1. Enter message volume
Use the number of suspicious or confirmed phishing messages that reach users in a typical month.
2. Set the interaction rate
Estimate the share of recipients who click, reply, open an attachment, or otherwise engage.
3. Set the compromise rate
Enter the share of interactions that are expected to produce an account or device compromise.
4. Add the average loss
Include the direct and operational cost you expect from one successful compromise.
5. Choose the period and control effect
Set the number of months and the estimated percentage reduction delivered by current controls.
6. Review exposure
Compare gross exposure, residual exposure, expected compromises, and avoided exposure.