Per health record breached
The most expensive record type in the model. PII runs $180, payment cards $295, credentials $150 — and it costs the same whether the breach happens at your office or at your vendor's. IBM Cost of a Data Breach 2024.
List the third parties that hold your records — payroll, billing, EHR, CRM, the backup provider nobody thinks about — and see what a breach at each one would cost you. Priced from published per-record breach costs, the same figures our paid platform uses. It will not tell you how likely a breach is, and it will explain why not.
The most expensive record type in the model. PII runs $180, payment cards $295, credentials $150 — and it costs the same whether the breach happens at your office or at your vendor's. IBM Cost of a Data Breach 2024.
A vendor breach costs you what you handed them — not the value of everything that vendor holds for everyone. Pricing anything else inflates the number and measures somebody else's loss.
No letter grade, no risk percentage, no traffic light. Those require observing a vendor's live exposed systems. A form that returns one the moment you type a company name invented it.
What a breach costs comes from record counts and published per-record costs: both are things you can supply and we can cite. How often it happens depends on the vendor's live internet-facing systems and the exploitability of what is running on them. That is a measurement taken against a specific vendor on a specific day, not something inferable from a name in a form field.
This page runs entirely in your browser. It performs no lookup, no scan and no reconnaissance against any company you name, and nothing you type is transmitted anywhere. A public page that probed arbitrary third parties on demand would be a service for attackers as much as for buyers.
Organisations tend to discover that one supplier carries most of their third-party exposure. That changes the response: a single vendor incident stops being a partial loss and becomes most of the loss. The calculator surfaces that share as soon as you have more than one vendor priced.
The half this page deliberately leaves blank.
We observe each vendor's internet-facing surface passively, take the vulnerabilities actually present on it, and convert their EPSS scores — the empirically calibrated probability that a given vulnerability sees exploitation — into an annual rate. Presence in CISA's Known Exploited Vulnerabilities catalogue raises our confidence in the estimate; it never inflates the number.
Frequency and magnitude combine into three figures rather than one: the chance of a loss this year, what it costs in a year where one happens, and the expected annual loss you would hold a reserve against. Every input carries a citation, and anything we could not observe is reported as a stated gap rather than quietly assumed.