Risk & Savings CalculatorThe chainThe detailEvidencePartners

Partner tools · Exposure & savings

How many files can they never take back?

SuperFile exposure & savings summary

Start with headcount and follow it through to the money. The average U.S. data breach now costs $10.22 million — but the real question is how many sensitive documents are already outside anyone's control, and what it is worth to get them back.

Size band
    Sensitive files outside their control every one a permanent liability until it can be revoked

    What SuperFile costs them

    “Best value” is simply whichever plan leaves the most money behind, and on savings alone that is usually the cheapest one that does the job. Higher tiers are bought for capability this model does not price — MAP view to see every copy, the full share-and-unshare record, single sign-on, and the admin control a security review will insist on. Sell those on the requirement, not on this number.

    What they save every year

    Illustrative. Anchored on IBM Cost of a Data Breach 2025; size bands are an exposure model, not IBM figures.

    Where these numbers come from

    One hard anchor, and an exposure model built on top of it. Both are labelled so nobody has to guess which is which.

    Checked against the IBM 2025 U.S. average of $10.22M.

    What a breach costs

    PublishedIBM Cost of a Data Breach 2025
    $10.22M
    U.S. average — an all-time high

    The average cost of a breach at a U.S. organisation, and the reasonableness check this calculator measures itself against.

    IBM 2025
    $7.42M
    Healthcare

    The most expensive sector, year after year. Loaded by the Healthcare profile.

    IBM 2025
    $4.44M
    Global average

    All industries worldwide — well under the U.S. figure. For non-U.S. organisations, not as a discount on a U.S. one.

    IBM 2025
    What $10.22M does and does not cover.

    It is the cost of handling an incident: detection and escalation, response, business interruption, lost customers, regulatory penalties, legal expenses, notification and recovery. It is not what the escaped documents are worth for the rest of their life. A file that leaves without control keeps costing after the incident closes — copied, resold, re-leaked, produced in litigation years later. That gap is what persistent control and revocation address, and this calculator does not attempt to price it. Every number here is the conservative one.

    Why the reduction is high: taking the files is not the same as having them.

    Most of what makes a breach expensive is triggered by data being usable — notification, credit monitoring, regulatory response, litigation. Nearly every U.S. state breach-notification statute carries an encryption safe harbour: data that cannot be read, where the key was not taken with it, generally is not a reportable breach. A SuperFile that leaves the building opens for nobody, and can be revoked afterwards. That is why the default credits SuperFile with stopping most of the document-driven cost rather than a token share.

    What it still does not stop, and why the figure is not 100%: an attacker inside an authorised user's live session, screenshots and photographs of an open document, sensitive data living somewhere other than a file, and everything non-document — ransomware downtime, wire fraud, credential theft. Safe-harbour wording also varies by state and by regulator. Lower the number for any organisation where those routes dominate.

    When it goes badly

    Stress caseCompany filings & regulators
    $2.2B
    UnitedHealth · Change Healthcare

    2024 direct-response costs — loans, network restoration, notifications and increased care expenditure. A mega-event: stress-test with it, never base-case with it.

    UnitedHealth 10-K
    $575M
    Equifax settlement

    2019 minimum global settlement with the FTC, CFPB and states; the potential maximum reached $700M with up to $425M for consumer relief.

    FTC / CFPB
    $40M
    CNA Financial ransomware

    2021 reported ransom payment — and a cost SuperFile would not prevent, which is what the document-only credit exists to keep honest.

    SEC statement

    How to argue with this. Three numbers decide everything: files per employee, the share that are sensitive, and the share caught in one breach. If a prospect thinks 5,000 files a head is high, halve it — the chain updates and the worth-up-to figure moves with it. Knowing where that line sits is worth more in the room than a big number nobody believes.