Guides

The reasoning behind the numbers — how breach cost and risk are modeled, and how to read the calculators.

How data breach cost is calculatedThe model behind every estimate: fixed plus variable cost, the five IBM cost components, and why breach cost is not linear in the number of records.The true cost of a data breach for a small businessWhy small businesses face a higher cost per record, how fixed and variable costs split, and what an SMB breach really adds up to.US breach notification laws: what they cost youThe 50-state patchwork, attorney-general thresholds and deadlines, and the per-record cost of notifying affected people.GDPR, HIPAA, CCPA & PCI: which penalties apply to an SMBWhich regulation covers which data, the published penalty thresholds, and how maximum exposure differs from what an SMB is likely to face. Informational.Annual Loss Expectancy: putting a dollar figure on breach riskALE = ARO × SLE: how to estimate the rate of occurrence and single-loss expectancy, and the limits of the model.Does security spending pay off? The ROI of controlsHow to weigh the cost of a control against the breach loss it avoids, using IBM cost-mitigation factors and your own ALE.Why faster detection saves money: the cost of dwell timeThe IBM finding that breaches taking over 200 days to contain cost about $1.88M more — and why detection speed is one of the highest-ROI investments.Is the average cost of a data breach misleading?Why the headline average breach cost misleads small firms: how a skewed mean, the median and per-record figures differ, and which number to plan with.Quantitative vs qualitative cyber risk assessmentWhy a red-amber-green risk matrix stalls at budget time, how quantitative analysis differs, and how to turn an existing risk register into dollar figures.How much should a small business spend on cybersecurity?Not a percentage of revenue: build a defensible security budget from the obligations you cannot decline, your expected annual loss and control-level return.What CCPA compliance actually costs a small businessWhat it costs a small business to comply with the CCPA: applicability thresholds, the eight cost lines, a worked first-year total and the annual run-rate.What PCI DSS compliance actually costs a small merchantWhat PCI DSS compliance costs a small merchant: how your questionnaire sets the bill, the annual cost lines, and why cutting scope beats haggling on price.CCPA fines and fees: what a violation costsWhat a CCPA violation costs: the $2,500 and $7,500 administrative penalties, statutory damages of $100-$750 per consumer, and how violations get counted.How to estimate ARO when you have no incident dataHow to estimate the annual rate of occurrence for an ALE calculation with no breach history: sector base rates, defensible multipliers and a reported band.