← Back to Tools
Security Breach Probability Model
Assess the statistical likelihood of a successful ransomware deployment within a 12-month window based on current technical controls.
Interactive Model
0
100
0
365
Probability of Breach (%)
Model Assumptions: Model weights MFA enforcement heavily (80% of risk profile). Lack of tested backups increases probability due to inability to recover from minor localized infections.
Common Mistakes
Assuming that because the firm uses a 'cloud' document portal, local infrastructure is immune to credential-based attacks.
Frequently Asked Questions
Why is MFA enforcement weighted so heavily?
Stolen credentials are the primary initial access vector for 85% of CPA firm breaches. If MFA is bypassed for legacy VPNs or executive accounts, the perimeter is functionally open.
Does cybersecurity insurance lower this probability?
No. Insurance mitigates financial loss; it does not prevent the technical execution of a breach.