scenario or send it to someone.
About this calculator
Cyber liability limits should be sized around a realistic worst-case breach scenario, not a round number pulled from a peer's policy. The core driver is the number of sensitive records you hold, multiplied by a per-record notification and remediation cost benchmark that industry breach reports put around $150–$180 per record on average, though healthcare and financial records run higher. On top of that, you need to add ransomware extortion exposure, business interruption from system downtime, and regulatory fine exposure if you handle regulated data like health or payment card information. This calculator combines those pieces into a total exposure estimate and compares it to a chosen limit so you can see your coverage gap in dollar terms.
Worked example
Using the values the calculator loads with:
Inputs
- Sensitive records held: 50000
- Cost per record (notification, credit monitoring, legal): 165 $
- Ransomware extortion exposure: 250000 $
- Expected downtime from an incident: 10 days
- Daily revenue loss during downtime: 8000 $
- Regulatory fine exposure (HIPAA, PCI, state law): 100000 $
- Cyber policy limit you're considering: 1000000 $
Results
- Total estimated breach exposure: $8,680,000
- Notification & remediation cost: $8,250,000
- Business interruption from downtime: $80,000
- Coverage gap vs. chosen limit: $7,680,000
- Limit as % of total exposure: 12%
What each field means
Inputs
- Sensitive records held
- The sensitive records held used in the calculation. Starts at 50000 so you have a working example on load.
- Cost per record (notification, credit monitoring, legal) ($)
- The cost per record (notification, credit monitoring, legal) used in the calculation, measured in $. Starts at 165 $ so you have a working example on load.
- Ransomware extortion exposure ($)
- The ransomware extortion exposure used in the calculation, measured in $. Starts at 250000 $ so you have a working example on load.
- Expected downtime from an incident (days)
- The expected downtime from an incident used in the calculation, measured in days. Starts at 10 days so you have a working example on load.
- Daily revenue loss during downtime ($)
- The daily revenue loss during downtime used in the calculation, measured in $. Starts at 8000 $ so you have a working example on load.
- Regulatory fine exposure (HIPAA, PCI, state law) ($)
- The regulatory fine exposure (hipaa, pci, state law) used in the calculation, measured in $. Starts at 100000 $ so you have a working example on load.
- Cyber policy limit you're considering ($)
- The cyber policy limit you're considering used in the calculation, measured in $. Starts at 1000000 $ so you have a working example on load.
Results
- Total estimated breach exposure
- Returned as a money amount in US dollars and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Notification & remediation cost
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Business interruption from downtime
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Coverage gap vs. chosen limit
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Limit as % of total exposure
- Returned as a percentage. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
FAQ
Where does the $150–$180 per-record cost benchmark come from?
It's a widely cited industry average combining forensic investigation, customer notification, credit monitoring, legal fees, and call center costs per compromised record, drawn from annual breach cost studies. Healthcare records tend to cost more per record due to regulatory complexity, while simple email/password breaches cost less, so adjust the input if your data sensitivity differs from the average.
Should ransomware extortion be modeled separately from the per-record breach cost?
Yes. A pure ransomware event may not involve any data exfiltration or notification obligation at all — it's a business disruption and extortion payment problem, not a records-breach problem. Modeling it as its own line item avoids double-counting or under-counting depending on which type of incident actually occurs.
Do I need cyber insurance if I use cloud vendors like AWS or Google Workspace?
Yes. Your cloud vendor's infrastructure security doesn't cover your liability for a breach of data you control, misconfigured access, phishing-based account compromise, or business interruption from your own systems being knocked offline. Vendor contracts almost always disclaim liability for your data handling practices.
What's typically excluded from cyber policies?
Prior known incidents, acts of war (a growing point of dispute after major state-sponsored attacks), and betterment costs to upgrade security beyond restoring pre-incident state are common exclusions. Some policies also sublimit ransomware payments separately from the main limit, so read the ransomware sublimit carefully against your total exposure estimate.
Accuracy and limitations
- Results are estimates before tax, fees, and inflation unless an input explicitly covers them.
- Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.
- This is educational maths, not financial advice. Check anything contractual with the lender or your accountant.
Related tools
Cite this calculator
Writing about this topic? Grab a citation — every link helps keep these tools free.
RevenueLab. (2026). Cyber Liability Limit Sizing Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/cyber-liability-limit-sizing
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/cyber-liability-limit-sizing" target="_blank" rel="noopener">Cyber Liability Limit Sizing Calculator — RevenueLab</a> (2026).</p>
Source: [Cyber Liability Limit Sizing Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/cyber-liability-limit-sizing) (2026).
