Resources
Simulator Journal Glossary Extensions Trust Service status ContactChange language
Rare events eventually happen. This simulator estimates, from a profile you enter on this page, the statistical probability that a secret leak will affect your organisation at one year, five years, ten years, and thirty years (a career).
No profiles saved yet · be the first.
The entire calculation runs in your browser. No data is sent to our servers unless you explicitly click “Save my result”.
Annual probability
2,3 %
chance of a leak this year
Median horizon
14 years
until the next probable breach
| Horizon | Cumulative probability |
|---|---|
| Over 1 year | 2,3 % |
| Over 5 years | 11 % |
| Over 10 years | 21 % |
| Over 30 years (career) | 50 % |
Warning:
Download your PDF report or anonymously save your profile to contribute to aggregated statistics.
This page details the coefficients used, sources and limitations of the actuarial model. Everything is public, reproducible and open to discussion.
The cumulative probability over N years is calculated from the independent annual probability P using the geometric distribution formula:
P_cumulative = 1 − (1 − P)^N
This formula assumes year-on-year independence · a reasonable assumption provided no incident has occurred, meaning no structural vulnerability has been revealed.
| Annual P | 5 years | 10 years | 30 years |
|---|---|---|---|
| 0,1 % | 0,5 % | 1,0 % | 3,0 % |
| 0,5 % | 2,5 % | 4,9 % | 14 % |
| 1,0 % | 4,9 % | 9,6 % | 26 % |
| 2,0 % | 9,6 % | 18 % | 45 % |
| 5,0 % | 23 % | 40 % | 79 % |
Key reading. An event with a 1% annual probability seems negligible in isolation, but represents a 26% probability over a 30-year career.
Sector baseline
Consulting & services: 2.0%. Tech & software, legal, other: 2.5%. Industry, public sector: 3.0%. Retail & e-commerce: 3.5%. Finance & banking: 4.0%. Healthcare: 4.5%. Figures smoothed over the last three editions of the Verizon DBIR, cross-referenced with average per-incident cost from IBM Cost of a Data Breach.
Size factor
Below 50 employees, the baseline is not adjusted. Beyond that, the increase is sub-linear on a decimal logarithm scale: an organisation of 1,000 people is not exposed 20× more than one of 50, but approximately 3.3×.
Hygiene multipliers
Generalised MFA: × 0.55 (approx. −45%). Password manager for entire team: × 0.65 (approx. −35%). Audit in the last 12 months: × 0.85 (approx. −15%). All three are multiplicative and therefore cumulative.
Prior incident
Incident in the last 5 years: × 1.6 (a past incident reveals an unaddressed structural vulnerability). No known incident: × 0.9. “Don't know”: × 1.05 (lack of incident awareness signals a detection gap).
Three typical profiles use this simulator in a professional context. In all three cases, the goal is to have a quantified, defensible benchmark for board meetings or auditor reviews.
Converting an annual probability into cumulative exposure over five and ten years gives the board a figure comparable to the cost of a password manager or a PASSI audit.
A data protection impact assessment requires an “incident probability” component in the risk profile. The simulator result, together with the sources and methodology published on this page, constitutes a defensible benchmark.
The simulator quantifies the exposure delta between a current state (no generalised MFA, no password manager) and a target state (all three boxes ticked).
A zero-knowledge B2B vault does not change your industry sector or team size. However, it acts on the three measurable hygiene multipliers: it shifts the annual probability by a factor of 0.3 to 0.5 on a comparable baseline.
A secrets manager eliminates password reuse between professional and personal accounts. DBIR statistics show approximately 40% fewer identity-related incidents in organisations that have deployed an enterprise password manager.
Emails, Slack, shared notes, CSV files · every cleartext transmission of a secret is an untracked exfiltration vector. A B2B vault replaces these flows with client-side encrypted sharing (zero-knowledge), with instant revocation and access logging.
Every access to a secret is sealed by HMAC-SHA-256 in an audit chain you can independently verify via a public CLI command · without relying on a proprietary binary.
The four following reports form the calibration dataset. All are public, annual and downloadable from their respective publishers.
Assumed limits. This simulator is an order of magnitude, not an audit. It gives you a benchmark to decide whether a review of your secrets management is worthwhile. For a formal, documented audit of your architecture, consult an ANSSI-listed PASSI provider. ARDNTECH EI cannot be held liable for any decision made solely on the basis of this tool.
The most frequently asked questions about how the simulator works, data privacy and the meaning of the probabilities produced.
No, unless you explicitly click “Save my result”. The entire calculation runs in your browser via a public Stimulus controller. No network call is triggered by simply moving the sliders or changing the checkboxes.
The sector baseline coefficients come from the Verizon DBIR smoothed over three editions. The hygiene multipliers (MFA, password manager, annual audit) are calibrated from the same report's “controls effectiveness” appendix, cross-referenced with IBM Cost of a Data Breach data. Details are published in the Methodology section of this page.
The PDF report is generated on demand server-side, streamed in response to your button click, and is neither stored nor indexed on the server. The HTTP header {Content-Disposition: attachment} forces direct download. You receive a self-contained PDF you can keep, share or attach to a risk dossier.
30 years is the span of a professional career. It is the timeframe that makes actuarial propagation of an annual risk tangible: an event with a 2% annual probability reaches 45% cumulative probability over 30 years · a figure that resonates with a board of directors where “2% this year” remains abstract.
Choose the sector closest in terms of attack surface and attacker targeting. A cybersecurity consultancy would choose “Consulting / services”. A fintech is better represented by “Finance / banking” than “Tech / software”.
No, they serve different purposes. This simulator produces a statistical order of magnitude in seconds, without access to your information system. An ANSSI-listed PASSI audit produces a factual, documented assessment of your actual architecture, configurations and processes. The simulator may justify commissioning an audit; it does not replace one.
Only in anonymised form: headcount bracket (bucket “2–10”, “11–50”, etc.), normalised sector from the nine available, three hygiene booleans, incident history and the calculated result. No IP address, user agent or session identifier is retained.
As profiles are anonymised at source, there is no identifier that would allow us to locate yours among the aggregated data. If you wish to have the file containing your contribution deleted, contact us via the contact page: we will delete the corresponding JSONL file within 72 hours.
Go deeper into each lever mentioned in the methodology: zero-knowledge architecture, HMAC audit chain, jurisdictional sovereignty, target sectors.
For organisations seeking a vault hosted in mainland France, operated by a French-law company, with no American subcontractor in the data path.
Read the pageHMAC-SHA-256 sealing of every event in an audit chain independently verifiable via the CLI · without relying on a proprietary binary.
Read the pageWhy a vault hosted in France, with French capital, structurally escapes extra-European CLOUD Act requisitions.
Read the pageDetailed cryptographic choices: OpenPGP.js v6, Argon2id (RFC 9106), AES-256-GCM SEIPDv2, HMAC-SHA-256 RFC 2104. For CISOs and PASSI auditors.
Read the pageFive B2B sectors prioritised: cybersecurity consulting, tech law firms, HDS healthcare, defence, energy and OIV. Each with its specific regulatory requirements.
Read the pageFree for life up to 3 users, Team plan at €4/seat/month, Business plan at €7/seat/month with 99.5% SLA, Enterprise on request.
Read the pageYou now have a quantified estimate of your exposure. The next step is to deploy the only lever that shifts probability by 35 to 65% on measured vectors: a zero-knowledge B2B vault, hosted in France, auditable by your CISO.