Phishing Risk Exposure Estimator

This estimator converts a phishing volume, user interaction rate, compromise rate, and average incident loss into an expected monetary exposure for a selected period. It is useful for security leaders, risk owners, and finance teams that need a transparent scenario rather than a generic industry benchmark.

The result separates gross exposure from the portion remaining after current controls. That distinction can support risk-register entries, control prioritization, and comparisons between awareness, filtering, identity, and response investments. Because the inputs are assumptions, the output is a planning estimate rather than a prediction of a specific breach.

Enter your assumptions

messages
%
%
USD
months
%
Result
Residual annual exposure
Gross expected exposure
Expected compromises
Exposure avoided by controls

1. Enter message volume

Use the number of suspicious or confirmed phishing messages that reach users in a typical month.

2. Set the interaction rate

Estimate the share of recipients who click, reply, open an attachment, or otherwise engage.

3. Set the compromise rate

Enter the share of interactions that are expected to produce an account or device compromise.

4. Add the average loss

Include the direct and operational cost you expect from one successful compromise.

5. Choose the period and control effect

Set the number of months and the estimated percentage reduction delivered by current controls.

6. Review exposure

Compare gross exposure, residual exposure, expected compromises, and avoided exposure.

Expected compromises = Messages × Months × Interaction rate × Compromise rate Gross exposure = Expected compromises × Average loss Residual exposure = Gross exposure × (1 − Control reduction)

Rates are entered as percentages and converted to decimals. The model assumes each successful compromise has the same average loss and that event probability remains stable during the selected period.

What the result means

Use the result as a scenario-based planning estimate. Compare several plausible inputs rather than relying on one point value.

This calculator does not replace a formal risk assessment, incident analysis, legal advice, or financial advice.

Given: 1,200 messages per month, a 3% interaction rate, an 8% compromise rate, an average loss of $7,500, 12 months, and 35% control reduction.

Calculation: 1,200 × 12 × 0.03 × 0.08 = 34.56 expected compromises. Gross exposure = 34.56 × $7,500 = $259,200. Residual exposure = $259,200 × 0.65 = $168,480.

Result: Estimated residual annual exposure is $168,480.

What does residual exposure represent?

It is the expected loss left after applying the risk reduction attributed to current controls. It is not a guaranteed loss or a maximum-loss estimate.

Should message volume include blocked email?

Use the population that matches your decision. For user-focused exposure, count messages that reach users; for an email-gateway scenario, include the broader volume and adjust rates accordingly.

How should I estimate average loss?

Use internal incident records where possible and include costs relevant to your organization, such as investigation, recovery, downtime, fraud, and notification.

Can I use this for a single campaign?

Yes. Set the message volume to the campaign size and the assessment period to one month, then interpret the result as a campaign scenario.

How is this different from expected loss?

This page emphasizes exposure before and after controls. An expected-loss estimator may focus more narrowly on incident frequency and loss severity without explicitly showing control reduction.