
Rex says
Money math without the spreadsheet headache. Plug in your numbers and I'll show you exactly where the dollars land.
Try a scenario
Click to load — tweak from there.Inputs
Result
Estimated annual risk exposure
$307,500
Composite risk score (1-10)
6.2
Recommended oversight tier
High — annual review + contractual controls
Data sensitivity input
7
Control maturity input
5

Psst — share this and help Rex grow
One click, a permanent link with your numbers baked in.
How to use this
- 1Enter data sensitivity vendor can access (1=none, 10=crown jewel pii/financial).
- 2Enter operational criticality if vendor is disrupted (1-10).
- 3Enter vendor security control maturity (1=poor, 10=excellent — soc2, mfa, insurance).
- 4Enter typical breach cost for your org.
- 5Enter share of your data/systems vendor can reach.
- 6Read your estimated annual risk exposure on the right — it updates as you type.
- 7Hit Share to keep the scenario or send it to someone.
About this calculator
Third-party and supply chain incidents (think SolarWinds, MOVEit, or a compromised managed service provider) now account for a large and growing share of major breaches, yet most vendor risk programs still rely on a static questionnaire filed away and never revisited. This calculator produces a composite risk score by weighting data sensitivity the vendor can access, how critical the vendor is to your operations, and their control maturity (based on things like whether they hold a current SOC 2 report, use MFA, and have cyber insurance), then converts that score into an estimated annual exposure dollar figure by applying it against your typical breach cost. Use it to prioritize which vendors need deeper due diligence, contractual security requirements, or continuous monitoring versus which represent immaterial risk and don't need the same scrutiny, since treating every vendor identically wastes review capacity on low-risk relationships while under-scrutinizing the handful that actually carry your crown-jewel data.
Worked example
Using the values the calculator loads with:
Inputs
- Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial): 7
- Operational criticality if vendor is disrupted (1-10): 6
- Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance): 5
- Typical breach cost for your org: 2000000
- Share of your data/systems vendor can reach: 25
Results
- Estimated annual risk exposure: $307,500
- Composite risk score (1-10): 6.2
- Recommended oversight tier: High — annual review + contractual controls
- Data sensitivity input: 7
- Control maturity input: 5
What each field means
Inputs
- Data sensitivity vendor can access (1=none, 10=crown jewel PII/financial)
- The data sensitivity vendor can access (1=none, 10=crown jewel pii/financial) used in the calculation. Starts at 7 so you have a working example on load. Accepted range: 1–10.
- Operational criticality if vendor is disrupted (1-10)
- The operational criticality if vendor is disrupted (1-10) used in the calculation. Starts at 6 so you have a working example on load. Accepted range: 1–10.
- Vendor security control maturity (1=poor, 10=excellent — SOC2, MFA, insurance)
- The vendor security control maturity (1=poor, 10=excellent — soc2, mfa, insurance) used in the calculation. Starts at 5 so you have a working example on load. Accepted range: 1–10.
- Typical breach cost for your org
- The typical breach cost for your org used in the calculation. Starts at 2000000 so you have a working example on load.
- Share of your data/systems vendor can reach
- The share of your data/systems vendor can reach used in the calculation. Starts at 25 so you have a working example on load. Accepted range: 1–100.
Results
- Estimated annual risk exposure
- Returned as a money amount in US dollars and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Composite risk score (1-10)
- Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Recommended oversight tier
- Returned as a plain value. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Data sensitivity input
- Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Control maturity input
- Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
FAQ
What counts as 'control maturity' evidence?
A current SOC 2 Type II report (not just Type I, which only tests design, not operating effectiveness), evidence of MFA enforcement, a named security contact, incident notification commitments in the contract, and active cyber insurance coverage are the baseline items most vendor risk questionnaires should verify rather than just ask about.
Why does access scope matter separately from data sensitivity?
A vendor could have access to extremely sensitive data but only for a narrow slice of your environment (like a benefits provider seeing SSNs for HR only), versus a vendor with broad infrastructure access but lower per-record sensitivity (like an MSP with admin rights across your whole network). Both create real risk, but the calculation needs to separately weight how much of your environment is actually reachable.
How often should high-risk vendors be reassessed?
Annually at minimum for critical/high-tier vendors, with immediate reassessment triggered by any vendor security incident (even one that doesn't touch your data directly), significant vendor infrastructure changes, or contract renewal, since control maturity can degrade between review cycles without any visible warning sign.
Should this replace a formal vendor risk questionnaire?
No, it's a prioritization and budget-justification tool that sits on top of your questionnaire process, helping you decide where to spend limited due-diligence time and whether to require additional contractual security terms, cyber insurance minimums, or right-to-audit clauses for your highest-exposure vendors.
Accuracy and limitations
- Results are estimates before tax, fees, and inflation unless an input explicitly covers them.
- Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.
- This is educational maths, not financial advice. Check anything contractual with the lender or your accountant.
Related tools
Annualized Loss Expectancy (ALE) Calculator
Turn asset value, exposure, and threat frequency into a yearly risk dollar figure.
Data Breach Cost Calculator
Estimate total breach cost from records exposed, industry, and detection speed.
Pen Test vs. Bug Bounty Cost Calculator
Compare annual cost and expected coverage of scheduled pen tests vs. an ongoing bounty program.
Cite this calculator
Writing about this topic? Grab a citation — every link helps keep these tools free.
RevenueLab. (2026). Vendor Risk Exposure Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/vendor-risk-exposure
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/vendor-risk-exposure" target="_blank" rel="noopener">Vendor Risk Exposure Calculator — RevenueLab</a> (2026).</p>
Source: [Vendor Risk Exposure Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/vendor-risk-exposure) (2026).
