1. Estimate annual probability
Enter the chance of at least one material ransomware incident during a year.
2. Add downtime impact
Include lost contribution, idle labor, service credits, and operational disruption.
3. Enter response costs
Add forensics, restoration, external specialists, and internal recovery labor.
4. Include other loss categories
Enter payment exposure, data or business loss, and legal or notification costs.
5. Review expected loss
Use annualized expected loss to compare risk-reduction investments with a consistent baseline.