Estimate what a data breach could cost your organization, based on figures from IBM's Cost of a Data Breach Report. Use it to weigh a breach against what prevention would cost.
IBM's averages come from breaches of 2,590 to 115,380 records, and IBM warns against multiplying a per-record cost out to large breaches. So we treat the average as a breach of about 17,300 records and assume cost grows 1.8× to 2.8× for every tenfold increase in records. That curve is our assumption; IBM doesn't publish one.
Breaches identified and contained within 200 days averaged $4.32M, against $5.65M for slower ones. Each control's saving is IBM's measured drop in average cost for that factor. IBM measures them one at a time, so the combined saving is probably a little lower than shown.
Unanswered and “Not sure” questions widen the range instead of assuming the worst. Every range also carries ±15%, because an average hides a lot of variation.
Cyber insurance isn't included: it moves the cost of a breach to your insurer rather than making the breach cheaper.