← Back

How “Valuation at Risk” is calculated

A plain-English account of the figure, how it is built, and — stated up front — what it can and cannot tell you.

What the number is

A conditional figure: if this company suffers a disclosed material breach, this is the equity value we would expect to be at risk — moved up or down by the company’s own findings. It is shown as a range, not a single point.

What it is not

  • Not a certain annual loss (“your cyber cost is £N”).
  • Not based on an invented breach probability — we never fabricate a frequency.
  • Not a permanent-loss claim — it is a short-window market repricing (see limits below).
  • Not an audited or actuarially signed-off valuation.

How it is built

The £ is computed deterministically by code — not by an AI — from four inputs, each labelled by where it came from:

VaR = measured repricing (CAR) × your valuation × data-sensitivity × exposure-from-your-scans, then an optional analyst overlay

  • Measured repricing (CAR): from a real event-study of 110 disclosed breaches (102 measurable). Disclosed breaches cost public firms about −2.7% of market value on average — statistically robust (p≈0.0008) and survives clustering, calendar-time and sector-matched controls. An empirical market reaction — not the FAIR framework, and not a per-record cost model.
  • Exposure from your scans (Observed): the findings set a bounded tilt (±20%) — a nudge on the headline, never an invented magnitude.
  • Analyst overlay (disclosed): the PE-calibration sliders re-weight the headline within a bounded range, shown as its own line with the measured basis kept separate.

Every figure is labelled by where it came from

MEASUREDEstimated from real, disclosed breaches (our event-study corpus).
OBSERVEDA fact about this company, taken from its own scan.
LITERATUREA published external estimate we adopt (e.g. the data-sensitivity multiplier).
ANALYSTA judgment the analyst owns and discloses (e.g. the PE-calibration overlay).
USER-SUPPLIEDA value you provide (e.g. the declared valuation).
DERIVEDA deterministic combination of the above — it carries the weakest input’s tier.

Separately, a figure’s confidence is marked MEASURED (a well-populated comparable cell) or EXPLORATORY (a small comparable sample — read it as a wide band). Most mid-market companies land in an EXPLORATORY cell today.

Model-risk disclosures

  • The market reaction is a short-window repricing (≈53-day recovery, ≈3% six-month drift) — not proven permanent destruction; about 30% of corpus events had a positive reaction.
  • The corpus is small and self-selected — skewed toward large US public firms and severe, well-known incidents (an upward severity bias).
  • For private companies the market reaction is transported from public comparables — an assumption, carried with a widened band and always labelled.
  • Per-industry precision is coarse at this sample size; thin cells shrink toward the global anchor.
  • There is no per-event predictive skill — the aggregate effect is real, but a single company’s outcome is not forecastable. That is why we show a band, never a confident point.

Conditional “if breached” · calibration elm-cal-1 · indicative, not an audited assessment.