Skip to main content
← Back to Tools

Security Breach Probability Model

Assess the statistical likelihood of a successful ransomware deployment within a 12-month window based on current technical controls.

Interactive Model

0 100
0 365
Probability of Breach (%)

Model Assumptions: Model weights MFA enforcement heavily (80% of risk profile). Lack of tested backups increases probability due to inability to recover from minor localized infections.

Common Mistakes

Assuming that because the firm uses a 'cloud' document portal, local infrastructure is immune to credential-based attacks.

Frequently Asked Questions

Why is MFA enforcement weighted so heavily?

Stolen credentials are the primary initial access vector for 85% of CPA firm breaches. If MFA is bypassed for legacy VPNs or executive accounts, the perimeter is functionally open.

Does cybersecurity insurance lower this probability?

No. Insurance mitigates financial loss; it does not prevent the technical execution of a breach.