Sefri-Cime lost it in December 2021. FACC AG lost €42M in 2016. Arup lost $25M USD in 2024. Estimate in 60 seconds your exposure to Business Email Compromise (BEC) / CEO fraud — annual probability and total expected cost (amount diverted + forensics + legal + crisis communication; reputation excluded, not quantifiable), with a public, auditable methodology.
Every coefficient comes from a public source. The full XLSX workbook can be downloaded at the bottom of the page. No data is sent to any server: the entire calculation runs in your browser.
Reproducible and auditable. The model was submitted to an adversarial audit via Perplexity Sonar-Reasoning-Pro. Initial score 3/10 → defensible after 8 documented corrections. Every coefficient has a public source.
P_attempt × P_success × attempts_year × (1 - recovery) × loss_per_incident — capped at the IC3 95th percentile (revenue × 8%).
Calibrated on 21 international cases + 7 French cases (Sefri-Cime €38M, Etna, Forges de Courcelles, Pathé NL, Saône-et-Loire, Ploudaniel, Le Cerf & Bachelet).
MFA factor 0.3 → 0.5 (Beazley: ~50% bypass). Base success 0.12 → 0.035 (IC3 / universe × underreporting). Revenue × 8% cap documented (IC3 p95).
Direct EAL + uninsurable net loss (deductible, sublimit, exclusion) + BEC-specific remediation (€7k-130k) + qualitative risks (reputation, HR, legal).
Verifiable quantitative claims (public XLSX), no overstatement (80% interval), no concealment (unmodeled factors listed). GDPR: no personal data is processed by the calculation.
Art. L.561-15 Monetary and Financial Code (Tracfin via bank), art. 314-1 (breach of trust — intent required), art. 62-2 Code of Criminal Procedure (conditional police custody), L225-251 Commercial Code, MAR Art. 17, AMF General Regulation 223-2.
These figures are not used in your calculation — they situate BEC within your sector's broader cyber landscape. Scale: mid-market organization (200 – 2,000 employees) in France.
3 to 5 people in the company are high-value targets: CFO, treasurer, CEO, head of payments. Attackers research them (LinkedIn, press releases, company registries) and probe continuously — monthly to weekly attempts, all year round. No malware, no network access — the attack arrives by email, phone, or video call (deepfake).
Any employee can be the entry point (a click on an attachment, an exposed RDP port, a VPN flaw). The attack then compromises the entire network: lateral movement, encryption, exfiltration. When it happens — often just once in the company's lifetime — it's a catastrophic event that halts operations.
| Sector | BEC — prob/year | BEC — median loss | Ransomware — prob/year | Ransomware — total cost | RW / BEC cost ratio |
|---|---|---|---|---|---|
| Construction / Real Estate | 5 – 8% | €100k – 200k | 10 – 18% | €1M – 4M | ≈ 20 × |
| Manufacturing | 4 – 7% | €80k – 150k | 15 – 25% | €2M – 5M | ≈ 30 × |
| Professional services | 4 – 6% | €60k – 130k | 10 – 18% | €2M – 5M | ≈ 30 × |
| Healthcare | 3 – 5% | €60k – 120k | 15 – 25% | €4M – 10M | ≈ 60 × |
| Finance / Insurance | 4 – 6% | €100k – 200k | 8 – 15% | €3M – 6M | ≈ 30 × |
| Tech / Digital | 3 – 5% | €50k – 110k | 8 – 15% | €2M – 5M | ≈ 30 × |
| Commerce / Retail | 4 – 6% | €50k – 110k | 8 – 15% | €1M – 3M | ≈ 20 × |
| Public sector / Local government | 3 – 5% | €60k – 120k | 10 – 20% | €1M – 3M | ≈ 20 × |
14-BEC-vs-Ransomware of the XLSX workbook.
Everything is public. An auditor, a journalist, or a competitor can fully reproduce this model. We commit to correcting any documented discrepancy within 7 days via methodologie@inkan.link.
Each question had to meet 3 criteria: measurable differential signal (±30% on the EAL), answerable in < 10s, and at least one public institutional source validating the factor. Noisier signals (anti-phishing training, cyber insurance, security budget) were excluded for lack of quantifiable evidence.
No. The entire calculation runs in your browser (client-side JavaScript). No information is transmitted to Inkan.link or any third party. No cookies are set.
Because a precise estimate would be a misleading commercial claim (UCPD). Propagating uncertainty across the coefficients yields an 80% confidence interval of ±50% to ±100% on the EAL. It's an order of magnitude, not a prediction.
Because BEC is a social engineering fraud with minimal technical footprint. Arup's CIO (Hong Kong, $25M USD, 2024) publicly stated "no systems compromised." The €700k ranges sometimes cited correspond to ransomware IR engagements (network mapping, enterprise EDR, AD rebuild). For a typical BEC: DMARC + MFA + training = €2k-25k, not €500k.
Police custody is not automatic for a BEC victim. The standard French procedure (art. 61-1 Code of Criminal Procedure) is a voluntary interview (audition libre). Police custody (art. 62-2 Code of Criminal Procedure) is only possible in cases of suspected internal complicity, production of falsified documents, or violation of specific obligations. Article 314-5 of the Penal Code, sometimes cited, does not exist; the actual basis for breach of trust is article 314-1, which requires intent to misappropriate (not mere negligence).
All coefficients are in the XLSX workbook, sheet 3-Coefficients and 4-Base-Rates. Every cell has a source URL in sheet 6-Sources. Any discrepancy with our calculation is a bug, not an opinion — we correct it within 7 days.
Contact: methodologie@inkan.link. Send us the disputed XLSX cell along with an alternative public source. We publish the correction (or the reason for keeping it as-is) in a public CHANGELOG within 7 days.