Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Data Breach Cost Calculator

Estimate what a data breach could realistically cost your company. Enter your record count, sector, and the controls you already have in place to see a cost range with the assumptions spelled out.

Estimated total breach cost (range)
$0 - $0
    How we estimate. A sector-based per-record cost times your record count, plus a response and notification baseline of about $90,000, discounted for each control you have in place. The low end is a well-contained incident; the high end adds legal and regulatory exposure. Use it for planning; it excludes contract penalties, settlements and brand damage.

    Questions

    How is breach cost calculated?

    We start from a per-record cost estimate that varies by sector, multiply by the number of exposed records, add a fixed incident response and notification baseline, then apply a discount for security controls you already have in place. The result is a range, not a single number.

    Are these numbers accurate for my company?

    No estimate can be exact. The figures are reasonable industry estimates meant for planning and budgeting conversations, not a forecast. Actual costs depend on legal exposure, regulatory fines, contract penalties, and the specifics of the incident.

    What counts as a record?

    A record is one individual whose personal data you hold: a customer, patient, user, or employee. If a single person has multiple data points, that is still one record for this estimate.

    How do controls reduce the estimate?

    Controls like encryption, an incident response plan, MFA, and a tested backup strategy are associated with lower breach costs because they reduce blast radius and recovery time. We apply a modest discount per control to reflect this.

    Is this calculator free?

    Yes, it is completely free with no signup. If you want a tailored risk and cost analysis, book a call with our team.

    Not ready for a call yet?

    Get the security playbook

    A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Cyber Insurance Readiness

    Get the controls in place to be insurable and lower premiums.

    Explore Cyber Insurance Readiness →

    Worried about a breach?

    We help teams reduce breach exposure and build incident response capability before they need it. Get a real risk picture from a CVE researcher, not a calculator. Not sure where to start? Talk to a fractional CISO or look at ongoing vulnerability management to close gaps before they turn into a breach.

    See incident response Book a call

    Want the full picture?

    This gives you the shape of the problem. traztech Workspace walks you through every control of whichever frameworks apply to you, in plain English, with an evidence register, policy templates, a risk register, vendor questionnaires, and an audit-readiness score. Start a free assessment and walk every control.

    Start your free assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.