U.S. average — an all-time high
The average cost of a breach at a U.S. organisation, and the reasonableness check this calculator measures itself against.
IBM 2025 ›Partner tools · Exposure & savings
SuperFile exposure & savings summary
Start with headcount and follow it through to the money. The average U.S. data breach now costs $10.22 million — but the real question is how many sensitive documents are already outside anyone's control, and what it is worth to get them back.
—
“Best value” is simply whichever plan leaves the most money behind, and on savings alone that is usually the cheapest one that does the job. Higher tiers are bought for capability this model does not price — MAP view to see every copy, the full share-and-unshare record, single sign-on, and the admin control a security review will insist on. Sell those on the requirement, not on this number.
—
Illustrative. Anchored on IBM Cost of a Data Breach 2025; size bands are an exposure model, not IBM figures.
Change anything here and the chain above moves. Replace them with the organisation's own data before anyone signs anything.
How the document estate is sized. Nobody counts their files, so these are the two numbers worth arguing about first.
One breach does not expose the whole estate — this is the bridge between a file count and a credible loss. And files taken as SuperFiles cannot be opened, so most of what is left never becomes a reportable incident at all.
The exposure a breach model never counts: files that have already left over the years and cannot be recalled. Only SuperFile can pull these back — this is the part of the value nothing else on the market addresses.
Every departure takes copies with it — the deck on a laptop, the folder in personal cloud, the attachments in a personal inbox. Off-boarding closes the account; it has never closed the documents. Revocation does, and single sign-on is what makes it instant.
Documents that go to counsel, auditors, vendors and clients every year and simply stay there — readable long after the engagement ends. This is the supply-chain half of document exposure, and nothing else recalls it either.
The common ones — a file to the wrong address, a link left open, someone who left and kept a copy.
Proving control of documents to an auditor, producing them for a legal matter, and standing in front of a regulator. Fixed per organisation rather than per seat — a 250-person regulated business carries nearly what a 2,000-person one does. Enforcement here means a finding without a breach (a failed audit, a missing control); the fines that follow an incident are already inside the per-record cost above, and counting them twice is the easiest way to lose an argument with a CFO.
A commercial segmentation for conversation, not a published finding. IBM does not say headcount equals breach cost — these ranges are an exposure model. The one hard anchor is the $10.22M U.S. average.
Yearly return at each price and breach probability. Your inputs are outlined — anything green sits inside what their own numbers support.
Priced above their case · Breaks even · Saves money
Illustrative, in USD, on an expected-value basis. SuperFile is credited only with document exposure — it does not claim to stop ransomware downtime, wire fraud or credential theft.
One hard anchor, and an exposure model built on top of it. Both are labelled so nobody has to guess which is which.
The average cost of a breach at a U.S. organisation, and the reasonableness check this calculator measures itself against.
IBM 2025 ›The most expensive sector, year after year. Loaded by the Healthcare profile.
IBM 2025 ›All industries worldwide — well under the U.S. figure. For non-U.S. organisations, not as a discount on a U.S. one.
IBM 2025 ›It is the cost of handling an incident: detection and escalation, response, business interruption, lost customers, regulatory penalties, legal expenses, notification and recovery. It is not what the escaped documents are worth for the rest of their life. A file that leaves without control keeps costing after the incident closes — copied, resold, re-leaked, produced in litigation years later. That gap is what persistent control and revocation address, and this calculator does not attempt to price it. Every number here is the conservative one.
Most of what makes a breach expensive is triggered by data being usable — notification, credit monitoring, regulatory response, litigation. Nearly every U.S. state breach-notification statute carries an encryption safe harbour: data that cannot be read, where the key was not taken with it, generally is not a reportable breach. A SuperFile that leaves the building opens for nobody, and can be revoked afterwards. That is why the default credits SuperFile with stopping most of the document-driven cost rather than a token share.
What it still does not stop, and why the figure is not 100%: an attacker inside an authorised user's live session, screenshots and photographs of an open document, sensitive data living somewhere other than a file, and everything non-document — ransomware downtime, wire fraud, credential theft. Safe-harbour wording also varies by state and by regulator. Lower the number for any organisation where those routes dominate.
2024 direct-response costs — loans, network restoration, notifications and increased care expenditure. A mega-event: stress-test with it, never base-case with it.
UnitedHealth 10-K ›2019 minimum global settlement with the FTC, CFPB and states; the potential maximum reached $700M with up to $425M for consumer relief.
FTC / CFPB ›2021 reported ransom payment — and a cost SuperFile would not prevent, which is what the document-only credit exists to keep honest.
SEC statement ›How to argue with this. Three numbers decide everything: files per employee, the share that are sensitive, and the share caught in one breach. If a prospect thinks 5,000 files a head is high, halve it — the chain updates and the worth-up-to figure moves with it. Knowing where that line sits is worth more in the room than a big number nobody believes.
We use cookies and similar technologies to improve your experience and to understand our marketing efforts. We may share data with ad partners. Opt out of this sharing via cookie settings or by configuring the GPC signal for this browser. To learn more, visit our Privacy Policy.
We use cookies and similar technologies for various purposes, including ensuring that you get the best experience on our website, to help us understand our marketing efforts, and to reach potential customers across the web. Because we respect your right to privacy, you can choose not to allow some of these technologies which are not strictly necessary. Click on the different category headings to find out more and change our default settings. Please note that blocking certain technologies may impact your experience of the site and the services we are able to offer. See more information in our Privacy Policy.