The following document outlines the detailed methodology, technical assumptions, and legal frameworks utilized by the Risk Calculator's analytical engine. The tool provides rigorous estimates based on European Union directives and IT industry standards regarding Disaster Recovery (DR) procedures during ransomware attacks.
Downtime costs are calculated based on the time required to restore business continuity. Depending on the chosen backup strategy, this time scales linearly or exponentially.
The calculator retrieves the organization's total, global gross turnover and applies the maximum percentage thresholds stipulated by EU law in the event of a successful attack and operational paralysis.
NIS2 Directive (Art. 34): For Essential Entities, fines can reach up to €10,000,000 or up to 2% of the total global annual turnover of the preceding financial year (whichever is higher). For Important Entities, up to €7,000,000 or up to 1.4%.
GDPR: For severe personal data (PII) breaches resulting from an attack, fines can amount to €20,000,000 or up to 4% of total global annual turnover.
DORA (Financial & ICT sectors): Penalties for the disruption of critical ICT operations and lack of digital operational resilience.
Even without an actual hacker attack, organizations are subject to supervisory inspections. Fines in the 'Audit Failure' section are levied simply for lacking a documented, effective, and tested DR plan.
Estimation Model: We estimate that failing a routine audit (e.g., inability to prove rapid server recovery from a test environment to an inspector) results in a fine amounting to 15% to 20% of the maximum theoretical penalty threshold.
CIS / ISO 27001 Sanctions: Besides statutory fines, lacking verifiable DR procedures leads to the loss of ISO certification, directly resulting in SLA breaches and contractual penalties.
The calculator reflects a minimized or €0 (Full Compliance) penalty risk for advanced DR solutions because the system:
Legal Note: This tool is for educational and analytical purposes. Final penalty amounts are determined individually by the respective supervisory authorities in EU Member States following administrative proceedings.