Methodology

How we cost the data risk avoided

Putting a price on security sounds impossible. In practice, finance departments and insurers do it every day, with a simple and widely recognised method: expected annual loss. Here, in full transparency, is the reasoning behind the “Annual probability / sovereign reduction” field of our simulator.

The principle: expected loss

You cannot predict whether an incident will happen, but you can estimate its average expected cost over a year. That is the product of two factors: how much an incident costs, and how likely it is to occur.

Annual exposure = Cost of an incident × Annual probability

This is exactly the method used in risk management (the ISO 27005 standard) and by cyber insurers when pricing a policy.

The two values you adjust

1. Annual probability of an incident

default: 5%

The probability that a data incident occurs during the year when internal documents flow out to third-party services you do not control: consumer AI tools used without any framework, personal cloud subscriptions, attachments sent to free tools. This is the “shadow IT” risk: ungoverned computing.

5% is one chance in twenty per year. A deliberately cautious assumption: public bodies are prime targets for ransomware, and real incidents there are frequent. You can raise or lower this value according to your own judgement.

2. Sovereign reduction

default: 80%

The share of that risk which the sovereign architecture eliminates, thanks to its structural protections:

  • Data no longer leaves for third-party services you do not control
  • Daily wipe of the processing servers (nothing persists)
  • Private encrypted tunnel, hosting in the European Union
  • No exposure to the CLOUD Act or to a vendor's telemetry

80% means that 20% of residual risk remains: no architecture cancels risk entirely (human error, phishing, and so on). We never claim to reach 100%.

A worked example, step by step

With the default values of the simulator:

Average cost of a data incident€500,000
× Annual probability of an incident5%
= Annual exposure (without a sovereign solution)€25,000 / year
× Sovereign reduction80%
= Data risk avoided€20,000 / year

This “risk avoided” (€20,000 per year in this example) is added to the value of the time saved by your users to make up the overall ROI displayed by the simulator. It is the translation into euros of a benefit that is usually intangible: security.

Deliberately cautious assumptions

Our assumed incident cost (€500,000) is seven times lower than the average observed in France, which the IBM 2025 report puts at €3.59 million. We would rather understate the benefit than oversell it: if you replace our values with the market benchmarks, the return on investment only goes up.

Source: IBM Cost of a Data Breach Report 2025, average cost of a data breach in France: €3.59m.

Back to the simulator