Calculation Methodology & Legal Framework – NIS2, DORA, and GDPR Risk Calculator

The following document outlines the detailed methodology, technical assumptions, and legal frameworks utilized by the Risk Calculator's analytical engine. The tool provides rigorous estimates based on European Union directives and IT industry standards regarding Disaster Recovery (DR) procedures during ransomware attacks.

1. Recovery Time Objective (RTO)

Downtime costs are calculated based on the time required to restore business continuity. Depending on the chosen backup strategy, this time scales linearly or exponentially.

  • File BackupFile Backup: Assumes a fixed base of 96 hours (securing forensic evidence, reinstalling clean OS, patch management) + 24 hours per additional server. File backups cannot restore encrypted OS from scratch.
  • Block Backup (VM)Block Backup (Standard VM Images): Assumes a base of 24 hours + 4 hours per additional server. This stems from physical network bottleneck limits and hypervisor array I/O constraints during massive, parallel VM recovery.
  • Modern DR (Instant Mount)Modern Immutable DR: Assumes a base of 15 minutes + 5 minutes per additional server. Such rapid recovery is achieved through iSCSI Instant Mount technology. We eliminate the need to copy data over the network—machines boot instantly, directly from the immutable backup repository.

RTO Comparison (5 Servers)

File Backup216h
Block Backup44h
Modern DR (Instant Mount)0.6h

2. Maximum Regulatory Fine Thresholds (Incident & Breach)

The calculator retrieves the organization's total, global gross turnover and applies the maximum percentage thresholds stipulated by EU law in the event of a successful attack and operational paralysis.

NIS2

NIS2 Directive (Art. 34): For Essential Entities, fines can reach up to €10,000,000 or up to 2% of the total global annual turnover of the preceding financial year (whichever is higher). For Important Entities, up to €7,000,000 or up to 1.4%.

GDPR / RODO

GDPR: For severe personal data (PII) breaches resulting from an attack, fines can amount to €20,000,000 or up to 4% of total global annual turnover.

DORA

DORA (Financial & ICT sectors): Penalties for the disruption of critical ICT operations and lack of digital operational resilience.

3. Risk of Failing a Routine Audit (No Incident)

Even without an actual hacker attack, organizations are subject to supervisory inspections. Fines in the 'Audit Failure' section are levied simply for lacking a documented, effective, and tested DR plan.

Estimation Model: We estimate that failing a routine audit (e.g., inability to prove rapid server recovery from a test environment to an inspector) results in a fine amounting to 15% to 20% of the maximum theoretical penalty threshold.

CIS / ISO 27001 Sanctions: Besides statutory fines, lacking verifiable DR procedures leads to the loss of ISO certification, directly resulting in SLA breaches and contractual penalties.

4. Why Modern DR Minimizes This Risk ('Defensible' Clause)

The calculator reflects a minimized or €0 (Full Compliance) penalty risk for advanced DR solutions because the system:

  • Ensures procedure auditability via cryptographic logs.
  • Protects backups with post-quantum algorithms (ML-KEM / FIPS 203), proving Due Diligence.
  • Guarantees recovery testing compliant with DORA requirements (resilience proven on demand).

Legal Note: This tool is for educational and analytical purposes. Final penalty amounts are determined individually by the respective supervisory authorities in EU Member States following administrative proceedings.