The principle: expected loss
You cannot predict whether an incident will happen, but you can estimate its average expected cost over a year. That is the product of two factors: how much an incident costs, and how likely it is to occur.
This is exactly the method used in risk management (the ISO 27005 standard) and by cyber insurers when pricing a policy.
The two values you adjust
1. Annual probability of an incident
default: 5%The probability that a data incident occurs during the year when internal documents flow out to third-party services you do not control: consumer AI tools used without any framework, personal cloud subscriptions, attachments sent to free tools. This is the “shadow IT” risk: ungoverned computing.
5% is one chance in twenty per year. A deliberately cautious assumption: public bodies are prime targets for ransomware, and real incidents there are frequent. You can raise or lower this value according to your own judgement.
2. Sovereign reduction
default: 80%The share of that risk which the sovereign architecture eliminates, thanks to its structural protections:
- ✓ Data no longer leaves for third-party services you do not control
- ✓ Daily wipe of the processing servers (nothing persists)
- ✓ Private encrypted tunnel, hosting in the European Union
- ✓ No exposure to the CLOUD Act or to a vendor's telemetry
80% means that 20% of residual risk remains: no architecture cancels risk entirely (human error, phishing, and so on). We never claim to reach 100%.
A worked example, step by step
With the default values of the simulator:
| Average cost of a data incident | €500,000 |
| × Annual probability of an incident | 5% |
| = Annual exposure (without a sovereign solution) | €25,000 / year |
| × Sovereign reduction | 80% |
| = Data risk avoided | €20,000 / year |
This “risk avoided” (€20,000 per year in this example) is added to the value of the time saved by your users to make up the overall ROI displayed by the simulator. It is the translation into euros of a benefit that is usually intangible: security.
Deliberately cautious assumptions
Our assumed incident cost (€500,000) is seven times lower than the average observed in France, which the IBM 2025 report puts at €3.59 million. We would rather understate the benefit than oversell it: if you replace our values with the market benchmarks, the return on investment only goes up.
Source: IBM Cost of a Data Breach Report 2025, average cost of a data breach in France: €3.59m.