← Back How “Valuation at Risk” is calculated
A plain-English account of the figure, how it is built, and — stated up front — what it can
and cannot tell you.
What the number is
A conditional figure: if this company suffers a disclosed material breach, this is the equity value we would
expect to be at risk — moved up or down by the company’s own findings. It is shown as a range, not
a single point.
What it is not
- Not a certain annual loss (“your cyber cost is £N”).
- Not based on an invented breach probability — we never fabricate a frequency.
- Not a permanent-loss claim — it is a short-window market repricing (see limits below).
- Not an audited or actuarially signed-off valuation.
How it is built
The £ is computed deterministically by code — not by an AI — from four inputs, each labelled
by where it came from:
VaR = measured repricing (CAR) × your valuation × data-sensitivity × exposure-from-your-scans,
then an optional analyst overlay
- Measured repricing (CAR): from a real event-study of 110 disclosed breaches (102 measurable). Disclosed breaches cost public
firms about −2.7% of market value on average — statistically robust
(p≈0.0008) and survives clustering, calendar-time and sector-matched controls. An empirical market reaction — not the FAIR framework, and not a per-record cost model.
- Exposure from your scans (Observed): the findings set a bounded tilt (±20%) —
a nudge on the headline, never an invented magnitude.
- Analyst overlay (disclosed): the PE-calibration sliders re-weight the headline
within a bounded range, shown as its own line with the measured basis kept separate.
Every figure is labelled by where it came from
| MEASURED | Estimated from real, disclosed breaches (our event-study corpus). |
| OBSERVED | A fact about this company, taken from its own scan. |
| LITERATURE | A published external estimate we adopt (e.g. the data-sensitivity multiplier). |
| ANALYST | A judgment the analyst owns and discloses (e.g. the PE-calibration overlay). |
| USER-SUPPLIED | A value you provide (e.g. the declared valuation). |
| DERIVED | A deterministic combination of the above — it carries the weakest input’s tier. |
Separately, a figure’s confidence is marked MEASURED (a well-populated comparable cell) or EXPLORATORY (a small comparable sample — read it as a wide band).
Most mid-market companies land in an EXPLORATORY cell today.
Model-risk disclosures
- The market reaction is a short-window repricing (≈53-day recovery, ≈3% six-month
drift) — not proven permanent destruction; about 30% of corpus events had a positive reaction.
- The corpus is small and self-selected — skewed toward large US public firms and
severe, well-known incidents (an upward severity bias).
- For private companies the market reaction is transported from public
comparables — an assumption, carried with a widened band and always labelled.
- Per-industry precision is coarse at this sample size; thin cells shrink toward
the global anchor.
- There is no per-event predictive skill — the aggregate effect is real, but a
single company’s outcome is not forecastable. That is why we show a band, never a confident point.
Conditional “if breached” · calibration elm-cal-1 · indicative, not an audited assessment.